Repository navigation
0.3.404
0.3.404
Pins snowplow and snowplow-crd to 1.12.37, carrying two unreleased security fixes:
- Secret data leaked into OpenTelemetry logs. The debug-level "resolved api" log emitted every stage body, including Secret values, into
otel_logs. Now suppressed. - Credentials leaked in spans and logs. URLs with embedded credentials were not scrubbed before being recorded in outbound client spans (
url.full) or log fields. A schemeless URL bypassed the sanitiser entirely —url.Parsetreated the leading token as the scheme, leaving noUserfield to clear, so passwords round-tripped verbatim.
Also included in 1.12.37 (no installer action required): re-mint warmth gating fix, live-refresh no longer dropping a quiet key's last change, and invalidation-to-fresh measurement.
One file changed: chart/files/component-pins.yaml.