allow manually tagging of known vulnerabilities
There is the "KnownVuln" Anti-Feature which is available both for the whole app, and for each APK. This is based on automated scans of the APK. There should also be a way to manually tag Anti-Features per-APK, for cases like the OpenVPN vulns that were recently found. The quick way to do this is to just add antifeatures=
as a build flag, i.e.:
Build:0.6.63,144
commit=v0.6.63-production
subdir=main
submodules=yes
gradle=normal
scandelete=main/breakpad
build=USE_BREAKPAD=0 ./misc/build-native.sh
antifeatures=KnownVuln