Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Broken "cloud.google.com/go/compute/metadata" dependency #1555

Conversation

dualBreath
Copy link
Contributor

Description

go mod tidy doesn't work due to problematic dependency "cloud.google.com/go/compute/metadata"

Issue link

#1551

How Has This Been Tested?

  • Added unit testing to cover
  • Tested manually
  • Tested by integration testing
  • Have not tested

Types of changes

  • Bug fix
  • New functionality
  • Documentation
  • Refactoring
  • CI

…dency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Copy link

codecov bot commented Nov 13, 2023

Codecov Report

All modified and coverable lines are covered by tests ✅

❗ No coverage uploaded for pull request base (main@c7c00eb). Click here to learn what that means.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1555   +/-   ##
=======================================
  Coverage        ?   66.86%           
=======================================
  Files           ?      259           
  Lines           ?    12327           
  Branches        ?        0           
=======================================
  Hits            ?     8242           
  Misses          ?     3566           
  Partials        ?      519           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

go.opentelemetry.io/otel/sdk/metric v1.19.0-rc.1
go.opentelemetry.io/otel/trace v1.19.0-rc.1
go.opentelemetry.io/otel v1.20.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v0.43.0
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This version contains CVE-2023-47108, could you update otel to v0.46.0?

Suggested change
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v0.43.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v0.46.0

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Have you specified the correct dependency? It is the latest one:
Screenshot 2023-11-13 at 16 11 27

Copy link
Contributor Author

@dualBreath dualBreath Nov 13, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've updated go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc to version v0.46.0. Hope this will solve the problem

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to break the build. I'll revert this change and try to update the version in a separate task.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've updated go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc to version v0.46.0 and disabled linter

@dualBreath
Copy link
Contributor Author

Alexander Peretyatko added 3 commits November 13, 2023 16:21
Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
…olang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
@denis-tingaikin denis-tingaikin merged commit 70f3d88 into networkservicemesh:main Nov 14, 2023
17 checks passed
nsmbot pushed a commit to networkservicemesh/cmd-csi-driver that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-map-ip-k8s that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-admission-webhook-k8s that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-ipam-vl3 that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/sdk-kernel that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-registry-proxy-dns that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nse-vfio that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/sdk-k8s that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nsc-init that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-registry-memory that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nsmgr that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nse-remote-vlan that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-cluster-info-k8s that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nsmgr-proxy that referenced this pull request Nov 14, 2023
…k@main

PR link: networkservicemesh/sdk#1555

Commit: 70f3d88
Author: Alexander Peretyatko
Date: 2023-11-14 21:15:17 +0700
Message:
  - Broken "cloud.google.com/go/compute/metadata" dependency (#1555)
* Task:1551 Fix problem with cloud.google.com/go/compute/metadata dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update vulnerable dependency

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 revert version update that brokes the build

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

* Task:1551 Update go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc version

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>

---------

Signed-off-by: Alexander Peretyatko <alexander.peretyatko@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants