Skip to content

Update OpenTelemetry so govulncheck passes - #78

Merged
om986 merged 1 commit into
mainfrom
fix/govulncheck-otel-sdk
Oct 2, 2026
Merged

om986 merged 1 commit into
mainfrom
fix/govulncheck-otel-sdk

Conversation

@om986

@om986 om986 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • govulncheck on main failed because go.opentelemetry.io/otel/sdk v1.44.0 is affected by GO-2026-6505 (CVE-2026-81870): exporter config logging can leak endpoint URLs.
  • The GCP storage client and the Postgres pool both reach that code, so the scan treats it as called. v1.45.0 is the fixed release. The matching OpenTelemetry API modules and go-logr/logr move with it.
  • go test ./... passes, and govulncheck no longer reports a reachable vulnerability.

Test plan

  • CI govulncheck job is green
  • CI go job (build and tests, including Postgres) is green

Made with Cursor

otel/sdk v1.44.0 can log exporter endpoint URLs, and the GCP collector plus the Postgres pool reach that code. v1.45.0 is the release that fixes GO-2026-6505.

Co-authored-by: Cursor <cursoragent@cursor.com>
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: OpenSourceOM/core/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 5063c4e3-1c47-4992-8f5b-fe52e8de8e1a

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@om986
om986 merged commit ff6791a into main Oct 2, 2026
7 checks passed
@om986
om986 deleted the fix/govulncheck-otel-sdk branch October 2, 2026 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant