Package
tempo-fips-2.8-vulture
Component
github.com/prometheus/prometheus
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Remediating this CVE requires bumping github.com/prometheus/prometheus to v0.311.3, which removed the storage/remote/otlptranslator/prometheus and tsdb/errors packages. Tempo source directly imports tsdb/errors (modules/generator/storage/instance.go), so the bump cannot be applied cleanly until upstream Tempo migrates off the removed package.
Status