v2.2.2
Security updates
- Updated
go.etcd.io/etcd/client/pkg/v3to v3.6.14, addressing CVE-2026-73500 (#5527). - Updated
actions/create-github-app-tokento v0.3.1 to prevent generated GitHub App tokens from being exposed in workflow logs (#5531). - Updated
google.golang.org/grpcto v1.83.1, addressing CVE-2026-84304 (#5583, #5584). - Updated
golang.org/x/cryptoto v0.56.0, addressing CVE-2026-78662 and CVE-2026-56855 (#5572). - Updated
golang.org/x/modto v0.40.0 and UInanoidto v3.3.18, addressing CVE-2026-56864, CVE-2026-56865, and CVE-2026-67213 (#5598).
As always, feedback is more than welcome, feel free to open issues/discussions.
You can reach out to the team using:
Docker Images
docker pull grafana/pyroscope:2.2.2