Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @opentelemetry/sdk-node from 0.41.0 to 0.41.2 #128

Merged
merged 1 commit into from
Aug 21, 2023

Conversation

will0684
Copy link
Member

@will0684 will0684 commented Aug 8, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 691/1000
Why? Recently disclosed, Has a fix available, CVSS 8.1
Arbitrary Code Execution
SNYK-JS-IMPORTINTHEMIDDLE-5826054
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @opentelemetry/sdk-node The new version differs by 25 commits.
  • 48fb158 chore: prepare release 1.15.2/0.41.2 (#4036)
  • ffe641c chore(deps): update all patch versions (#4043)
  • a421318 fix(parseKeyPairsIntoRecord): allow equals in baggage value #3974 (#3975)
  • 3732256 docs(README): clarify browser support (#4037)
  • 5fd656b docs(resources): Fixes detectResources deprecated typos (#4003)
  • b4cda7a chore(deps): update all patch versions (#3997)
  • 4cffe5d fix(sdk-metrics): ignore invalid metric values (#3988)
  • 87fff2e fix(instrumentation-grpc): instrument @ grpc/grpc-js Client methods (#3804)
  • 1a7488e chore(exporter-logs-otlp-http): commit missing generated changes to tsconfig.json (#4032)
  • 0755a5c fix(ci): don't collect coverage for eol tests (#4030)
  • c021b10 fix(core): stop rounding to nearest int in hrTimeTo*seconds() functions (#4014)
  • 2b20565 fix: Add otel-api as dev dep for sandbox tests (#4020)
  • 9f71800 chore: prepare release 1.15.1/0.41.1 (#4016)
  • 0f20b2a Revert tslib #3914 (#4011)
  • 87f21ef chore(deps): update dependency nock to v13.3.2 (#3994)
  • 65483a4 chore(deps): update all patch versions (#3984)
  • 5352cc7 chore: apply update-ts-configs (#3987)
  • 013695d docs(api-logs): add disclaimers (#3979)
  • 552abc8 feat(sdk-node): logs support added (#3969)
  • fc28665 docs(sdk-metrics): add example of exponential histogram metric (#3855)
  • 6d13eb4 chore(deps): update dependency semver to v7.5.4 (#3977)
  • cab31aa chore(deps): update all patch versions (#3972)
  • 68039c5 chore(deps): update dependency eslint to v8.44.0 (#3916)
  • b34c39b chore(deps): update dependency eslint to v8.43.0 (#3929)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Arbitrary Code Execution

@Fbasham Fbasham merged commit 511f82f into main Aug 21, 2023
8 checks passed
@Fbasham Fbasham deleted the snyk-fix-4f11c5069153893dc4eb6930c9be9379 branch August 21, 2023 11:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants