Yes, it can happen with our remediation logic. When looking for upgrade paths, our remediation checks against the vulnerabilities that were detected in the original project tree.
Articles in this section
- Snyk changed the "resolved" URL's in my Lock file
- Cannot create a Fix PR
- When I can choose, how should I decide whether to upgrade or patch?
- What if there is no upgrade or patch available?
- What is a Snyk Patch?
- What can I do if I'm vulnerable?
- Is it possible that a fix pull request could introduce new vulnerabilities?
- Can patching break my code?
- How are Snyk patches created?
- How are Snyk patches tested?