Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-5927

[ClairCore] Can't parse Ruby version from vuln in matcher

XMLWordPrintable

    • Rox Sprint 4.4B - Global
    • 0

      Ruby versions are weird and don't conform to server. This is an issue for the Ruby matcher which currently throws errors on versions like "6.0.3.1". We need to be able to parse and compare these versions that aren't semver.

      https://github.com/quay/claircore/blob/main/ruby/matcher.go#L64

      7:09PM WRN unable to parse ruby vulnerability 'fixed version' or 'last affected' component=internal/matcher/Controller.Match matcher=ruby package=railties request_id=83681190a47a8a20 version=5.2.2.1 vulnerability=GHSA-m42h-mh85-4qgc

            rtannenb@redhat.com Ross Tannenbaum
            jcroslan@redhat.com Joseph Crosland
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: