security: fix Dependabot alerts for grpc and OTel - #3835
Conversation
Fixes GHSA-hrxh-6v49-42gf (gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities) in modules: dex, couchbase, etcd, milvus, pinecone. Co-Authored-By: Claude <noreply@anthropic.com>
Bumps go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp from v0.4.0 to v0.20.0 to fix unbounded HTTP response body reads. Also bumps related log packages (otel/log, otel/sdk/log, otelslog bridge) for compatibility. Co-Authored-By: Claude <noreply@anthropic.com>
✅ Deploy Preview for testcontainers-go ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (6)
📒 Files selected for processing (6)
Summary by CodeRabbit
WalkthroughThe pull request updates dependency versions in six Go modules. It refreshes Google API, genproto, gRPC, protobuf, OpenTelemetry logging, and grpc-gateway references. ChangesDependency refresh
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What does this PR do?
Fixes actionable Dependabot security alerts with one commit per vulnerability:
google.golang.org/grpcto v1.82.1 in dex, couchbase, etcd, milvus, pinecone modulesgo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttpto v0.20.0 (+ related OTel log/bridge packages) in grafana-lgtm moduleAlerts NOT addressed (no fix available)
docker/dockerimport path first.go 1.26, incompatible with this repo'sgo 1.25.0directive. Needs a Go version bump first.