Skip to content

Update third party libraries flagged for vulnerability scans#1123

Closed
collin-lee wants to merge 1 commit intoenvoyproxy:mainfrom
collin-lee:third_part_vulnerability_scans_20260429
Closed

Update third party libraries flagged for vulnerability scans#1123
collin-lee wants to merge 1 commit intoenvoyproxy:mainfrom
collin-lee:third_part_vulnerability_scans_20260429

Conversation

@collin-lee
Copy link
Copy Markdown
Contributor

@collin-lee collin-lee commented Apr 29, 2026

Summary

Updates third-party libraries to address security vulnerabilities identified in the CDP policy engine security scan for
`sfci/3pp/3pp/docker.io/envoyproxy/ratelimit`.

Changes

Go Dependencies (go.mod)

  • Go: `1.26.1` → `1.26.2`
    • Addresses vulnerabilities in `golang:crypto/x509`, `golang:crypto/tls`, and `golang:html/template`
  • OpenTelemetry SDK: `1.40.0` → `1.43.0`
    • `go.opentelemetry.io/otel`
    • `go.opentelemetry.io/otel/sdk`
    • `go.opentelemetry.io/otel/trace`
    • `go.opentelemetry.io/otel/metric`
  • OpenTelemetry OTLP Exporters: → `1.43.0`
    • `go.opentelemetry.io/otel/exporters/otlp/otlptrace` (`1.28.0` → `1.43.0`)
    • `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc` (`1.28.0` → `1.43.0`)
    • `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` (`1.27.0` → `1.43.0`)
  • gRPC: Remains at `1.80.0` (required by OpenTelemetry 1.43.0)

Docker Images

  • Updated all Dockerfiles to use `golang:1.26.2@sha256:7095ad02810845fa35d1fb090b8e57dd20dce4ca36b29b42951802350d2ec90e`
    • `Dockerfile`
    • `Dockerfile.integration`
    • `examples/xds-sotw-config-server/Dockerfile`

CI/CD

  • Updated GitHub Actions workflows to use Go 1.26.2
    • `.github/workflows/pullrequest.yaml`
    • `.github/workflows/main.yaml`

Signed-off-by: collin-lee <collin.lee@salesforce.com>
@collin-lee
Copy link
Copy Markdown
Contributor Author

@agrawroh FYI... addressing some vulnerability scans

@collin-lee collin-lee closed this Apr 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant