Skip to content

High severity vulnerability in v1.29.4 #9494

@roei-levi-qedma

Description

@roei-levi-qedma

Expected Behavior

Update dependencies to resolve CVEs of HIGH severity.

Actual Behavior

Following CVEs have been found in temporalio/server:1.29.4

Steps to Reproduce the Problem

The following CVEs were found in dependencies:

CVE Severity Package Installed Version Fixed Version
CVE-2026-26958 LOW filippo.io/edwards25519 1.1.0 1.1.1
CVE-2026-24051 HIGH go.opentelemetry.io/otel/sdk 1.34.0 1.40.0

Specifications

  • Version: v1.29.4
  • Platform: doesn't matter.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions