Repository navigation
APPSEC-1202: Suppress CVE-2026-54285 false positive for prometheus tracer modules - #98
Merged
Merged
Conversation
…acer modules OWASP dependency-check incorrectly maps OpenTelemetry CPE findings onto io.prometheus prometheus-metrics-tracer-otel artifacts; add a scoped suppression.
Kunal-8789
requested review from
aaron-steinfeld,
ravisingal and
tim-mwangi
as code owners
October 6, 2026 11:26
ravisingal
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds a scoped OWASP dependency-check suppression in
dependency-check/global-suppressions.xmlfor CVE-2026-54285 onio.prometheus:prometheus-metrics-tracer-otelandprometheus-metrics-tracer-otel-agent.What: dependency-check flags these Prometheus Java client tracer modules (versions including 1.3.5, 1.3.10, and 1.9.0) because they match CPE
cpe:2.3:a:opentelemetry:opentelemetry(OpenTelemetry versioning; affected range below 2.8.0). That CPE does not apply to these Maven artifacts.Why: False positive blocking dependency-check in Hypertrace repos that consume the shared suppressions file from this repository. Maintainer agreed in Slack that suppression is the appropriate handling (APPSEC-1202).
Affected repos (examples): hypertrace/hypertrace-bom (PR 113), hypertrace/service-framework (PR 156), and other repos using this action's global suppressions.
CI evidence: hypertrace-bom workflow run 37420249243 flagged the 1.9.0 tracer jars on the same OpenTelemetry CPE.
Testing
xmllint --noout dependency-check/global-suppressions.xmlChecklist:
Documentation
N/A — suppression note is documented in the XML entry.