Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-5927

[ClairCore] Can't parse Ruby version from vuln in matcher

XMLWordPrintable

    • Rox Sprint 4.4B - Global

      Ruby versions are weird and don't conform to server. This is an issue for the Ruby matcher which currently throws errors on versions like "6.0.3.1". We need to be able to parse and compare these versions that aren't semver.

      https://github.com/quay/claircore/blob/main/ruby/matcher.go#L64

      7:09PM WRN unable to parse ruby vulnerability 'fixed version' or 'last affected' component=internal/matcher/Controller.Match matcher=ruby package=railties request_id=83681190a47a8a20 version=5.2.2.1 vulnerability=GHSA-m42h-mh85-4qgc

              rtannenb@redhat.com Ross Tannenbaum
              jcroslan@redhat.com Joseph Crosland
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: