Update vulnerable dependencies [SECURITY] - #4807
Open
pulumi-renovate[bot] wants to merge 1 commit into
Open
Conversation
Contributor
Author
|
Contributor
Does the PR have any schema changes?Looking good! No breaking changes found. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #4807 +/- ##
=======================================
Coverage 64.95% 64.96%
=======================================
Files 94 94
Lines 11886 11886
=======================================
+ Hits 7721 7722 +1
+ Misses 3438 3437 -1
Partials 727 727 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v5.19.1→v5.19.2v1.33.0→v1.45.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
go-git: Worktree operations may follow symlinks
CVE-2026-71556 / GHSA-hc8v-wwc9-vgxm
More information
Details
Impact
A symlink traversal issue in
go-gitcould allow worktree operations to modify files outside the intended worktree path.The
worktreeFilesystemwrapper rejected dangerous path strings, including paths containing.git, parent-directory components, or control characters. However, it did not prevent filesystem operations from following symbolic links that were already present in the worktree.As a result, a path that is safe when evaluated as a string could still resolve into the repository's Git metadata directory. For example, if
sis a symbolic link to.git, writing tos/configwould modify.git/config.A symbolic link at the final path component could also be followed. For example, if
spoints directly to.git/config, openingsfor writing with truncation could overwrite the repository configuration.Exploitation requires an attacker to be able to introduce or control a symbolic link in the worktree and cause the application to perform a write through that path.
Applications using
storage/memoryfor their Storer, orgo-billy/memfsfor theirWorktree, are not affected by this vulnerability.Patches
The issue has been addressed by making the worktree filesystem wrapper a symlink-safe boundary.
Worktree operations now reject paths where an existing symbolic link in any path component could cause the operation to escape the intended worktree location, including symbolic links at the final component.
Users of filesystem-backed worktrees should upgrade to a patched version.
Credits
Thanks to @kodareef5 for reporting this issue and working with the go-git security team toward its resolution. 🥇
We would also like to thank @HughLewis20, who independently reported the same issue while a fix was already in progress.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
go-git: Malicious reference names may modify files outside the reference storage
CVE-2026-71557 / GHSA-qgq7-7hm3-q39j
More information
Details
Impact
A path traversal issue in
go-gitcould allow malicious reference names to access files outside the repository's intended reference storage.Loose references are stored under
.git/<reference-name>. The reference name was previously used as a path without verifying that the resolved path remained within the reference storage. A name such asrefs/heads/../../configcould therefore resolve to unrelated repository metadata such as.git/configor.git/HEAD.A malicious Git server could advertise such a reference name. The name may also survive refspec mapping; for example, it could be mapped to
refs/remotes/origin/../../configduring a clone or fetch operation.This vulnerability affects filesystem-backed repositories using the
storage/filesystempackage and itsdotgitreference storage. Users relying exclusively on the in-memory storage implementation,storage/memory, are not affected, because reference names are not resolved as filesystem paths.Exploitation requires an application using
go-gitwith filesystem-backed storage to interact with a malicious Git server or otherwise process attacker-controlled reference names.Patches
The issue has been addressed by validating reference names at the
dotgitstorage entry points and rejecting names whose resolved paths could escape the reference storage.Users of filesystem-backed storage should upgrade to a patched version.
Workarounds
Applications that exclusively use
storage/memoryare not affected and do not require a workaround for this vulnerability.For applications using filesystem-backed storage, avoid cloning from or fetching from untrusted Git servers until an upgrade is possible.
Applications that directly construct or process reference names may also validate them before passing them to filesystem-backed
go-gitstorage. Application-level validation should only be considered a temporary mitigation and does not replace upgrading to a patched version.References
Credits
Thanks to @Saku0512 for reporting this issue and @Sahana2524 for proposing the initial fix. 🙇
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
go-git: Worktree operations may follow symlinks
CVE-2026-71556 / GHSA-hc8v-wwc9-vgxm
More information
Details
Impact
A symlink traversal issue in
go-gitcould allow worktree operations to modify files outside the intended worktree path.The
worktreeFilesystemwrapper rejected dangerous path strings, including paths containing.git, parent-directory components, or control characters. However, it did not prevent filesystem operations from following symbolic links that were already present in the worktree.As a result, a path that is safe when evaluated as a string could still resolve into the repository's Git metadata directory. For example, if
sis a symbolic link to.git, writing tos/configwould modify.git/config.A symbolic link at the final path component could also be followed. For example, if
spoints directly to.git/config, openingsfor writing with truncation could overwrite the repository configuration.Exploitation requires an attacker to be able to introduce or control a symbolic link in the worktree and cause the application to perform a write through that path.
