You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: splunk-otel-collector.advisories.yaml
+28Lines changed: 28 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -95,6 +95,10 @@ advisories:
95
95
componentType: go-module
96
96
componentLocation: /usr/bin/otelcol
97
97
scanner: grype
98
+
- timestamp: 2025-08-04T13:02:46Z
99
+
type: pending-upstream-fix
100
+
data:
101
+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
98
102
99
103
- id: CGA-5fjc-fxmq-vggm
100
104
aliases:
@@ -179,6 +183,10 @@ advisories:
179
183
componentType: go-module
180
184
componentLocation: /usr/bin/otelcol
181
185
scanner: grype
186
+
- timestamp: 2025-08-04T13:02:46Z
187
+
type: pending-upstream-fix
188
+
data:
189
+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
182
190
183
191
- id: CGA-8226-gq6c-h5h6
184
192
aliases:
@@ -299,6 +307,10 @@ advisories:
299
307
componentType: go-module
300
308
componentLocation: /usr/bin/otelcol
301
309
scanner: grype
310
+
- timestamp: 2025-08-04T13:02:46Z
311
+
type: pending-upstream-fix
312
+
data:
313
+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
302
314
303
315
- id: CGA-crqj-9642-5m2w
304
316
aliases:
@@ -406,6 +418,10 @@ advisories:
406
418
componentType: go-module
407
419
componentLocation: /usr/bin/otelcol
408
420
scanner: grype
421
+
- timestamp: 2025-08-04T13:02:46Z
422
+
type: pending-upstream-fix
423
+
data:
424
+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
409
425
410
426
- id: CGA-jr6h-pq36-654c
411
427
aliases:
@@ -511,6 +527,10 @@ advisories:
511
527
componentType: go-module
512
528
componentLocation: /usr/bin/otelcol
513
529
scanner: grype
530
+
- timestamp: 2025-08-04T13:02:46Z
531
+
type: pending-upstream-fix
532
+
data:
533
+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
514
534
515
535
- id: CGA-v69g-6284-r2qx
516
536
aliases:
@@ -564,6 +584,10 @@ advisories:
564
584
componentType: go-module
565
585
componentLocation: /usr/bin/otelcol
566
586
scanner: grype
587
+
- timestamp: 2025-08-04T13:02:46Z
588
+
type: pending-upstream-fix
589
+
data:
590
+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
567
591
568
592
- id: CGA-xgcq-m8cr-rf2h
569
593
aliases:
@@ -582,6 +606,10 @@ advisories:
582
606
componentType: go-module
583
607
componentLocation: /usr/bin/otelcol
584
608
scanner: grype
609
+
- timestamp: 2025-08-04T13:02:46Z
610
+
type: pending-upstream-fix
611
+
data:
612
+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
0 commit comments