Title
#core
mark

mark

02/08/2019, 10:55 PM
I noticed that osquery's code for retrieving a file's version number on windows is actually accessing the VS_FIXEDFILEINFO's
dwProductVersion*
fields rather than the
dwFileVersion*
fields, just wondering if there was any story behind this? https://github.com/facebook/osquery/blob/992d2d3396aa13ca42cc775fcfae2af5cd008d29/osquery/filesystem/windows/fileops.cpp#L137-L140 https://docs.microsoft.com/en-us/windows/desktop/api/verrsrc/ns-verrsrc-tagvs_fixedfileinfo
3:55 PM
hey @ryanheffernan , i noticed that it looks like you authored this code in PR 3436 -- any chance you might be able to help me understand this? 🙂