Skip to content

Conversation

@ezhang6811
Copy link
Contributor

Issue #, if available:

Description of changes:
Fixes CVE-2025-58056. See upstream PR.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@ezhang6811 ezhang6811 requested a review from a team as a code owner September 5, 2025 00:19
@codecov-commenter
Copy link

codecov-commenter commented Sep 5, 2025

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 67.07%. Comparing base (09e6487) to head (9b17464).
⚠️ Report is 475 commits behind head on main.
❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@              Coverage Diff              @@
##               main    #1173       +/-   ##
=============================================
- Coverage     85.71%   67.07%   -18.64%     
- Complexity       19      525      +506     
=============================================
  Files             3       54       +51     
  Lines            49     2694     +2645     
  Branches          5      376      +371     
=============================================
+ Hits             42     1807     +1765     
- Misses            3      750      +747     
- Partials          4      137      +133     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copy link
Contributor

@thpierce thpierce left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We also depend on "com.amazonaws:aws-java-sdk-bom:1.12.599", they need to update too, right? Maybe open a PR or an issue there and update the comment to clarify.

@ezhang6811 ezhang6811 merged commit fb742d5 into aws-observability:main Sep 5, 2025
8 of 10 checks passed
@ezhang6811 ezhang6811 deleted the cve-2025-58057 branch September 5, 2025 18:45
majanjua-amzn pushed a commit to majanjua-amzn/aws-otel-java-instrumentation that referenced this pull request Sep 9, 2025
*Issue #, if available:*

*Description of changes:*
Fixes
[CVE-2025-58056](GHSA-fghv-69vj-qj49). See
upstream [PR](aws/aws-sdk-java-v2#6398).

By submitting this pull request, I confirm that my contribution is made
under the terms of the Apache 2.0 license.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants