Skip to content

SECURESIGN-5299 bump go.opentelemetry.io/otel to v1.44.0 - #762

Merged
jkopriva merged 1 commit into
release-1.4from
SECURESIGN-5299
Oct 5, 2026
Merged

jkopriva merged 1 commit into
release-1.4from
SECURESIGN-5299

Conversation

@jkopriva

@jkopriva jkopriva commented Sep 7, 2026

Copy link
Copy Markdown

Bump the OpenTelemetry-Go family to v1.44.0 (fixes CVE-2026-41178, baggage-parsing DoS). Also covers SECURESIGN-5298, SECURESIGN-5295, SECURESIGN-5290, SECURESIGN-5281, SECURESIGN-5256, SECURESIGN-5255, SECURESIGN-5252, SECURESIGN-5247, SECURESIGN-5238.

Assisted-by: Claude

Bump the OpenTelemetry-Go family to v1.44.0 (fixes CVE-2026-41178,
baggage-parsing DoS). Also covers SECURESIGN-5298, SECURESIGN-5295,
SECURESIGN-5290, SECURESIGN-5281, SECURESIGN-5256, SECURESIGN-5255,
SECURESIGN-5252, SECURESIGN-5247, SECURESIGN-5238.

Assisted-by: Claude
@qodo-for-securesign

Copy link
Copy Markdown

PR Summary by Qodo

Upgrade OpenTelemetry Go to v1.44.0 for CVE-2026-41178

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Upgrades OpenTelemetry Go to v1.44.0, fixing the baggage-parsing denial-of-service vulnerability.
• Aligns OpenTelemetry instrumentation, exporters, SDK, metrics, and tracing dependencies.
• Refreshes supporting Go, gRPC, and Google API dependency versions.
Diagram

graph TD
  A["go.mod"] --> B["OTel Contrib"] --> C["OTel Core"] --> D["OTLP Exporters"]
  C --> E["Metrics and Tracing"]
  A --> F["Supporting Modules"]
  A --> G["go.sum"]
Loading
High-Level Assessment

The coordinated dependency-family upgrade is the appropriate approach because OpenTelemetry core, SDK, exporters, and contrib instrumentation are version-coupled. Selectively overriding only the vulnerable package could create incompatibilities, while replacing OpenTelemetry would be disproportionate to a patch-level security update.

Files changed (2) +47 / -45

Other (2) +47 / -45
go.modUpgrade OpenTelemetry and supporting Go modules +15/-15

Upgrade OpenTelemetry and supporting Go modules

• Upgrades the OpenTelemetry core family to v1.44.0 and contrib instrumentation to their corresponding releases, addressing CVE-2026-41178. Also refreshes compatible x/net, x/sys, gRPC, and Google generated API dependencies.

go.mod

go.sumRefresh checksums for upgraded dependencies +32/-30

Refresh checksums for upgraded dependencies

• Replaces checksums for superseded OpenTelemetry and supporting module versions. Adds checksum entries for the newly introduced OpenTelemetry metric extension module.

go.sum

@qodo-for-securesign

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can copy the agent prompt from any finding and feed it to your IDE agent

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@jkopriva
jkopriva merged commit 22be886 into release-1.4 Oct 5, 2026
19 of 21 checks passed
@jkopriva
jkopriva deleted the SECURESIGN-5299 branch October 5, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants