Skip to content

fix(security): update vulnerability-updates [security] - #2059

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/vulnerability-updates
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/vulnerability-updates

Conversation

@renovate

@renovate renovate Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.18.0 → v0.21.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 → v1.45.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.42.0 → v1.45.0 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 → v1.45.0 age confidence
go.opentelemetry.io/otel/sdk v1.44.0 → v1.45.0 age confidence
go.opentelemetry.io/otel/sdk/log v0.19.0 → v0.21.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning

CVE-2026-81871 / GHSA-w34q-cm8f-9c5x

More information

Details

Summary

The OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, or related client certificate variables for CA pinning or mTLS get a connection that falls back to system roots and omits the env-supplied client certificate. A network attacker who can intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry.

Introduced in commit: d99c76f

Details

The affected code is in exporters/otlp/otlplog/otlploggrpc.

newConfig resolves env-based TLS configuration into cfg.tlsCfg at exporters/otlp/otlplog/otlploggrpc/config.go:106-116. The finding also identifies loadEnvTLS at config.go:451-492 as the code that builds a *tls.Config containing RootCAs and client certificates from OTEL_EXPORTER_OTLP[_LOGS]_CERTIFICATE and OTEL_EXPORTER_OTLP[_LOGS]_CLIENT_CERTIFICATE/KEY.

However, newGRPCDialOptions in exporters/otlp/otlplog/otlploggrpc/client.go:83-92 only checks cfg.gRPCCredentials and cfg.insecure. When neither is set, which is the normal env-only TLS configuration path, it uses credentials.NewTLS(nil). That default trusts the host system root CAs and contains no env-supplied client certificate. The finding evidence reports no other tlsCfg use in the package, so env-based CA pinning and mTLS settings are loaded but not enforced.

PoC

validation-artifact.zip

The validation artifact contains a ready-to-run test at validation-artifact.zip:./poc_env_tls_ignored_test.go and brief instructions at validation-artifact.zip:./README.md.

From a checkout of pellared/opentelemetry-go at commit d99c76f, with Go module dependencies available:

FINDING_DIR=/path/to/02-e6e2897a969c8191b260f243fbc99ebd-log-grpc-exporter-ignores-env-tls-certs-bypassing-mtls-pinning
cd /path/to/opentelemetry-go
git checkout d99c76f
tar -xOf validation-artifact.tar ./poc_env_tls_ignored_test.go > exporters/otlp/otlplog/otlploggrpc/poc_env_tls_ignored_test.go
cd exporters/otlp/otlplog/otlploggrpc
GO111MODULE=on go test -v -run TestEnvTLSIgnored -count=1

The test generates a private CA and a TLS gRPC logs server certificate signed by that CA. It sets:

OTEL_EXPORTER_OTLP_LOGS_ENDPOINT=https://127.0.0.1:<test-port>
OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE=<temp-dir>/ca.pem

Expected output includes an unknown authority failure for the first export call even though the env certificate points to the server CA, followed by a passing test after the same cfg.tlsCfg is explicitly wired through WithTLSCredentials:

=== RUN   TestEnvTLSIgnored
    poc_env_tls_ignored_test.go:...: export error (expected due to ignored tlsCfg): ... x509: certificate signed by unknown authority
--- PASS: TestEnvTLSIgnored
PASS

This demonstrates that the env CA is parsed into cfg.tlsCfg but ignored by the default gRPC dial path.

Impact

This is improper TLS certificate validation and endpoint authentication caused by ignoring configured trust material. Users of the OTLP log gRPC exporter who configure TLS, CA pinning, or mTLS through environment variables are impacted when they do not also supply explicit WithTLSCredentials. TLS still occurs with system roots, but the intended private CA pinning and client certificate authentication are bypassed. An attacker with a suitable network position and a system-trusted certificate for the collector endpoint can intercept or tamper with log telemetry that operators expected to be protected by the configured CA or mTLS policy.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs

CVE-2026-81870 / GHSA-8wmf-6v46-5gfg

More information

Details

Summary

OpenTelemetry Go versions 1.5.0 through 1.44.0 can include trace exporter endpoint configuration in an internal diagnostic log emitted when an SDK TracerProvider is created. The default OpenTelemetry logger does not emit this event. Exposure requires an application to install a logger that enables OpenTelemetry's internal Info-level diagnostics and for someone other than the intended audience to have access to those logs.

The logged configuration can disclose the address of the trace collector and whether the OTLP/HTTP connection is configured as insecure. The Zipkin exporter logs its complete collector URL, so credentials in URL userinfo or tokens in the query string are also disclosed if an application embeds them there. OTLP authentication headers, TLS key material, and exported span data are not included in this log.

Exporter MarshalLog implementations that caused this configuration to be included in internal logs were introduced by a1fff3c.

Details

When sdk/trace.NewTracerProvider constructs a provider, it records a TracerProvider created internal Info event containing the provider configuration. In affected versions, the configuration's MarshalLog methods recursively include:

  1. the provider's span processors;
  2. each processor's span exporter; and
  3. for the OTLP trace exporter, its client configuration.

This causes the following values to be present in the event:

  • OTLP trace gRPC: the configured endpoint;
  • OTLP trace HTTP: the configured endpoint and the Insecure flag; and
  • Zipkin: the complete collector URL.

OpenTelemetry Go does not emit this event with its default logger, which only emits errors. An application must explicitly configure a sufficiently verbose logger with otel.SetLogger. The required logr verbosity is version-dependent:

  • versions 1.5.0 through 1.14.x use V(1) for this Info event; and
  • versions 1.15.0 through 1.44.0 use V(4).

OTLP header configuration is not part of the marshaled object, so credentials supplied with WithHeaders or the corresponding environment variables are not exposed. The documented OTLP WithEndpoint input is a collector address rather than a credential-bearing URL. The higher-risk case is therefore the Zipkin collector URL, which is retained and logged in full, or an application passing sensitive data in an OTLP endpoint outside the documented format.

Proof of concept

The following program demonstrates the behavior with OpenTelemetry Go 1.44.0. It deliberately places credentials and a token in the Zipkin collector URL and enables internal Info logging:

package main

import (
	"bytes"
	"context"
	"fmt"

	"github.com/go-logr/logr/funcr"
	"go.opentelemetry.io/otel"
	"go.opentelemetry.io/otel/exporters/zipkin"
	sdktrace "go.opentelemetry.io/otel/sdk/trace"
)

func main() {
	var logs bytes.Buffer
	otel.SetLogger(funcr.New(func(_, args string) {
		_, _ = logs.WriteString(args)
	}, funcr.Options{Verbosity: 4}))

	exporter, err := zipkin.New(
		"http://user:pass@zipkin.internal:9411/api/v2/spans?token=secret",
	)
	if err != nil {
		panic(err)
	}

	tp := sdktrace.NewTracerProvider(sdktrace.WithBatcher(exporter))
	_ = tp.Shutdown(context.Background())

	fmt.Println(logs.String())
}

The TracerProvider created event contains:

http://user:pass@zipkin.internal:9411/api/v2/spans?token=secret

For versions before 1.15.0, set funcr.Options{Verbosity: 1} instead.

Impact

This is a conditional disclosure through application logs. Affected applications must enable verbose OpenTelemetry internal diagnostics and configure a trace exporter containing information they do not intend to expose to readers of those logs. In that configuration, a person or system with log access can learn the trace collector address and internal network topology. If credentials or tokens are embedded directly in a Zipkin collector URL, those values can also be recovered from the logs.

There is no exposure with the default OpenTelemetry logger, and the vulnerable log is generated from local application configuration rather than remotely supplied span data. OTLP authentication headers, certificate or private-key contents, and telemetry payloads are not logged by this path.

Remediation

Upgrade the affected OpenTelemetry Go modules to version 1.45.0 or later. The fix in 3a1412d stops recursively marshaling exporter and client configuration and records their types instead.

If an immediate upgrade is not possible:

  • keep OpenTelemetry internal logging below the Info verbosity described above;
  • do not embed credentials or tokens in exporter endpoint URLs; use authentication headers or another supported credential mechanism; and
  • restrict access to existing logs and rotate any credentials that may already have been recorded.

Severity

  • CVSS Score: 2.0 / 10 (Low)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full

CVE-2026-81872 / GHSA-hjf4-fphr-2h65

More information

Details

Summary

A BatchingProcessor in go.opentelemetry.io/otel/sdk/log can enter a tight CPU loop when the asynchronous export buffer is full. Under exporter backpressure, attacker-driven high-volume log emission can keep the queue at or above the batch size, causing repeated immediate export retries and a denial of service through CPU exhaustion.

Introduced in commit: 4af9c20

Details

NewBatchingProcessor wraps the exporter with newBufferExporter(exporter, 1) (sdk/log/batch.go:116-122), so the asynchronous export input can fill quickly when the downstream exporter blocks. The poll goroutine dequeues a batch with b.q.TryDequeue, calls b.exporter.EnqueueExport(r), and then immediately sends on b.pollTrigger whenever qLen >= b.batchSize (sdk/log/batch.go:129-165).

bufferExporter.EnqueueExport is non-blocking: it sends to e.input if possible and returns false in the default case when the channel is full (sdk/log/exporter.go:221-248). TryDequeue leaves q.len unchanged when the write callback returns false (sdk/log/batch.go:289-314). Therefore, while the exporter is backpressured, EnqueueExport fails, the queue remains at or above one full batch, and the poll loop continuously retriggers itself without waiting for the ticker.

PoC

validation-artifact.zip

The validation artifact contains a PoC bundle:

  • validation-artifact.tar:main.go: PoC source.
  • validation-artifact.tar:README.md: build/run notes.
  • validation-artifact.tar:build_failed.log: captured build failure from the validation environment.

The PoC configures a blocking exporter and a BatchingProcessor with WithExportMaxBatchSize(1), WithExportInterval(5*time.Second), and WithMaxQueueSize(2048). It emits 1000 records, records a CPU profile for 750 ms while the exporter is blocked, then writes /workspace/validation_artifacts/busyloop.pprof.

Reproduction steps from an affected checkout at commit 4af9c20:

cd /workspace/opentelemetry-go
git checkout 4af9c20

mkdir -p validation_poc/busyloop /workspace/validation_artifacts /tmp/batchingprocessor-busyloop-poc
tar -xf /path/to/this/finding/validation-artifact.tar -C /tmp/batchingprocessor-busyloop-poc
cp /tmp/batchingprocessor-busyloop-poc/main.go validation_poc/busyloop/main.go

go build -o validation_poc/busyloop/busyloop ./validation_poc/busyloop
./validation_poc/busyloop/busyloop
go tool pprof -top /workspace/validation_artifacts/busyloop.pprof

Expected program output:

cpu profile written to /workspace/validation_artifacts/busyloop.pprof

Expected profile evidence: hot functions should include (*BatchingProcessor).poll, (*queue).TryDequeue, and (*bufferExporter).EnqueueExport, showing repeated export attempts while the exporter is blocked.

Impact

This is an availability vulnerability: uncontrolled CPU consumption caused by a busy-spin retry loop. Applications using sdk/log BatchingProcessor are impacted when an attacker can cause sustained log emission and the configured exporter or downstream collector is slow, blocked, or otherwise backpressured. The impact is limited to the embedding process but can degrade or deny service for that application.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

open-telemetry/opentelemetry-go (go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc)

v0.20.0

Compare Source

Added
  • The OTLP exporter now has two new convenience functions, NewExportPipeline and InstallNewPipeline, setup and install the exporter in tracing and metrics pipelines. (#​1373)
  • Adds semantic conventions for exceptions. (#​1492)
  • Added Jaeger Environment variables: OTEL_EXPORTER_JAEGER_AGENT_HOST, OTEL_EXPORTER_JAEGER_AGENT_PORT
    These environment variables can be used to override Jaeger agent hostname and port (#​1752)
  • Option ExportTimeout was added to batch span processor. (#​1755)
  • trace.TraceFlags is now a defined type over byte and WithSampled(bool) TraceFlags and IsSampled() bool methods have been added to it. (#​1770)
  • The Event and Link struct types from the go.opentelemetry.io/otel package now include a DroppedAttributeCount field to record the number of attributes that were not recorded due to configured limits being reached. (#​1771)
  • The Jaeger exporter now reports dropped attributes for a Span event in the exported log. (#​1771)
  • Adds test to check BatchSpanProcessor ignores OnEnd and ForceFlush post Shutdown. (#​1772)
  • Extract resource attributes from the OTEL_RESOURCE_ATTRIBUTES environment variable and merge them with the resource.Default resource as well as resources provided to the TracerProvider and metric Controller. (#​1785)
  • Added WithOSType resource configuration option to set OS (Operating System) type resource attribute (os.type). (#​1788)
  • Added WithProcess* resource configuration options to set Process resource attributes. (#​1788)
    • process.pid
    • process.executable.name
    • process.executable.path
    • process.command_args
    • process.owner
    • process.runtime.name
    • process.runtime.version
    • process.runtime.description
  • Adds k8s.node.name and k8s.node.uid attribute keys to the semconv package. (#​1789)
  • Added support for configuring OTLP/HTTP and OTLP/gRPC Endpoints, TLS Certificates, Headers, Compression and Timeout via Environment Variables. (#​1758, #​1769 and #​1811)
    • OTEL_EXPORTER_OTLP_ENDPOINT
    • OTEL_EXPORTER_OTLP_TRACES_ENDPOINT
    • OTEL_EXPORTER_OTLP_METRICS_ENDPOINT
    • OTEL_EXPORTER_OTLP_HEADERS
    • OTEL_EXPORTER_OTLP_TRACES_HEADERS
    • OTEL_EXPORTER_OTLP_METRICS_HEADERS
    • OTEL_EXPORTER_OTLP_COMPRESSION
    • OTEL_EXPORTER_OTLP_TRACES_COMPRESSION
    • OTEL_EXPORTER_OTLP_METRICS_COMPRESSION
    • OTEL_EXPORTER_OTLP_TIMEOUT
    • OTEL_EXPORTER_OTLP_TRACES_TIMEOUT
    • OTEL_EXPORTER_OTLP_METRICS_TIMEOUT
    • OTEL_EXPORTER_OTLP_CERTIFICATE
    • OTEL_EXPORTER_OTLP_TRACES_CERTIFICATE
    • OTEL_EXPORTER_OTLP_METRICS_CERTIFICATE
  • Adds otlpgrpc.WithTimeout option for configuring timeout to the otlp/gRPC exporter. (#​1821)
Fixed
  • The Span.IsRecording implementation from go.opentelemetry.io/otel/sdk/trace always returns false when not being sampled. (#​1750)
  • The Jaeger exporter now correctly sets tags for the Span status code and message.
    This means it uses the correct tag keys ("otel.status_code", "otel.status_description") and does not set the status message as a tag unless it is set on the span. (#​1761)
  • The Jaeger exporter now correctly records Span event's names using the "event" key for a tag.
    Additionally, this tag is overridden, as specified in the OTel specification, if the event contains an attribute with that key. (#​1768)
  • Zipkin Exporter: Ensure mapping between OTel and Zipkin span data complies with the specification. (#​1688)
  • Fixed typo for default service name in Jaeger Exporter. (#​1797)
  • Fix flaky OTLP for the reconnnection of the client connection. (#​1527, #​1814)
Changed
  • Span RecordError now records an exception event to comply with the semantic convention specification. (#​1492)
  • Jaeger exporter was updated to use thrift v0.14.1. (#​1712)
  • Migrate from using internally built and maintained version of the OTLP to the one hosted at go.opentelemetry.io/proto/otlp. (#​1713)
  • Migrate from using github.com/gogo/protobuf to google.golang.org/protobuf to match go.opentelemetry.io/proto/otlp. (#​1713)
  • The storage of a local or remote Span in a context.Context using its SpanContext is unified to store just the current Span.
    The Span's SpanContext can now self-identify as being remote or not.
    This means that "go.opentelemetry.io/otel/trace".ContextWithRemoteSpanContext will now overwrite any existing current Span, not just existing remote Spans, and make it the current Span in a context.Context. (#​1731)
  • Improve OTLP/gRPC exporter connection errors. (#​1737)
  • Information about a parent span context in a "go.opentelemetry.io/otel/export/trace".SpanSnapshot is unified in a new Parent field.
    The existing ParentSpanID and HasRemoteParent fields are removed in favor of this. (#​1748)
  • The ParentContext field of the "go.opentelemetry.io/otel/sdk/trace".SamplingParameters is updated to hold a context.Context containing the parent span.
    This changes it to make SamplingParameters conform with the OpenTelemetry specification. (#​1749)
  • Updated Jaeger Environment Variables: JAEGER_ENDPOINT, JAEGER_USER, JAEGER_PASSWORD
    to OTEL_EXPORTER_JAEGER_ENDPOINT, OTEL_EXPORTER_JAEGER_USER, OTEL_EXPORTER_JAEGER_PASSWORD
    in compliance with OTel spec (#​1752)
  • Modify BatchSpanProcessor.ForceFlush to abort after timeout/cancellation. (#​1757)
  • The DroppedAttributeCount field of the Span in the go.opentelemetry.io/otel package now only represents the number of attributes dropped for the span itself.
    It no longer is a conglomerate of itself, events, and link attributes that have been dropped. (#​1771)
  • Make ExportSpans in Jaeger Exporter honor context deadline. (#​1773)
  • Modify Zipkin Exporter default service name, use default resouce's serviceName instead of empty. (#​1777)
  • The go.opentelemetry.io/otel/sdk/export/trace package is merged into the go.opentelemetry.io/otel/sdk/trace package. (#​1778)
  • The prometheus.InstallNewPipeline example is moved from comment to example test (#​1796)
  • The convenience functions for the stdout exporter have been updated to return the TracerProvider implementation and enable the shutdown of the exporter. (#​1800)
  • Replace the flush function returned from the Jaeger exporter's convenience creation functions (InstallNewPipeline and NewExportPipeline) with the TracerProvider implementation they create.
    This enables the caller to shutdown and flush using the related TracerProvider methods. (#​1822)
  • Updated the Jaeger exporter to have a default enpoint, http://localhost:14250, for the collector. (#​1824)
  • Changed the function WithCollectorEndpoint in the Jaeger exporter to no longer accept an endpoint as an argument.
    The endpoint can be passed with the CollectorEndpointOption using the WithEndpoint function or by setting the OTEL_EXPORTER_JAEGER_ENDPOINT environment variable value appropriately. (#​1824)
  • The Jaeger exporter no longer batches exported spans itself, instead it relies on the SDK's BatchSpanProcessor for this functionality. (#​1830)
  • The Jaeger exporter creation functions (NewRawExporter, NewExportPipeline, and InstallNewPipeline) no longer accept the removed Option type as a variadic argument. (#​1830)
Removed
  • Removed Jaeger Environment variables: JAEGER_SERVICE_NAME, JAEGER_DISABLED, JAEGER_TAGS
    These environment variables will no longer be used to override values of the Jaeger exporter (#​1752)
  • No longer set the links for a Span in go.opentelemetry.io/otel/sdk/trace that is configured to be a new root.
    This is unspecified behavior that the OpenTelemetry community plans to standardize in the future.
    To prevent backwards incompatible changes when it is specified, these links are removed. (#​1726)
  • Setting error status while recording error with Span from oteltest package. (#​1729)
  • The concept of a remote and local Span stored in a context is unified to just the current Span.
    Because of this "go.opentelemetry.io/otel/trace".RemoteSpanContextFromContext is removed as it is no longer needed.
    Instead, "go.opentelemetry.io/otel/trace".SpanContextFromContex can be used to return the current Span.
    If needed, that Span's SpanContext.IsRemote() can then be used to determine if it is remote or not. (#​1731)
  • The HasRemoteParent field of the "go.opentelemetry.io/otel/sdk/trace".SamplingParameters is removed.
    This field is redundant to the information returned from the Remote method of the SpanContext held in the ParentContext field. (#​1749)
  • The trace.FlagsDebug and trace.FlagsDeferred constants have been removed and will be localized to the B3 propagator. (#​1770)
  • Remove Process configuration, WithProcessFromEnv and ProcessFromEnv, and type from the Jaeger exporter package.
    The information that could be configured in the Process struct should be configured in a Resource instead. (#​1776, #​1804)
  • Remove the WithDisabled option from the Jaeger exporter.
    To disable the exporter unregister it from the TracerProvider or use a no-operation TracerProvider. (#​1806)
  • Removed the functions CollectorEndpointFromEnv and WithCollectorEndpointOptionFromEnv from the Jaeger exporter.
    These functions for retrieving specific environment variable values are redundant of other internal functions and
    are not intended for end user use. (#​1824)
  • Removed the Jaeger exporter WithSDKOptions Option.
    This option was used to set SDK options for the exporter creation convenience functions.
    These functions are provided as a way to easily setup or install the exporter with what are deemed reasonable SDK settings for common use cases.
    If the SDK needs to be configured differently, the NewRawExporter function and direct setup of the SDK with the desired settings should be used. (#​1825)
  • The WithBufferMaxCount and WithBatchMaxCount Options from the Jaeger exporter are removed.
    The exporter no longer batches exports, instead relying on the SDK's BatchSpanProcessor for this functionality. (#​1830)
  • The Jaeger exporter Option type is removed.
    The type is no longer used by the exporter to configure anything.
    All of the previous configuration these options provided were duplicates of SDK configuration.
    They have all been removed in favor of using the SDK configuration and focuses the exporter configuration to be only about the endpoints it will send telemetry to. (#​1830)

Raw changes made between v0.19.0 and v0.20.0

02d8bdd (HEAD -> main, tag: v0.20.0, tag: trace/v0.20.0, tag: sdk/v0.20.0, tag: sdk/metric/v0.20.0, tag: sdk/export/metric/v0.20.0, tag: oteltest/v0.20.0, tag: metric/v0.20.0, tag: exporters/trace/zipkin/v0.20.0, tag: exporters/trace/jaeger/v0.20.0, tag: exporters/stdout/v0.20.0, tag: exporters/otlp/v0.20.0, tag: exporters/metric/prometheus/v0.20.0, tag: example/zipkin/v0.20.0, tag: example/prometheus/v0.20.0, tag: example/prom-collector/v0.20.0, tag: example/otel-collector/v0.20.0, tag: example/opencensus/v0.20.0, tag: example/namedtracer/v0.20.0, tag: example/jaeger/v0.20.0, tag: bridge/opentracing/v0.20.0, tag: bridge/opencensus/v0.20.0, upstream/main, origin/main) Release v0.20.0 (#​1837)
aa66fe7 OS and Process resource detectors (#​1788)
7374d67 Fix Links documents (#​1835)
856f5b8 Add feature request issue template (#​1831)
0fdc3d7 Remove bundler from Jaeger exporter (#​1830)
738ef11 Fix flaky global ErrorHandler delegation test (#​1829)
e43d9c0 Update Default Value for Jaeger Exporter Endpoint (#​1824)
0032bd6 Fix default merging of resource attributes from environment variable (#​1785)
96c5e4b Add SpanProcessor example for Span annotation on start (#​1733)
543c814 Remove the WithSDKOptions from the Jaeger exporter (#​1825)
66389ad Update function docs in sdk.go (#​1826)
70bc9eb Adds support for timeout on the otlp/gRPC exporter (#​1821)
081cc61 Update Jaeger exporter convenience functions (#​1822)
1b9f16d Remove the WithDisabled option from Jaeger exporter (#​1806)
6867faa Bump actions/cache from v2.1.4 to v2.1.5 (#​1818)
a2bf04d Build context pipeline in Jaeger upload process (#​1809)
2de86f2 Remove locking from Jaeger exporter shutdown/export (#​1807)
4f9fec2 Add ExportSpans benchmark to Jaeger exporter (#​1805)
d9566ab Fix OTLP testing flake: signal connection from mock collector (#​1816)
a2cecb6 add support for env var configuration to otlp/gRPC (#​1811)
d616df6 (fix-1527) Fix flaky OTLP exporter reconnect test (#​1814)
b09df84 Changes stdout to expose the *sdktrace.TracerProvider (#​1800)
0489060 Remove options field from Jaeger exporter (#​1808)
6db20e0 Remove the abandoned Process struct in Jaeger exporter (#​1804)
086abf3 docs: use test example to document prometheus.InstallNewPipeline (#​1796)
d0cea04 Bump google.golang.org/api from 0.43.0 to 0.44.0 in /exporters/trace/jaeger (#​1792)
99c477f Fixed typo for default service name in Jaeger Exporter (#​1797)
95fd8f5 Bump google.golang.org/grpc from 1.36.1 to 1.37.0 in /exporters/otlp (#​1791)
9b25164 Zipkin Exporter: Use default resouce's serviceName as default serivce name (#​1777) (#​1786)
4d141e4 Add k8s.node.name and k8s.node.uid to semconv (#​1789)
5c99a34 Fix golint issue caused by incorrect comment (#​1795)
c5d006c Update Jaeger environment variables (#​1752)
5843280 add NewExportPipeline and InstallNewPipeline for otlp (#​1373)
7d8e6bd Zipkin Exporter: Adjust span transformation to comply with the spec (#​1688)
2817c09 (ro-span) Merge sdk/export/trace into sdk/trace (#​1778)
c61e654 Refactor prometheus exporter tests to match file headers as well (#​1470)
23422c5 Remove process config for Jaeger exporter (#​1776)
0d49b59 Add test to check bsp ignores OnEnd and ForceFlush post Shutdown (#​1772)
e9aaa04 Record links/events attribute drops independently (#​1771)
5bbfc22 Make ExportSpans for Jaeger Exporter honor deadline (#​1773)
0786fe3 (default-res) Add Bug report issue templates (#​1775)
3c7face Add ExportTimeout option to batch span processor (#​1755)
c6b92d5 Make TraceFlags spec-compliant (#​1770)
ee687ca Bump github.com/itchyny/gojq from 0.12.2 to 0.12.3 in /internal/tools (#​1774)
52a2477 add support for configuring tls certs via env var to otlp/HTTP (#​1769)
35cfbc7 Update precedence of event name in Jaeger exporter (#​1768)
33699d2 Adds semantic conventions for exceptions (#​1492)
928e3c3 Modify ForceFlush to abort after timeout/cancellation (#​1757)
3947cab Fix testCollectorEndpoint typo and add tag assertions in jaeger_test (#​1753)
ecc635d add website docs (#​1747)
07a8d19 Fix Jaeger span status reporting and unify tag keys (#​1761)
4fa35c9 add partial support for env var config to otlp/HTTP (#​1758)
bf180d0 improve OTLP/gRPC connection errors (#​1737)
d575865 Fix span IsRecording when not sampling (#​1750)
20c93b0 Update SamplingParameters (#​1749)
97501a3 Update SpanSnapshot to use parent SpanContext (#​1748)
604b05c Store current Span instead of local and remote SpanContext in context.Context (#​1731)
c61f4b6 Set @​lizthegrey to emeritus status (#​1745)
b1342fe Bump github.com/golangci/golangci-lint in /internal/tools (#​1743)
54e1bd1 Bump google.golang.org/api from 0.41.0 to 0.43.0 in /exporters/trace/jaeger (#​1741)
4d25b6a Bump github.com/prometheus/client_golang from 1.9.0 to 1.10.0 in /exporters/metric/prometheus (#​1740)
0a47b66 Bump google.golang.org/grpc from 1.36.0 to 1.36.1 in /exporters/otlp (#​1739)
26f006b Reinstate @​paivagustavo as an Approver (#​1734)
382c7ce Remove hasRemoteParent field from SDK span (#​1728)
862a5a6 Remove setting error status while recording error with Span from oteltest package (#​1729)
6defcfd Remove links on NewRoot spans (#​1726)
a9b2f85 upgrade thrift to v0.14.1 in jaeger exporter (#​1712)
5a6a854 Bump google.golang.org/protobuf from 1.25.0 to 1.26.0 in /exporters/otlp (#​1724)
2348621 Migrate to using go.opentelemetry.io/proto/otlp (#​1713)
5d559b4 Remove makeSamplingDecision func (#​1711)
e24702d Update the TraceContext.Extract docs (#​1720)
9d4eb1f Update dates in CHANGELOG.md for 2021 releases (#​1723)

v0.19.0

Compare Source

Added
  • Added Marshaler config option to otlphttp to enable otlp over json or protobufs. (#​1586)
  • A ForceFlush method to the "go.opentelemetry.io/otel/sdk/trace".TracerProvider to flush all registered SpanProcessors. (#​1608)
  • Added WithSampler and WithSpanLimits to tracer provider. (#​1633, #​1702)
  • "go.opentelemetry.io/otel/trace".SpanContext now has a remote property, and IsRemote() predicate, that is true when the SpanContext has been extracted from remote context data. (#​1701)
  • A Valid method to the "go.opentelemetry.io/otel/attribute".KeyValue type. (#​1703)
Changed
  • trace.SpanContext is now immutable and has no exported fields. (#​1573)
    • trace.NewSpanContext() can be used in conjunction with the trace.SpanContextConfig struct to initialize a new SpanContext where all values are known.
  • Update the ForceFlush method signature to the `"go.opentelemetry.io/otel/sdk/trace".SpanProce

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested review from a team as code owners September 18, 2026 01:01
@renovate renovate Bot added the renovate label Sep 18, 2026
@renovate

renovate Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: core/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 5 additional dependencies were updated

Details:

Package Change
github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 -> v2.29.0
go.opentelemetry.io/otel/log v0.19.0 -> v0.21.0
go.opentelemetry.io/proto/otlp v1.10.0 -> v1.11.0
google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa -> v0.0.0-20260803160001-6ac0973c030d
google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa -> v0.0.0-20260803160001-6ac0973c030d
File name: flagd-proxy/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 6 additional dependencies were updated

Details:

Package Change
github.com/open-feature/flagd/core v0.15.6 -> v0.18.0
go.opentelemetry.io/otel/metric v1.44.0 -> v1.45.0
go.opentelemetry.io/otel/sdk/metric v1.44.0 -> v1.45.0
github.com/go-logr/logr v1.4.3 -> v1.4.4
go.opentelemetry.io/otel v1.44.0 -> v1.45.0
go.opentelemetry.io/otel/trace v1.44.0 -> v1.45.0
File name: flagd/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 6 additional dependencies were updated

Details:

Package Change
github.com/open-feature/flagd/core v0.17.0 -> v0.18.0
github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 -> v2.29.0
go.opentelemetry.io/otel/log v0.19.0 -> v0.21.0
go.opentelemetry.io/proto/otlp v1.10.0 -> v1.11.0
google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa -> v0.0.0-20260803160001-6ac0973c030d
google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa -> v0.0.0-20260803160001-6ac0973c030d

@netlify

netlify Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for polite-licorice-3db33c canceled.

Name Link
🔨 Latest commit d3a0f92
🔍 Latest deploy log https://app.netlify.com/projects/polite-licorice-3db33c/deploys/6abda35b5000eb00089d57ef

@coderabbitai

coderabbitai Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 0b3c7945-3a4c-4453-ae65-ed3d78128bec

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/vulnerability-updates branch 10 times, most recently from c35174c to b2a7a6e Compare September 25, 2026 16:49
@renovate
renovate Bot force-pushed the renovate/vulnerability-updates branch from b2a7a6e to d3a0f92 Compare October 1, 2026 00:03
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants