Skip to content

fix(deps): remediate OpenTelemetry SDK CVE-2026-81870 - #805

Closed
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/fix-otel-cve-2026-81870-1780000000000
Closed

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/fix-otel-cve-2026-81870-1780000000000

Conversation

@plural-copilot

Copy link
Copy Markdown
Contributor

Summary

  • Remediates CVE-2026-81870 in the plural CLI dependency graph.
  • The live finding is reported for ghcr.io/pluralsh/console:0.12.47 at /usr/local/bin/plural; that binary is owned and built by this pluralsh/plural-cli repository, not the Console repository.

Dependency changes

Aligned the compatible OpenTelemetry v1 module family from v1.44.0 to v1.45.0:

  • go.opentelemetry.io/otel: v1.44.0 → v1.45.0
  • go.opentelemetry.io/otel/metric: v1.44.0 → v1.45.0
  • go.opentelemetry.io/otel/sdk: v1.44.0 → v1.45.0
  • go.opentelemetry.io/otel/sdk/metric: v1.44.0 → v1.45.0
  • go.opentelemetry.io/otel/trace: v1.44.0 → v1.45.0

The modules were aligned rather than pinning only the transitive SDK, preserving compatible API/SDK/metric/trace versions in the resolved graph. Go also selected github.com/go-logr/logr v1.4.4 (from v1.4.3) as required by the updated OTel modules. go.sum was regenerated accordingly.

Validation

Run in golang:1.26.6-alpine3.24:

  • go mod tidy — passed
  • go mod verify — passed
  • go list -m all — confirmed otel, otel/metric, otel/sdk, otel/sdk/metric, and otel/trace all resolve to v1.45.0; golang.org/x/crypto resolves to unchanged v0.56.0
  • git diff --check — passed
  • go build -o /tmp/plural ./cmd/plural and go test ./cmd/plural/... — attempted with a 10-minute timeout; dependency compilation exceeded the bound and the container was stopped without a compile/test error emitted.

Scope exclusions

  • GO-2026-5932 / golang.org/x/crypto was intentionally not updated: it has no fixed version and is out of scope.
  • No Console image tag, release/image publication, GitOps, deployment, or other repository changes are included.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create one focused remediation PR for the live mgmt/console Trivy finding in the CLI binary....
🔗 Run history View run history

@greptile-apps

greptile-apps Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge, with no concrete correctness, security, or dependency-integrity issue identified.

Summary

This PR updates the aligned OpenTelemetry v1 module family from v1.44.0 to v1.45.0 to remediate the reported SDK vulnerability.

  • Updates the API, metric, SDK, SDK metric, and trace modules together.
  • Accepts the corresponding go-logr and metric/x transitive updates.
  • Regenerates checksums without changing application source code.

Reviews (1) · Last reviewed commit: "fix(deps): remediate OpenTelemetry SDK C..."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants