github grafana/pyroscope v2.3.2

2 hours ago

Version 2.3.2 release notes

Security fixes

  • Updated UI undici to v8.10.2, addressing CVE-2026-84961, a TLS certificate validation bypass (#5749).
  • Updated google.golang.org/grpc to v1.83.2, addressing CVE-2026-84445 (#5609, #5610).
  • Updated OpenTelemetry trace exporters to v1.45.0 (#5649, #5650, #5651).
  • Updated OpenTelemetry log modules to v0.21.0 (#5722).
  • Updated UI js-yaml to v4.3.2 (#5616).
  • Updated UI brace-expansion to v5.0.12 (#5705).

Documentation

  • Expanded recording rules CLI documentation, added Rust jemalloc profiling documentation and a v2.0 upgrade guide, and corrected profile type documentation (#5622).

Changelog

  • 0707df2 [release/v2.3] docs: Expand recording rules CLI, add Rust jemalloc profiling, fix profile types, add v2.0 upgrade guide (#5622)
  • 1bdb9a6 docs: Update release notes for v2.3.1/v2.2.2 (#5603)
  • 3c4756f docs: add v2.3.2 release notes (#5751)
  • 7a681d2 fix(deps): update otel log modules to v0.21.0 [security] (release/v2.3) (#5722)
  • 729f36f fix(deps): update undici to 8.10.2 to address TLS validation bypass (#5747) (#5749)
  • a7274c2 fix(security/high/): update module google.golang.org/grpc to v1.83.2 [security] (#5609)
  • 3ddd069 fix(security/high/api): update module google.golang.org/grpc to v1.83.2 [security] (#5610)
  • a77692b fix(security/high/ui): update dependency brace-expansion to v5.0.12 [security] (release/v2.3) (#5705)
  • 0c751c0 fix(security/high/ui): update dependency js-yaml to v4.3.2 [security] (release/v2.3) (#5616)
  • 634fe73 fix(security/low/): update module go.opentelemetry.io/otel/exporters/otlp/otlptrace to v1.45.0 [security] (#5649)
  • 287630f fix(security/unknown/): update module go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc to v1.45.0 [security] (#5650)
  • 28c325e fix(security/unknown/): update module go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to v1.45.0 [security] (#5651)

As always, feedback is more than welcome, feel free to open issues/discussions.
You can reach out to the team using:

Docker Images

  docker pull grafana/pyroscope:2.3.2

Don't miss a new pyroscope release

NewReleases is sending notifications on new releases.