Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Latest Otel JS Release #768

Closed
kumachop2 opened this issue Jul 31, 2023 · 15 comments
Closed

Latest Otel JS Release #768

kumachop2 opened this issue Jul 31, 2023 · 15 comments

Comments

@kumachop2
Copy link

kumachop2 commented Jul 31, 2023

I'm looking for latest Otel JS version that should be bundle with Pull Request #753 changes. Please do advice.

@seemk
Copy link
Collaborator

seemk commented Aug 1, 2023

Hi, 2.3.0 has been released now

@seemk seemk closed this as completed Aug 2, 2023
@kumachop2
Copy link
Author

@seemk Looks like package referencing to old version. Here is screens. Please check and advice.

v2.2.4:
image

======================================================
v2.3.0:

image

@kumachop2
Copy link
Author

@seemk upon further analysis the latest version 2.3.0, I assume below modules protobufjs still referring to before 7.2.4 versions

image

@kumachop2
Copy link
Author

kumachop2 commented Aug 2, 2023 via email

@seemk seemk reopened this Aug 3, 2023
@seemk
Copy link
Collaborator

seemk commented Aug 3, 2023

Can you elaborate what's the current issue?

@kumachop2
Copy link
Author

kumachop2 commented Aug 3, 2023 via email

@seemk
Copy link
Collaborator

seemk commented Aug 3, 2023

Can you show the security issue? From the screens it looks everything is using 7.2.4

@seemk
Copy link
Collaborator

seemk commented Aug 3, 2023

You can check here that everything is using 7.2.4: https://npmgraph.js.org/?q=%40splunk%2Fotel

@kumachop2
Copy link
Author

kumachop2 commented Aug 3, 2023

@seemk Please find below screens that referring old versions in package-lock.json

image

image

@kumachop2
Copy link
Author

@seemk I did performed NexusIQ scanning against Otel JS v2.4.0 but no luck, still policy violation reported for protobufjs : 7.2.4

@seemk
Copy link
Collaborator

seemk commented Aug 23, 2023

Is this the same CVE as in this issue? protobufjs/protobuf.js#1918

@kumachop2
Copy link
Author

kumachop2 commented Aug 23, 2023 via email

@kumachop2
Copy link
Author

kumachop2 commented Dec 14, 2023

@seemk Please do provide timelines for bumping protobuf ( source & dist files) to 7.2.5 to address CVE. I did quick validation https://npmgraph.js.org/?q=%40splunk%2Fotel and every thing pointing to 7.25 but latest 2.6.0 version package.json references to 7.2.4. Appreciate your response.

@seemk
Copy link
Collaborator

seemk commented Dec 19, 2023

@kumachop2 Version 2.6.1 of @splunk/otel now has protobuf.js 7.2.5

@seemk seemk closed this as completed Dec 19, 2023
@kumachop2
Copy link
Author

@seemk Thank You for the upgrade and noticed still package-lock.json have protobuf.js 7.2.4 & 7.2.3 references.

"protobufjs": "^7.2.3"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants