Skip to content

fix(deps): remediate CVE-2026-81870 - #808

Merged
michaeljguarino merged 1 commit into
mainfrom
agent/fix-cve-2026-81870-1758724741000
Sep 25, 2026
Merged

michaeljguarino merged 1 commit into
mainfrom
agent/fix-cve-2026-81870-1758724741000

Conversation

@plural-copilot

Copy link
Copy Markdown
Contributor

Summary

Remediates CVE-2026-81870 in plural-cli by upgrading the OpenTelemetry runtime dependency family from v1.44.0 to v1.45.0.

The affected deployed artifact evidence is ghcr.io/pluralsh/console:sha-76cf70e, digest sha256:a43dd40a2257168ecd04e417f2975fd666ee72cd49cd80f417003a39bce6f8c9. The vulnerable component is its embedded usr/local/bin/plural binary, which is built by this plural-cli repository (despite the artifact being a Console image).

Changes

  • Updated the sole root Go module's selected go.opentelemetry.io/otel, otel/metric, otel/sdk, otel/sdk/metric, and otel/trace modules from v1.44.0 to fixed v1.45.0.
  • Updated github.com/go-logr/logr from v1.4.3 to v1.4.4, as required by Go module resolution for the fixed OTel release.
  • Regenerated committed Go dependency metadata in go.mod and go.sum with Go tooling.
  • No deployment GitOps, Dockerfile, workflow, or image-tag changes are included.

Build-path review

Inspected every applicable path producing or packaging ./cmd/plural:

  • the sole root go.mod (no workspace or additional Go module exists);
  • Dockerfile multi-stage image build;
  • Makefile install-cli, build-cli, and release targets;
  • .goreleaser.yaml release builds;
  • CI image-build and CD/release workflows.

Validation

  • Passed: go mod verify
  • Passed: selected-module assertions plus go list -m all confirmed otel, metric, sdk, sdk/metric, and trace resolve to v1.45.0; vulnerable otel/sdk v1.44.0 is not selected.
  • Passed: go build -o /tmp/plural ./cmd/plural
  • Passed: go test ./cmd/command/... in golang:1.26.6-alpine3.24 after apk add --no-cache git.
    • Initial test attempt without git failed only because existing crypto tests invoke git init; rerun with git passed.
  • Passed: git diff --check; final change scope is only go.mod and go.sum.
  • Limitation: Dockerfile image build was attempted with a 12-minute timeout and timed out while compiling ./cmd/plural in the constrained runtime. The direct binary build passed.

Deployment limitation

The deployed image remains unchanged until builds publish a rebuilt CLI/Console image. After publication, promotion is a separate deployment/GitOps action.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create exactly one remediation PR in this repository for CVE-2026-81870....
🔗 Run history View run history

@greptile-apps

greptile-apps Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge based on the reviewed dependency and checksum changes.

Summary

The PR upgrades the selected OpenTelemetry runtime modules from v1.44.0 to v1.45.0 and updates the indirect logr dependency, with corresponding checksums. It does not change deployment artifacts.

Reviews (1) · Last reviewed commit: "fix(deps): remediate CVE-2026-81870"

@michaeljguarino
michaeljguarino merged commit a1d5065 into main Sep 25, 2026
16 of 17 checks passed
@michaeljguarino
michaeljguarino deleted the agent/fix-cve-2026-81870-1758724741000 branch September 25, 2026 18:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants