Bump the nuget group with 4 updates - #513
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps OpenTelemetry to 1.15.3 Bumps OpenTelemetry.Api from 1.11.2 to 1.15.3 Bumps OpenTelemetry.Api.ProviderBuilderExtensions from 1.11.2 to 1.15.3 Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol to 1.15.3 --- updated-dependencies: - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget - dependency-name: OpenTelemetry dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget - dependency-name: OpenTelemetry dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget - dependency-name: OpenTelemetry dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget - dependency-name: OpenTelemetry.Api dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget - dependency-name: OpenTelemetry.Api.ProviderBuilderExtensions dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.15.3 dependency-type: direct:production dependency-group: nuget ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit be7bae1. Configure here.
| </dependentAssembly> | ||
| <dependentAssembly> | ||
| <assemblyIdentity name="OpenTelemetry.Exporter.OpenTelemetryProtocol" publicKeyToken="7bd6737fe5b67e3c" culture="neutral" /> | ||
| <bindingRedirect oldVersion="0.0.0.0-1.0.0.0" newVersion="1.0.0.0" /> |
There was a problem hiding this comment.
Missing binding redirects for upgraded assemblies in Web.config
High Severity
The Web.config is missing binding redirects for numerous assemblies whose versions were bumped across major assembly versions. For example, System.Diagnostics.DiagnosticSource went from assembly version 9.0.0.0 to 10.0.0.7, and all Microsoft.Extensions.* assemblies went from 9.0.0.0 to 10.0.0.7, yet no redirects were added. Non-updated assemblies like OpenTelemetry.Extensions.Hosting 1.11.2, OpenTelemetry.Exporter.Console 1.9.0, and Microsoft.Extensions.Hosting.Abstractions 9.0.0 were compiled against the old versions and will fail to load them at runtime, causing FileLoadException. This packages.config-style .NET Framework project has no AutoGenerateBindingRedirects setting, so redirects must be added manually.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit be7bae1. Configure here.
…bygems (#732) ## Summary Automated dependency-vulnerability remediation for findings reported by GitHub Dependabot and Wiz. Only findings that are actionable under the severity/age policy (critical immediately; high/moderate after a 7-day hold; low ignored; must have a published fixed version) and that are still present in the manifests/lockfiles are included. Stale alerts (already patched in the lockfile, e.g. `next`, `vite`, `django` in `sdk/highlight-py` after this change) were verified against the lockfiles rather than trusted blindly. Fixed: | Ecosystem | Package | Change | Severity | Advisory | |---|---|---|---|---| | go | `github.com/gofiber/fiber/v2` | 2.52.13 → 2.52.14 (3 modules) | moderate | GHSA-gcfq-8gqf-4876 | | npm | `turbo` | 2.8.7 → 2.9.14 | moderate | GHSA-hcf7-66rw-9f5r | | npm | `hono` | resolution → ^4.12.34 (4.13.2) | moderate | GHSA-8j4g-w8fx-2239, GHSA-f23p-vx2j-j53r, GHSA-54fx-42gc-7vw4 | | npm | `valibot` | 1.2.0 → 1.4.2 | moderate | GHSA-5qjj-4xww-7phc | | npm | `@remix-run/router` | 1.23.2 → 1.23.3 | moderate | GHSA-2j2x-hqr9-3h42 | | npm | `markdown-it` | 14.1.1 → 14.3.0 | moderate | GHSA-6v5v-wf23-fmfq | | npm | `uuid` | 11.1.0 → 11.1.1 | moderate | GHSA-w5hq-g745-h8pq | | npm | `@remix-run/node` (e2e/react-native) | 2.15.2 → 2.17.5 | critical (Wiz) | CVE-2025-61686 | | npm | `ajv` (e2e/react-native) | 8.17.1 → 8.20.0 | moderate | GHSA-2g4f-4pwh-qvx6 | | npm | `yaml` (e2e/react-native) | 1.10.2 → 1.10.3 | moderate | GHSA-48c2-rrv3-qjmp | | npm | `js-yaml` | resolutions → ^3.15.1 / ^4.3.1 | high | GHSA-5p4m-2wfm-xmqj | | pip | `django` (sdk/highlight-py dev dep) | 4.2.30 → 5.2.17 | moderate | GHSA-8qcx-xf44-272x, GHSA-crhf-3pfg-w68w | | pip | `django` (e2e/python) | 5.2.14 → 5.2.17 | moderate | GHSA-8qcx-xf44-272x, GHSA-crhf-3pfg-w68w | | pip | `pytest` (e2e/tests) | 7.4.4 → 9.1.1 | moderate | GHSA-6w46-j5rx-g56g | | pip | `loguru` (e2e/python) | constraint `^0` → `^0.7.3` | moderate | GHSA-39ph-wr67-j4xq | | rubygems | `activesupport` (RN example Gemfiles) | `>= 6.1.7.5` → `>= 7.2.3.1` | moderate | GHSA-2j26-frm8-cmj9, GHSA-89vf-4333-qx8v, GHSA-cg4j-q9v8-6v38 | Deferred, with reasons: - **Critical `org.bouncycastle:bcprov-jdk18on` 1.77 → 1.80.2** (Wiz, CVE-2025-14813) in `sdk/@launchdarkly/flutter/.../android/build.gradle` and `sdk/@launchdarkly/react-native-ld-session-replay/android/build.gradle`. It is a build-time-only transitive of the `com.android.tools.build:gradle` 8.7.2 buildscript classpath (not shipped in artifacts); the real fix is an AGP upgrade. No Android SDK and no Maven Central access in this environment, so the change could not be built or verified — left for a dedicated PR. - **No published fix**: `@angular/*`, `apollo-server-core`, `extract-zip`, `image-size`, `react-router-dom`. - **Major upgrades requiring code changes** (kept out of this bump-only PR): `@nestjs/core` 10 → 11, `svelte` 4 → 5, `react-router` 6 → 7, `@opentelemetry/core` 1.30 → 2.x, `file-type` 20 → 21, `fast-xml-parser` 4 → 5, `ts-deepmerge` 2 → 8, transitive `nanoid` 4 → 5 and `markdown-it` 12 → 14. - **Under the 7-day hold**: `@hono/node-server` 1.19.15, plus the newest `image-size` advisories. - **`nanoid`**: the 3.x line is already at 3.3.18 in the lockfile (patched); the remaining alert covers the transitive `nanoid@4.0.2`, whose fix is the ESM-only 5.x major, so it stays in the major-upgrade bucket. - **Blocked by a peer constraint**: `pytest` 9 in `e2e/python` — `pytest-asyncio` 0.25.3 requires `pytest <9`, so that manifest stays on `^8.2.0`. - **NuGet OpenTelemetry packages** (`e2e/dotnet4/cs/packages.config`): already covered by open Dependabot PRs (#513, #509, #496) and nuget.org is not reachable here, so no duplicate change. - **Low severity** findings are out of policy scope (`webpack`, `body-parser`, `@babel/core`, `json`, `msgpack`, `sqlite3`, `flask`, `@tootallnate/once`). Excluded because it did not build: none — but see the environment caveats below. ## How did you test this change? Dependency-only change, no runtime behavior change, so no screenshots or staging link apply. - `yarn install` + `yarn dedupe --check` — clean (Puppeteer's Chrome-download postinstall fails in this sandbox because its CDN is blocked; unrelated to these bumps). - `yarn build:sdk` — 20/20 tasks pass. `yarn build` — 49/53; only `angular.io-example#build` fails, because font inlining needs `fonts.googleapis.com`, which is blocked in this sandbox. - `yarn lint` — 49/49 pass. - `yarn test` — 76/77 pass. `@highlight-run/next#test` fails because the test boots a Next app whose corepack step downloads yarn from `repo.yarnpkg.com` (blocked here). `aws-lambda#build` needs the `sam` CLI, which is not installed. - Re-validated after the `js-yaml` bump: `yarn build:sdk` 20/20 pass and `yarn test` 57/61, with `angular.io-example#build` the only failure (blocked Google Fonts, as above). - `yarn format-check` — the only warnings are local build artifacts under `lib/` (not tracked); all changed manifests pass Prettier. - Go: `go build ./...`, `go vet ./...`, `go mod verify` pass in `sdk/highlight-go` and `e2e/go-plugin`. `sdk/highlight-go` tests pass except a pre-existing `log.TestParseConsoleMessages` failure (reproduced on the unmodified module), and `e2e/go` has a pre-existing duplicate `main` in `fiber.go`/`echo.go`. - Python: `sdk/highlight-py` suite passes on Django 5.2.17 (259 tests); `e2e/tests` installs and collects on pytest 9; `e2e/python` imports Django/loguru/Flask cleanly. - Not validated in this environment: the Android/Gradle and Ruby/Bundler paths (no Android SDK, Maven Central and RubyGems not reachable). Pre-commit hooks could not run because their hook environments clone from GitHub directly; the equivalent checks were run manually. ## Are there any deployment considerations? No migrations or backfills. Notes for reviewers: - `sdk/highlight-py` moves its **dev** dependency Django from 4.x to 5.2.17 (the advisories have no 4.x fix); the shipped package is unaffected and the Django integration tests pass. - The React Native example Gemfiles now require `activesupport >= 7.2.3.1`, which needs Ruby >= 3.1. The Gemfiles still declare `ruby ">= 2.6.10"`; CI runners use modern Ruby, but this is worth a look if anyone builds those examples on an old Ruby. - `turbo` moves 2.8.7 → 2.9.14. Note `yarn build` cannot parse `rrweb/turbo.json` (missing `extends`) on **either** version in a fresh checkout of this branch's base, so the build was validated with that submodule file locally patched; the submodule itself is untouched by this PR. - Lockfile churn (`yarn.lock`, `poetry.lock`, `package-lock.json`, `go.sum`) is expected from these bumps; the React Native lockfile was regenerated and reformatted back to the repo's tab indentation to keep the diff readable. Previous session: https://app.devin.ai/sessions/142c0a5e060144ec97c9177f692e8cb9 <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Overview** > Bumps **dependency versions and lockfiles** across e2e, SDK, and root tooling to clear Dependabot/Wiz findings, without changing application logic. > > **Go:** `github.com/gofiber/fiber/v2` **2.52.13 → 2.52.14** in `sdk/highlight-go`, `e2e/go`, and `e2e/go-plugin` (with `go.sum` updates). > > **npm/yarn:** Root `package.json` raises **`turbo` to 2.9.14** and adds/updates **resolutions** for `hono`, `valibot`, `@remix-run/router`, `markdown-it`, and `uuid`; `yarn.lock` follows. **`e2e/react-native`** adds overrides for `@remix-run/node`, `ajv@8`, and `yaml@1` and refreshes `package-lock.json`. > > **Python:** **`django` → 5.2.17** in `e2e/python` and `sdk/highlight-py` (dev); **`e2e/python`** pins **`loguru` to ^0.7.3**; **`e2e/tests`** upgrades **`pytest` to ^9** (lockfile includes **pygments**). > > **Ruby:** React Native example **Gemfiles** require **`activesupport >= 7.2.3.1`** instead of the older minimum/exclusion pattern. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 92b9ed3. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Link to Devin session: https://app.devin.ai/sessions/52f99250d37f411190c5f723b21ab8b7 --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
## Summary Automated dependency-vulnerability remediation run for this repo. Only one finding was actionable this run; everything else was either already remediated on `main`, has no fix, or needs a major bump. - Pins `image-size` to `^1.2.1` via npm `overrides` in the React Native e2e app, closing a High Wiz finding (CVE-2025-71319) against `e2e/react-native/package-lock.json` - Manifest + lockfile only (3 lockfile lines); no source changes, no major bumps - The root `yarn.lock` was already on `image-size` 1.2.1 via root `resolutions`, so only the standalone npm lockfile needed the pin - Most open Dependabot alerts for this repo are stale (already fixed by the resolutions on `main`); the rest require major upgrades or have no patched version ## How did you test this change? Backend/tooling change, no UI. `npm install` in the react-native e2e app resolves `image-size@1.2.1`, and the monorepo yarn install + `yarn build:sdk` were unaffected (20/20 packages build). ## Are there any deployment considerations? No — the change is limited to an e2e example app's dev dependency tree. <details> <summary>Implementation details</summary> ### Findings addressed | Package | Ecosystem | Current → Target | Severity | Age | Source(s) | Advisory | |---|---|---|---|---|---|---| | image-size (in `e2e/react-native`) | npm | 1.2.0 → 1.2.1 | High | ~2.5 months | Wiz | CVE-2025-71319 | ### Not addressed (require a major version bump) - `nanoid` 4.0.2 → 5.1.16 (5.x is ESM-only) - `react-router` 6.30.4 → 7.18.0; `@opentelemetry/core` 1.30.1 → 2.8.0; `svelte` 4.2.19 → 5.55.7; `@nestjs/core` 10.4.22 → 11.1.18; `file-type` 20.4.1 → 21.3.2; `ts-deepmerge` 2.0.7 → 8.0.0; `markdown-it` 12.3.2 → 14.2.0; `fast-xml-parser` 4.5.6 → 5.7.0; `uuid` (legacy 3.x/7.x/8.x/9.x copies) → 11.1.1; `@angular/*` 19.2.x → 20.3.27; `pytest` 8.3.5 → 9.0.3 - Java/Android build-time transitives from the Gradle toolchain (`bcprov-jdk18on` — the only Critical, `netty-*`, `jackson-*`, `wire-runtime`, `jose4j`, `jdom2`, `grpc-netty`, `commons-io`, `protobuf-java`): not declared in any manifest here and Maven Central is not reachable from the automation environment. ### Not addressed (no patched version) `extract-zip`, `image-size` CVE-2025-71329/71330 (affect all versions incl. 2.x), `@angular/*` advisories with no fix, `apollo-server-core`, `react-router-dom` 6.30.4. ### Stale alerts (already fixed on `main`) `vite` (6.4.3), `next` (15.5.22/16.2.12), `sqlparse` (0.6.0), `image-size` in root `yarn.lock` (1.2.1), `markdown-it` 14.3.0, `@opentelemetry/core` 2.10.0 — all pinned by root `resolutions` / lockfiles already. ### Deferred: NuGet OTel bumps in `e2e/dotnet4/cs/packages.config` `OpenTelemetry.Api`/`Exporter.OpenTelemetryProtocol` 1.11.2, `Exporter.Zipkin`/`Extensions.Propagators` 1.9.0 → 1.15.3 and `Resources.Azure` beta → 1.15.1-beta.1 are in-major bumps, but nuget.org is not reachable from the automation environment so a restore/build could not be validated; Dependabot PRs #513 / #509 / #496 already target them. ### Verification - Install: npm (react-native e2e app) ✅ / yarn (monorepo) ✅ — only the known `@highlight-run/rrvideo` puppeteer postinstall failure (Chrome CDN unreachable) - Build: `yarn build:sdk` ✅ 20/20 - Tests: unchanged by this diff; the react-native e2e app is not part of `yarn test` or CI - Lint/format: `prettier --check` ✅ on both changed files Note: the `Require additional human oversight on bot PRs` check is `action_required` by design on bot-authored PRs and needs a human approval. </details> Link to Devin session: https://app.devin.ai/sessions/4f3892ef6ba94c30abfeafe43b95a6e9 <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Overview** > Addresses **CVE-2025-71319** by forcing transitive **`image-size`** from **1.2.0 → 1.2.1** in the React Native e2e example, which uses its own npm lockfile instead of the monorepo yarn resolutions. > > Adds an **`overrides`** entry in `e2e/react-native/package.json` and updates **`package-lock.json`** accordingly. No application source changes. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 7870763. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…751) ## Summary Bumps `next` past the Critical [GHSA-2xp9-vwfh-vxw4](GHSA-2xp9-vwfh-vxw4) / CVE-2026-75604 advisory (Wiz, first detected 2026-08-26). Root `resolutions` only; `yarn.lock` regenerated. - `next` 15.5.22 → **15.5.24** and 16.2.12 → **16.3.3** — patch-level, no major crossing - Both fix versions were published 2026-08-25, i.e. 6 days old, so they are still quarantined by this repo's `npmMinimalAgeGate: 7d`. The gate is resolution-time only, so the committed lockfile pins install cleanly (`yarn install --immutable` is green) and **`.yarnrc.yml` is deliberately left untouched** — no `npmPreapprovedPackages` exemption, no gate lowering. The pins were computed with a local, uncommitted `YARN_NPM_MINIMAL_AGE_GATE=0` override. From 2026-09-01 the versions clear the gate on their own. - Everything else in this run was deferred, not fixed — see below. <details> <summary>Findings: fixed, deferred, and why</summary> ### Fixed | Package | From | To | Severity | Advisory | Source | | --- | --- | --- | --- | --- | --- | | `next` | 15.5.22 | 15.5.24 | Critical | GHSA-2xp9-vwfh-vxw4 / CVE-2026-75604 | Wiz | | `next` | 16.2.12 | 16.3.3 | Critical | GHSA-2xp9-vwfh-vxw4 / CVE-2026-75604 | Wiz | Dependabot's `next` alerts (High/Moderate, 2026-06-18 and 2026-07-23) ask for older patched versions (14.2.3x, 15.0.8, 15.5.16, 15.5.21) and are subsumed by these bumps. ### Deferred — inside the 7-day hold | Package | Current → required | Severity | Oldest first-seen | | --- | --- | --- | --- | | `pacote` | 21.0.0 → 21.5.1 | High | 2026-08-28 (3d) | | `django` (e2e/python) | 5.2.16 → 5.2.17 | High/Moderate | 2026-08-25 (6d) | | `django` (e2e/python) | 6.0.7 → 6.0.8 | Moderate | 2026-08-25 (6d) | ### Deferred — would require a major bump (not permitted; pinning a transitive across a major counts as one) `svelte` 4.2.19 → 5.51.5, `react-router` 6.30.4 → 7.x, `@nestjs/core` 10.4.22 → 11.x, `@opentelemetry/core` 1.30.1 → 2.x, `@angular/*` → 20.3.27, `nanoid` 4.0.2 → 5.x (5.x is ESM-only), `pacote` 20.0.0 → 21.5.1, `uuid` 3.4.0/7.0.3/8.3.2 in `e2e/react-native/package-lock.json` → 11.x, `file-type` 20.4.1 → 21.x, `fast-xml-parser` 4.5.6 → 5.x. ### Deferred — no actionable manifest entry / blocked registry - Java/Gradle toolchain transitives (`bcprov-jdk18on`, `netty-*`, `jackson-*`, `wire-runtime`, `jose4j`, `jdom2`, `grpc-netty`, `commons-io`, `protobuf-java`): pulled in by the Android/Java toolchain, no declared manifest entry to bump. - `e2e/dotnet4/cs/packages.config` OpenTelemetry 1.11 → 1.15: nuget.org is blocked in this environment; Dependabot #513/#509/#496 already cover it. - Root `resolutions` already fix `vite`, `markdown-it`, `image-size`, `@opentelemetry/core`, `uuid` — several Dependabot alerts here lag a scan behind and are already remediated on `main` (`image-size` via merged #747). Nothing was excluded for failing to build. </details> ## How did you test this change? - `node .yarn/releases/yarn-4.13.0.cjs install --immutable` — resolution clean, no lockfile churn, no quarantine error (only the pre-existing `rrvideo` puppeteer postinstall failure, caused by a blocked Chrome CDN in this environment) - `yarn dedupe --check` — no packages can be deduped - `yarn format-check` — clean - `yarn build:sdk` — 20/20 tasks pass - `yarn lint` — 49/49 tasks pass ## Are there any deployment considerations? No. Dependency manifest + lockfile only; no source or published-artifact change. Link to Devin session: https://app.devin.ai/sessions/62467b8f5f3f4b9ab820356b42af5efa Open in Devin Desktop: https://app.devin.ai/desktop/session/62467b8f5f3f4b9ab820356b42af5efa?variant=devin <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Overview** > Addresses **Critical** [GHSA-2xp9-vwfh-vxw4](GHSA-2xp9-vwfh-vxw4) / CVE-2026-75604 by raising root Yarn **`resolutions`** for `next` and regenerating **`yarn.lock`**. Patched lines are **15.5.22 → 15.5.24** and **16.2.12 → 16.3.3** (no major version jumps). > > The lockfile refresh pulls matching **`@next/env`** / platform **`@next/swc-*`** binaries. For the 16.x line, transitive updates include **`@swc/helpers` 0.5.23**, **`postcss` 8.5.23**, and a broader **`sharp`** range on 15.x (`^0.34.3 || ^0.35.3`) plus **`^0.35.3`** on 16.x. No application or SDK source changes—only how the monorepo pins Next for e2e (`e2e/nextjs`, `e2e/nextjs-ld`) and peers on `@launchdarkly/observability-next`. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 0a7a0cf. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>


Updated OpenTelemetry from 1.11.2 to 1.15.3.
Release notes
Sourced from OpenTelemetry's releases.
1.15.3
For highlights and announcements pertaining to this release see: Release Notes > 1.15.3.
The following changes are from the previous release 1.15.2.
NuGet: OpenTelemetry v1.15.3
Fix resource leak in batch and periodic exporting task workers for Blazor/WASM.
(#7069)
Fixed
LogRecord.LogLevelto preserveLogLevel.Noneand handleunspecified or out-of-range severities without returning invalid enum values.
(#7092)
Fixed
OTEL_TRACES_SAMPLER_ARGhandling to treat out-of-range,NaN, andinfinite values as invalid and fall back to the default ratio when using
traceidratioandparentbased_traceidratiosamplers.(#7103)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.15.3
Fix baggage and trace headers not respecting the maximum length in some cases.
(#7061)
Improve efficiency of parsing of baggage and B3 propagation headers.
(#7061)
Breaking change: Fixed
tracestateparsing to reject keys that do notbegin with a lowercase letter, including keys beginning with digits, to
align with the W3C Trace Context specification.
(#7065)
Fixed
BaggagePropagatorto trim optional whitespace (OWS) around=separators when parsing the
baggageheader, as required by theW3C Baggage specification.
(#7009)
Fixed
BaggagePropagatorto strip baggage properties (e.g.;metadata)from values when parsing the
baggageheader.(#7009)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.15.3
No notable changes.
See CHANGELOG for details.
... (truncated)
1.15.3-beta.1
The following changes are from the previous release 1.15.2-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.15.3-beta.1
Fixed metric unit strings containing invalid Prometheus characters (e.g.
# RU)not being sanitized, resulting in malformed metric names.
(#6187)
Fixed Prometheus metric serialization to handle empty label names without
throwing during scrape rendering.
(#7077)
Updated OpenTelemetry core component version(s) to
1.15.3.(#7125)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.15.3-beta.1
Fixed metric unit strings containing invalid Prometheus characters (e.g.
# RU)not being sanitized, resulting in malformed metric names.
(#6187)
Fixed Prometheus metric serialization to handle empty label names without
throwing during scrape rendering.
(#7077)
Updated OpenTelemetry core component version(s) to
1.15.3.(#7125)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.15.3-beta.1
Fixes support for
byte,short,int, andfloatattributes.(#7080)
Updated OpenTelemetry core component version(s) to
1.15.3.(#7125)
See CHANGELOG for details.
1.15.2
For highlights and announcements pertaining to this release see: Release Notes > 1.15.2.
The following changes are from the previous release 1.15.1.
NuGet: OpenTelemetry v1.15.2
BatchExportProcessorandPeriodicExportingMetricReaderto enable OpenTelemetry to work insingle-threaded WebAssembly environments such as Blazor and Uno Platform.
The implementation automatically detects the WebAssembly runtime and switches
to Task-based workers accordingly; the Thread-based approach remains the
default on all other platforms.
(#6379)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.15.2
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.15.2
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.15.2
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.InMemory v1.15.2
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.OpenTelemetryProtocol v1.15.2
error logging is enabled.
(#7017)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Zipkin v1.15.2
... (truncated)
1.15.2-beta.1
The following changes are from the previous release 1.15.1-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.15.2-beta.1
1.15.2.(#7049)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.15.2-beta.1
1.15.2.(#7049)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.15.2-beta.1
1.15.2.(#7049)
See CHANGELOG for details.
1.15.1
For highlights and announcements pertaining to this release see: Release Notes > 1.15.1.
The following changes are from the previous release 1.15.0.
NuGet: OpenTelemetry v1.15.1
Fixed
Tracer.StartSpan()leaving the new span asActivity.Currentwhenthe previous activity was stopped by another thread during span creation.
(#6257)
Fixed
OverflowExceptioninTraceIdRatioBasedSamplerwhen trace ID bytesproduced
long.MinValue.([#6928])
Fixed precision issues when using
Histogram<float>with customHistogramBucketBoundaries.(#6866)
Fixed a thread-safety issue in
LogRecordSharedPool.Rent().(#6833)
Fixed observable instruments (ObservableCounter, ObservableUpDownCounter,
ObservableGauge) continuing to export stale data points after a callback
stops reporting a series.
(#5950)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.15.1
specification,
which disallows empty baggage names and treats baggage names and values as case
sensitive.
(#6931)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.15.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.15.1
No notable changes.
See CHANGELOG for details.
... (truncated)
1.15.1-beta.1
The following changes are from the previous release 1.15.0-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.15.1-beta.1
1.15.1.(#7010)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.15.1-beta.1
1.15.1.(#7010)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.15.1-beta.1
This package is deprecated and it will stop receiving any updates in
March 2027. Use the OpenTelemetry API and SDK directly instead of the OpenTracing
shims.
(#6976)
Updated OpenTelemetry core component version(s) to
1.15.1.(#7010)
See CHANGELOG for details.
1.15.0
For highlights and announcements pertaining to this release see: Release Notes > 1.15.0.
The following changes are from the previous release 1.14.0.
NuGet: OpenTelemetry v1.15.0
Added support for the
OTEL_SDK_DISABLEDenvironment variable in TracerProvider,MeterProvider, and LoggerProvider. When
OTEL_SDK_DISABLED=true,the SDK returns no-op implementations for all telemetry signals.
The
OTEL_SDK_DISABLEDenvironment variable is only evaluated upon applicationstartup, later changes have no effect.
(#6568)
Added
LowMemorytemporality as an option in the OTLP metrics exporter.(#6648)
Added support for
Meter.TelemetrySchemaUrlproperty.(#6714)
Improve performance and reduce memory consumption for metrics histograms.
(#6715)
Decode
valuein OTEL_RESOURCE_ATTRIBUTES environment variable.(#6737)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.15.0
TracerProvider.GetTracerwhich accepts an optionalstring? schemaUrlparameter, allowing a schema URL to be set on theTracer.(#6736)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.15.0
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.15.0
Added support for
ActivitySource.TelemetrySchemaUrlproperty.(#6713)
Added support for
Meter.TelemetrySchemaUrlproperty.(#6714)
See CHANGELOG for details.
... (truncated)
1.15.0-beta.1
The following changes are from the previous release 1.14.0-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.15.0-beta.1
1.15.0.(#6841)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.15.0-beta.1
1.15.0.(#6841)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.15.0-beta.1
1.15.0.(#6841)
See CHANGELOG for details.
1.14.0
For highlights and announcements pertaining to this release see: Release Notes > 1.14.0.
The following changes are from the previous release 1.14.0-rc.1.
NuGet: OpenTelemetry v1.14.0
Breaking Change NuGet packages now use the Sigstore bundle format
(
.sigstore.json) for digital signatures instead of separate signature(
.sig) and certificate (.pem) files. This requires cosign 3.0 or laterfor verification. See the Digital signing
section for updated verification instructions.
(#6623)
Update to stable versions for .NET 10.0 NuGet packages.
(#6667)
Update
Microsoft.Extensions.*dependencies to10.0.0for .NET Frameworkand .NET Standard.
(#6667)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.14.0
Breaking Change NuGet packages now use the Sigstore bundle format
(
.sigstore.json) for digital signatures instead of separate signature(
.sig) and certificate (.pem) files. This requires cosign 3.0 or laterfor verification. See the Digital signing
section for updated verification instructions.
(#6623)
Update
System.Diagnostics.DiagnosticSourcedependency to10.0.0for all target frameworks.
(#6667)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.14.0
Breaking Change NuGet packages now use the Sigstore bundle format
(
.sigstore.json) for digital signatures instead of separate signature(
.sig) and certificate (.pem) files. This requires cosign 3.0 or laterfor verification. See the Digital signing
section for updated verification instructions.
(#6623)
Update to stable versions for .NET 10.0 NuGet packages.
(#6667)
Update
Microsoft.Extensions.*dependencies to10.0.0for .NET Framework... (truncated)
1.14.0-rc.1
The following changes are from the previous release 1.13.1.
NuGet: OpenTelemetry v1.14.0-rc.1
Breaking Change When targeting
net8.0, the package now depends on version8.0.0of theMicrosoft.Extensions.DependencyInjection.Abstractions,Microsoft.Extensions.Diagnostics.AbstractionsandMicrosoft.Extensions.Logging.ConfigurationNuGet packages.(#6327)
Add support for .NET 10.0.
(#6307)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.14.0-rc.1
Add support for .NET 10.0.
(#6307)
Update
System.Diagnostics.DiagnosticSourcedependency to10.0.0for all target frameworks.
(#6307)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.14.0-rc.1
Breaking Change When targeting
net8.0, the package now depends on version8.0.0of theMicrosoft.Extensions.DependencyInjection.AbstractionsNuGet package.(#6327)
Add support for .NET 10.0.
(#6307)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.14.0-rc.1
Breaking Change When targeting
net8.0, the package now depends on version8.0.0of theMicrosoft.Extensions.DependencyInjection.Abstractions,Microsoft.Extensions.Diagnostics.AbstractionsandMicrosoft.Extensions.Logging.ConfigurationNuGet packages.(#6327)
Add support for .NET 10.0.
(#6307)
See CHANGELOG for details.
... (truncated)
1.14.0-beta.1
The following changes are from the previous release 1.13.1-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.14.0-beta.1
Breaking Change When targeting
net8.0, the package now depends on version8.0.0of theMicrosoft.Extensions.DependencyInjection.Abstractions,Microsoft.Extensions.Diagnostics.AbstractionsandMicrosoft.Extensions.Logging.ConfigurationNuGet packages.(#6327)
Add support for .NET 10.0.
(#6307)
Added the possibility to disable timestamps via the
PrometheusAspNetCoreOptions.(#6600)
Breaking Change NuGet packages now use the Sigstore bundle format
(
.sigstore.json) for digital signatures instead of separate signature(
.sig) and certificate (.pem) files. This requires cosign 3.0 or laterfor verification. See the Digital signing
section for updated verification instructions.
(#6623)
Updated OpenTelemetry core component version(s) to
1.14.0.(#6689)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.14.0-beta.1
Breaking Change When targeting
net8.0, the package now depends on version8.0.0of theMicrosoft.Extensions.DependencyInjection.Abstractions,Microsoft.Extensions.Diagnostics.AbstractionsandMicrosoft.Extensions.Logging.ConfigurationNuGet packages.(#6327)
Add support for .NET 10.0.
(#6307)
Added the possibility to disable timestamps via the
PrometheusHttpListenerOptions.(#6600)
Breaking Change NuGet packages now use the Sigstore bundle format
(
.sigstore.json) for digital signatures instead of separate signature(
.sig) and certificate (.pem) files. This requires cosign 3.0 or laterfor verification. See the Digital signing
section for updated verification instructions.
(#6623)
Updated OpenTelemetry core component version(s) to
1.14.0.... (truncated)
1.13.1
For highlights and announcements pertaining to this release see: Release Notes > 1.13.1.
The following changes are from the previous release 1.13.0.
NuGet: OpenTelemetry v1.13.1
scale to 20 after each collection cycle when using delta aggregation temporality.
(#6557)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.13.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.13.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.13.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.InMemory v1.13.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.OpenTelemetryProtocol v1.13.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Zipkin v1.13.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Extensions.Hosting v1.13.1
... (truncated)
1.13.1-beta.1
The following changes are from the previous release 1.13.0-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.13.1-beta.1
1.13.1.(#6598)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.13.1-beta.1
1.13.1.(#6598)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.13.1-beta.1
1.13.1.(#6598)
See CHANGELOG for details.
1.13.0
For highlights and announcements pertaining to this release see: Release Notes > 1.13.0.
The following changes are from the previous release 1.12.0.
NuGet: OpenTelemetry v1.13.0
Added a verification to ensure that a
MetricReadercan only be registeredto a single
MeterProvider, as required by the OpenTelemetry specification.(#6458)
Added
FormatMessageconfiguration option to self-diagnostics feature. Whenset to
true(default is false), log messages will be formatted by replacingplaceholders with actual parameter values for improved readability.
Example
OTEL_DIAGNOSTICS.json:{ "LogDirectory": ".", "FileSize": 32768, "LogLevel": "Warning", "FormatMessage": true }Fixed parsing of
OTEL_TRACES_SAMPLER_ARGdecimal values to always use.as the delimiter when using the
traceidratiosampler, preventinglocale-specific parsing issues.
(#6444)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.13.0
Added
AddLink(SpanContext, SpanAttributes?)toTelemetrySpanto supportlinking spans and associating optional attributes for advanced trace relationships.
(#6305)
Experimental (only in pre-release versions): Added the
EventNamepropertyto
LogRecordData(#6306)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.13.0
No notable changes.
See CHANGELOG for details.
... (truncated)
1.13.0-beta.1
The following changes are from the previous release 1.12.0-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.13.0-beta.1
1.13.0.(#6552)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.13.0-beta.1
1.13.0.(#6552)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.13.0-beta.1
1.13.0.(#6552)
See CHANGELOG for details.
1.12.0
For highlights and announcements pertaining to this release see: Release Notes > 1.12.0.
The following changes are from the previous release 1.11.2.
NuGet: OpenTelemetry v1.12.0
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.12.0
TracerProvider.GetTracerwhich accepts an optionalIEnumerable<KeyValuePair<string, object?>>? tagsparameter, allowingadditional attributes to be associated with the
Tracer.(#6137)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.12.0
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.12.0
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.InMemory v1.12.0
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.OpenTelemetryProtocol v1.12.0
exporting over OTLP/HTTP instead of OTLP/gRPC. This change could result in a
failure to export telemetry unless appropriate measures are taken.
Additionally, if you explicitly configure the exporter to use OTLP/gRPC it may
result in a
NotSupportedExceptionwithout further configuration. Pleasecarefully review issue
(#6209)
for additional information and workarounds.
(#6229)
See CHANGELOG for details.
... (truncated)
1.12.0-beta.1
The following changes are from the previous release 1.11.2-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.12.0-beta.1
1.12.0.(#6269)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.12.0-beta.1
1.12.0.(#6269)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.12.0-beta.1
1.12.0.(#6269)
See CHANGELOG for details.
Commits viewable in compare view.
Updated OpenTelemetry from 1.12.0 to 1.15.3.
Release notes
Sourced from OpenTelemetry's releases.
1.15.3
For highlights and announcements pertaining to this release see: Release Notes > 1.15.3.
The following changes are from the previous release 1.15.2.
NuGet: OpenTelemetry v1.15.3
Fix resource leak in batch and periodic exporting task workers for Blazor/WASM.
(#7069)
Fixed
LogRecord.LogLevelto preserveLogLevel.Noneand handleunspecified or out-of-range severities without returning invalid enum values.
(#7092)
Fixed
OTEL_TRACES_SAMPLER_ARGhandling to treat out-of-range,NaN, andinfinite values as invalid and fall back to the default ratio when using
traceidratioandparentbased_traceidratiosamplers.(#7103)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.15.3
Fix baggage and trace headers not respecting the maximum length in some cases.
(#7061)
Improve efficiency of parsing of baggage and B3 propagation headers.
(#7061)
Breaking change: Fixed
tracestateparsing to reject keys that do notbegin with a lowercase letter, including keys beginning with digits, to
align with the W3C Trace Context specification.
(#7065)
Fixed
BaggagePropagatorto trim optional whitespace (OWS) around=separators when parsing the
baggageheader, as required by theW3C Baggage specification.
(#7009)
Fixed
BaggagePropagatorto strip baggage properties (e.g.;metadata)from values when parsing the
baggageheader.(#7009)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.15.3
No notable changes.
See CHANGELOG for details.
... (truncated)
1.15.3-beta.1
The following changes are from the previous release 1.15.2-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.15.3-beta.1
Fixed metric unit strings containing invalid Prometheus characters (e.g.
# RU)not being sanitized, resulting in malformed metric names.
(#6187)
Fixed Prometheus metric serialization to handle empty label names without
throwing during scrape rendering.
(#7077)
Updated OpenTelemetry core component version(s) to
1.15.3.(#7125)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.15.3-beta.1
Fixed metric unit strings containing invalid Prometheus characters (e.g.
# RU)not being sanitized, resulting in malformed metric names.
(#6187)
Fixed Prometheus metric serialization to handle empty label names without
throwing during scrape rendering.
(#7077)
Updated OpenTelemetry core component version(s) to
1.15.3.(#7125)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.15.3-beta.1
Fixes support for
byte,short,int, andfloatattributes.(#7080)
Updated OpenTelemetry core component version(s) to
1.15.3.(#7125)
See CHANGELOG for details.
1.15.2
For highlights and announcements pertaining to this release see: Release Notes > 1.15.2.
The following changes are from the previous release 1.15.1.
NuGet: OpenTelemetry v1.15.2
BatchExportProcessorandPeriodicExportingMetricReaderto enable OpenTelemetry to work insingle-threaded WebAssembly environments such as Blazor and Uno Platform.
The implementation automatically detects the WebAssembly runtime and switches
to Task-based workers accordingly; the Thread-based approach remains the
default on all other platforms.
