Skip to content

fix(deps): remediate OpenTelemetry SDK CVE-2026-81870 - #807

Closed
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/remediate-otel-cve-2026-81870-1790258191278
Closed

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/remediate-otel-cve-2026-81870-1790258191278

Conversation

@plural-copilot

Copy link
Copy Markdown
Contributor

Summary

Remediates CVE-2026-81870 / GHSA-8wmf-6v46-5gfg in the Console CLI source for the deployed image ghcr.io/pluralsh/console:sha-76cf70e.

That image's plural binary resolved the vulnerable go.opentelemetry.io/otel/sdk v1.44.0. The fixed version is v1.45.0.

  • Updated the coherent OTel v1 module family—otel, metric, sdk, sdk/metric, and trace—from v1.44.0 to v1.45.0.
  • Recorded the required transitive resolution updates: go.opentelemetry.io/otel/metric/x v0.67.0 and github.com/go-logr/logr v1.4.4.
  • Changed only go.mod and go.sum.

Validation

Run in golang:1.26.6-alpine3.24:

  • go mod verify — passed
  • go test -mod=readonly ./pkg/utils — passed
  • go build -mod=readonly -o /tmp/plural ./cmd/plural — passed
  • Resolved-module check confirmed core OTel API, metric, SDK, SDK metric, and trace modules are all v1.45.0; git diff --check passed.

Deployment scope

No Plural service tag, GitOps, deployment, or image-tag changes are included. Deployment promotion/image-tag changes await publication of the rebuilt Console image.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create one focused remediation PR for the deployed Console service console image source. Do not make any GitOps image-tag/deployment changes....
🔗 Run history View run history

@greptile-apps

greptile-apps Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The dependency update appears safe to merge based on the reviewed changes.

Summary

The PR upgrades the core OpenTelemetry modules from v1.44.0 to v1.45.0, updates the transitive go-logr/logr resolution, and records the corresponding checksums. No actionable issue caused by these changes was identified.

Reviews (1) · Last reviewed commit: "fix(deps): remediate OpenTelemetry SDK v..."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants