Skip to content

Bump the otel group with 4 updates - #27

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/otel-c0ce51578d
Open

Bump the otel group with 4 updates#27
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/otel-c0ce51578d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the otel group with 4 updates: @opentelemetry/auto-instrumentations-node, @opentelemetry/sdk-metrics, @opentelemetry/sdk-node and @opentelemetry/sdk-trace-node.

Updates @opentelemetry/auto-instrumentations-node from 0.72.0 to 0.74.0

Release notes

Sourced from @​opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.74.0

0.74.0 (2026-04-29)

Features

  • deps: update deps matching '@opentelemetry/*' (#3497) (a91133a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.70.0 to ^0.71.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.31.0 to ^0.32.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.32.0 to ^0.33.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-express bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.24.0 to ^0.25.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-net bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.13.0 to ^0.14.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-router bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.28.0 to ^0.29.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.25.0 to ^0.26.0

... (truncated)

Changelog

Sourced from @​opentelemetry/auto-instrumentations-node's changelog.

0.74.0 (2026-04-29)

Features

  • deps: update deps matching '@opentelemetry/*' (#3497) (a91133a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.70.0 to ^0.71.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.31.0 to ^0.32.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.32.0 to ^0.33.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-express bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.24.0 to ^0.25.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-net bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.13.0 to ^0.14.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.63.0 to ^0.64.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-router bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.28.0 to ^0.29.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.25.0 to ^0.26.0
      • @​opentelemetry/instrumentation-winston bumped from ^0.59.0 to ^0.60.0

... (truncated)

Commits

Updates @opentelemetry/sdk-metrics from 2.6.1 to 2.7.1

Release notes

Sourced from @​opentelemetry/sdk-metrics's releases.

v2.7.1

2.7.1

🐛 Bug Fixes

  • fix(core, api): defer trace state validation. Deprecate trace state implementation in api #6459 @​david-luna
    • important: this bug fix may be breaking for certain uses of TraceState
      • set now returns the same TraceState instance if key/value are invalid or makes the while trace state invalid.
      • unset now returns the same TraceState instance if key is not present.
      • best-effort parsing of invalid TraceStates has changed: when multiple keys with the same name are present, the most recent one will win.

🏠 Internal

v2.7.0

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

Changelog

Sourced from @​opentelemetry/sdk-metrics's changelog.

2.7.1

🐛 Bug Fixes

  • fix(core, api): defer trace state validation. Deprecate trace state implementation in api #6459 @​david-luna
    • important: this bug fix may be breaking for certain uses of TraceState
      • set now returns the same TraceState instance if key/value are invalid or makes the while trace state invalid.
      • unset now returns the same TraceState instance if key is not present.
      • best-effort parsing of invalid TraceStates has changed: when multiple keys with the same name are present, the most recent one will win.

🏠 Internal

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

Commits
  • 2400d83 chore: prepare next release (#6647)
  • f7a9b7c fix(otlp-transformer): pin protobufjs to 8.0.1 (#6646)
  • cb38d7f test(otlp-transformer): add metrics transfrom benchmark (#6628)
  • a28f12f fix(opentelemetry-core): defer tracestate vaidation (#6459)
  • b27c514 refactor(opentelemetry-exporter-prometheus): do not call `enforcePrometheusNa...
  • a2a8186 perf(sdk-trace-base): optimize TraceIdRatioBasedSampler hex parsing (#6284)
  • 4c0f3f1 feat(sdk-node): set TracerProvider in startNodeSDK() (#6607)
  • 417f2f1 fix(instr-xhr): do not unpatch XHR methods (#6611)
  • 47ac523 Revert "chore: allow browser maintainers to approve changelog edits" (#6627)
  • 86c621d fix(instrumentation-fetch): tolerate non-writable globalThis.fetch and fix pr...
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-node from 0.214.0 to 0.216.0

Release notes

Sourced from @​opentelemetry/sdk-node's releases.

experimental/v0.216.0

0.216.0

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-xml-http-request): avoid unwrapping XMLHttpRequest API when disabling #6611 @​david-luna
  • fix(instrumentation-fetch): tolerate non-writable globalThis.fetch and fix premature _isEnabled / _isFetchPatched flips in enable() @​brunorodmoreira
  • fix(instrumentation-xhr): resolve relative URLs before matching ignoreUrls #6551 @​Maximiliano-Zeballos
  • fix(sdk-node): fix setting of ViewOption#name from ConfigurationModel #6620 @​trentm
  • fix(web-common): add limit for timeout #6601 @​maryliag
  • fix(otlp-transformer): pin protobufjs@8.0.1 as protobufjs@8.0.3 is broken for browser use #6646

🏠 Internal

  • test(otlp-transformer): add metrics transform benchmark #6628 @​pichlermarc
  • refactor(opentelemetry-exporter-prometheus): do not call enforcePrometheusNamingConvention() multiple times per metric #6636 @​cjihrig

experimental/v0.215.0

0.215.0

💥 Breaking Changes

  • feat(sdk-logs)!: add required forceFlush() to LogRecordExporter interface #6356 @​pichlermarc
    • (user-facing): LogRecordExporter interface now requires a forceFlush() method to be implemented. Custom exporters will need to implement this method to continue working with the Logs SDK.
  • feat(api-logs, sdk-logs)!: add Logger#enabled() #6371 @​david-luna

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-fetch): preserve init overrides when input is a Request object #6421 @​akandic47
  • fix(otlp-exporter-base): limit Node.js HTTP transport response body to 4 MiB #6552 @​kartikgola
  • fix(instrumentation-fetch): avoid unwrapping fetch API when disabling #6575 @​david-luna
  • fix(web-common): add check for possible unsafe json parse #6589 @​maryliag
  • fix(otlp-transformer): add check for possible unsafe json parse #6588 @​maryliag
Commits
  • 2400d83 chore: prepare next release (#6647)
  • f7a9b7c fix(otlp-transformer): pin protobufjs to 8.0.1 (#6646)
  • cb38d7f test(otlp-transformer): add metrics transfrom benchmark (#6628)
  • a28f12f fix(opentelemetry-core): defer tracestate vaidation (#6459)
  • b27c514 refactor(opentelemetry-exporter-prometheus): do not call `enforcePrometheusNa...
  • a2a8186 perf(sdk-trace-base): optimize TraceIdRatioBasedSampler hex parsing (#6284)
  • 4c0f3f1 feat(sdk-node): set TracerProvider in startNodeSDK() (#6607)
  • 417f2f1 fix(instr-xhr): do not unpatch XHR methods (#6611)
  • 47ac523 Revert "chore: allow browser maintainers to approve changelog edits" (#6627)
  • 86c621d fix(instrumentation-fetch): tolerate non-writable globalThis.fetch and fix pr...
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-trace-node from 2.6.1 to 2.7.1

Release notes

Sourced from @​opentelemetry/sdk-trace-node's releases.

v2.7.1

2.7.1

🐛 Bug Fixes

  • fix(core, api): defer trace state validation. Deprecate trace state implementation in api #6459 @​david-luna
    • important: this bug fix may be breaking for certain uses of TraceState
      • set now returns the same TraceState instance if key/value are invalid or makes the while trace state invalid.
      • unset now returns the same TraceState instance if key is not present.
      • best-effort parsing of invalid TraceStates has changed: when multiple keys with the same name are present, the most recent one will win.

🏠 Internal

v2.7.0

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

Changelog

Sourced from @​opentelemetry/sdk-trace-node's changelog.

2.7.1

🐛 Bug Fixes

  • fix(core, api): defer trace state validation. Deprecate trace state implementation in api #6459 @​david-luna
    • important: this bug fix may be breaking for certain uses of TraceState
      • set now returns the same TraceState instance if key/value are invalid or makes the while trace state invalid.
      • unset now returns the same TraceState instance if key is not present.
      • best-effort parsing of invalid TraceStates has changed: when multiple keys with the same name are present, the most recent one will win.

🏠 Internal

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

Commits
  • 2400d83 chore: prepare next release (#6647)
  • f7a9b7c fix(otlp-transformer): pin protobufjs to 8.0.1 (#6646)
  • cb38d7f test(otlp-transformer): add metrics transfrom benchmark (#6628)
  • a28f12f fix(opentelemetry-core): defer tracestate vaidation (#6459)
  • b27c514 refactor(opentelemetry-exporter-prometheus): do not call `enforcePrometheusNa...
  • a2a8186 perf(sdk-trace-base): optimize TraceIdRatioBasedSampler hex parsing (#6284)
  • 4c0f3f1 feat(sdk-node): set TracerProvider in startNodeSDK() (#6607)
  • 417f2f1 fix(instr-xhr): do not unpatch XHR methods (#6611)
  • 47ac523 Revert "chore: allow browser maintainers to approve changelog edits" (#6627)
  • 86c621d fix(instrumentation-fetch): tolerate non-writable globalThis.fetch and fix pr...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the otel group with 4 updates: [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node), [@opentelemetry/sdk-metrics](https://github.com/open-telemetry/opentelemetry-js), [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) and [@opentelemetry/sdk-trace-node](https://github.com/open-telemetry/opentelemetry-js).


Updates `@opentelemetry/auto-instrumentations-node` from 0.72.0 to 0.74.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.74.0/packages/auto-instrumentations-node)

Updates `@opentelemetry/sdk-metrics` from 2.6.1 to 2.7.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.6.1...v2.7.1)

Updates `@opentelemetry/sdk-node` from 0.214.0 to 0.216.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.214.0...experimental/v0.216.0)

Updates `@opentelemetry/sdk-trace-node` from 2.6.1 to 2.7.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.6.1...v2.7.1)

---
updated-dependencies:
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.74.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: otel
- dependency-name: "@opentelemetry/sdk-metrics"
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: otel
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.216.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: otel
- dependency-name: "@opentelemetry/sdk-trace-node"
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: otel
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants