Skip to content

fix(deps): remediate OpenTelemetry SDK CVE-2026-81870 - #801

Closed
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/otel-sdk-cve-2026-81870-1789690000000
Closed

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/otel-sdk-cve-2026-81870-1789690000000

Conversation

@plural-copilot

Copy link
Copy Markdown
Contributor

Summary

  • Plural Service: mgmt/console
  • Affected image: ghcr.io/pluralsh/console:sha-a16b6ee
  • Remediates CVE-2026-81870 / GHSA-8wmf-6v46-5gfg.

This source finding maps to this repository because the sole github.com/pluralsh/plural-cli Go module is consumed by the repository Dockerfile, which copies go.mod/go.sum and builds ./cmd/plural for the Console image path.

Dependency changes

Updated the coherent OpenTelemetry core API/SDK family:

  • go.opentelemetry.io/otel/sdk v1.44.0 -> v1.45.0
  • go.opentelemetry.io/otel v1.44.0 -> v1.45.0
  • go.opentelemetry.io/otel/metric v1.44.0 -> v1.45.0
  • go.opentelemetry.io/otel/sdk/metric v1.44.0 -> v1.45.0
  • go.opentelemetry.io/otel/trace v1.44.0 -> v1.45.0

go mod tidy regenerated metadata and selected compatible transitive github.com/go-logr/logr v1.4.4.

Validation

Passed in golang:1.26.6-alpine3.24:

go mod tidy
git diff --check
go list -m go.opentelemetry.io/otel/sdk
# go.opentelemetry.io/otel/sdk v1.45.0

Attempted with explicit bounds but did not complete within them while downloading/compiling the large dependency graph:

timeout 3m docker run --rm -v "$PWD:/workspace" -w /workspace golang:1.26.6-alpine3.24 sh -ec 'go test ./pkg/console/...'
timeout 12m docker build --build-arg APP_VSN=otel-1.45.0 --build-arg APP_DATE=2026-09-18T00:00:00Z --build-arg APP_COMMIT=local -t plural-cli:otel-1.45.0 .

Follow-up

After this source PR merges, a future Console image release and GitOps image-tag promotion are required. No promotion is included here because rebuilt image tags do not yet exist.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create a single remediation PR for the live mgmt/console vulnerability finding below. Do not modify any GitOps repository or attempt an image-tag promotion....
🔗 Run history View run history

@greptile-apps

greptile-apps Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The dependency-only update appears safe to merge, with no concrete compatibility, reachability, or repository-rule issues identified.

Summary

This PR updates the transitive OpenTelemetry API and SDK family from v1.44.0 to v1.45.0 to remediate the identified SDK vulnerability.

  • Keeps the OpenTelemetry core, metric, SDK, and trace modules aligned at v1.45.0.
  • Updates associated transitive metadata, including metric/x and go-logr.
  • Correctly reclassifies gqlparser as direct because repository tests import it.

Reviews (1) · Last reviewed commit: "fix(deps): upgrade OpenTelemetry SDK to ..."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants