chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285 - #1413

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core
Jul 2, 2026
Merged

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285#1413
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1365
Fixes SOU-1358
Fixes SOU-1359

Addresses CVE-2026-54285 (GHSA-8988-4f7v-96qf) — unbounded memory allocation in @opentelemetry/core's W3C Baggage extract() path. The advisory affects all versions < 2.8.0.

Why a resolutions override

@opentelemetry/core is a transitive dependency requested at several exact pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry, the OpenTelemetry instrumentation packages, and PostHog. A yarn up -R @opentelemetry/core refresh moves the caret ranges to 2.8.0 but cannot get past the exact pins (e.g. @opentelemetry/instrumentation-http@0.211.0 pins @opentelemetry/core@2.5.0).

Since every requested version is in the affected range, this adds a root resolutions override pinning @opentelemetry/core to ^2.8.0, consistent with the existing @opentelemetry/resources override. After the change, yarn why @opentelemetry/core collapses to a single 2.8.0 instance, so Dependabot alert #235 will clear.

Note on duplicate issues

SOU-1358, SOU-1359, and SOU-1365 are all the same CVE against the same package (all tied to Dependabot alert #235). Prior PRs #1340/#1341/#1343 used this identical fix but were closed as mutual duplicates, so nothing ever merged and main still shipped the vulnerable versions. This single PR resolves all three.

Verification

  • yarn install clean; yarn why @opentelemetry/core → single 2.8.0 instance, no < 2.8.0 requesters remain.
  • No direct @opentelemetry/core imports in app source (purely transitive).
  • @sourcebot/backend (the flagged Sentry → instrumentation-http → core path) builds clean with tsc.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated a bundled telemetry-related dependency to a newer version.
    • Added a changelog entry documenting the update.

@opentelemetry/core is a transitive dependency requested at several exact
pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry,
the OpenTelemetry instrumentation packages, and PostHog. The advisory
(GHSA-8988-4f7v-96qf) affects all versions < 2.8.0, so a `yarn up -R`
refresh alone can't reach the patched 2.8.0 past the exact pins.
Add a root `resolutions` override pinning @opentelemetry/core to ^2.8.0,
consistent with the existing @opentelemetry/resources override. After the
change `yarn why @opentelemetry/core` collapses to a single 2.8.0 instance.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 94f1285b-60ae-4429-8178-2682f79d9171

📥 Commits

Reviewing files that changed from the base of the PR and between efcabdf and dded950.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Adds a resolutions entry in package.json pinning @opentelemetry/core to ^2.8.0, with a corresponding CHANGELOG.md entry under [Unreleased]### Fixed documenting the upgrade.

Changes

Dependency resolution update

Layer / File(s)Summary
Pin @opentelemetry/core resolution
package.json, CHANGELOG.md
Adds a resolutions entry pinning @opentelemetry/core to ^2.8.0 and documents this in the changelog's Fixed section.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/opentelemetry-core

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@github-actions

github-actionsBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2221
Resolved (non-standard)12
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.11(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (12)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry (package.json license field)
element-source0.0.3UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
khroma2.1.0UNKNOWNMITGitHub repo (license file at fabiospampinato/khroma)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry (package.json license field)
map-stream0.1.0UNKNOWNMITnpm registry (package.json license field)
memorystream0.3.1UNKNOWNMITnpm registry (licenses array object, extracted type)
pause-stream0.0.11["MIT","Apache2"]MITextracted from object (license field ["MIT","Apache2"], primary type MIT)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file at PostHog/posthog-js)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file at ogt/valid-url)

@brendan-kellam
brendan-kellam merged commit fd6720f into mainJul 2, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/opentelemetry-core branch July 2, 2026 02:32
@github-actionsgithub-actionsBot mentioned this pull request Jul 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285 - #1413

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core
Jul 2, 2026
Merged

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285#1413
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1365
Fixes SOU-1358
Fixes SOU-1359

Addresses CVE-2026-54285 (GHSA-8988-4f7v-96qf) — unbounded memory allocation in @opentelemetry/core's W3C Baggage extract() path. The advisory affects all versions < 2.8.0.

Why a resolutions override

@opentelemetry/core is a transitive dependency requested at several exact pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry, the OpenTelemetry instrumentation packages, and PostHog. A yarn up -R @opentelemetry/core refresh moves the caret ranges to 2.8.0 but cannot get past the exact pins (e.g. @opentelemetry/instrumentation-http@0.211.0 pins @opentelemetry/core@2.5.0).

