Skip to content

Question: Snyk incorrectly flagging v1.13.6-x86_64-linux for CVE-2022-29181 #2561

Discussion options

You must be logged in to vote

Hi! Thanks for raising this, that does look confusing.

I'm not familiar with Snyk's product, so you should probably ask them this question. However my guess is that their software is confused by the native platform string -x86_64-linux in the gem name and has incorrectly identified it as something different from plain v1.13.6. However, it's not -- they are the same software, but one contains precompiled libraries and one does not.

In summary: this message appears to be in error and you should talk to your vendor about it!

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@dferdian
Comment options

Answer selected by flavorjones
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants