v2.1.2
Security updates
- Updated
github.com/getkin/kin-openapito v0.144.0, addressing GHSA-r277-6w6q-xmqw (#5417). - Updated
google.golang.org/grpcto v1.82.1, addressing GHSA-hrxh-6v49-42gf (#5394, #5395). - Updated
golang.org/x/textto v0.39.0, addressing CVE-2026-56852 (#5387, #5389). - Updated
golang.org/x/netto v0.56.0, addressing CVE-2026-46600 (#5386, #5388). - Updated
github.com/klauspost/compressto v1.18.7 (#5430). - UI: bumped
tar,js-yaml, andbrace-expansion, addressing CVE-2026-59871, CVE-2026-59873, CVE-2026-59874, and CVE-2026-59869 (#5413, #5423). - UI: bumped
brace-expansionto 1.1.18 and 5.0.9, addressing CVE-2026-14257 and CVE-2026-69152 (#5466, #5470). - UI: refreshed the Yarn lockfile, removing the vulnerable
ip-addresspackage (CVE-2026-69192) and updatingpostcss(GHSA-r28c-9q8g-f849) (#5420).
Changelog
As always, feedback is more than welcome, feel free to open issues/discussions.
You can reach out to the team using:
Docker Images
docker pull grafana/pyroscope:2.1.2