Skip to content

APPSEC-1202: Suppress CVE-2026-54285 false positive for prometheus tracer modules - #98

Merged
Kunal-8789 merged 1 commit into
mainfrom
APPSEC-1202-ghactions-suppress-prom-otel
Oct 6, 2026
Merged

Kunal-8789 merged 1 commit into
mainfrom
APPSEC-1202-ghactions-suppress-prom-otel

Conversation

@Kunal-8789

Copy link
Copy Markdown
Contributor

Description

Adds a scoped OWASP dependency-check suppression in dependency-check/global-suppressions.xml for CVE-2026-54285 on io.prometheus:prometheus-metrics-tracer-otel and prometheus-metrics-tracer-otel-agent.

What: dependency-check flags these Prometheus Java client tracer modules (versions including 1.3.5, 1.3.10, and 1.9.0) because they match CPE cpe:2.3:a:opentelemetry:opentelemetry (OpenTelemetry versioning; affected range below 2.8.0). That CPE does not apply to these Maven artifacts.

Why: False positive blocking dependency-check in Hypertrace repos that consume the shared suppressions file from this repository. Maintainer agreed in Slack that suppression is the appropriate handling (APPSEC-1202).

Affected repos (examples): hypertrace/hypertrace-bom (PR 113), hypertrace/service-framework (PR 156), and other repos using this action's global suppressions.

CI evidence: hypertrace-bom workflow run 37420249243 flagged the 1.9.0 tracer jars on the same OpenTelemetry CPE.

Testing

  • xmllint --noout dependency-check/global-suppressions.xml

Checklist:

  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • Any dependent changes have been merged and published in downstream modules

Documentation

N/A — suppression note is documented in the XML entry.

…acer modules

OWASP dependency-check incorrectly maps OpenTelemetry CPE findings onto
io.prometheus prometheus-metrics-tracer-otel artifacts; add a scoped suppression.
@Kunal-8789
Kunal-8789 merged commit a8f9c84 into main Oct 6, 2026
2 checks passed
@Kunal-8789
Kunal-8789 deleted the APPSEC-1202-ghactions-suppress-prom-otel branch October 6, 2026 11:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants