Skip to content

fix(deps): remediate OTel CVE-2026-81870 - #802

Closed
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/remediate-otel-cve-2026-81870-1789751000000
Closed

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/remediate-otel-cve-2026-81870-1789751000000

Conversation

@plural-copilot

Copy link
Copy Markdown
Contributor

Summary

Remediates Console service mgmt/console for CVE-2026-81870 / GHSA-8wmf-6v46-5gfg. The affected embedded /usr/local/bin/plural binary originates from pluralsh/plural-cli, so this dependency remediation is made here rather than in pluralsh/console.

Updated the OpenTelemetry trace dependency family atomically to compatible fixed versions. No dependency version was lowered.

Final resolved OpenTelemetry modules

  • go.opentelemetry.io/otel v1.45.0
  • go.opentelemetry.io/otel/trace v1.45.0
  • go.opentelemetry.io/otel/metric v1.45.0
  • go.opentelemetry.io/otel/sdk v1.45.0
  • go.opentelemetry.io/otel/sdk/metric v1.45.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.45.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.45.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.45.0
  • go.opentelemetry.io/otel/metric/x v0.67.0 (directly coupled)
  • go.opentelemetry.io/proto/otlp v1.11.0 (directly coupled)

Changed files

  • go.mod — raises the OTel dependency requirements and compatible transitive requirements.
  • go.sum — records checksums for the resolved dependency graph.

Validation

  • go mod tidy (root/sole CLI module)
  • go test ./pkg/utils/... (Docker Go 1.26.6)
  • go test ./cmd/... ./pkg/console/... && go build ./cmd/plural (Docker Go 1.26.6)
  • git diff --check

No GitOps promotion.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create a single remediation PR in this repository for CVE-2026-81870 / GHSA-8wmf-6v46-5gfg....
🔗 Run history View run history

@greptile-apps

greptile-apps Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge with no blocking or non-blocking findings.

Summary

Updates the OpenTelemetry trace dependency family to fixed, mutually aligned versions for CVE-2026-81870.

  • Raises the OTel core, trace, SDK, metric, OTLP trace exporter, and protocol modules.
  • Refreshes coupled transitive dependencies and module checksums.
  • Reclassifies gqlparser as direct because it is imported by repository tests.

Reviews (1) · Last reviewed commit: "fix(deps): remediate OTel CVE-2026-81870"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants