Skip to content

Bump OpenTelemetry.Api from 1.15.3 to 1.17.0#10

Closed
dependabot[bot] wants to merge 15 commits into
mainfrom
dependabot/nuget/OpenTelemetry.Api-1.17.0
Closed

Bump OpenTelemetry.Api from 1.15.3 to 1.17.0#10
dependabot[bot] wants to merge 15 commits into
mainfrom
dependabot/nuget/OpenTelemetry.Api-1.17.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 16, 2026

Copy link
Copy Markdown
Contributor

Updated OpenTelemetry.Api from 1.15.3 to 1.17.0.

Release notes

Sourced from OpenTelemetry.Api's releases.

1.17.0

For highlights and announcements pertaining to this release see: Release Notes > 1.17.0.

The following changes are from the previous release 1.17.0-rc.1.

... (truncated)

1.17.0-rc.1

The following changes are from the previous release 1.16.0.

  • NuGet: OpenTelemetry v1.17.0-rc.1

    • Fixed a metric point reclaim data race on CPU ARM architectures.
      (#​7401)

    • The library is now marked as trim and AOT compatible.
      (#​7441)

    • Replaced the vendored copy of
      EnvironmentVariablesConfigurationProvider with a direct
      Microsoft.Extensions.Configuration.EnvironmentVariables package dependency.
      Consumers gain automatic pickup of upstream bug fixes and security patches;
      no public API or behavioural change.
      (#​7146)

    • Added a verbose OpenTelemetry-Sdk self-diagnostics event that is emitted
      when an activity is dropped because its local (in-process) parent is not
      recorded.
      (#​7427)

    • Added support for a Schema URL on Resource instances.
      (#​7472)

    • Fixed a metric storage leak that occurred when meters and instruments were
      repeatedly created and disposed.
      (#​7466)

    • Added ExcludedTagKeys property to MetricStreamConfiguration to support
      excluding specific tag keys from metric streams.
      (#​7373)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api v1.17.0-rc.1

    • Fixed TraceContextPropagator to normalize empty tracestate header values
      to null when extracting trace context.
      (#​7407,
      #​7433)

    • The library is now marked as trim and AOT compatible.
      (#​7441)

    • Experimental (pre-release builds only): Updated EnvironmentVariableCarrier.Get
      to read only the normalized environment variable name, following the updated
      environment variable carrier specification.
      Non-normalized carrier keys are no longer matched, even when they would
      normalize to the requested key.
      ... (truncated)

1.17.0-beta.1

The following changes are from the previous release 1.16.0-beta.1.

  • NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.17.0-beta.1

    • Added a verbose-level diagnostic event for ignored metrics.
      (#​7429)

    • The library is now marked as trim and AOT compatible.
      (#​7441)

    • Fix double unit suffixes in metric names when using OpenMetrics.
      (#​7454)

    • Fix incorrect handling of leading digits in metric names for OpenMetrics.
      (#​7454)

    • Add PrometheusAspNetCoreOptions.ScopeInfoEnabled property to enable or
      disable scope labels in Prometheus metrics. Defaults to true.
      (#​7436)

    • Added support for the dots and values Prometheus UTF-8 name escaping
      schemes when negotiated via the Accept header.
      (#​7439)

    • Add PrometheusAspNetCoreOptions.TargetInfoEnabled property to enable or
      disable the target_info metric in Prometheus metrics. Defaults to true.
      (#​7438)

    • Added support for the allow-utf-8 Prometheus UTF-8 name escaping scheme
      when negotiated via the Accept header.
      (#​7440)

    • Add PrometheusAspNetCoreOptions.ResourceConstantLabels property to select
      resource attributes to add to each metric as constant labels. Defaults to
      null (no resource attributes are added as metric labels).
      (#​7471)

    • Add PrometheusAspNetCoreOptions.MaxScrapeResponseSizeBytes to configure
      the maximum size of a scrape response. The default is now ~166 MiB.
      (#​7487)

    • A scrape whose serialized output exceeds the maximum scrape response size
      limit now responds with HTTP 500.
      (#​7487)

    • Fixed the Prometheus text exposition format emitting redundant comments.
      (#​7491)

    • Made Accept header content negotiation consistent with the
      PrometheusHttpListener endpoint.
      ... (truncated)

1.16.0

For highlights and announcements pertaining to this release see: Release Notes > 1.16.0.

The following changes are from the previous release 1.16.0-rc.1.

... (truncated)

1.16.0-rc.1

The following changes are from the previous release 1.15.3.

  • NuGet: OpenTelemetry v1.16.0-rc.1

    • Stop validating View-provided metric stream Name against the instrument
      name syntax, per
      spec clarification.
      (#​7300)

    • Fix incorrect validation of OTEL_BSP_* and OTEL_BLRP_* environment
      variables.
      (#​7187)

    • Fix observable instrument callbacks running once per reader instead of
      once per collection cycle.
      (#​7188)

    • Added exception safety for user-supplied ExemplarReservoir implementations.
      Exceptions thrown from Offer are now caught and logged rather than propagating
      out of Counter.Add/Histogram.Record.
      (#​7277)

    • Update OpenTelemetrySdkEventSource to support the W3C randomness flag.
      (#​7301)

    • Added ObservedTimestamp property to LogRecord.
      (#​6979)

    • Breaking Change Explicit histogram boundaries no longer allow more than
      10 million values.
      (#​7165)

    • Fixed a circular reference which could cause a LoggerProvider to fail to
      resolve when one of its dependencies depends on ILogger or ILoggerFactory.
      As part of this fix the LoggerProvider resolved from dependency injection
      is now created lazily when the first logger is created rather than when
      ILoggerProvider or ILoggerFactory is resolved. A consequence is that any
      invalid configuration now surfaces when the first log record is written instead
      of when the logging services are resolved.
      (#​7308)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api v1.16.0-rc.1

    • Experimental (pre-release builds only):
      Add support for using environment variables as context propagation carriers.
      (#​7174)

    • Fix BaggagePropagator to correctly follow Key and Value Encoding rules as per
      ... (truncated)

1.16.0-beta.1

The following changes are from the previous release 1.15.3-beta.1.

  • NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.16.0-beta.1

    • Fixed scrape response cache freshness using monotonic time so it is not
      affected by NTP system clock adjustments.
      (#​7253)

    • Breaking Change Removed DisableTimestamp property from
      PrometheusAspNetCoreOptions.
      (#​7176)

    • Fixed the serialization of NaN, PositiveInfinity, and NegativeInfinity
      values in Prometheus metrics to be compliant with the specification.
      (#​7179)

    • Fixed loss of precision when serializing double and float values in
      Prometheus metrics to be compliant with the specification by using 17
      significant digits to represent such values.
      (#​7179)

    • Fix non-ASCII characters in metric names and unit strings not being sanitized
      correctly during Prometheus serialization.
      (#​7184)

    • Fix case where reader tracking could be reset while readers were still active.
      (#​7190)

    • Improve Accept header handling for format negotiation so OpenMetrics is
      selected correctly by considering whitespace and q weights.
      (#​7208)

    • Emit OpenMetrics exemplars for counters and histogram buckets.
      (#​7222)

    • Fix incorrect handling of untyped metrics when using OpenMetrics format.
      (#​7219)

    • Fix Prometheus/OpenMetrics serialization to emit metric and label names
      containing _ instead of dropping them and prefixing leading digits.
      Invalid characters are replaced with _ instead of being dropped.
      (#​7209)

    • Add escaping=underscores to the Accept header handling for content
      negotiation so OpenMetrics are handled correctly.
      (#​7209)

    • Omit histogram _sum and _count in OpenMetrics when negative bucket
      thresholds are present.
      (#​7221)
      ... (truncated)

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

kkora and others added 15 commits July 16, 2026 00:04
…tion (Phases 1-6)

- Product discovery: vision, problem statement, use cases, personas, competitive analysis, roadmap, positioning
- Feature planning: catalog (F-001..F-029), matrix, MVP scope, future roadmap
- Architecture: overview, package boundaries, dependency rules, extension model, error model, observability, Mermaid diagrams, ADRs 0001-0009
- Public API design, naming guidelines, backward-compatibility policy, review checklist
- Implementation plan, backlog, milestones, risk register, definition of done

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
…s 0-3)

- Build infrastructure: Directory.Build.props layers, central package management, global.json, editorconfig, NuGet.Config, solution with 17 projects
- Community files: CLAUDE.md, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY, SUPPORT, CHANGELOG, ROADMAP, issue/PR templates
- CI: build/test/package/release/codeql/dependency-review workflows + dependabot
- Koras.AI.Abstractions: IChatClient/IEmbeddingClient/IProviderHealthProbe, chat models, streaming updates, AiTool with delegate schema generation, response formats, embeddings, AiException/AiErrorCode
- Koras.AI core: DelegatingChatClient, retry with backoff+jitter+Retry-After, fallback client, tool-invocation loop, structured output extensions, PromptTemplate, DI builder/factory, logging + GenAI-convention telemetry, provider plumbing (SSE/JSONL readers, error normalization)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
…4-6, 8 partial)

- Providers: OpenAI (reference), AzureOpenAI (deployment URLs, api-key auth), Anthropic (Messages API, forced-tool structured output, SSE event grammar), Gemini (generateContent, schema dialect cleaning, header auth), Ollama (JSON-lines streaming, native API, localhost hints)
- Integrations: AspNetCore health checks with probe discovery through decorator chains; OpenTelemetry registration package
- Tests: 207 unit tests (models, tools, schema, templates, retry with manual TimeProvider, fallback, tool loop, DI, telemetry via Activity/MeterListener, per-provider wire mapping, shared provider contract suite), 16 architecture tests (dependency rules + public API snapshots), 8 Kestrel end-to-end integration tests (SSE/JSONL streaming, retry, fallback, health, cancellation)
- SseReader/JsonLinesReader observe cancellation on buffered data
- OpenTelemetry.Api pinned to 1.15.3 after NuGet audit flagged 1.11.x/1.12.0 advisories

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
- Console sample: chat, streaming, structured output, automatic tool loop, embeddings; Ollama default with OpenAI opt-in via user secrets
- Minimal API sample: /chat JSON endpoint + /chat/stream SSE endpoint
- Web API sample: controllers, conditional provider registration, fallback chain as default client, AiException-to-HTTP mapping, health checks
- Worker Service sample: retry-hardened background summarizer with graceful shutdown
- BenchmarkDotNet project covering serialization, round-trip dispatch, SSE parsing, schema generation, template rendering
- Full solution builds warning-free; 438 test executions green across net8/net9/net10; dotnet format clean

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
…y statement

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
…es 8-10, 16)

- Security: threat model (STRIDE, trust boundaries), secure configuration, data protection, dependency security, consumer+maintainer checklists
- Performance: performance guide, benchmark methodology, memory management
- Testing: test strategy, test matrix, integration/compatibility/performance testing
- Release: versioning policy, release process, NuGet publishing, release checklist with 0.1.0-preview.1 → 1.0.0 plan

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
One guide per feature (chat, streaming, structured output, tools, embeddings, templates,
resilience, fallback, error handling, telemetry, health checks, DI, custom providers) and
per provider (OpenAI, Azure OpenAI, Anthropic, Gemini, Ollama) with options tables,
error-mapping tables, and provider quirks. Align error-model doc with the implemented
Gemini invalid-key mapping (HTTP 400 → InvalidRequest).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
…tion, and API reference

- docs/index.md documentation home with full linked table of contents
- Recipes: common scenarios, advanced scenarios, production configuration, testing recipes
- Configuration: all-options reference, environment variables, appsettings, validation
- Troubleshooting: common errors (AiErrorCode table), diagnostics, logging, provider quirks, FAQ
- Migration: versioning policy, upgrading, breaking-changes template
- API reference overview (namespace/type map per package)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YFvY1FYd6V7xaAnbBAC31D
…preview.1) (#1)

feat: Koras.AI SDK — provider-neutral AI client for .NET (MVP, 0.1.0-preview.1)
---
updated-dependencies:
- dependency-name: OpenTelemetry.Api
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Jul 16, 2026
@kkora kkora closed this Jul 16, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/nuget/OpenTelemetry.Api-1.17.0 branch July 16, 2026 19:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants