etcd-io/etcd

Bump `go.opentelemetry.io/otel` to 1.41.0

Fermée

#21 917 ouverte le 5 juin 2026

 (1 commentaire) (1 réaction) (1 personne assignée)Go (10 352 forks)batch import
area/securityhelp wantedrelease/v3.5release/v3.6

Métriques du dépôt

Stars
 (51 701 étoiles)
Métriques de merge PR
 (Merge moyen 6j 3h) (71 PRs mergées en 30 j)

Description

What would you like to be added?

The go.opentelemetry.io/otel has the CVE-2026-29181 high severity vulnerability reported. We have version 1.40.0 in both 3.5 and 3.6.

We should also bump go.opentelemetry.io/otel/sdk to 1.43.0, due to CVE-2026-39883.

We need to update the dependency, and add a CHANGELOG entry.

Why is this needed?

To address CVE-2026-29181 and CVE-2026-39883.

Guide contributeur