<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Version matching &#x2F; sorting fails for maven with string suffix]]></title><description><![CDATA[<p dir="auto">Hi,<br />
for Versions, that have a string suffix, like "2.3.23.Final" the vulnerability matching doesn't work. Most probably the root cause is the failing sort. Regarding the improper sort, see attached screenshot.<br />
Example regarding vulnerability matching:<br />
PGV: <a href="https://security.inedo.com/vulnerability/details/PGV-2314320" rel="nofollow">https://security.inedo.com/vulnerability/details/PGV-2314320</a><br />
io.undertow:undertow-core ≥ 2.3.0 &amp; &lt; 2.3.5.Final, &lt; 2.2.24.Final<br />
but even versions &gt; 2.3.5.Final are still marked with severe (like the 2.3.23.Final).</p>
<p dir="auto"><img src="/assets/uploads/files/1778215716636-image-1.png" alt="image (1).png" class="img-responsive img-markdown" /></p>
<p dir="auto">Best regards</p>
]]></description><link>https://forums.inedo.com/topic/5745/version-matching-sorting-fails-for-maven-with-string-suffix</link><generator>RSS for Node</generator><lastBuildDate>Fri, 08 May 2026 11:41:26 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5745.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 May 2026 04:50:05 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Version matching &#x2F; sorting fails for maven with string suffix on Fri, 08 May 2026 04:50:05 GMT]]></title><description><![CDATA[<p dir="auto">Hi,<br />
for Versions, that have a string suffix, like "2.3.23.Final" the vulnerability matching doesn't work. Most probably the root cause is the failing sort. Regarding the improper sort, see attached screenshot.<br />
Example regarding vulnerability matching:<br />
PGV: <a href="https://security.inedo.com/vulnerability/details/PGV-2314320" rel="nofollow">https://security.inedo.com/vulnerability/details/PGV-2314320</a><br />
io.undertow:undertow-core ≥ 2.3.0 &amp; &lt; 2.3.5.Final, &lt; 2.2.24.Final<br />
but even versions &gt; 2.3.5.Final are still marked with severe (like the 2.3.23.Final).</p>
<p dir="auto"><img src="/assets/uploads/files/1778215716636-image-1.png" alt="image (1).png" class="img-responsive img-markdown" /></p>
<p dir="auto">Best regards</p>
]]></description><link>https://forums.inedo.com/post/19651</link><guid isPermaLink="true">https://forums.inedo.com/post/19651</guid><dc:creator><![CDATA[devops_8569]]></dc:creator><pubDate>Fri, 08 May 2026 04:50:05 GMT</pubDate></item></channel></rss>