Skip to content

Upgrade dependencies and fix security vulnerabilities#210

Merged
krzysztofreczek merged 1 commit intomasterfrom
upgrade-dependencies-security
Mar 13, 2026
Merged

Upgrade dependencies and fix security vulnerabilities#210
krzysztofreczek merged 1 commit intomasterfrom
upgrade-dependencies-security

Conversation

@krzysztofreczek
Copy link
Copy Markdown
Owner

Fixes two high severity Dependabot alerts (CVE in go.opentelemetry.io/otel/sdk — arbitrary code execution via PATH hijacking, fixed in v1.40.0) and upgrades a broad set of transitive dependencies in cmd/example and cmd/example-yaml, including golang.org/x/crypto, golang.org/x/net, google.golang.org/grpc, github.com/klauspost/compress, and others. The OpenTelemetry Collector packages are intentionally held at their current versions due to a compatibility constraint with jaeger v1.76.0.

Fixes high severity CVE in go.opentelemetry.io/otel/sdk (PATH hijacking, fixed in v1.40.0) and upgrades related packages including golang.org/x/crypto, golang.org/x/net, google.golang.org/grpc, and other transitive dependencies in cmd/example and cmd/example-yaml modules.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@krzysztofreczek krzysztofreczek merged commit c55e3f2 into master Mar 13, 2026
7 checks passed
@krzysztofreczek krzysztofreczek deleted the upgrade-dependencies-security branch March 13, 2026 15:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant