open-telemetry / opentelemetry-cpp

The OpenTelemetry C++ Client
https://opentelemetry.io/
Apache License 2.0
890 stars 425 forks source link

[SECURITY] Audit the opentelemetry-cpp repository for supply chain attacks #2623

Open marcalff opened 7 months ago

marcalff commented 7 months ago

In light of the xz attack:

audit the opentelemetry-cpp repository for possible attack vectors.

Full list of checks to be determined.

To start with:

Subtasks:

marcalff commented 7 months ago

Upstream unnecessary permission found, seen with github submodules:

github-actions[bot] commented 5 months ago

This issue was marked as stale due to lack of activity.