#3750·sarama

Security Alerts — IBM/sarama

Author: security-ops-bot[bot]Created Sep 18, 2026Updated Sep 18, 2026
Labelssecurity

Security Alerts — IBM/sarama

Action required: Remediate the alerts listed below before their SLA deadline. This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline. Alerts at or above medium severity will trigger a warning comment before the deadline and repo archiving if unresolved. Low-severity alerts are tracked here for visibility only — they will never trigger warnings or archiving.

Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable Dependabot security updates in your repo settings: Settings → Advanced Security → Dependabot security updates → Enable.

New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @dnwe

Dependabot Alerts

Severity CVE/GHSA Package Affected Patched Fix PR
low CVE-2026-81870 go.opentelemetry.io/otel/sdk >= 1.5.0, <= 1.44.0 1.45.0

Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.