Skip to content

fix(deps): fix Go dependency vulnerabilities on alauda-v0.43.0 - #89

Closed
l-qing wants to merge 1 commit into
alauda-v0.43.0from
fix/vuln-alauda-v0.43.0-by-go-vuln-fix
Closed

l-qing wants to merge 1 commit into
alauda-v0.43.0from
fix/vuln-alauda-v0.43.0-by-go-vuln-fix

Conversation

@l-qing

@l-qing l-qing commented Apr 10, 2026

Copy link
Copy Markdown

Fixes

Package Fixed version CVE Severity
go.opentelemetry.io/otel/sdk v1.43.0 CVE-2026-39883 HIGH

Verification

  • trivy re-scan: 0 vulnerabilities
  • go build ./... passed

- Upgrade go.opentelemetry.io/otel/sdk from v1.40.0 to v1.43.0 for CVE-2026-39883
- Refresh the related OpenTelemetry module set and vendored dependencies
- Regenerate go.sum and vendor metadata after the dependency update
@l-qing l-qing closed this Apr 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant