Update security-audit-results.md (#4861)

Co-authored-by: opentelemetrybot <107717825+opentelemetrybot@users.noreply.github.com>
This commit is contained in:
Austin Parker 2024-07-22 15:20:18 -04:00 committed by GitHub
parent a2618ccc9c
commit 2d88c10e1a
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 6 additions and 7 deletions

View File

@ -17,13 +17,12 @@ upon a security audit of the OpenTelemetry Collector and four SDKs Go, Java,
C#, and Python. C#, and Python.
We are pleased to announce the publication of this audit, as well as its We are pleased to announce the publication of this audit, as well as its
results. Two CVEs were identified and remediated prior to the publication of results. One CVE was identified and remediated prior to the publication of this
this audit (see audit (see [CVE-2024-36129](https://nvd.nist.gov/vuln/detail/CVE-2024-36129) for
[CVE-2024-36129](https://nvd.nist.gov/vuln/detail/CVE-2024-36129) for information) in the OpenTelemetry Collector, and five hardening recommendations
information on both) in the OpenTelemetry Collector, and five hardening were made. Overall, the results of the audit are very positive, with the
recommendations were made. Overall, the results of the audit are very positive, auditors noting the high quality of source code and the security best practices
with the auditors noting the high quality of source code and the security best that the project is following.
practices that the project is following.
The conclusion of this audit marks an important milestone on our journey towards The conclusion of this audit marks an important milestone on our journey towards
the next stage of maturity in the CNCF, graduation. Well have more to share on the next stage of maturity in the CNCF, graduation. Well have more to share on