Repository navigation
chore(deps): bump OpenTelemetry Go to v1.45.0 for GO-2026-6505 - #386
Open
FrameAutomata wants to merge 1 commit into
Open
FrameAutomata wants to merge 1 commit into
FrameAutomata wants to merge 1 commit into
Conversation
govulncheck has failed on main since 2026-10-02: GO-2026-6505 is reachable in go.opentelemetry.io/otel/sdk v1.44.0 on all three storage tag sets and is fixed in v1.45.0. The otel, otel/metric, otel/sdk, otel/sdk/metric and otel/trace modules move together to v1.45.0, which raises go-logr/logr to v1.4.4 and golang.org/x/sys to v0.47.0. The go and toolchain lines are unchanged. cli/test/contract builds the backend through a local replace, so its go.mod is tidied to the same versions; without that the CLI Contract job stops at "updates to go.mod needed". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Backend Vulncheckhas failed onmainsince 2026-10-02. GO-2026-6505 (exporter config logging may leak endpoint URLs in info logs) is reachable ingo.opentelemetry.io/otel/sdk@v1.44.0under all three storage tag sets and is fixed in v1.45.0. Until it is patched, the gate fails on every push tomainand on every PR that gets thecilabel, whatever the PR changes.Fix
backend/go.mod:otel,otel/metric,otel/sdk,otel/sdk/metricandotel/tracemove together to v1.45.0, which raisesgo-logr/logrto v1.4.4 andgolang.org/x/systo v0.47.0. All are indirect requirements. Thegoandtoolchainlines are unchanged.cli/test/contract/go.mod: tidied to the same versions. It builds the backend through a localreplace, and without the sync the CLI Contract job stops atupdates to go.mod needed.No source changes.
Relation to #385
#385 carries this same commit, because it could not validate green without it. The diff here is byte-identical to that commit, so the two PRs merge in either order with no conflict. Landing this one first turns
mainand the other open PRs green without waiting on #385.Not in this PR
Two sample modules still require
otel/sdkv1.44.0. No CI job builds or scans either:examples/devtesting-embeddedreplaces the backend by path and is already out of sync onmain(gRPC v1.82.1 against the backend's v1.83.1), so it does not build there today.testing/shop/backendhas its own pins.Verification
On this branch (
mainplus this commit):govulncheckreportsNo vulnerabilities foundon all three tag sets, with the CI matrix'sCGO_ENABLEDvalues. Onmainthe same command reports GO-2026-6505 with 13 example traces.go build ./...on the default build andgo vet ./...on all three tag sets are clean;go mod tidy -diffis empty forbackendandcli/test/contract.go test ./...on the default build passes (36 packages), and the CLI contract tests pass.🤖 Generated with Claude Code