Applications using
storage/memoryfor their Storer, orgo-billy/memfsfor theirWorktree, are not affected by this vulnerability.Patches
The issue has been addressed by making the worktree filesystem wrapper a symlink-safe boundary.
Worktree operations now reject paths where an existing symbolic link in any path component could cause the operation to escape the intended worktree location, including symbolic links at the final component.
Users of filesystem-backed worktrees should upgrade to a patched version.
Credits
Thanks to @kodareef5 for reporting this issue and working with the go-git security team toward its resolution. 🥇
We would also like to thank @HughLewis20, who independently reported the same issue while a fix was already in progress.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
go-git: Malicious reference names may modify files outside the reference storage
CVE-2026-71557 / GHSA-qgq7-7hm3-q39j
More information
Details
Impact
A path traversal issue in
go-gitcould allow malicious reference names to access files outside the repository's intended reference storage.Loose references are stored under
.git/<reference-name>. The reference name was previously used as a path without verifying that the resolved path remained within the reference storage. A name such asrefs/heads/../../configcould therefore resolve to unrelated repository metadata such as.git/configor.git/HEAD.A malicious Git server could advertise such a reference name. The name may also survive refspec mapping; for example, it could be mapped to
refs/remotes/origin/../../configduring a clone or fetch operation.This vulnerability affects filesystem-backed repositories using the
storage/filesystempackage and itsdotgitreference storage. Users relying exclusively on the in-memory storage implementation,storage/memory, are not affected, because reference names are not resolved as filesystem paths.Exploitation requires an application using
go-gitwith filesystem-backed storage to interact with a malicious Git server or otherwise process attacker-controlled reference names.Patches
The issue has been addressed by validating reference names at the
dotgitstorage entry points and rejecting names whose resolved paths could escape the reference storage.Users of filesystem-backed storage should upgrade to a patched version.
Workarounds
Applications that exclusively use
storage/memoryare not affected and do not require a workaround for this vulnerability.For applications using filesystem-backed storage, avoid cloning from or fetching from untrusted Git servers until an upgrade is possible.
Applications that directly construct or process reference names may also validate them before passing them to filesystem-backed
go-gitstorage. Application-level validation should only be considered a temporary mitigation and does not replace upgrading to a patched version.References
Credits
Thanks to @Saku0512 for reporting this issue and @Sahana2524 for proposing the initial fix. 🙇
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
CVE-2026-45404 / GHSA-42cj-99w8-cp2p
More information
Details
Summary
go.opentelemetry.io/otel/bridge/opentracingintroduced an unsynchronizedextraBaggageItemsmap onbridgeSpan. One goroutine can write this map throughSpan.SetBaggageItemwhile another goroutine reads and iterates it during correlation baggage propagation, which can trigger Go's fatal concurrent map access panic and crash the process. The finding is low severity because exploitation requires a specific OpenTracing bridge configuration and concurrent use of the same span.Introduced in commit: 8cddf30
Details
bridge/opentracing/bridge.go:80-85addsextraBaggageItems map[string]stringtobridgeSpanwithout a mutex or other synchronization primitive.bridge/opentracing/bridge.go:219-234showsSetBaggageItemcallingupdateOtelContext, which lazily creates the map and writess.extraBaggageItems[restrictedKey] = valuewithout locking.bridge/opentracing/bridge.go:359-377showscorrelationGetHookreadingbSpan.extraBaggageItems, checkinglen(items), and iteratingfor k, v := range itemswithout locking. The finding evidence also identifiesapi/correlation/context.go:160-165as the path wherecorrelation.MapFromContextinvokes the get hook, allowing a read path to run concurrently with baggage writes.Because Go maps are not safe for concurrent read/write access, concurrent
SetBaggageItemandcorrelation.MapFromContextcalls on the same hookedbridgeSpancan terminate the process with a runtime error such asfatal error: concurrent map read and map writeorfatal error: concurrent map iteration and map write.PoC
validation-artifact.zip
The validation artifact contains a PoC at
validation-artifact.tar:validation_poc_concurrent_map.goand supporting notes atvalidation-artifact.tar:validation_poc_README.txt.Use a checkout of
