The Snyk security team creates the patch usually by backporting a fix which has been added to the dependency. Backporting is the action of taking a fix that was built for a particular version of a piece of software, and applying it to a previous version of that software, by updating it to be functionally identical but with the fix for the vulnerability applied. For more information take a look at Red Hat's description https://access.redhat.com/security/updates/backporting
Articles in this section
- Cannot create a Fix PR
- Can patching break my code?
- Failed to detect issues
- Failed to update the yarn.lock, please update manually before merging.
- Fixed in version vs. fixable attribute in vulnerabilities
- How are Snyk patches created?
- How are Snyk patches tested?
- Is it possible that a fix pull request could introduce new vulnerabilities?
- Snyk changed the "resolved" URLs in my lockfile
- What can I do if I my scan reports vulnerabilities?