Details in tracker. This package bundles the vulnerable Go package, is the exporter actually vulnerable?