gitsafehub
github.com/googlecloudplatform/opentelemetry-samples ↗

googlecloudplatform/opentelemetry-samples

scanned 2026-08-08 · git 6277f32
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies227Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 227 found · 3 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-33186). Fix: Update that package to its patched version.
  • Serious CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
    javascript/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-33186). Fix: Update that package to its patched version.
  • Serious CVE-2026-33186 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
    python/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-33186). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
    golang/metric/otlpgrpc/go.mod
    A package you depend on has a known security hole (CVE-2026-56852). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
    golang/metric/otlpgrpc/go.mod
    A package you depend on has a known security hole (GHSA-hrxh-6v49-42gf). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
    golang/trace/otlpgrpc/go.mod
    A package you depend on has a known security hole (CVE-2026-56852). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-56852 golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
    golang/trace/otlphttp/go.mod
    A package you depend on has a known security hole (CVE-2026-56852). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
    golang/trace/otlphttp/go.mod
    A package you depend on has a known security hole (GHSA-hrxh-6v49-42gf). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-25621 github.com/containerd/containerd: containerd local privilege escalation
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2024-25621). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-46680 github.com/containerd/containerd: containerd: Privilege escalation via incorrect user ID handling
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-46680). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53488 github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-53488). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53489 github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-53489). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-53492 github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-53492). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-64329 github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2025-64329). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-47262 github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-47262). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-50195 github.com/containerd/containerd: containerd: Arbitrary code execution via CRI checkpoint image tag poisoning
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-50195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-15558 docker/cli: Docker CLI for Windows: Privilege escalation via malicious plugin binaries
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2025-15558). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34040 Moby: Moby: Authorization bypass vulnerability
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-34040). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33997 moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installation
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-33997). Fix: Update that package to its patched version.
  • Worth fixing GHSA-pmwq-pjrm-6p5r in-toto-golang and in-toto-python have inconsistent negation behavior
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (GHSA-pmwq-pjrm-6p5r). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33747 BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-33747). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33748 github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-33748). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-35469 Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-35469). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-39882 github.com/open-telemetry/opentelemetry-go: golang: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-39882). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-39882 github.com/open-telemetry/opentelemetry-go: golang: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading
    java/instrumentation-quickstart/integrationtest/go.mod
    A package you depend on has a known security hole (CVE-2026-39882). Fix: Update that package to its patched version.
… 202 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner timed out

Your dependencies cross-checked against the OSV vulnerability database.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OSV-Scanner v1.9.2 · Apache-2.0

error: timeout after 120s

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.