The gems have probably been updated by the developers of the gem.
The data used in the article contains a list of the versions being used in production by real app, not the latest versions released by the gem developers.
The data used in the article contains a list of the versions being used in production by real app, not the latest versions released by the gem developers.
If it's a bug in a YAML parser but you're not loading YAML from untrusted sources, then it would be a false positive.
The should be able to calculate what percentage of these would still be vulnerable if fully updated - now that would be an interesting stat!