pellared/opentelemetry-goat commit8cddf30with Go module downloads enabled. The local validation environment could not complete the run becauseGOPROXY=offblocked dependency resolution; that blocked output is saved invalidation-artifact.tar:validation_poc_run.log.Commands:
The PoC starts a
BridgeTracer, creates a span, installs correlation hooks withtracer.NewHookedContext(ctx), initializes baggage once, then runs one goroutine repeatedly callingspan.SetBaggageItem(...)while another repeatedly callsotelcorrelation.MapFromContext(ctx). A vulnerable build is expected to terminate with a Go runtime concurrent map access error, for example:or:
Impact
This is a race condition / improper synchronization vulnerability in a shared Go map. Applications using the OpenTelemetry OpenTracing bridge with correlation hooks can crash if the same
bridgeSpanis accessed concurrently, with one execution path setting baggage and another propagating correlation baggage. The practical impact is denial of service for the affected application process; exposure depends on whether application request handling or internal concurrency can trigger those operations on the same span.Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
go-git/go-git (github.com/go-git/go-git/v5)
v5.19.2Compare Source
What's Changed
Full Changelog: go-git/go-git@v5.19.1...v5.19.2
open-telemetry/opentelemetry-go (go.opentelemetry.io/otel/bridge/opentracing)
v1.45.0: /v0.67.0/v0.21.0/v0.0.18Compare Source
Overview
Added
BatchProcessoringo.opentelemetry.io/otel/sdk/log. (#7124)WithUnsafeAttributesno-copy attribute option togo.opentelemetry.io/otel/metric/xfor future performance improvements. This API is a work in progress. (#8251)MapandMapValuefunctions for the newMAPattribute type ingo.opentelemetry.io/otel/attribute. (#8445)MAPattributes ingo.opentelemetry.io/otel/exporters/otlp/otlptrace. (#8453)MAPattributes ingo.opentelemetry.io/otel/exporters/otlp/otlplog. (#8453)MAPattributes ingo.opentelemetry.io/otel/exporters/otlp/otlpmetric. (#8453)MAPattributes ingo.opentelemetry.io/otel/exporters/zipkin. (#8453)AttributeValueLengthLimitrecursively to values contained inattribute.MAPattributes ingo.opentelemetry.io/otel/sdk/trace. (#8454)attribute.MAPvalues ingo.opentelemetry.io/otel/sdk/resourceusing last-value-wins semantics. (#8471)attribute.MAPvalues in instrumentation scope attributes ingo.opentelemetry.io/otel/sdk/logusing last-value-wins semantics. (#8471)attribute.MAPvalues in span, event, link, and instrumentation scope attributes ingo.opentelemetry.io/otel/sdk/traceusing last-value-wins semantics. (#8471)attribute.MAPvalues in measurement and instrumentation scope attributes ingo.opentelemetry.io/otel/sdk/metricusing last-value-wins semantics. (#8471)WithAllowKeyDuplicationingo.opentelemetry.io/otel/sdk/logto disable duplicate-key removal inattribute.MAPvalues for instrumentation scope attributes. (#8471)go.opentelemetry.io/otel/semconv/v1.42.0package.The package contains semantic conventions from the
v1.42.0version of the OpenTelemetry Semantic Conventions.See the migration documentation for information on how to upgrade from
go.opentelemetry.io/otel/semconv/v1.41.0. (#8484)WithoutPanicRecordingas aTracerProviderOptioningo.opentelemetry.io/otel/sdk/traceto disable exception event recording for panics. (#8532)go.opentelemetry.io/otel/semconv/v1.43.0package.The package contains semantic conventions from the
v1.43.0version of the OpenTelemetry Semantic Conventions.See the migration documentation for information on how to upgrade from
go.opentelemetry.io/otel/semconv/v1.42.0. (#8628)Changed
HistogramReservoiringo.opentelemetry.io/otel/sdk/metric/exemplarnow uses a time-unbiased sampling algorithm for exemplars. (#8306)go.opentelemetry.io/otel/attribute.Valueandgo.opentelemetry.io/otel/attribute.KeyValuefor log bodies and attributes ingo.opentelemetry.io/otel/log,go.opentelemetry.io/otel/log/logtest,go.opentelemetry.io/otel/sdk/log, andgo.opentelemetry.io/otel/sdk/log/logtest. (#8490)go.opentelemetry.io/otel/attribute.ValueJSON ingo.opentelemetry.io/otel/exporters/stdout/stdoutlog. (#8490)BOOLSLICE,INT64SLICE,FLOAT64SLICE, andSTRINGSLICEattribute values by avoiding reflection for short slices ingo.opentelemetry.io/otel/attribute. (#8511)WithEndpointURLingo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpno longer appends the default signal path when an endpoint URL has no path, making the behavior consistent withgo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttpand with setting the endpoint throughOTEL_EXPORTER_OTLP_METRICS_ENDPOINT. If the URL has no path component, the root path (/) is used. UseWithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))to preserve the previous behavior. (#8538)WithEndpointURLingo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpno longer appends the default signal path when an endpoint URL has no path, making the behavior consistent withgo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttpand with setting the endpoint throughOTEL_EXPORTER_OTLP_TRACES_ENDPOINT. If the URL has no path component, the root path (/) is used. UseWithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))to preserve the previous behavior. (#8538)Deprecated
WithExportBufferSizeingo.opentelemetry.io/otel/sdk/log. The option remains available for source compatibility but no longer affects behavior;BatchProcessorno longer maintains a separate export-request buffer. (#8620)Removed
Kind,Value,KeyValue, their constructors, and attribute conversion helpers fromgo.opentelemetry.io/otel/log. (#8490)AttributeValueLengthLimitandAttributeCountLimitfields fromRecordFactoryingo.opentelemetry.io/otel/sdk/log/logtest; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. (#8556)Fixed
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc.go.opentelemetry.io/otel/bridge/opentracingwhen OpenTracing baggage is propagated concurrently withSpan.SetBaggageItem.FixedSizeReservoiringo.opentelemetry.io/otel/sdk/metric/exemplarthat prevented the first exemplar from being sampled after the reservoir was filled. (#8309)Retry-Afterheader values as seconds instead of nanoseconds when retrying OTLP HTTP exports ingo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp,go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, andgo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8383)Reservoirimplementation ingo.opentelemetry.io/otel/sdk/metric/exemplar, where storing the fullcontext.Contextpinned large objects such as gRPC transport buffers. (#8389)go.opentelemetry.io/otel/attribute. (#8402)go.opentelemetry.io/otel/sdk/metricaggregation to avoid leaking stale sum, minimum, and maximum values when they are disabled in subsequent collections. (#8403)go.opentelemetry.io/otel/exporters/prometheus. (#8404)Retry-Afterheader when retrying OTLP HTTP exports ingo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp,go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, andgo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8417)BucketCountsandExemplarsslices acrossCollectcycles in the cumulative histogram aggregation ingo.opentelemetry.io/otel/sdk/metric. (#8428)go.opentelemetry.io/otel/exporters/stdout/stdouttraceself-observability to recorderror.typeon the operation-duration histogram when theexportedSpansmetric is disabled. (#8432)go.opentelemetry.io/otel/sdk/trace,go.opentelemetry.io/otel/exporters/otlp/otlptrace,go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc,go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, andgo.opentelemetry.io/otel/exporters/zipkin. (#8438)go.opentelemetry.io/otel/codes. (#8497)go.opentelemetry.io/otel/logthatLogger.Enabledshould be checked for every log emission because its result may change over time. (#8565)go.opentelemetry.io/otel/sdk/log. (#8566)WithAttributeCountLimit(0)andOTEL_LOGRECORD_ATTRIBUTE_COUNT_LIMIT=0discard all log record attributes ingo.opentelemetry.io/otel/sdk/log. (#8570)Recordmethods ofFloat64HistogramandInt64Histogramingo.opentelemetry.io/otel/metricexpect non-negative values. (#8574)go.opentelemetry.io/otel/logthatLoggerProviderimplementations should retain an emptyLoggername instead of replacing it with a default. (#8587)go.opentelemetry.io/otel/sdk/logcall exporterForceFlushduringShutdown. (#8599)go.opentelemetry.io/otel/bridge/opentracingwhen OpenTracing baggage is propagated concurrently withSpan.SetBaggageItem. (GHSA-42cj-99w8-cp2p)go.opentelemetry.io/otel/sdk/logfrom overlapping with processor shutdown or running afterLoggerProvidershutdown. (#8608)BatchProcessoringo.opentelemetry.io/otel/sdk/logfrom busy-spinning under exporter backpressure and serialize dequeue, export, force-flush, and shutdown work in one worker. (#8620)BatchProcessoringo.opentelemetry.io/otel/sdk/logreturn errors encountered while draining records duringForceFlushandShutdown, while continuing to attempt later batches as long as the request context remains valid. (#8620)BatchProcessormaximum export batch size ingo.opentelemetry.io/otel/sdk/logat or below the configured maximum queue size. (#8620)What's Changed
bc171b2by @renovate[bot] in #8405c761662by @renovate[bot] in #83846cf7526by @renovate[bot] in #84080ec5bd2by @renovate[bot] in #84194308a22by @renovate[bot] in #844035bcb73by @renovate[bot] in #84367ab31c2by @renovate[bot] in #8447fb80ec8by @renovate[bot] in #84442399af7by @renovate[bot] in #846072dfd24by @renovate[bot] in #846262b3387by @renovate[bot] in #84634de325eby @renovate[bot] in #84669b6dc03by @renovate[bot] in #847487f3d3eby @renovate[bot] in #8483a6991f1by @renovate[bot] in #8482e028baeby @renovate[bot] in #8493semconv/v1.42.0by @MrAlias in #8484f39628cby @renovate[bot] in #8498b703f56by @renovate[bot] in #8502Configuration
📅 Schedule: (UTC)
* * * * 1-5)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.