VERIFIED VERSION

OpenTelemetry eBPF Instrumentation

v0.11.0

Every version proves itself.

VersionPass issued 20 August 2026 at 06:25 UTC · Revision 1

VersionPass integrity verified
VersionPass integrityVERIFIEDEd25519 signature valid
Release bindingVERIFIEDArtifact SHA-256 matched
Bound evidenceVERIFIEDAll preserved evidence digests matched
Security observationOBSERVED20/08/2026, 06:27:56 UTC

WHY SHOULD I TRUST THIS?

Independent checks, stated precisely.

Independently verified: the VersionPass signature, canonical payload digest, exact artifact binding, and every preserved evidence digest.

Observed from an identified source: GitHub release/tag/commit metadata and OSV package-version matches.

VersionPass assessed: the Sigstore bundle matched the expected GitHub workflow identity and bound artifact when this revision was issued.

Declared by the vendor: no claims were included. Support duration has not been declared.

Could not be verified: SBOM completeness and full build provenance. Missing evidence is not silently downgraded.

RELEASE IDENTITY

The exact software evaluated

Repository
open-telemetry/opentelemetry-ebpf-instrumentation
Git tag
v0.11.0
Commit SHA
2f8603c7232a93e798f3673a15d8077e6a509047
Artifact
obi-v0.11.0-linux-amd64.tar.gz
Artifact SHA-256
5118e6e03f23…d05f0ce6
Identity strength
Cryptographic artifact binding

CURRENTLY KNOWN

12 matched vulnerability records

Observed from OSV across 223 identified components at 20/08/2026, 06:27:56 UTC. This live observation does not mutate the signed publication snapshot.

GO-2026-5932The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issuesUNKNOWN
GO-2026-6179Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlogUNKNOWN
GO-2026-6180Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdbUNKNOWN
GO-2026-4970Root escape via symlink plus trailing slash in osUNKNOWN
GO-2026-5026Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaUNKNOWN
GO-2026-5856Invoking Encrypted Client Hello privacy leak in crypto/tlsUNKNOWN
GO-2026-5972Enforce maximum recursion depth in encoding/asn1UNKNOWN
GO-2026-6088Add recursion depth guard during decode in encoding/xmlUNKNOWN

+ 4 additional current records.

AT PUBLICATION

12 matched vulnerability records

This immutable snapshot records what the OSV query returned when revision 1 was signed.

Source
OSV
Observed
20/08/2026, 06:25:09 UTC
Interpretation
Potential matches; exploitability not established

COMPONENTS / SBOM

229 components

CYCLONEDX 1.6

Original SBOM preserved and digest-bound. Syntax and structure were validated; completeness was not independently assessed.

ComponentVersionIdentifier
actions/cachev5.0.4pkg:github/actions/cache@v5.0.4
actions/checkoutv3.3.0pkg:github/actions/checkout@v3.3.0
actions/checkoutv6.0.2pkg:github/actions/checkout@v6.0.2
actions/setup-gov3.5.0pkg:github/actions/setup-go@v3.5.0
actions/setup-gov6.4.0pkg:github/actions/setup-go@v6.4.0
actions/upload-artifactbbbca2ddaa5d8feaa63e36b76fdaad77386f024fpkg:github/actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f
cloud.google.com/go/compute/metadatav0.9.0pkg:golang/cloud.google.com/go/compute/metadata@v0.9.0
github.com/AlessandroPomponio/go-gibberishv0.0.0-20191004143433-a2d4156f0396pkg:golang/github.com/AlessandroPomponio/go-gibberish@v0.0.0-20191004143433-a2d4156f0396
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcpv1.35.0pkg:golang/github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp@v1.35.0
github.com/andybalholm/brotliv1.2.2pkg:golang/github.com/andybalholm/brotli@v1.2.2
github.com/aws/aws-sdk-go-v2v1.43.3pkg:golang/github.com/aws/aws-sdk-go-v2@v1.43.3
github.com/aws/aws-sdk-go-v2/configv1.32.34pkg:golang/github.com/aws/aws-sdk-go-v2/config@v1.32.34

Showing 12 of 229. Full inventory is included in the JSON download.

PROVENANCE

Artifact signature cryptographically verified

Evidence
Sigstore bundle
OIDC issuer
https://token.actions.githubusercontent.com
Subject digest
MATCHED
Verifier
cosign v3.1.2
Build provenance
UNAVAILABLE

FACTS, ASSESSMENTS & CLAIMS

FACT

Git tag v0.11.0 resolved to commit 2f8603c7232a93e798f3673a15d8077e6a509047.GitHub API

obi-v0.11.0-linux-amd64.tar.gz SHA-256 is 5118e6e03f23c153bdb69b34fbbe18000a5d63d0c29b14b3688a5263d05f0ce6.Downloaded GitHub release asset

Imported CycloneDX 1.6 SBOM contains 229 components.obi-v0.11.0-linux-amd64.cyclonedx.json

ASSESSMENT

12 OSV vulnerability records matched the queried component identifiers at issue time. Match does not establish exploitability.ReleasePass

VENDOR CLAIM

No vendor claims were included.Absence shown explicitly

CRYPTOGRAPHIC VERIFICATION

8/8 mandatory checks passed

structureSupported passport envelope
issuerIssuer and key match verifier expectations
payload-digestCanonical payload digest matched
signatureEd25519 signature valid
release-bindingRequired artifact subject digest matched
evidence:sbomEvidence bytes matched reference digest
evidence:sigstore-bundleEvidence bytes matched reference digest
evidence:evidence-ledgerEvidence bytes matched reference digest

Signature: valid · Evidence objects: all digests matched

PORTABLE VERSIONPASS

Verify and retain the evidence.

Download the signed canonical VersionPass for security review, procurement records, or independent tooling.

Download VersionPass JSON