Skip to content

chore(deps): bump OpenTelemetry Go to v1.45.0 for GO-2026-6505 - #386

Open
FrameAutomata wants to merge 1 commit into
mainfrom
chore/bump-otel-go-2026-6505
Open

FrameAutomata wants to merge 1 commit into
mainfrom
chore/bump-otel-go-2026-6505

Conversation

@FrameAutomata

Copy link
Copy Markdown
Collaborator

Problem

Backend Vulncheck has failed on main since 2026-10-02. GO-2026-6505 (exporter config logging may leak endpoint URLs in info logs) is reachable in go.opentelemetry.io/otel/sdk@v1.44.0 under all three storage tag sets and is fixed in v1.45.0. Until it is patched, the gate fails on every push to main and on every PR that gets the ci label, whatever the PR changes.

Fix

  • backend/go.mod: otel, otel/metric, otel/sdk, otel/sdk/metric and otel/trace move together to v1.45.0, which raises go-logr/logr to v1.4.4 and golang.org/x/sys to v0.47.0. All are indirect requirements. The go and toolchain lines are unchanged.
  • cli/test/contract/go.mod: tidied to the same versions. It builds the backend through a local replace, and without the sync the CLI Contract job stops at updates to go.mod needed.

No source changes.

Relation to #385

#385 carries this same commit, because it could not validate green without it. The diff here is byte-identical to that commit, so the two PRs merge in either order with no conflict. Landing this one first turns main and the other open PRs green without waiting on #385.

Not in this PR

Two sample modules still require otel/sdk v1.44.0. No CI job builds or scans either:

  • examples/devtesting-embedded replaces the backend by path and is already out of sync on main (gRPC v1.82.1 against the backend's v1.83.1), so it does not build there today.
  • testing/shop/backend has its own pins.

Verification

On this branch (main plus this commit):

  • govulncheck reports No vulnerabilities found on all three tag sets, with the CI matrix's CGO_ENABLED values. On main the same command reports GO-2026-6505 with 13 example traces.
  • go build ./... on the default build and go vet ./... on all three tag sets are clean; go mod tidy -diff is empty for backend and cli/test/contract.
  • Full go test ./... on the default build passes (36 packages), and the CLI contract tests pass.

🤖 Generated with Claude Code

govulncheck has failed on main since 2026-10-02: GO-2026-6505 is reachable
in go.opentelemetry.io/otel/sdk v1.44.0 on all three storage tag sets and
is fixed in v1.45.0.

The otel, otel/metric, otel/sdk, otel/sdk/metric and otel/trace modules
move together to v1.45.0, which raises go-logr/logr to v1.4.4 and
golang.org/x/sys to v0.47.0. The go and toolchain lines are unchanged.

cli/test/contract builds the backend through a local replace, so its
go.mod is tidied to the same versions; without that the CLI Contract job
stops at "updates to go.mod needed".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Run CI on this PR (remove and re-add to re-validate after a push)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant