-
Notifications
You must be signed in to change notification settings - Fork 1
feat: bump otelcol base version to 0.124.0 #192
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Orca Security Scan Summary
Status | Check | Issues by priority | |
---|---|---|---|
![]() |
Infrastructure as Code | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
SAST | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
Secrets | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
Vulnerabilities | ![]() ![]() ![]() ![]() |
View in Orca |
☢️ The following Vulnerabilities (CVEs) have been detected
PACKAGE | FILE | CVE ID | INSTALLED VERSION | FIXED VERSION | ||
---|---|---|---|---|---|---|
![]() |
uplot | ...ui/package-lock.json | CVE-2024-21489 | 1.6.30 | 1.6.31 | View in code |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Orca Security Scan Summary
Status | Check | Issues by priority | |
---|---|---|---|
![]() |
Infrastructure as Code | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
SAST | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
Secrets | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
Vulnerabilities | ![]() ![]() ![]() ![]() |
View in Orca |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Orca Security Scan Summary
Status | Check | Issues by priority | |
---|---|---|---|
![]() |
Infrastructure as Code | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
SAST | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
Secrets | ![]() ![]() ![]() ![]() |
View in Orca |
![]() |
Vulnerabilities | ![]() ![]() ![]() ![]() |
View in Orca |
☢️ The following Vulnerabilities (CVEs) have been detected
PACKAGE | FILE | CVE ID | INSTALLED VERSION | FIXED VERSION | ||
---|---|---|---|---|---|---|
![]() |
uplot | ...ui/package-lock.json | CVE-2024-21489 | 1.6.30 | 1.6.31 | View in code |
Can't bump the prometheus version since prometheus receiver needs version https://github.com/open-telemetry/opentelemetry-collector-contrib/blob/c2e12729a13e4cef07b503fede311cb8c8942af9/receiver/prometheusreceiver/go.mod#L18 hopefully vuln will be fixable later but not fixable now without removing critical functionality |
a413347
to
befeb86
Compare
@@ -3,75 +3,75 @@ dist: | |||
module: github.com/observeinc/observe-agent/observecol | |||
description: Observe Distribution of OTEL Collector | |||
output_path: ./ocb-build | |||
version: 0.121.0 | |||
version: 0.124.1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why is this 0.124.1
?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
they released a patch version so i figured why not. but if you actually use 0.124.0 for the other components they're not found. so i guess they dont release all the components for patch releases
Description
Bump otelcol base version to 0.124.0
Checklist