Security3.0.3
v3.0.3
Security patches for Go dependencies and multiple CVEs, including updates to Go 1.26.5, google.golang.org/grpc, golang.org/x/net, golang.org/x/text, and opentelemetry dependencies. Also includes bug fixes for version reporting and enhancements to query-frontend documentation.
Security
operations: Update Go to 1.26.5 (CVE-2026-39822, CVE-2026-27145, CVE-2026-42504, CVE-2026-42505, CVE-2026-42507), google.golang.org/grpc to v1.82.1 (GHSA-hrxh-6v49-42gf), golang.org/x/net to v0.56.0 (CVE-2026-46600), golang.org/x/text to v0.39.0 (CVE-2026-56852), and go.opentelemetry.io/otel to v1.44.0 (CVE-2026-41178) (#7726) (@mattdurham)
Enhancements
query-frontend: Add Tempo configuration documentation to the MCP server via thedocs-configtool anddocs://config/overviewanddocs://config/referenceresources (#7521) (@knylander-grafana)
The configuration reference is generated from the default configuration, so it stays in sync with the code.query-frontend: Update the TraceQL and metrics documentation served by the MCP server to match current capabilities. (#7375) (@knylander-grafana)
Bug fixes
tempo: Fix incorrect version reported by--version, the build-info metric, and/api/status/buildinfo. The build version is now read from the new top-level VERSION file instead of the most recently created git tag, which could belong to a different release. (#7469) (@zhxiaogg)
Changes
docs: remove guidance on running multiple monolithic instances. (#7636) (@mattdurham)
securitydependenciesgoquery-frontendbugfix
Source: original entry ↗