Navigation

    Inedo Community Forums

    Forums

    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    1. Home
    2. devops_8569
    3. Posts
    D
    • Profile
    • Following
    • Followers
    • Topics
    • Posts
    • Best
    • Groups

    Posts made by devops_8569

    • Version matching / sorting fails for maven with string suffix

      Hi,
      for Versions, that have a string suffix, like "2.3.23.Final" the vulnerability matching doesn't work. Most probably the root cause is the failing sort. Regarding the improper sort, see attached screenshot.
      Example regarding vulnerability matching:
      PGV: https://security.inedo.com/vulnerability/details/PGV-2314320
      io.undertow:undertow-core ≥ 2.3.0 & < 2.3.5.Final, < 2.2.24.Final
      but even versions > 2.3.5.Final are still marked with severe (like the 2.3.23.Final).

      image (1).png

      Best regards

      posted in Support
      D
      devops_8569
    • 1 / 1