chore: upgrade OpenTelemetry-Go exporters and SDK to v1.45.0 for CVE-2026-81870 - #28
Open
claude[bot] wants to merge 1 commit into
Open
claude[bot] wants to merge 1 commit into
claude[bot] wants to merge 1 commit into
Conversation
…2026-81870 Upgrades go.opentelemetry.io/otel/exporters/otlp/otlptrace, otlptracegrpc, otlptracehttp (v1.43.0) and go.opentelemetry.io/otel/sdk (v1.44.0) to v1.45.0, which stops recursively marshaling exporter and client configuration into the internal "TracerProvider created" Info log. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Remediates CVE-2026-81870 (OpenTelemetry-Go: exporter config logging may leak endpoint URLs in info logs, severity LOW).
In OpenTelemetry Go 1.5.0–1.44.0,
sdk/trace.NewTracerProvideremits aTracerProvider createdinternal Info event whoseMarshalLogimplementations recursively include span processor, exporter, and OTLP client configuration — disclosing the configured collector endpoint and the OTLP/HTTPInsecureflag to anyone with access to those logs. Upstream fix3a1412drecords exporter/client types instead of their configuration.Changes
go.mod/go.sumonly — no source changes were required, the upgrade is API-compatible.go.opentelemetry.io/otel/exporters/otlp/otlptracego.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcgo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpgo.opentelemetry.io/otel/sdkTransitive bumps pulled in by
go mod tidyas a consequence of the above:go.opentelemetry.io/proto/otlpv1.10.0 → v1.11.0,github.com/grpc-ecosystem/grpc-gateway/v2v2.28.0 → v2.29.0, andgoogle.golang.org/genproto/googleapis/apitov0.0.0-20260803160001-6ac0973c030d. The already-upgradedgo.opentelemetry.io/otel,otel/trace,otel/metric, andotel/bridge/opentracingwere at v1.45.0 and are unchanged.Verification
go list -mconfirms all four affected modules resolve to v1.45.0; no vulnerable version remains in the module graph.go mod verify— all modules verified (checksums intact).go build ./...— clean.go vet ./...— output is byte-identical tomain(26 pre-existing findings in test files andcmd/zoekt-sourcegraph-indexserver).go test ./... -short— the only failing package isinternal/e2e, which fails identically on unmodifiedmainin this environment (ctags-dependent scoring assertions). No regression introduced by this change.Fixes SOU-2288
🤖 Generated with Claude Code
Note
Low Risk
Dependency-only, API-compatible bump in the OTLP tracing stack; main effect is safer startup logging, not behavioral changes to search or indexing logic.
Overview
Upgrades OpenTelemetry tracing dependencies in
go.mod/go.sumonly to address CVE-2026-81870, where older SDK versions could write OTLP collector endpoints and HTTPInsecuresettings into internal Info logs when creating aTracerProvider.go.opentelemetry.io/otel/exporters/otlp/otlptrace(plus gRPC/HTTP clients) move from v1.43.0 to v1.45.0, andgo.opentelemetry.io/otel/sdkfrom v1.44.0 to v1.45.0, aligning with the already-at-v1.45.0 coreotelmodules.go mod tidyalso refreshes transitive pins (proto/otlp,grpc-gateway/v2,genproto/googleapis/api). No application source changes; tracing still goes throughinternal/tracer/opentelemetry.gowith the same APIs.Reviewed by Cursor Bugbot for commit 8819d81. Bugbot is set up for automated code reviews on this repo. Configure here.