go.opentelemetry.io/collector/component is vulnerable to Deadlock
20
Low Risk
Affected versions of the package are vulnerable to a potential deadlock in the persistent queue due to a race condition, where the used value in sizedChannel becomes out of sync with the channel length.
You are affected if you are using a version that falls within the vulnerable range.
go.opentelemetry.io/collector/component is vulnerable to Deadlock in versions 0.100.0 - 0.108.1.
Upgrade the go.opentelemetry.io/collector/component library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant