Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 27, 2025

Bumps the production-dependencies group with 13 updates:

Package From To
@opentelemetry/auto-instrumentations-node 0.65.0 0.66.0
@opentelemetry/core 2.1.0 2.2.0
@opentelemetry/exporter-logs-otlp-proto 0.206.0 0.207.0
@opentelemetry/exporter-metrics-otlp-proto 0.206.0 0.207.0
@opentelemetry/exporter-trace-otlp-proto 0.206.0 0.207.0
@opentelemetry/instrumentation-kafkajs 0.16.0 0.17.0
@opentelemetry/resource-detector-container 0.7.9 0.7.10
@opentelemetry/resources 2.1.0 2.2.0
@opentelemetry/sdk-logs 0.206.0 0.207.0
@opentelemetry/sdk-metrics 2.1.0 2.2.0
@opentelemetry/sdk-node 0.206.0 0.207.0
@opentelemetry/sdk-trace-base 2.1.0 2.2.0
@opentelemetry/sdk-trace-node 2.1.0 2.2.0

Updates @opentelemetry/auto-instrumentations-node from 0.65.0 to 0.66.0

Release notes

Sourced from @​opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.66.0

0.66.0 (2025-10-21)

Features

  • auto-instrumentations-node: add OpenAI instrumentation (#3164) (d2b090e)
  • deps: update deps matching '@opentelemetry/*' (#3187) (ab96334)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.22.0 to ^0.23.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.24.0 to ^0.25.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-express bumped from ^0.55.0 to ^0.56.0
      • @​opentelemetry/instrumentation-fastify bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.26.0 to ^0.27.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.54.0 to ^0.55.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.54.0 to ^0.55.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.16.0 to ^0.17.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.55.0 to ^0.56.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-net bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.4.0 to ^0.5.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.32.0 to ^0.33.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.55.0 to ^0.56.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-router bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.20.0 to ^0.21.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.53.0 to ^0.54.0

... (truncated)

Changelog

Sourced from @​opentelemetry/auto-instrumentations-node's changelog.

0.66.0 (2025-10-21)

Features

  • auto-instrumentations-node: add OpenAI instrumentation (#3164) (d2b090e)
  • deps: update deps matching '@opentelemetry/*' (#3187) (ab96334)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.22.0 to ^0.23.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.24.0 to ^0.25.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-express bumped from ^0.55.0 to ^0.56.0
      • @​opentelemetry/instrumentation-fastify bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.26.0 to ^0.27.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.54.0 to ^0.55.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.54.0 to ^0.55.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.16.0 to ^0.17.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.55.0 to ^0.56.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-net bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.4.0 to ^0.5.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.32.0 to ^0.33.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.55.0 to ^0.56.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-router bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.20.0 to ^0.21.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.25.0 to ^0.26.0

... (truncated)

Commits

Updates @opentelemetry/core from 2.1.0 to 2.2.0

Release notes

Sourced from @​opentelemetry/core's releases.

v2.2.0

2.2.0

🐛 Bug Fixes

  • fix(core): avoid leaking Node.js types via unrefTimer() util #5986 @​pichlermarc
  • fix(core): avoid leaking Node.js types via otperformance #5987 @​pichlermarc
    • important: this bug fix may be breaking for certain uses of otperformance
      • otperformance.now() and otperformance.timeOrigin are not affected.
      • the previously used type was incorrect and overly broad, leading to unexpected run-time behavior runtimes that are not Node.js.
      • these problems are now caught on compile-time: if you have been using this API and this change is breaking to you, please consider using your target platform's performance implementation instead.

🏠 Internal

  • test(shim-opentracing): add comparison thresholds in flaky assertions #5974 @​cjihrig
  • test(exporter-jaeger): clean up OTEL_EXPORTER_JAEGER_AGENT_PORT between tests #6003 @​cjihrig
  • test(sdk-trace-base): ensure environment variables are cleaned up between tests #6011 @​cjihrig
  • perf(opentelemetry-core): optimize attribute serialization #5866 @​43081j
  • test: test Node.js 25 in CI #6019 @​cjihrig
Changelog

Sourced from @​opentelemetry/core's changelog.

2.2.0

🐛 Bug Fixes

  • fix(core): avoid leaking Node.js types via unrefTimer() util #5986 @​pichlermarc
  • fix(core): avoid leaking Node.js types via otperformance #5987 @​pichlermarc
    • important: this bug fix may be breaking for certain uses of otperformance
      • otperformance.now() and otperformance.timeOrigin are not affected.
      • the previously used type was incorrect and overly broad, leading to unexpected run-time behavior runtimes that are not Node.js.
      • these problems are now caught on compile-time: if you have been using this API and this change is breaking to you, please consider using your target platform's performance implementation instead.

🏠 Internal

  • test(shim-opentracing): add comparison thresholds in flaky assertions #5974 @​cjihrig
  • test(exporter-jaeger): clean up OTEL_EXPORTER_JAEGER_AGENT_PORT between tests #6003 @​cjihrig
  • test(sdk-trace-base): ensure environment variables are cleaned up between tests #6011 @​cjihrig
  • perf(opentelemetry-core): optimize attribute serialization #5866 @​43081j
  • test: test Node.js 25 in CI #6019 @​cjihrig
Commits
  • fb6476d chore: prepare next release (#6008)
  • 2d115fd test: test Node.js 25 in CI (#6019)
  • fe8fd65 feat(opentelemetry-configuration): support file with format rc.2 (#6029)
  • 91e0d23 chore(deps): update actions/setup-node action to v6 (#6028)
  • 3bb5717 test(opentelemetry-configuration): ensure process.env is cleaned up after `...
  • a93b1dc chore(move-to-emeriuts): create token before checkout (#6018)
  • a39500d test(otlp-grpc-exporter-base): remove duplicated delete statements (#6022)
  • 8c62fb1 chore(deps): Update import-in-the-middle (#6020)
  • 6854413 test(sdk-logs): ensure process.env is cleaned up between tests (#6017)
  • 3353b6f feat(otlp-exporter-base): accept TLS config for node HTTP exporters from env ...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​opentelemetry/core since your current version.


Updates @opentelemetry/exporter-logs-otlp-proto from 0.206.0 to 0.207.0

Release notes

Sourced from @​opentelemetry/exporter-logs-otlp-proto's releases.

experimental/v0.207.0

0.207.0

💥 Breaking Changes

🚀 Features

  • feat(sdk-node): always set up propagtion and context manager #5930
    • using (new NodeSDK).start() will now automatically set up a context management and propagation, even if no Trace SDK is initialized.
  • feat(otlp-exporter-base, otlp-grpc-exporter-base): add an option to let an SDK distribution prepend their own user-agent string in HTTP & GRPC exporters #5928 @​david-luna
  • feat(web): add session handling implementation 5173 @​martinkuba

🐛 Bug Fixes

  • fix(sdk-logs): Fix the batchLogProcessor exporting only upon _scheduledDelayMillis and ignoring maxExportBatchSize #5961 @​jacksonweber
  • fix(otlp-grpc-exporter-base): fix GRPC exporter not sending the user-agent header #5687 @​david-luna

🏠 Internal

  • test(opentelemetry-configuration): simplify management of environment variables #6004 @​cjihrig
  • test(opentelemetry-configuration): preserve special process.env behavior #6010 @​cjihrig
  • test(sdk-logs): ensure process.env is cleaned up between tests #6017 @​cjihrig
  • test(otlp-grpc-exporter-base): remove duplicated delete statements #6022 @​cjihrig
  • test(opentelemetry-configuration): ensure process.env is cleaned up after envVariableSubstitution tests #6026 @​cjihrig
Commits
  • fb6476d chore: prepare next release (#6008)
  • 2d115fd test: test Node.js 25 in CI (#6019)
  • fe8fd65 feat(opentelemetry-configuration): support file with format rc.2 (#6029)
  • 91e0d23 chore(deps): update actions/setup-node action to v6 (#6028)
  • 3bb5717 test(opentelemetry-configuration): ensure process.env is cleaned up after `...
  • a93b1dc chore(move-to-emeriuts): create token before checkout (#6018)
  • a39500d test(otlp-grpc-exporter-base): remove duplicated delete statements (#6022)
  • 8c62fb1 chore(deps): Update import-in-the-middle (#6020)
  • 6854413 test(sdk-logs): ensure process.env is cleaned up between tests (#6017)
  • 3353b6f feat(otlp-exporter-base): accept TLS config for node HTTP exporters from env ...
  • Additional commits viewable in compare view

Updates @opentelemetry/exporter-metrics-otlp-proto from 0.206.0 to 0.207.0

Release notes

Sourced from @​opentelemetry/exporter-metrics-otlp-proto's releases.

experimental/v0.207.0

0.207.0

💥 Breaking Changes

🚀 Features

  • feat(sdk-node): always set up propagtion and context manager #5930
    • using (new NodeSDK).start() will now automatically set up a context management and propagation, even if no Trace SDK is initialized.
  • feat(otlp-exporter-base, otlp-grpc-exporter-base): add an option to let an SDK distribution prepend their own user-agent string in HTTP & GRPC exporters #5928 @​david-luna
  • feat(web): add session handling implementation 5173 @​martinkuba

🐛 Bug Fixes

  • fix(sdk-logs): Fix the batchLogProcessor exporting only upon _scheduledDelayMillis and ignoring maxExportBatchSize #5961 @​jacksonweber
  • fix(otlp-grpc-exporter-base): fix GRPC exporter not sending the user-agent header #5687 @​david-luna

🏠 Internal

  • test(opentelemetry-configuration): simplify management of environment variables #6004 @​cjihrig
  • test(opentelemetry-configuration): preserve special process.env behavior #6010 @​cjihrig
  • test(sdk-logs): ensure process.env is cleaned up between tests #6017 @​cjihrig
  • test(otlp-grpc-exporter-base): remove duplicated delete statements #6022 @​cjihrig
  • test(opentelemetry-configuration): ensure process.env is cleaned up after envVariableSubstitution tests #6026 @​cjihrig
Commits
  • fb6476d chore: prepare next release (#6008)
  • 2d115fd test: test Node.js 25 in CI (#6019)
  • fe8fd65 feat(opentelemetry-configuration): support file with format rc.2 (#6029)
  • 91e0d23 chore(deps): update actions/setup-node action to v6 (#6028)
  • 3bb5717 test(opentelemetry-configuration): ensure process.env is cleaned up after `...
  • a93b1dc chore(move-to-emeriuts): create token before checkout (#6018)
  • a39500d test(otlp-grpc-exporter-base): remove duplicated delete statements (#6022)
  • 8c62fb1 chore(deps): Update import-in-the-middle (#6020)
  • 6854413 test(sdk-logs): ensure process.env is cleaned up between tests (#6017)
  • 3353b6f feat(otlp-exporter-base): accept TLS config for node HTTP exporters from env ...
  • Additional commits viewable in compare view

Updates @opentelemetry/exporter-trace-otlp-proto from 0.206.0 to 0.207.0

Release notes

Sourced from @​opentelemetry/exporter-trace-otlp-proto's releases.

experimental/v0.207.0

0.207.0

💥 Breaking Changes

🚀 Features

  • feat(sdk-node): always set up propagtion and context manager #5930
    • using (new NodeSDK).start() will now automatically set up a context management and propagation, even if no Trace SDK is initialized.
  • feat(otlp-exporter-base, otlp-grpc-exporter-base): add an option to let an SDK distribution prepend their own user-agent string in HTTP & GRPC exporters #5928 @​david-luna
  • feat(web): add session handling implementation 5173 @​martinkuba

🐛 Bug Fixes

  • fix(sdk-logs): Fix the batchLogProcessor exporting only upon _scheduledDelayMillis and ignoring maxExportBatchSize #5961 @​jacksonweber
  • fix(otlp-grpc-exporter-base): fix GRPC exporter not sending the user-agent header #5687 @​david-luna

🏠 Internal

  • test(opentelemetry-configuration): simplify management of environment variables #6004 @​cjihrig
  • test(opentelemetry-configuration): preserve special process.env behavior #6010 @​cjihrig
  • test(sdk-logs): ensure process.env is cleaned up between tests #6017 @​cjihrig
  • test(otlp-grpc-exporter-base): remove duplicated delete statements #6022 @​cjihrig
  • test(opentelemetry-configuration): ensure process.env is cleaned up after envVariableSubstitution tests #6026 @​cjihrig
Commits
  • fb6476d chore: prepare next release (#6008)
  • 2d115fd test: test Node.js 25 in CI (#6019)
  • fe8fd65 feat(opentelemetry-configuration): support file with format rc.2 (#6029)
  • 91e0d23 chore(deps): update actions/setup-node action to v6 (#6028)
  • 3bb5717 test(opentelemetry-configuration): ensure process.env is cleaned up after `...
  • a93b1dc chore(move-to-emeriuts): create token before checkout (#6018)
  • a39500d test(otlp-grpc-exporter-base): remove duplicated delete statements (#6022)
  • 8c62fb1 chore(deps): Update import-in-the-middle (#6020)
  • 6854413 test(sdk-logs): ensure process.env is cleaned up between tests (#6017)
  • 3353b6f feat(otlp-exporter-base): accept TLS config for node HTTP exporters from env ...
  • Additional commits viewable in compare view

Updates @opentelemetry/instrumentation-kafkajs from 0.16.0 to 0.17.0

Release notes

Sourced from @​opentelemetry/instrumentation-kafkajs's releases.

instrumentation-kafkajs: v0.17.0

0.17.0 (2025-10-21)

Features

  • deps: update deps matching '@opentelemetry/*' (#3187) (ab96334)

Dependencies

  • The following workspace dependencies were updated
    • devDependencies
      • @​opentelemetry/contrib-test-utils bumped from ^0.53.0 to ^0.54.0

instrumentation-undici: v0.17.0

0.17.0 (2025-10-06)

Features

  • deps: update deps matching '@opentelemetry/*' (#3145) (704c716)
Changelog

Sourced from @​opentelemetry/instrumentation-kafkajs's changelog.

0.17.0 (2025-10-21)

Features

  • deps: update deps matching '@opentelemetry/*' (#3187) (ab96334)

Dependencies

  • The following workspace dependencies were updated
    • devDependencies
      • @​opentelemetry/contrib-test-utils bumped from ^0.53.0 to ^0.54.0
Commits

Updates @opentelemetry/resource-detector-container from 0.7.9 to 0.7.10

Release notes

Sourced from @​opentelemetry/resource-detector-container's releases.

resource-detector-container: v0.7.10

0.7.10 (2025-10-21)

Dependencies

  • The following workspace dependencies were updated
    • devDependencies
      • @​opentelemetry/contrib-test-utils bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.26.0 to ^0.27.0
Changelog

Sourced from @​opentelemetry/resource-detector-container's changelog.

0.7.10 (2025-10-21)

Dependencies

  • The following workspace dependencies were updated
    • devDependencies
      • @​opentelemetry/contrib-test-utils bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.26.0 to ^0.27.0
Commits

Updates @opentelemetry/resources from 2.1.0 to 2.2.0

Release notes

Sourced from @​opentelemetry/resources's releases.

v2.2.0

2.2.0

🐛 Bug Fixes

  • fix(core): avoid leaking Node.js types via unrefTimer() util #5986 @​pichlermarc
  • fix(core): avoid leaking Node.js types via otperformance #5987 @​pichlermarc
    • important: this bug fix may be breaking for certain uses of otperformance
      • otperformance.now() and otperformance.timeOrigin are not affected.
      • the previously used type was incorrect and overly broad, leading to unexpected run-time behavior runtimes that are not Node.js.
      • these problems are now caught on compile-time: if you have been using this API and this change is breaking to you, please consider using your target platform's performance implementation instead.

🏠 Internal

  • test(shim-opentracing): add comparison thresholds in flaky assertions #5974 @​cjihrig
  • test(exporter-jaeger): clean up OTEL_EXPORTER_JAEGER_AGENT_PORT between tests #6003 @​cjihrig
  • test(sdk-trace-base): ensure environment variables are cleaned up between tests #6011 @​cjihrig
  • perf(opentelemetry-core): optimize attribute serialization #5866 @​43081j
  • test: test Node.js 25 in CI #6019 @​cjihrig
Changelog

Sourced from @​opentelemetry/resources's changelog.

2.2.0

🐛 Bug Fixes

  • fix(core): avoid leaking Node.js types via unrefTimer() util #5986 @​pichlermarc
  • fix(core): avoid leaking Node.js types via otperformance #5987 @​pichlermarc
    • important: this bug fix may be breaking for certain uses of otperformance
      • otperformance.now() and otperformance.timeOrigin are not affected.
      • the previously used type was incorrect and overly broad, leading to unexpected run-time behavior runtimes that are not Node.js.
      • these problems are now caught on compile-time: if you have been using this API and this change is breaking to you, please consider using your target platform's performance implementation instead.

🏠 Internal

  • test(shim-opentracing): add comparison thresholds in flaky assertions #5974 @​cjihrig
  • test(exporter-jaeger): clean up OTEL_EXPORTER_JAEGER_AGENT_PORT between tests #6003 @​cjihrig
  • test(sdk-trace-base): ensure environment variables are cleaned up between tests #6011 @​cjihrig
  • perf(opentelemetry-core): optimize attribute serialization #5866 @​43081j
  • test: test Node.js 25 in CI #6019 @​cjihrig
Commits
  • fb6476d chore: prepare next release (#6008)
  • 2d115fd test: test Node.js 25 in CI (#6019)
  • fe8fd65 feat(opentelemetry-configuration): support file with format rc.2 (#6029)
  • 91e0d23 chore(deps): update actions/setup-node action to v6 (#6028)
  • 3bb5717 test(opentelemetry-configuration): ensure process.env is cleaned up after `...
  • a93b1dc chore(move-to-emeriuts): create token before checkout (#6018)
  • a39500d test(otlp-grpc-exporter-base): remove duplicated delete statements (#6022)
  • 8c62fb1 chore(deps): Update import-in-the-middle (#6020)
  • 6854413 test(sdk-logs): ensure process.env is cleaned up between tests (#6017)
  • 3353b6f feat(otlp-exporter-base): accept TLS config for node HTTP exporters from env ...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​opentelemetry/resources since your current version.


Updates @opentelemetry/sdk-logs from 0.206.0 to 0.207.0

Release notes

Sourced from @​opentelemetry/sdk-logs's releases.

experimental/v0.207.0

0.207.0

💥 Breaking Changes

🚀 Features

  • feat(sdk-node): always set up propagtion and context manager #5930
    • using (new NodeSDK).start() will now automatically set up a context management and propagation, even if no Trace SDK is initialized.
  • feat(otlp-exporter-base, otlp-grpc-exporter-base): add an option to let an SDK distribution prepend their own user-agent string in HTTP & GRPC exporters #5928 @​david-luna
  • feat(web): add session handling implementation 5173 @​martinkuba

🐛 Bug Fixes

  • fix(sdk-logs): Fix the batchLogProcessor exporting only upon _scheduledDelayMillis and ignoring maxExportBatchSize #5961 @​jacksonweber
  • fix(otlp-grpc-exporter-base): fix GRPC exporter not sending the user-agent header #5687 @​david-luna

🏠 Internal

  • test(opentelemetry-configuration): simplify management of environment variables #6004 @​cjihrig
  • test(opentelemetry-configuration): preserve special process.env behavior #6010 @​cjihrig
  • test(sdk-logs): ensure process.env is cleaned up between tests #6017 @​cjihrig
  • test(otlp-grpc-exporter-base): remove duplicated delete statements #6022 @​cjihrig
  • test(opentelemetry-configuration): ensure process.env is cleaned up after envVariableSubstitution tests #6026 @​cjihrig
Commits

Bumps the production-dependencies group with 13 updates:

| Package | From | To |
| --- | --- | --- |
| [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node) | `0.65.0` | `0.66.0` |
| [@opentelemetry/core](https://github.com/open-telemetry/opentelemetry-js) | `2.1.0` | `2.2.0` |
| [@opentelemetry/exporter-logs-otlp-proto](https://github.com/open-telemetry/opentelemetry-js) | `0.206.0` | `0.207.0` |
| [@opentelemetry/exporter-metrics-otlp-proto](https://github.com/open-telemetry/opentelemetry-js) | `0.206.0` | `0.207.0` |
| [@opentelemetry/exporter-trace-otlp-proto](https://github.com/open-telemetry/opentelemetry-js) | `0.206.0` | `0.207.0` |
| [@opentelemetry/instrumentation-kafkajs](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-kafkajs) | `0.16.0` | `0.17.0` |
| [@opentelemetry/resource-detector-container](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/resource-detector-container) | `0.7.9` | `0.7.10` |
| [@opentelemetry/resources](https://github.com/open-telemetry/opentelemetry-js) | `2.1.0` | `2.2.0` |
| [@opentelemetry/sdk-logs](https://github.com/open-telemetry/opentelemetry-js) | `0.206.0` | `0.207.0` |
| [@opentelemetry/sdk-metrics](https://github.com/open-telemetry/opentelemetry-js) | `2.1.0` | `2.2.0` |
| [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) | `0.206.0` | `0.207.0` |
| [@opentelemetry/sdk-trace-base](https://github.com/open-telemetry/opentelemetry-js) | `2.1.0` | `2.2.0` |
| [@opentelemetry/sdk-trace-node](https://github.com/open-telemetry/opentelemetry-js) | `2.1.0` | `2.2.0` |


Updates `@opentelemetry/auto-instrumentations-node` from 0.65.0 to 0.66.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.66.0/packages/auto-instrumentations-node)

Updates `@opentelemetry/core` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.1.0...v2.2.0)

Updates `@opentelemetry/exporter-logs-otlp-proto` from 0.206.0 to 0.207.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.206.0...experimental/v0.207.0)

Updates `@opentelemetry/exporter-metrics-otlp-proto` from 0.206.0 to 0.207.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.206.0...experimental/v0.207.0)

Updates `@opentelemetry/exporter-trace-otlp-proto` from 0.206.0 to 0.207.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.206.0...experimental/v0.207.0)

Updates `@opentelemetry/instrumentation-kafkajs` from 0.16.0 to 0.17.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/instrumentation-kafkajs/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/winston-transport-v0.17.0/packages/instrumentation-kafkajs)

Updates `@opentelemetry/resource-detector-container` from 0.7.9 to 0.7.10
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/resource-detector-container/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/resource-detector-container-v0.7.10/packages/resource-detector-container)

Updates `@opentelemetry/resources` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.1.0...v2.2.0)

Updates `@opentelemetry/sdk-logs` from 0.206.0 to 0.207.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.206.0...experimental/v0.207.0)

Updates `@opentelemetry/sdk-metrics` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.1.0...v2.2.0)

Updates `@opentelemetry/sdk-node` from 0.206.0 to 0.207.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.206.0...experimental/v0.207.0)

Updates `@opentelemetry/sdk-trace-base` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.1.0...v2.2.0)

Updates `@opentelemetry/sdk-trace-node` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.1.0...v2.2.0)

---
updated-dependencies:
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/core"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/exporter-logs-otlp-proto"
  dependency-version: 0.207.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/exporter-metrics-otlp-proto"
  dependency-version: 0.207.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/exporter-trace-otlp-proto"
  dependency-version: 0.207.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/instrumentation-kafkajs"
  dependency-version: 0.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/resource-detector-container"
  dependency-version: 0.7.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/resources"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/sdk-logs"
  dependency-version: 0.207.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/sdk-metrics"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.207.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/sdk-trace-base"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@opentelemetry/sdk-trace-node"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 27, 2025
@dependabot dependabot bot requested a review from a team as a code owner October 27, 2025 06:29
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 27, 2025
@socket-security
Copy link

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
safer-buffer@2.1.2 has Obfuscated code.

Confidence: 0.94

Location: Package overview

From: test/apps/express-typescript/package-lock.jsonnpm/express@4.21.2npm/safer-buffer@2.1.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/safer-buffer@2.1.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@sonarqubecloud
Copy link

@ten15bit ten15bit merged commit 411657d into main Oct 27, 2025
12 checks passed
@ten15bit ten15bit deleted the dependabot/npm_and_yarn/production-dependencies-de1e9cf3e6 branch October 27, 2025 07:24
@github-actions
Copy link

🎉 This PR is included in version 3.0.6 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code released

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants