envoyproxy / go-control-plane

Go implementation of data-plane-api
Apache License 2.0
1.48k stars 505 forks source link

Vulnerabilities in opencensus-proto dependency #952

Open GalBr opened 3 weeks ago

GalBr commented 3 weeks ago

Our security scan flags go-control-plane because of 3 vulnerabilities found in the opencensus-proto dependency:

opencensus-proto is archived and they suggest moving to OpenTelemetry instead.

Is there a plan to solve these issues by moving to OpenTelemetry or by getting rid of the opencensus-proto dependency?