# Avoiding cryptonite-verse packages in your dependency closure

**URL:** https://discourse.haskell.org/t/avoiding-cryptonite-verse-packages-in-your-dependency-closure/14526
**Category:** Uncategorized
**Created:** [August 6, 2026, 1:41pm UTC](https://discourse.haskell.org/t/avoiding-cryptonite-verse-packages-in-your-dependency-closure/14526 "2026-08-06T13:41:36Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Ambrose](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.haskell.org/ambrose/32/5672_2.png) [@Ambrose](https://discourse.haskell.org/u/Ambrose)
#### Post date: [August 6, 2026, 2:58pm UTC](https://discourse.haskell.org/t/avoiding-cryptonite-verse-packages-in-your-dependency-closure/14526/2 "2026-08-06T14:58:37Z")

</div>

So cryptonite and deps are just sitting on Hackage with vulnerabilities?

Is there a way for Hackage to mark them as bad so cabal won’t plan for them unless the user explicitly overrides it? I know it says it’s deprecated but that doesn’t feel like enough.

Feels like a pretty important feature! Given the maintainer refuses to do any maintenance but also refuses to allow people to contribute in order to fix vulnerabilities.

---

_[View the full topic](https://discourse.haskell.org/t/avoiding-cryptonite-verse-packages-in-your-dependency-closure/14526)._
