Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 13, 2025

Bumps the observability group with 3 updates in the / directory: @opentelemetry/auto-instrumentations-node, @opentelemetry/exporter-trace-otlp-http and @opentelemetry/sdk-node.

Updates @opentelemetry/auto-instrumentations-node from 0.62.2 to 0.64.1

Release notes

Sourced from @​opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.64.1

0.64.1 (2025-09-11)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-redis bumped from ^0.54.0 to ^0.54.1
      • @​opentelemetry/resource-detector-gcp bumped from ^0.39.0 to ^0.40.0

auto-instrumentations-node: v0.64.0

0.64.0 (2025-09-10)

Features

  • deps: update deps matching '@opentelemetry/*' (#3034) (bee0a66)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.55.0 to ^0.56.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.20.0 to ^0.21.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.22.0 to ^0.23.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-express bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-fastify bumped from ^0.49.0 to ^0.50.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.24.0 to ^0.25.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.14.0 to ^0.15.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.49.0 to ^0.50.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.49.0 to ^0.50.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.50.0 to ^0.51.0

... (truncated)

Changelog

Sourced from @​opentelemetry/auto-instrumentations-node's changelog.

0.64.1 (2025-09-11)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-redis bumped from ^0.54.0 to ^0.54.1
      • @​opentelemetry/resource-detector-gcp bumped from ^0.39.0 to ^0.40.0

0.64.0 (2025-09-10)

Features

  • deps: update deps matching '@opentelemetry/*' (#3034) (bee0a66)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.55.0 to ^0.56.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.20.0 to ^0.21.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.22.0 to ^0.23.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-express bumped from ^0.53.0 to ^0.54.0
      • @​opentelemetry/instrumentation-fastify bumped from ^0.49.0 to ^0.50.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.24.0 to ^0.25.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.14.0 to ^0.15.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.49.0 to ^0.50.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.52.0 to ^0.53.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.49.0 to ^0.50.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.51.0 to ^0.52.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.50.0 to ^0.51.0
      • @​opentelemetry/instrumentation-net bumped from ^0.48.0 to ^0.49.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.30.0 to ^0.31.0

... (truncated)

Commits

Updates @opentelemetry/exporter-trace-otlp-http from 0.203.0 to 0.205.0

Release notes

Sourced from @​opentelemetry/exporter-trace-otlp-http's releases.

experimental/v0.205.0

0.205.0

💥 Breaking Changes

  • fix(otlp-exporter-base)!: split node and browser config types in two #5917 @​pichlermarc
    • Fixes a bug where Node.js modules would be incorrectly used in the instantiation of a web-targeted exporter
    • Breaking changes:
      • (user-facing) createOtlpHttpExportDelegate(OtlpHttpConfiguration) has been changed to take a different, but identical type OtlpNodeHttpConfiguration to differentiate it from the web-targeted exporters
      • (user-facing) convertLegacyHttpOptions(...) now returns OtlpNodeHttpConfiguration, the returned object's contents remain identical.
      • (user-facing) agentFactory has been dropped from OtlpHttpConfiguration as it is node-specific and is now part of OtlpNodeHttpConfiguration instead

experimental/v0.204.0

0.204.0

💥 Breaking Changes

  • feat(api-logs)!: Marked private methods as "conventionally private". #5789
  • feat(exporter-otlp-*): support custom HTTP agents #5719 @​raphael-theriault-swi
    • OtlpHttpConfiguration.agentOptions has been removed and functionality has been rolled into OtlpHttpConfiguration.agentFactory
      • (old) { agentOptions: myOptions }
      • (new) { agentFactory: httpAgentFactoryFromOptions(myOptions) }

🚀 Features

  • feat(otlp-exporter-base): Add fetch transport for fetch-only environments like service workers. #5807
    • when using headers, the Browser exporter now prefers fetch over XMLHttpRequest if present. Sending via XMLHttpRequest will be removed in a future release.
  • feat(opentelemetry-configuration): creation of basic ConfigProvider #5809 @​maryliag
  • feat(opentelemetry-configuration): creation of basic FileConfigProvider #5863 @​maryliag
  • feat(sdk-node): Add support for multiple metric readers via the new metricReaders option in NodeSDK configuration. Users can now register multiple metric readers (e.g., Console, Prometheus) directly through the NodeSDK constructor. The old metricReader (singular) option is now deprecated and will show a warning if used, but remains supported for backward compatibility. Comprehensive tests and documentation have been added. #5760
    • Migration:

      • Before:

        const sdk = new NodeSDK({ metricReader: myMetricReader });
      • After:

        const sdk = new NodeSDK({ metricReaders: [myMetricReader] });
    • Users should migrate to the new metricReaders array option for future compatibility. The old option will be removed in an upcoming experimental version.

