chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace from 1.43.0 to 1.45.0 in /cli - #1496
Conversation
|
PR author is not in the allowed authors list. |
Bumps [go.opentelemetry.io/otel/exporters/otlp/otlptrace](https://github.com/open-telemetry/opentelemetry-go) from 1.43.0 to 1.45.0. - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.43.0...v1.45.0) --- updated-dependencies: - dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace dependency-version: 1.45.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
1d74539 to
81f013a
Compare
Capslock capability diff:
|
…o/otel/exporters/otlp/otlptrace-1.45.0
Vulnerable dependencies3 advisories across 3 libraries need attention, 2 accepted. 🚨 Needs attention
|
| Advisory | CVE | Fixed in | Summary |
|---|---|---|---|
| GO-2026-6505 | CVE-2026-81870 | v1.45.0 |
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs in go.opentelemetry.io/otel/exporters/otlp/otlptrace |
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
In use: v0.19.0 — reached from cli, e2e
| Advisory | CVE | Fixed in | Summary |
|---|---|---|---|
| GO-2026-6508 | CVE-2026-81871 | v0.21.0 |
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc |
go.opentelemetry.io/otel/sdk/log
In use: v0.19.0 — reached from cli, e2e
| Advisory | CVE | Fixed in | Summary |
|---|---|---|---|
| GO-2026-6615 | CVE-2026-81872 | v0.21.0 |
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full in go.opentelemetry.io/otel/sdk/log |
Run make vulncheck for the call paths. Either upgrade the library, or add the
advisory to .govulncheck-ignore with a reason if no fix exists yet.
Accepted
Listed in .govulncheck-ignore with a reason.
github.com/pion/dtls/v2
In use: v2.2.12 — reached from cli, e2e
| Advisory | CVE | Fixed in | Summary |
|---|---|---|---|
| GO-2026-4479 | CVE-2026-26014 | no fix yet | Usage of random nonce generation with AES GCM ciphers risks leaking the authentication key in github.com/pion/dtls |
golang.org/x/crypto
In use: v0.56.0 — reached from cli, e2e
| Advisory | CVE | Fixed in | Summary |
|---|---|---|---|
| GO-2026-5932 | — | no fix yet | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues |
From make vulncheck-json on this run: logs.
…o/otel/exporters/otlp/otlptrace-1.45.0
Bumps go.opentelemetry.io/otel/exporters/otlp/otlptrace from 1.43.0 to 1.45.0.
Release notes
Sourced from go.opentelemetry.io/otel/exporters/otlp/otlptrace's releases.
... (truncated)
Changelog
Sourced from go.opentelemetry.io/otel/exporters/otlp/otlptrace's changelog.
... (truncated)
Commits
93a693eRelease v1.45.0 (#8693)c65d435Merge commit from fork223f9fdsdk/metric: remove obsolete randomFloat64 TODO (#8685)06272bcfix(deps): update googleapis to 6ac0973 (#8694)a4f238fchore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#...37140e7chore(deps): update codspeedhq/action action to v5.0.2 (#8690)cef0855chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 (#8689)e814a72Merge commit from forkbfd8eb7chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 (#8687)48db2c6chore(deps): update github/codeql-action action to v4.37.5 (#8692)