(#6379)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.15.2
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.15.2
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.15.2
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.InMemory v1.15.2
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.OpenTelemetryProtocol v1.15.2
error logging is enabled.
(#7017)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Zipkin v1.15.2
... (truncated)
1.15.2-beta.1
The following changes are from the previous release 1.15.1-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.15.2-beta.1
1.15.2.(#7049)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.15.2-beta.1
1.15.2.(#7049)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.15.2-beta.1
1.15.2.(#7049)
See CHANGELOG for details.
1.15.1
For highlights and announcements pertaining to this release see: Release Notes > 1.15.1.
The following changes are from the previous release 1.15.0.
NuGet: OpenTelemetry v1.15.1
Fixed
Tracer.StartSpan()leaving the new span asActivity.Currentwhenthe previous activity was stopped by another thread during span creation.
(#6257)
Fixed
OverflowExceptioninTraceIdRatioBasedSamplerwhen trace ID bytesproduced
long.MinValue.([#6928])
Fixed precision issues when using
Histogram<float>with customHistogramBucketBoundaries.(#6866)
Fixed a thread-safety issue in
LogRecordSharedPool.Rent().(#6833)
Fixed observable instruments (ObservableCounter, ObservableUpDownCounter,
ObservableGauge) continuing to export stale data points after a callback
stops reporting a series.
(#5950)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.15.1
specification,
which disallows empty baggage names and treats baggage names and values as case
sensitive.
(#6931)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.15.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.15.1
No notable changes.
See CHANGELOG for details.
... (truncated)
1.15.1-beta.1
The following changes are from the previous release 1.15.0-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.15.1-beta.1
1.15.1.(#7010)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.15.1-beta.1
1.15.1.(#7010)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.15.1-beta.1
This package is deprecated and it will stop receiving any updates in
March 2027. Use the OpenTelemetry API and SDK directly instead of the OpenTracing
shims.
(#6976)
Updated OpenTelemetry core component version(s) to
1.15.1.(#7010)
See CHANGELOG for details.
1.15.0
For highlights and announcements pertaining to this release see: Release Notes > 1.15.0.
The following changes are from the previous release 1.14.0.
NuGet: OpenTelemetry v1.15.0
Added support for the
OTEL_SDK_DISABLEDenvironment variable in TracerProvider,MeterProvider, and LoggerProvider. When
OTEL_SDK_DISABLED=true,the SDK returns no-op implementations for all telemetry signals.
The
OTEL_SDK_DISABLEDenvironment variable is only evaluated upon applicationstartup, later changes have no effect.
(#6568)
Added
LowMemorytemporality as an option in the OTLP metrics exporter.(#6648)
Added support for
Meter.TelemetrySchemaUrlproperty.(#6714)
Improve performance and reduce memory consumption for metrics histograms.
(#6715)
Decode
valuein OTEL_RESOURCE_ATTRIBUTES environment variable.(#6737)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.15.0
TracerProvider.GetTracerwhich accepts an optionalstring? schemaUrlparameter, allowing a schema URL to be set on theTracer.(#6736)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.15.0
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.15.0
Added support for
ActivitySource.TelemetrySchemaUrlproperty.(#6713)
Added support for
Meter.TelemetrySchemaUrlproperty.(#6714)
See CHANGELOG for details.
... (truncated)
1.15.0-beta.1
The following changes are from the previous release 1.14.0-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.15.0-beta.1
1.15.0.(#6841)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.15.0-beta.1
1.15.0.(#6841)
See CHANGELOG for details.
NuGet: OpenTelemetry.Shims.OpenTracing v1.15.0-beta.1
1.15.0.(#6841)
See CHANGELOG for details.
1.14.0
For highlights and announcements pertaining to this release see: Release Notes > 1.14.0.
The following changes are from the previous release 1.14.0-rc.1.
NuGet: OpenTelemetry v1.14.0
Breaking Change NuGet packages now use the Sigstore bundle format
(
.sigstore.json) for digital signatures instead of separate signature(
.sig) and certificate (.pem) files. This requires cosign 3.0 or laterfor verification. See the Digital signing
section for updated verification instructions.
(#6623)
Update to stable versions for .NET 10.0 NuGet packages.
(#6667)
Update
Microsoft.Extensions.*dependencies to10.0.0for .NET Frameworkand .NET Standard.
(#6667)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.14.0
Breaking Change NuGet packages now use the Sigstore bundle format
(
.sigstore.json) for digital signatures instead of separate signature(
.sig) and certificate (.pem) files. This requires cosign 3.0 or laterfor verification. See the Digital signing
section for updated verification instructions.
(#6623)
Update
System.Diagnostics.DiagnosticSourcedependency to10.0.0for all target frameworks.
(#6667)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.14.0
Breaking Change NuGet packages now use the Sigstore bundle format
(
.sigstore.json) for digital signatures instead of separate signature(
.sig) and certificate (.pem) files. This requires cosign 3.0 or laterfor verification. See the Digital signing
section for updated verification instructions.
(#6623)
Update to stable versions for .NET 10.0 NuGet packages.
(#6667)
Update
Microsoft.Extensions.*dependencies to10.0.0for .NET Framework... (truncated)
1.14.0-rc.1
The following changes are from the previous release 1.13.1.
NuGet: OpenTelemetry v1.14.0-rc.1
net8.0, the package now depends on version8.0.0of theMicrosoft.Extensions.DependencyInjection.Abstractions,Microsoft.Extensions.Diagnostics.Abstractionsand`Microsoft.Exte...
Description has been truncated