  • feat(instrumentation-http): Added support for redacting specific url query string values and url credentials #5743 @​rads-1996

🐛 Bug Fixes

  • fix(otlp-exporter-base): prioritize esnext export condition as it is more specific #5458

... (truncated)

Commits

Updates @opentelemetry/sdk-node from 0.203.0 to 0.205.0

Release notes

Sourced from @​opentelemetry/sdk-node's releases.

experimental/v0.205.0

0.205.0

💥 Breaking Changes

  • fix(otlp-exporter-base)!: split node and browser config types in two #5917 @​pichlermarc
    • Fixes a bug where Node.js modules would be incorrectly used in the instantiation of a web-targeted exporter
    • Breaking changes:
      • (user-facing) createOtlpHttpExportDelegate(OtlpHttpConfiguration) has been changed to take a different, but identical type OtlpNodeHttpConfiguration to differentiate it from the web-targeted exporters
      • (user-facing) convertLegacyHttpOptions(...) now returns OtlpNodeHttpConfiguration, the returned object's contents remain identical.
      • (user-facing) agentFactory has been dropped from OtlpHttpConfiguration as it is node-specific and is now part of OtlpNodeHttpConfiguration instead

experimental/v0.204.0

0.204.0

💥 Breaking Changes

  • feat(api-logs)!: Marked private methods as "conventionally private". #5789
  • feat(exporter-otlp-*): support custom HTTP agents #5719 @​raphael-theriault-swi
    • OtlpHttpConfiguration.agentOptions has been removed and functionality has been rolled into OtlpHttpConfiguration.agentFactory
      • (old) { agentOptions: myOptions }
      • (new) { agentFactory: httpAgentFactoryFromOptions(myOptions) }

🚀 Features

  • feat(otlp-exporter-base): Add fetch transport for fetch-only environments like service workers. #5807
    • when using headers, the Browser exporter now prefers fetch over XMLHttpRequest if present. Sending via XMLHttpRequest will be removed in a future release.
  • feat(opentelemetry-configuration): creation of basic ConfigProvider #5809 @​maryliag
  • feat(opentelemetry-configuration): creation of basic FileConfigProvider #5863 @​maryliag
  • feat(sdk-node): Add support for multiple metric readers via the new metricReaders option in NodeSDK configuration. Users can now register multiple metric readers (e.g., Console, Prometheus) directly through the NodeSDK constructor. The old metricReader (singular) option is now deprecated and will show a warning if used, but remains supported for backward compatibility. Comprehensive tests and documentation have been added. #5760
    • Migration:

      • Before:

        const sdk = new NodeSDK({ metricReader: myMetricReader });
      • After:

        const sdk = new NodeSDK({ metricReaders: [myMetricReader] });
    • Users should migrate to the new metricReaders array option for future compatibility. The old option will be removed in an upcoming experimental version.

  • feat(instrumentation-http): Added support for redacting specific url query string values and url credentials #5743 @​rads-1996

🐛 Bug Fixes

  • fix(otlp-exporter-base): prioritize esnext export condition as it is more specific #5458

... (truncated)

Commits

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Sep 13, 2025

Assignees

The following users could not be added as assignees: user-service-team. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions
Copy link

github-actions bot commented Sep 13, 2025

Dependency Review

The following issues were found:

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.

View full job summary

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/observability-9e05851bff branch from 6d08992 to 0ad3680 Compare October 6, 2025 09:49
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/observability-9e05851bff branch 4 times, most recently from 22871e3 to 92c34bc Compare October 20, 2025 10:25
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/observability-9e05851bff branch from 92c34bc to c088149 Compare October 27, 2025 10:33
…dates

Bumps the observability group with 3 updates in the / directory: [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node), [@opentelemetry/exporter-trace-otlp-http](https://github.com/open-telemetry/opentelemetry-js) and [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js).


Updates `@opentelemetry/auto-instrumentations-node` from 0.62.2 to 0.64.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.64.1/packages/auto-instrumentations-node)

Updates `@opentelemetry/exporter-trace-otlp-http` from 0.203.0 to 0.205.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.203.0...experimental/v0.205.0)

Updates `@opentelemetry/sdk-node` from 0.203.0 to 0.205.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.203.0...experimental/v0.205.0)

---
updated-dependencies:
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.64.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: observability
- dependency-name: "@opentelemetry/exporter-trace-otlp-http"
  dependency-version: 0.205.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: observability
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.205.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: observability
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/observability-9e05851bff branch from c088149 to 329ef82 Compare November 10, 2025 11:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant