You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
[Blackduck](https://www.blackduck.com/) (an application security testing and software composition analysis tool) reports that gRPC contains a data corruption flaw in its zero-copy transmission functionality. This flaw could be exploited by a remote attacker to cause a denial-of-service (DoS). The opentelemetry-exporter-otlp-proto-grpc library uses gRPC with a flexible dependency: grpcio >= 1.63.2, < 2.0.0. Updating to a newer version (e.g., 1.70.0) of gRPC would resolve the vulnerability.
To Reproduce
Steps to reproduce the behavior:
Perform an analysis using Blackduck.
Expected behavior
The Blackduck analysis should report no vulnerabilities related to gRPC.
Screenshots
Environment:
OS: macOS Sequoia v15.3
Browser: Chrome
Application Version: Deepeval 2.2.7
Python: 3.11
Additional context
A similar PR was made previously: #1228
The text was updated successfully, but these errors were encountered:
Describe the bug
[Blackduck](https://www.blackduck.com/) (an application security testing and software composition analysis tool) reports that gRPC contains a data corruption flaw in its zero-copy transmission functionality. This flaw could be exploited by a remote attacker to cause a denial-of-service (DoS). The
opentelemetry-exporter-otlp-proto-grpc
library usesgRPC
with a flexible dependency:grpcio >= 1.63.2, < 2.0.0
. Updating to a newer version (e.g., 1.70.0) ofgRPC
would resolve the vulnerability.To Reproduce
Steps to reproduce the behavior:
Expected behavior
The Blackduck analysis should report no vulnerabilities related to gRPC.
Screenshots
data:image/s3,"s3://crabby-images/c4296/c4296175533cf05206d5d1bc818495069a1abc5d" alt="Image"
Environment:
Additional context
A similar PR was made previously: #1228
The text was updated successfully, but these errors were encountered: