Skip to content

Commit d08ffb4

Browse files
authored
feat(splunk-otel-collector): update advisory for several vulnerabilities (#21341)
Signed-off-by: Francesco Bartolini <[email protected]>
1 parent 01c8675 commit d08ffb4

File tree

1 file changed

+28
-0
lines changed

1 file changed

+28
-0
lines changed

splunk-otel-collector.advisories.yaml

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -95,6 +95,10 @@ advisories:
9595
componentType: go-module
9696
componentLocation: /usr/bin/otelcol
9797
scanner: grype
98+
- timestamp: 2025-08-04T13:02:46Z
99+
type: pending-upstream-fix
100+
data:
101+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
98102

99103
- id: CGA-5fjc-fxmq-vggm
100104
aliases:
@@ -179,6 +183,10 @@ advisories:
179183
componentType: go-module
180184
componentLocation: /usr/bin/otelcol
181185
scanner: grype
186+
- timestamp: 2025-08-04T13:02:46Z
187+
type: pending-upstream-fix
188+
data:
189+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
182190

183191
- id: CGA-8226-gq6c-h5h6
184192
aliases:
@@ -299,6 +307,10 @@ advisories:
299307
componentType: go-module
300308
componentLocation: /usr/bin/otelcol
301309
scanner: grype
310+
- timestamp: 2025-08-04T13:02:46Z
311+
type: pending-upstream-fix
312+
data:
313+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
302314

303315
- id: CGA-crqj-9642-5m2w
304316
aliases:
@@ -406,6 +418,10 @@ advisories:
406418
componentType: go-module
407419
componentLocation: /usr/bin/otelcol
408420
scanner: grype
421+
- timestamp: 2025-08-04T13:02:46Z
422+
type: pending-upstream-fix
423+
data:
424+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
409425

410426
- id: CGA-jr6h-pq36-654c
411427
aliases:
@@ -511,6 +527,10 @@ advisories:
511527
componentType: go-module
512528
componentLocation: /usr/bin/otelcol
513529
scanner: grype
530+
- timestamp: 2025-08-04T13:02:46Z
531+
type: pending-upstream-fix
532+
data:
533+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
514534

515535
- id: CGA-v69g-6284-r2qx
516536
aliases:
@@ -564,6 +584,10 @@ advisories:
564584
componentType: go-module
565585
componentLocation: /usr/bin/otelcol
566586
scanner: grype
587+
- timestamp: 2025-08-04T13:02:46Z
588+
type: pending-upstream-fix
589+
data:
590+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
567591

568592
- id: CGA-xgcq-m8cr-rf2h
569593
aliases:
@@ -582,6 +606,10 @@ advisories:
582606
componentType: go-module
583607
componentLocation: /usr/bin/otelcol
584608
scanner: grype
609+
- timestamp: 2025-08-04T13:02:46Z
610+
type: pending-upstream-fix
611+
data:
612+
note: 'The vulnerability originates from the Vault dependency. Upgrading Vault breaks the build due to a transitive conflict with k8s.io/client-go, which introduces incompatibility with Prometheus libraries. Once Prometheus addresses this (see issue #16767 and PR #16768) and the upstream resolves the issue, we’ll be able to upgrade and remediate the vulnerability.'
585613

586614
- id: CGA-xpgr-wj46-h3fx
587615
aliases:

0 commit comments

Comments
 (0)