Package
grafana-pyroscope-1.13
Component
google.golang.org/grpc
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Clearing this vulnerability requires bumping grpc-go past 1.83.0, which pulls in an OpenTelemetry otlp proto dependency that removed profiling API fields the package's OTLP ingestion code still uses directly. No release in the package's current minor version line adapts to the renamed/removed fields, so grpc-go cannot be upgraded without an incompatible build break. Resolution is pending either an upstream code update or a grpc-go release that fixes this vulnerability without requiring that proto bump.
Status