Skip to content
This repository has been archived by the owner on Apr 14, 2024. It is now read-only.

Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.17.2 #400

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 23, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
io.zipkin.reporter2:zipkin-sender-okhttp3 2.16.3 -> 2.17.2 age adoption passing confidence

Release Notes

openzipkin/zipkin-reporter-java (io.zipkin.reporter2:zipkin-sender-okhttp3)

v2.17.2: Zipkin Reporter 2.17.2

Compare Source

Zipkin Reporter v2.17.2 fixes a bug where the jars that should be at Java 1.6 or 1.7 bytecode were not.

Full Changelog: https://github.com/openzipkin/zipkin-reporter-java/compare/2.17.0..2.17.2

v2.17.1

Compare Source

v2.17.0: Zipkin Reporter 2.17.0

Compare Source

Zipkin Reporter v2.17.0 updates default versions of dependencies so that CVE scanners like trivy pass by default. Details below for the interested.

For example, trivy is now clean.

$ trivy -q --skip-files "**/src/it/*/pom.xml" repo https://github.com/openzipkin/zipkin-reporter-java

In order to do this, and based on user demand, we had to change some default practice in our senders (the transport plug-in for sending spans to a zipkin compatible endpoint). Here is a summary of each and how versions are handled.

  • activemq-client - Note that the recently released 6.x version is not compatible with 5.x due to package import change from javax.jms to jakarta.jms. Raise an issue if you need a later client as it will require a copy of the entire module to resolve.
  • amqp-client (rabbitmq) - The 4.x version is no longer maintained, so we set a 5.x version and test the old one.
  • kafka - the kafka-clients driver has not had any known compatibility problems, so we've left it as-is.
  • libthrift (scribe) - libthrift (used for the deprecated scribe transport) has never released a 1.0 version, so occasionally causes revlocks. @​zhfeng noticed this in apache camel, as updating past the 4 year old 0.13 was impossible to work around. Luckily versions after that seem compatible with each other.
  • okhttp3 - The 3.x version is no longer maintained, so we set a 4.x version and test the old one. Thanks @​evantorrie for explaining why this is important and @​shakuzen for helping in the discussion.

While not end-user affecting, we have also migrated from JUnit 4 to JUnit 5, thanks to OpenRewrite recipes from @​TeamModerne. Also, we use docker images to test all messaging transports. This ensures compatibility with upstream in transparent ways, and also removes classpath conflicts from java-based messaging transports such as ActiveMQ and Kafka.

Thanks a lot to @​anuraaga for copious support work on this release, as well.

Full Changelog: openzipkin/zipkin-reporter-java@2.16.5...2.17.0

Note: To pass Trivy at the moment, we have to skip old versions used only for compatibility testing. There is a discussion about making this default.

v2.16.5: Zipkin Reporter 2.16.5

Compare Source

Zipkin Reporter v2.16.5 updates dependencies and moves the build to work on current LTS JDKs (11, 17 and 21). Runtime Java versions remain the same. For example, the minimum Java version of the core jar remains 1.6.

Full Changelog: openzipkin/zipkin-reporter-java@2.16.4...2.16.5

v2.16.4: Zipkin Reporter 2.16.4

Compare Source

What's Changed

Full Changelog: openzipkin/zipkin-reporter-java@2.16.3...2.16.4


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.16.4 Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.16.5 Dec 11, 2023
@renovate renovate bot force-pushed the renovate/io.zipkin.reporter2-zipkin-sender-okhttp3-2.x branch 2 times, most recently from 22f5444 to ad7cc62 Compare December 14, 2023 19:40
@renovate renovate bot changed the title Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.16.5 Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.17.0 Dec 14, 2023
@renovate renovate bot force-pushed the renovate/io.zipkin.reporter2-zipkin-sender-okhttp3-2.x branch from ad7cc62 to b80d6de Compare December 18, 2023 06:17
@renovate renovate bot changed the title Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.17.0 Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.17.1 Dec 18, 2023
@renovate renovate bot force-pushed the renovate/io.zipkin.reporter2-zipkin-sender-okhttp3-2.x branch from b80d6de to abe7592 Compare January 6, 2024 09:26
@renovate renovate bot changed the title Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.17.1 Update dependency io.zipkin.reporter2:zipkin-sender-okhttp3 to v2.17.2 Jan 6, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants