Skip to content

Cardamon

v1.0.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2d Monitoring & Metrics
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

cardinality prometheus observability sre storage-optimization

Affected surfaces

deps

Summary

AI summary

Fixed a bug that caused recent queries to be silently missed when parsing query logs.

Full changelog

v1.0.1

Bug fixes:

  • Fixed a scan-termination bug in query log parsing that could cause
    DiscoverUsedMetricsFromLogs to silently miss recent queries, since
    query logs are append-only and sorted oldest-first (#17)
  • Fixed typo in Grafana crawl warning message

Chore:

  • Bumped Go to 1.25.12 to address several reachable stdlib CVEs
    (GO-2026-5856, GO-2026-5039, GO-2026-5037, GO-2026-4971, GO-2026-4918)
  • Fixed golangci-lint install step in CI (broken checksum in the
    upstream install script)
  • Bumped golang.org/x/net from 0.49.0 to 0.55.0

Security Fixes

  • Bumped Go to 1.25.12 addressing stdlib CVEs GO-2026-5856, GO-2026-5039, GO-2026-5037, GO-2026-4971, and GO-2026-4918

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Cardamon

Get notified when new releases ship.

Sign up free

About Cardamon

All releases →

Related context

Beta — feedback welcome: [email protected]