Skip to content

fix: move go.opentelemetry.io/otel/sdk to v1.45.0 for GO-2026-6505 - #30

Merged
k1LoW merged 1 commit into
mainfrom
fix/otel-sdk-govulncheck
Oct 2, 2026
Merged

k1LoW merged 1 commit into
mainfrom
fix/otel-sdk-govulncheck

Conversation

@k1LoW

@k1LoW k1LoW commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

govulncheck in the Test job now reports GO-2026-6505 against go.opentelemetry.io/otel/sdk v1.44.0, which the binary pulls in indirectly through dd-trace-go's OpenFeature provider. Every pull request fails on it until the module moves, #29 among them even though it only touches a workflow action. Renovate leaves indirect requirements alone, so this raises it directly instead of waiting for dd-trace-go to require v1.45.0.

The other otel modules and go-logr/logr move only because otel/sdk v1.45.0 requires them. Once this lands, re-running #29's checks should turn it green.

govulncheck in the Test job started reporting GO-2026-6505 against
otel/sdk v1.44.0, which reaches the binary indirectly through
dd-trace-go's OpenFeature provider. The job fails on every pull request
until the module moves, including Renovate's unrelated ones, and
Renovate does not bump an indirect requirement on its own, so it is
raised here rather than waiting for dd-trace-go to require v1.45.0.

The other otel modules and go-logr/logr move with it because v1.45.0
requires them at those versions.
@k1LoW k1LoW self-assigned this Oct 2, 2026
@k1LoW
k1LoW marked this pull request as ready for review October 2, 2026 09:07
@k1LoW
k1LoW requested a review from a team as a code owner October 2, 2026 09:07
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Code Metrics Report

main (61ad19b) #30 (67eba4c) +/-
Coverage 72.0% 72.0% 0.0%
Code to Test Ratio 1:1.2 1:1.2 0.0
Test Execution Time - 16s +16s
Details
  |                     | main (61ad19b) | #30 (67eba4c) | +/-  |
  |---------------------|----------------|---------------|------|
  | Coverage            |          72.0% |         72.0% | 0.0% |
  |   Files             |             12 |            12 |    0 |
  |   Lines             |            722 |           722 |    0 |
  |   Covered           |            520 |           520 |    0 |
  | Code to Test Ratio  |          1:1.2 |         1:1.2 |  0.0 |
  |   Code              |           2010 |          2010 |    0 |
  |   Test              |           2481 |          2481 |    0 |
- | Test Execution Time |              - |           16s | +16s |

Reported by octocov

@dragon3 dragon3 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@k1LoW
k1LoW merged commit 938363e into main Oct 2, 2026
5 checks passed
@k1LoW
k1LoW deleted the fix/otel-sdk-govulncheck branch October 2, 2026 09:23
@github-actions github-actions Bot mentioned this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants