Skip to content

fix(deps): upgrade OpenTelemetry SDK to v1.45.0 (CVE-2026-81870) - #806

Closed
plural-copilot[bot] wants to merge 3 commits into
mainfrom
agent/fix-otel-sdk-cve-2026-81870-1790174926914
Closed

plural-copilot[bot] wants to merge 3 commits into
mainfrom
agent/fix-otel-sdk-cve-2026-81870-1790174926914

Conversation

@plural-copilot

Copy link
Copy Markdown
Contributor

Summary

  • Remediates CVE-2026-81870 / GHSA-8wmf-6v46-5gfg affecting the deployed ghcr.io/pluralsh/console:0.12.47 image.
  • Updates resolved go.opentelemetry.io/otel/sdk from installed v1.44.0 to fixed v1.45.0.
  • Coherently updates the matching OpenTelemetry core modules (otel, metric, sdk/metric, and trace) to v1.45.0; Go tooling also selected required github.com/go-logr/logr v1.4.4 and generated go.sum entries.

Image linkage

The repository’s single root Go module is copied by Dockerfile, which runs go mod download and builds ./cmd/plural. The source-to-image mapping identifies this plural-cli build as authoritative for Go vulnerabilities reported in the console image. No GitOps or deployment image tags are modified.

Validation

  • Passed (Docker golang:1.26.6-alpine3.24): go mod verify
  • Passed (Docker Go 1.26.6): resolved module check confirms otel, metric, sdk, sdk/metric, and trace resolve to v1.45.0
  • Passed: git diff --check
  • Passed (Docker Go 1.26.6): go test ./pkg/console/errors
  • Attempted (10-minute bound): go mod verify && go build ./cmd/plural && go test ./pkg/console/.... The build completed and the test phase started, but the complete console test run exceeded the limit with a cold dependency/build cache.

Follow-up

A new console image must be rebuilt and published with this dependency update before any deployment image-tag change. No Plural Service tag is needed because this is application-source dependency remediation, not GitOps.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create one remediation PR in this repository for the fixed-version Go dependency vulnerability found in the deployed ghcr.io/pluralsh/console:0.12.47 image....
🔗 Run history View run history

@greptile-apps

greptile-apps Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge, with no actionable regression identified in the dependency updates.

Summary

Updates the root Go module’s OpenTelemetry dependencies for the stated CVE remediation.

  • Aligns otel, metric, sdk, sdk/metric, and trace at v1.45.0.
  • Updates go-logr/logr to v1.4.4 and adds dependency checksums.
  • Changes no application logic, build configuration, or deployment image tags.
  • No actionable defects were identified. Builds and tests were not independently rerun during this review; the PR reports a successful CLI build and targeted test, with the broader console test run timing out.

Reviews (1) · Last reviewed commit: "fix(deps): upgrade OpenTelemetry SDK to ..."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants