Skip to content

[FP]: opentelemetry-js reported against JVM dependencies #8775

Description

@xcq1

Package URl

pkg:maven/io.opentelemetry/opentelemetry-.*@1.62.0

CPE

cpe:2.3:a:opentelemetry:opentelemetry:1.62.0:::::::*

CVE

No response

ODC Integration

{"label" => "Gradle Plugin"}

ODC Version

13.0.0

Description

I am seeing CVE-2026-54285 with a CPE specifically for node.js which concerns something about the opentelemetry-js client being reported against 14 individual package URIs which are all JARs. Not sure if this can be solved at once or whether I'm really supposed to open 14 FP reports? I can say we already have the retirejs analyzer disabled.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions