Skip to content
This repository was archived by the owner on Mar 23, 2026. It is now read-only.

fix: update grpc to v1.79.3 and expr-lang to v1.17.7 to resolve vulnerabilities#1

Draft
aviadhahami wants to merge 1 commit into
mainfrom
aviad/RUN-560-odigos-collector-vulnerabilities-de82
Draft

fix: update grpc to v1.79.3 and expr-lang to v1.17.7 to resolve vulnerabilities#1
aviadhahami wants to merge 1 commit into
mainfrom
aviad/RUN-560-odigos-collector-vulnerabilities-de82

Conversation

@aviadhahami

Copy link
Copy Markdown

Summary

Fixes critical and high severity vulnerabilities in dependencies.

Vulnerabilities Fixed

Severity CVE/GHSA Package Old Version New Version
Critical GHSA-p77j-4mvh-x3m3 google.golang.org/grpc v1.59.0 v1.79.3
High GHSA-cfpf-hrx2-8rv6 github.com/expr-lang/expr v1.15.6 v1.17.7

Changes

  • Updated google.golang.org/grpc to v1.79.3 in both odigosotelcol/go.mod and processors/odigosresourcenameprocessor/go.mod
  • Updated github.com/expr-lang/expr to v1.17.7 in odigosotelcol/go.mod
  • Updated google.golang.org/api to v0.272.0 for grpc v1.79.3 compatibility
  • Ran go mod tidy on both modules
  • Verified build and tests pass

Resolves: RUN-560

Linear Issue: RUN-560

Open in Web Open in Cursor 

…rabilities

- Update google.golang.org/grpc from v1.59.0 to v1.79.3 (fixes GHSA-p77j-4mvh-x3m3)
- Update github.com/expr-lang/expr from v1.15.6 to v1.17.7 (fixes GHSA-cfpf-hrx2-8rv6)
- Update google.golang.org/api to v0.272.0 for grpc compatibility
- Run go mod tidy on both modules
- Verify build and tests pass

Resolves: RUN-560

Co-authored-by: Aviad Hahami <aviadhahami@users.noreply.github.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants