Skip to content

Commit bd14ea3

Browse files
committed
fix(yarn): protect against exotic version number of yarn (#7488)
1 parent cbc874f commit bd14ea3

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

core/src/main/java/org/owasp/dependencycheck/analyzer/YarnAuditAnalyzer.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -114,7 +114,7 @@ public AnalysisPhase getAnalysisPhase() {
114114
private int getYarnMajorVersion(Dependency dependency) {
115115
var yarnVersion = getYarnVersion(dependency);
116116
try {
117-
var semver = new Semver(yarnVersion);
117+
var semver = Semver.coerce(yarnVersion);
118118
return semver.getMajor();
119119
} catch (SemverException e) {
120120
throw new IllegalStateException("Invalid version string format", e);

0 commit comments

Comments
 (0)