Since every requested version is in the affected range, this adds a root resolutions override pinning @opentelemetry/core to ^2.8.0, consistent with the existing @opentelemetry/resources override. After the change, yarn why @opentelemetry/core collapses to a single 2.8.0 instance, so Dependabot alert #235 will clear.

Note on duplicate issues

SOU-1358, SOU-1359, and SOU-1365 are all the same CVE against the same package (all tied to Dependabot alert #235). Prior PRs #1340/#1341/#1343 used this identical fix but were closed as mutual duplicates, so nothing ever merged and main still shipped the vulnerable versions. This single PR resolves all three.

Verification

  • yarn install clean; yarn why @opentelemetry/core → single 2.8.0 instance, no < 2.8.0 requesters remain.
  • No direct @opentelemetry/core imports in app source (purely transitive).
  • @sourcebot/backend (the flagged Sentry → instrumentation-http → core path) builds clean with tsc.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated a bundled telemetry-related dependency to a newer version.
    • Added a changelog entry documenting the update.

@opentelemetry/core is a transitive dependency requested at several exact
pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry,
the OpenTelemetry instrumentation packages, and PostHog. The advisory
(GHSA-8988-4f7v-96qf) affects all versions < 2.8.0, so a `yarn up -R`
refresh alone can't reach the patched 2.8.0 past the exact pins.
Add a root `resolutions` override pinning @opentelemetry/core to ^2.8.0,
consistent with the existing @opentelemetry/resources override. After the
change `yarn why @opentelemetry/core` collapses to a single 2.8.0 instance.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 94f1285b-60ae-4429-8178-2682f79d9171

📥 Commits

Reviewing files that changed from the base of the PR and between efcabdf and dded950.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Adds a resolutions entry in package.json pinning @opentelemetry/core to ^2.8.0, with a corresponding CHANGELOG.md entry under [Unreleased]### Fixed documenting the upgrade.

Changes

Dependency resolution update

Layer / File(s)Summary
Pin @opentelemetry/core resolution
package.json, CHANGELOG.md
Adds a resolutions entry pinning @opentelemetry/core to ^2.8.0 and documents this in the changelog's Fixed section.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/opentelemetry-core

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@github-actions

github-actionsBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2221
Resolved (non-standard)12
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.11(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (12)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry (package.json license field)
element-source0.0.3UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
khroma2.1.0UNKNOWNMITGitHub repo (license file at fabiospampinato/khroma)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry (package.json license field)
map-stream0.1.0UNKNOWNMITnpm registry (package.json license field)
memorystream0.3.1UNKNOWNMITnpm registry (licenses array object, extracted type)
pause-stream0.0.11["MIT","Apache2"]MITextracted from object (license field ["MIT","Apache2"], primary type MIT)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file at PostHog/posthog-js)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file at ogt/valid-url)

@brendan-kellam
brendan-kellam merged commit fd6720f into mainJul 2, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/opentelemetry-core branch July 2, 2026 02:32
@github-actionsgithub-actionsBot mentioned this pull request Jul 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285 - #1413

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core
Jul 2, 2026
Merged

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285#1413
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1365
Fixes SOU-1358
Fixes SOU-1359

Addresses CVE-2026-54285 (GHSA-8988-4f7v-96qf) — unbounded memory allocation in @opentelemetry/core's W3C Baggage extract() path. The advisory affects all versions < 2.8.0.

Why a resolutions override

@opentelemetry/core is a transitive dependency requested at several exact pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry, the OpenTelemetry instrumentation packages, and PostHog. A yarn up -R @opentelemetry/core refresh moves the caret ranges to 2.8.0 but cannot get past the exact pins (e.g. @opentelemetry/instrumentation-http@0.211.0 pins @opentelemetry/core@2.5.0).

Since every requested version is in the affected range, this adds a root resolutions override pinning @opentelemetry/core to ^2.8.0, consistent with the existing @opentelemetry/resources override. After the change, yarn why @opentelemetry/core collapses to a single 2.8.0 instance, so Dependabot alert #235 will clear.

Note on duplicate issues

SOU-1358, SOU-1359, and SOU-1365 are all the same CVE against the same package (all tied to Dependabot alert #235). Prior PRs #1340/#1341/#1343 used this identical fix but were closed as mutual duplicates, so nothing ever merged and main still shipped the vulnerable versions. This single PR resolves all three.

Verification

  • yarn install clean; yarn why @opentelemetry/core → single 2.8.0 instance, no < 2.8.0 requesters remain.
  • No direct @opentelemetry/core imports in app source (purely transitive).
  • @sourcebot/backend (the flagged Sentry → instrumentation-http → core path) builds clean with tsc.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated a bundled telemetry-related dependency to a newer version.
    • Added a changelog entry documenting the update.

@opentelemetry/core is a transitive dependency requested at several exact
pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry,
the OpenTelemetry instrumentation packages, and PostHog. The advisory
(GHSA-8988-4f7v-96qf) affects all versions < 2.8.0, so a `yarn up -R`
refresh alone can't reach the patched 2.8.0 past the exact pins.
Add a root `resolutions` override pinning @opentelemetry/core to ^2.8.0,
consistent with the existing @opentelemetry/resources override. After the
change `yarn why @opentelemetry/core` collapses to a single 2.8.0 instance.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 94f1285b-60ae-4429-8178-2682f79d9171

📥 Commits

Reviewing files that changed from the base of the PR and between efcabdf and dded950.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Adds a resolutions entry in package.json pinning @opentelemetry/core to ^2.8.0, with a corresponding CHANGELOG.md entry under [Unreleased]### Fixed documenting the upgrade.

Changes

Dependency resolution update

Layer / File(s)Summary
Pin @opentelemetry/core resolution
package.json, CHANGELOG.md
Adds a resolutions entry pinning @opentelemetry/core to ^2.8.0 and documents this in the changelog's Fixed section.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/opentelemetry-core

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@github-actions

github-actionsBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2221
Resolved (non-standard)12
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.11(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (12)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry (package.json license field)
element-source0.0.3UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
khroma2.1.0UNKNOWNMITGitHub repo (license file at fabiospampinato/khroma)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry (package.json license field)
map-stream0.1.0UNKNOWNMITnpm registry (package.json license field)
memorystream0.3.1UNKNOWNMITnpm registry (licenses array object, extracted type)
pause-stream0.0.11["MIT","Apache2"]MITextracted from object (license field ["MIT","Apache2"], primary type MIT)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file at PostHog/posthog-js)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file at ogt/valid-url)

@brendan-kellam
brendan-kellam merged commit fd6720f into mainJul 2, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/opentelemetry-core branch July 2, 2026 02:32
@github-actionsgithub-actionsBot mentioned this pull request Jul 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285 - #1413

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core
Jul 2, 2026
Merged

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285#1413
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1365
Fixes SOU-1358
Fixes SOU-1359

Addresses CVE-2026-54285 (GHSA-8988-4f7v-96qf) — unbounded memory allocation in @opentelemetry/core's W3C Baggage extract() path. The advisory affects all versions < 2.8.0.

Why a resolutions override

@opentelemetry/core is a transitive dependency requested at several exact pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry, the OpenTelemetry instrumentation packages, and PostHog. A yarn up -R @opentelemetry/core refresh moves the caret ranges to 2.8.0 but cannot get past the exact pins (e.g. @opentelemetry/instrumentation-http@0.211.0 pins @opentelemetry/core@2.5.0).

Since every requested version is in the affected range, this adds a root resolutions override pinning @opentelemetry/core to ^2.8.0, consistent with the existing @opentelemetry/resources override. After the change, yarn why @opentelemetry/core collapses to a single 2.8.0 instance, so Dependabot alert #235 will clear.

Note on duplicate issues

SOU-1358, SOU-1359, and SOU-1365 are all the same CVE against the same package (all tied to Dependabot alert #235). Prior PRs #1340/#1341/#1343 used this identical fix but were closed as mutual duplicates, so nothing ever merged and main still shipped the vulnerable versions. This single PR resolves all three.

Verification

  • yarn install clean; yarn why @opentelemetry/core → single 2.8.0 instance, no < 2.8.0 requesters remain.
  • No direct @opentelemetry/core imports in app source (purely transitive).
  • @sourcebot/backend (the flagged Sentry → instrumentation-http → core path) builds clean with tsc.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated a bundled telemetry-related dependency to a newer version.
    • Added a changelog entry documenting the update.

@opentelemetry/core is a transitive dependency requested at several exact
pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry,
the OpenTelemetry instrumentation packages, and PostHog. The advisory
(GHSA-8988-4f7v-96qf) affects all versions < 2.8.0, so a `yarn up -R`
refresh alone can't reach the patched 2.8.0 past the exact pins.
Add a root `resolutions` override pinning @opentelemetry/core to ^2.8.0,
consistent with the existing @opentelemetry/resources override. After the
change `yarn why @opentelemetry/core` collapses to a single 2.8.0 instance.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 94f1285b-60ae-4429-8178-2682f79d9171

📥 Commits

Reviewing files that changed from the base of the PR and between efcabdf and dded950.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Adds a resolutions entry in package.json pinning @opentelemetry/core to ^2.8.0, with a corresponding CHANGELOG.md entry under [Unreleased]### Fixed documenting the upgrade.

Changes

Dependency resolution update

Layer / File(s)Summary
Pin @opentelemetry/core resolution
package.json, CHANGELOG.md
Adds a resolutions entry pinning @opentelemetry/core to ^2.8.0 and documents this in the changelog's Fixed section.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/opentelemetry-core

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@github-actions

github-actionsBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2221
Resolved (non-standard)12
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.11(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (12)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry (package.json license field)
element-source0.0.3UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
khroma2.1.0UNKNOWNMITGitHub repo (license file at fabiospampinato/khroma)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry (package.json license field)
map-stream0.1.0UNKNOWNMITnpm registry (package.json license field)
memorystream0.3.1UNKNOWNMITnpm registry (licenses array object, extracted type)
pause-stream0.0.11["MIT","Apache2"]MITextracted from object (license field ["MIT","Apache2"], primary type MIT)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file at PostHog/posthog-js)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file at ogt/valid-url)

@brendan-kellam
brendan-kellam merged commit fd6720f into mainJul 2, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/opentelemetry-core branch July 2, 2026 02:32
@github-actionsgithub-actionsBot mentioned this pull request Jul 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285 - #1413

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core
Jul 2, 2026
Merged

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285#1413
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1365
Fixes SOU-1358
Fixes SOU-1359

Addresses CVE-2026-54285 (GHSA-8988-4f7v-96qf) — unbounded memory allocation in @opentelemetry/core's W3C Baggage extract() path. The advisory affects all versions < 2.8.0.

Why a resolutions override

@opentelemetry/core is a transitive dependency requested at several exact pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry, the OpenTelemetry instrumentation packages, and PostHog. A yarn up -R @opentelemetry/core refresh moves the caret ranges to 2.8.0 but cannot get past the exact pins (e.g. @opentelemetry/instrumentation-http@0.211.0 pins @opentelemetry/core@2.5.0).

Since every requested version is in the affected range, this adds a root resolutions override pinning @opentelemetry/core to ^2.8.0, consistent with the existing @opentelemetry/resources override. After the change, yarn why @opentelemetry/core collapses to a single 2.8.0 instance, so Dependabot alert #235 will clear.

Note on duplicate issues

SOU-1358, SOU-1359, and SOU-1365 are all the same CVE against the same package (all tied to Dependabot alert #235). Prior PRs #1340/#1341/#1343 used this identical fix but were closed as mutual duplicates, so nothing ever merged and main still shipped the vulnerable versions. This single PR resolves all three.

Verification

  • yarn install clean; yarn why @opentelemetry/core → single 2.8.0 instance, no < 2.8.0 requesters remain.
  • No direct @opentelemetry/core imports in app source (purely transitive).
  • @sourcebot/backend (the flagged Sentry → instrumentation-http → core path) builds clean with tsc.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated a bundled telemetry-related dependency to a newer version.
    • Added a changelog entry documenting the update.

@opentelemetry/core is a transitive dependency requested at several exact
pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry,
the OpenTelemetry instrumentation packages, and PostHog. The advisory
(GHSA-8988-4f7v-96qf) affects all versions < 2.8.0, so a `yarn up -R`
refresh alone can't reach the patched 2.8.0 past the exact pins.
Add a root `resolutions` override pinning @opentelemetry/core to ^2.8.0,
consistent with the existing @opentelemetry/resources override. After the
change `yarn why @opentelemetry/core` collapses to a single 2.8.0 instance.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 94f1285b-60ae-4429-8178-2682f79d9171

📥 Commits

Reviewing files that changed from the base of the PR and between efcabdf and dded950.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Adds a resolutions entry in package.json pinning @opentelemetry/core to ^2.8.0, with a corresponding CHANGELOG.md entry under [Unreleased]### Fixed documenting the upgrade.

Changes

Dependency resolution update

Layer / File(s)Summary
Pin @opentelemetry/core resolution
package.json, CHANGELOG.md
Adds a resolutions entry pinning @opentelemetry/core to ^2.8.0 and documents this in the changelog's Fixed section.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/opentelemetry-core

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@github-actions

github-actionsBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2221
Resolved (non-standard)12
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.11(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (12)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry (package.json license field)
element-source0.0.3UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
khroma2.1.0UNKNOWNMITGitHub repo (license file at fabiospampinato/khroma)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry (package.json license field)
map-stream0.1.0UNKNOWNMITnpm registry (package.json license field)
memorystream0.3.1UNKNOWNMITnpm registry (licenses array object, extracted type)
pause-stream0.0.11["MIT","Apache2"]MITextracted from object (license field ["MIT","Apache2"], primary type MIT)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file at PostHog/posthog-js)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file at ogt/valid-url)

@brendan-kellam
brendan-kellam merged commit fd6720f into mainJul 2, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/opentelemetry-core branch July 2, 2026 02:32
@github-actionsgithub-actionsBot mentioned this pull request Jul 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285 - #1413

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core
Jul 2, 2026
Merged

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285#1413
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1365
Fixes SOU-1358
Fixes SOU-1359

Addresses CVE-2026-54285 (GHSA-8988-4f7v-96qf) — unbounded memory allocation in @opentelemetry/core's W3C Baggage extract() path. The advisory affects all versions < 2.8.0.

Why a resolutions override

@opentelemetry/core is a transitive dependency requested at several exact pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry, the OpenTelemetry instrumentation packages, and PostHog. A yarn up -R @opentelemetry/core refresh moves the caret ranges to 2.8.0 but cannot get past the exact pins (e.g. @opentelemetry/instrumentation-http@0.211.0 pins @opentelemetry/core@2.5.0).

Since every requested version is in the affected range, this adds a root resolutions override pinning @opentelemetry/core to ^2.8.0, consistent with the existing @opentelemetry/resources override. After the change, yarn why @opentelemetry/core collapses to a single 2.8.0 instance, so Dependabot alert #235 will clear.

Note on duplicate issues

SOU-1358, SOU-1359, and SOU-1365 are all the same CVE against the same package (all tied to Dependabot alert #235). Prior PRs #1340/#1341/#1343 used this identical fix but were closed as mutual duplicates, so nothing ever merged and main still shipped the vulnerable versions. This single PR resolves all three.

Verification

  • yarn install clean; yarn why @opentelemetry/core → single 2.8.0 instance, no < 2.8.0 requesters remain.
  • No direct @opentelemetry/core imports in app source (purely transitive).
  • @sourcebot/backend (the flagged Sentry → instrumentation-http → core path) builds clean with tsc.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated a bundled telemetry-related dependency to a newer version.
    • Added a changelog entry documenting the update.

@opentelemetry/core is a transitive dependency requested at several exact
pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry,
the OpenTelemetry instrumentation packages, and PostHog. The advisory
(GHSA-8988-4f7v-96qf) affects all versions < 2.8.0, so a `yarn up -R`
refresh alone can't reach the patched 2.8.0 past the exact pins.
Add a root `resolutions` override pinning @opentelemetry/core to ^2.8.0,
consistent with the existing @opentelemetry/resources override. After the
change `yarn why @opentelemetry/core` collapses to a single 2.8.0 instance.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 94f1285b-60ae-4429-8178-2682f79d9171

📥 Commits

Reviewing files that changed from the base of the PR and between efcabdf and dded950.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Adds a resolutions entry in package.json pinning @opentelemetry/core to ^2.8.0, with a corresponding CHANGELOG.md entry under [Unreleased]### Fixed documenting the upgrade.

Changes

Dependency resolution update

Layer / File(s)Summary
Pin @opentelemetry/core resolution
package.json, CHANGELOG.md
Adds a resolutions entry pinning @opentelemetry/core to ^2.8.0 and documents this in the changelog's Fixed section.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/opentelemetry-core

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@github-actions

github-actionsBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2221
Resolved (non-standard)12
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.11(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (12)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry (package.json license field)
element-source0.0.3UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
khroma2.1.0UNKNOWNMITGitHub repo (license file at fabiospampinato/khroma)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry (package.json license field)
map-stream0.1.0UNKNOWNMITnpm registry (package.json license field)
memorystream0.3.1UNKNOWNMITnpm registry (licenses array object, extracted type)
pause-stream0.0.11["MIT","Apache2"]MITextracted from object (license field ["MIT","Apache2"], primary type MIT)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file at PostHog/posthog-js)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file at ogt/valid-url)

@brendan-kellam
brendan-kellam merged commit fd6720f into mainJul 2, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/opentelemetry-core branch July 2, 2026 02:32
@github-actionsgithub-actionsBot mentioned this pull request Jul 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285 - #1413

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core
Jul 2, 2026
Merged

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285#1413
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1365
Fixes SOU-1358
Fixes SOU-1359

Addresses CVE-2026-54285 (GHSA-8988-4f7v-96qf) — unbounded memory allocation in @opentelemetry/core's W3C Baggage extract() path. The advisory affects all versions < 2.8.0.

Why a resolutions override

@opentelemetry/core is a transitive dependency requested at several exact pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry, the OpenTelemetry instrumentation packages, and PostHog. A yarn up -R @opentelemetry/core refresh moves the caret ranges to 2.8.0 but cannot get past the exact pins (e.g. @opentelemetry/instrumentation-http@0.211.0 pins @opentelemetry/core@2.5.0).

Since every requested version is in the affected range, this adds a root resolutions override pinning @opentelemetry/core to ^2.8.0, consistent with the existing @opentelemetry/resources override. After the change, yarn why @opentelemetry/core collapses to a single 2.8.0 instance, so Dependabot alert #235 will clear.

Note on duplicate issues

SOU-1358, SOU-1359, and SOU-1365 are all the same CVE against the same package (all tied to Dependabot alert #235). Prior PRs #1340/#1341/#1343 used this identical fix but were closed as mutual duplicates, so nothing ever merged and main still shipped the vulnerable versions. This single PR resolves all three.

Verification

  • yarn install clean; yarn why @opentelemetry/core → single 2.8.0 instance, no < 2.8.0 requesters remain.
  • No direct @opentelemetry/core imports in app source (purely transitive).
  • @sourcebot/backend (the flagged Sentry → instrumentation-http → core path) builds clean with tsc.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated a bundled telemetry-related dependency to a newer version.
    • Added a changelog entry documenting the update.

@opentelemetry/core is a transitive dependency requested at several exact
pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry,
the OpenTelemetry instrumentation packages, and PostHog. The advisory
(GHSA-8988-4f7v-96qf) affects all versions < 2.8.0, so a `yarn up -R`
refresh alone can't reach the patched 2.8.0 past the exact pins.
Add a root `resolutions` override pinning @opentelemetry/core to ^2.8.0,
consistent with the existing @opentelemetry/resources override. After the
change `yarn why @opentelemetry/core` collapses to a single 2.8.0 instance.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 94f1285b-60ae-4429-8178-2682f79d9171

📥 Commits

Reviewing files that changed from the base of the PR and between efcabdf and dded950.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Adds a resolutions entry in package.json pinning @opentelemetry/core to ^2.8.0, with a corresponding CHANGELOG.md entry under [Unreleased]### Fixed documenting the upgrade.

Changes

Dependency resolution update

Layer / File(s)Summary
Pin @opentelemetry/core resolution
package.json, CHANGELOG.md
Adds a resolutions entry pinning @opentelemetry/core to ^2.8.0 and documents this in the changelog's Fixed section.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/opentelemetry-core

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@github-actions

github-actionsBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2221
Resolved (non-standard)12
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.11(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (12)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry (package.json license field)
element-source0.0.3UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
khroma2.1.0UNKNOWNMITGitHub repo (license file at fabiospampinato/khroma)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry (package.json license field)
map-stream0.1.0UNKNOWNMITnpm registry (package.json license field)
memorystream0.3.1UNKNOWNMITnpm registry (licenses array object, extracted type)
pause-stream0.0.11["MIT","Apache2"]MITextracted from object (license field ["MIT","Apache2"], primary type MIT)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file at PostHog/posthog-js)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file at ogt/valid-url)

@brendan-kellam
brendan-kellam merged commit fd6720f into mainJul 2, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/opentelemetry-core branch July 2, 2026 02:32
@github-actionsgithub-actionsBot mentioned this pull request Jul 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285 - #1413

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core
Jul 2, 2026
Merged

chore: upgrade @opentelemetry/core to ^2.8.0 to address CVE-2026-54285#1413
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/opentelemetry-core

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1365
Fixes SOU-1358
Fixes SOU-1359

Addresses CVE-2026-54285 (GHSA-8988-4f7v-96qf) — unbounded memory allocation in @opentelemetry/core's W3C Baggage extract() path. The advisory affects all versions < 2.8.0.

Why a resolutions override

@opentelemetry/core is a transitive dependency requested at several exact pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry, the OpenTelemetry instrumentation packages, and PostHog. A yarn up -R @opentelemetry/core refresh moves the caret ranges to 2.8.0 but cannot get past the exact pins (e.g. @opentelemetry/instrumentation-http@0.211.0 pins @opentelemetry/core@2.5.0).

Since every requested version is in the affected range, this adds a root resolutions override pinning @opentelemetry/core to ^2.8.0, consistent with the existing @opentelemetry/resources override. After the change, yarn why @opentelemetry/core collapses to a single 2.8.0 instance, so Dependabot alert #235 will clear.

Note on duplicate issues

SOU-1358, SOU-1359, and SOU-1365 are all the same CVE against the same package (all tied to Dependabot alert #235). Prior PRs #1340/#1341/#1343 used this identical fix but were closed as mutual duplicates, so nothing ever merged and main still shipped the vulnerable versions. This single PR resolves all three.

Verification

  • yarn install clean; yarn why @opentelemetry/core → single 2.8.0 instance, no < 2.8.0 requesters remain.
  • No direct @opentelemetry/core imports in app source (purely transitive).
  • @sourcebot/backend (the flagged Sentry → instrumentation-http → core path) builds clean with tsc.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated a bundled telemetry-related dependency to a newer version.
    • Added a changelog entry documenting the update.

@opentelemetry/core is a transitive dependency requested at several exact
pins (2.5.0, 2.5.1, 2.2.0, 2.0.1) and ranges (^2.5.1, ^2.0.0) via Sentry,
the OpenTelemetry instrumentation packages, and PostHog. The advisory
(GHSA-8988-4f7v-96qf) affects all versions < 2.8.0, so a `yarn up -R`
refresh alone can't reach the patched 2.8.0 past the exact pins.
Add a root `resolutions` override pinning @opentelemetry/core to ^2.8.0,
consistent with the existing @opentelemetry/resources override. After the
change `yarn why @opentelemetry/core` collapses to a single 2.8.0 instance.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 94f1285b-60ae-4429-8178-2682f79d9171

📥 Commits

Reviewing files that changed from the base of the PR and between efcabdf and dded950.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (2)
  • CHANGELOG.md
  • package.json

Walkthrough

Adds a resolutions entry in package.json pinning @opentelemetry/core to ^2.8.0, with a corresponding CHANGELOG.md entry under [Unreleased]### Fixed documenting the upgrade.

Changes

Dependency resolution update

Layer / File(s)Summary
Pin @opentelemetry/core resolution
package.json, CHANGELOG.md
Adds a resolutions entry pinning @opentelemetry/core to ^2.8.0 and documents this in the changelog's Fixed section.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cve/opentelemetry-core

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
{}

@github-actions

github-actionsBot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2221
Resolved (non-standard)12
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.11(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (12)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/cli0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
@react-grab/mcp0.1.29UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry (package.json license field)
element-source0.0.3UNKNOWNMITGitHub repo (LICENSE file in published package tarball)
khroma2.1.0UNKNOWNMITGitHub repo (license file at fabiospampinato/khroma)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry (package.json license field)
map-stream0.1.0UNKNOWNMITnpm registry (package.json license field)
memorystream0.3.1UNKNOWNMITnpm registry (licenses array object, extracted type)
pause-stream0.0.11["MIT","Apache2"]MITextracted from object (license field ["MIT","Apache2"], primary type MIT)
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0GitHub repo (LICENSE file at PostHog/posthog-js)
valid-url1.0.9UNKNOWNMITGitHub repo (LICENSE file at ogt/valid-url)

@brendan-kellam
brendan-kellam merged commit fd6720f into mainJul 2, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/opentelemetry-core branch July 2, 2026 02:32
@github-actionsgithub-actionsBot mentioned this pull request Jul 2, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam