Security Alerts — IBM/sarama
Security Alerts — IBM/sarama
Action required: Remediate the alerts listed below before their SLA deadline. This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline. Alerts at or above medium severity will trigger a warning comment before the deadline and repo archiving if unresolved. Low-severity alerts are tracked here for visibility only — they will never trigger warnings or archiving.
Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable Dependabot security updates in your repo settings: Settings → Advanced Security → Dependabot security updates → Enable.
New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: @dnwe
Dependabot Alerts
| Severity | CVE/GHSA | Package | Affected | Patched | Fix PR |
|---|---|---|---|---|---|
| low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | >= 1.5.0, <= 1.44.0 | 1.45.0 | — |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
Source: IBM/sarama