Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request for VAPT Report for Open-Telemetry Agent, Otel Collector #13029

Open
Digvijay-mishra opened this issue Jan 13, 2025 · 1 comment
Open
Labels
enhancement New feature or request needs triage New issue that requires triage

Comments

@Digvijay-mishra
Copy link

Is your feature request related to a problem? Please describe.

I hope this message finds you well. I am reaching out to kindly request a Vulnerability Assesment and Pentration Testing (VAPT) report for the OpenTelemetry Agent and Collector .Understanding the security posture of these are crucial for our implementation, and any insights or documentation regarding its vulnerability would be greatly appreciated.

If such a report is available or if there are specific steps I should follow to conduct my own assessment ,please let me know.Thank you for your assistance

Best Regards
Digvijay Mishra

Describe the solution you'd like

I would like to receive a comprehensive Vulnerability Assessment and Penetration Testing (VAPT) report for the OpenTelemetry Agent and Collector. This report should ideally include:
Summary of Findings: An overview of identified vulnerabilities, categorized by severity.
Detailed Analysis: In-depth information about each vulnerability, including potential impacts and exploitability.
Remediation Guidance: Recommendations on how to mitigate or remediate the identified vulnerabilities.
Testing Methodology: A brief description of the testing methods used to assess the security posture of the OpenTelemetry components.
Documentation or Resources: Any existing documentation or resources that can assist in understanding the security measures implemented in these components.
If a formal VAPT report is not available, I would appreciate guidance on best practices for conducting a security assessment of the OpenTelemetry Agent and Collector, including any tools or resources that are recommended for this purpose.

Describe alternatives you've considered

No response

Additional context

No response

@Digvijay-mishra Digvijay-mishra added enhancement New feature or request needs triage New issue that requires triage labels Jan 13, 2025
@trask
Copy link
Member

trask commented Jan 13, 2025

See open-telemetry/opentelemetry-collector#12077 (comment) for the Collector.

The Java SDK was included in the OTel-wide security report, but not the Java agent component.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request needs triage New issue that requires triage
Projects
None yet
Development

No branches or pull requests

2 participants