etcd-io/etcd

Bump `go.opentelemetry.io/otel` to 1.41.0

Geschlossen

#21.917 geöffnet am 05.06.2026

 (1 Kommentar) (1 Reaktion) (1 zugewiesene Person)Go (10.352 Forks)batch import
area/securityhelp wantedrelease/v3.5release/v3.6

Repository-Metriken

Stars
 (51.701 Sterne)
PR-Merge-Metriken
 (Durchschn. Merge 6T 3h) (71 gemergte PRs in 30 T)

Beschreibung

What would you like to be added?

The go.opentelemetry.io/otel has the CVE-2026-29181 high severity vulnerability reported. We have version 1.40.0 in both 3.5 and 3.6.

We should also bump go.opentelemetry.io/otel/sdk to 1.43.0, due to CVE-2026-39883.

We need to update the dependency, and add a CHANGELOG entry.

Why is this needed?

To address CVE-2026-29181 and CVE-2026-39883.

Contributor Guide