Skip to content

chore(deps): bump the go-deps group across 1 directory with 10 updates - #338

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/go-deps-b7624a6edf
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/go-deps-b7624a6edf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 10 updates in the / directory:

Package From To
github.com/grafana/pyroscope-go 1.4.2 1.4.3
github.com/neo4j/neo4j-go-driver/v6 6.2.0 6.3.0
github.com/qdrant/go-client 1.19.0 1.19.3
go.opentelemetry.io/otel 1.46.0 1.47.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc 1.46.0 1.47.0
go.opentelemetry.io/otel/sdk 1.46.0 1.47.0
go.opentelemetry.io/otel/trace 1.46.0 1.47.0
golang.org/x/crypto 0.55.0 0.57.0
golang.org/x/net 0.58.0 0.59.0
google.golang.org/grpc 1.83.2 1.84.0

Updates github.com/grafana/pyroscope-go from 1.4.2 to 1.4.3

Commits
  • 167de62 fix(security/high/x/k6): update module google.golang.org/grpc to v1.83.2 [sec...
  • d506eb4 fix(security/high/x/k6): update module google.golang.org/grpc to v1.83.1 [sec...
  • 973382d chore(godeltaprof): remove vestigial mutex profile scaler (#247)
  • 6929698 fix(security/unknown/): update go toolchain directive to v1.25.13 [security] ...
  • 4bdc603 fix(security/unknown/godeltaprof): update go toolchain directive to v1.25.13 ...
  • a79a61e fix(security/unknown/godeltaprof/compat): update go toolchain directive to v1...
  • d2cde9f fix(security/unknown/x/k6): update go toolchain directive to v1.25.13 [securi...
  • See full diff in compare view

Updates github.com/neo4j/neo4j-go-driver/v6 from 6.2.0 to 6.3.0

Release notes

Sourced from github.com/neo4j/neo4j-go-driver/v6's releases.

v6.3.0

See https://github.com/neo4j/neo4j-go-driver/wiki/6.x-changelog for more information.

Commits
  • ef40a44 Prepare 6.3.0 release (#711)
  • 08584d7 Port Pass impersonated user when refreshing the routing table (#707)
  • 21cd1a5 Fix: log patch_bolt field in SUCCESS responses (#710)
  • cf47898 Add object mapping for query results (preview) (#703)
  • 8653612 Pin pre-commit staticcheck to the version CI uses (#708)
  • 87dec72 Correct EagerResult field name in ExecuteQuery example (#702)
  • See full diff in compare view

Updates github.com/qdrant/go-client from 1.19.0 to 1.19.3

Release notes

Sourced from github.com/qdrant/go-client's releases.

v1.19.3

What's Changed

Features

Maintenance

Full Changelog: qdrant/go-client@v1.19.2...v1.19.3

v1.19.2

What's Changed

Full Changelog: qdrant/go-client@v1.19.1...v1.19.2

v1.19.1

What's Changed

New Contributors

Full Changelog: qdrant/go-client@v1.19.0...v1.19.1

Commits
  • c72545c feat: support more integer and slice types in NewValue() (#158)
  • 59f0ef6 chore(deps): bump google.golang.org/grpc in the version-updates group (#157)
  • 10b614a chore(deps): bump google.golang.org/grpc in /examples/simple (#156)
  • f411843 chore: return all connection close errors from Client.Close (#155)
  • ae79372 fix: keep gRPC status reachable from QdrantResourceExhaustedError (#154)
  • 4e80c73 fix: clamp retry backoff before Duration conversion to avoid overflow (#153)
  • 9039136 fix: surface server version probe error, add Config.Logger (#152)
  • 0f036f3 chore: do not mutate Config.GrpcOptions when creating a client (#151)
  • 9ce7b28 chore(deps): bump google.golang.org/grpc in the version-updates group (#149)
  • ac94687 chore(deps): bump google.golang.org/grpc in /examples/simple (#148)
  • Additional commits viewable in compare view

Updates go.opentelemetry.io/otel from 1.46.0 to 1.47.0

Release notes

Sourced from go.opentelemetry.io/otel's releases.

v1.47.0/v0.69.0/v0.23.0/v0.1.0

This release contains the first stable release of the OpenTelemetry Go Logs API and SDK. Our project stability guarantees now apply to the following modules:

  • go.opentelemetry.io/otel/log
  • go.opentelemetry.io/otel/sdk/log

See our versioning policy for more information about these stability guarantees.

Added

  • Add String method for KeyValue type in go.opentelemetry.io/otel/attribute. (#8205)
  • Add String method for Set type in go.opentelemetry.io/otel/attribute. (#8347)
  • Add WithMaxExportBatchSize to go.opentelemetry.io/otel/sdk/metric to configure the maximum export batch size for PeriodicReader. (#8960)
  • Add WithAttributeValueDepthLimit, DefaultAttributeValueDepthLimit, and SpanLimits.AttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/trace to configure the maximum depth of span, event, link, and instrumentation scope attribute values. (#8938)
  • Add WithAttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/log to configure the maximum depth of log record and instrumentation scope attribute values. (#8938)
  • Add WithMaxResponseSize to go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, and go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8941)
  • Add experimental ProbabilitySampler in go.opentelemetry.io/otel/sdk/trace/x that conforms to the OpenTelemetry specification's threshold-based sampling algorithm. (#8123)
  • Add experimental *Binder extension interfaces in go.opentelemetry.io/otel/metric/x for instruments that support binding attributes ahead of time. (#8760)
  • Add the experimental Finisher synchronous metric instrument extension interface to go.opentelemetry.io/otel/metric/x. (#8906)

Changed

  • Use the OpenTelemetry Attribute Collection representation for non-OTLP protocols for metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8993)
  • Apply a maximum depth of 64 by default to span, event, link, log record, and instrumentation scope attribute values in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log. (#8938)
  • Reduce allocations when applying attribute value length limits in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log by rebuilding composite values only when truncation is needed. (#8912)
  • Decode traceparent using a hex lookup table in go.opentelemetry.io/otel/propagation, which rejects the specification-disallowed upper-case characters without a separate scan of the header. (#8739)
  • Decode all characters at constant indices in TraceIDFromHex and SpanIDFromHex in go.opentelemetry.io/otel/trace to eliminate bounds checks. (#8740)

Fixed

  • Count valid U+FFFD replacement characters toward attribute value length limits in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log.
  • Truncate string attribute values to empty strings when the configured length limit is zero, including malformed UTF-8, in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log. (#9054)
  • Fix a data race in NewPeriodicReader where r.inst was assigned after the background goroutine was launched in go.opentelemetry.io/otel/sdk/metric. (#9028)
  • Prevent precision loss for large int64 values in Sum, Histogram, and ExponentialHistogram aggregations in go.opentelemetry.io/otel/sdk/metric. (#8981)
  • Ensure grpc.DialOption values passed via WithDialOption take precedence over conflicting internally-computed defaults in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc, and go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#8805, #8834, #8836)
  • Treat overflowing OTEL_METRIC_EXPORT_INTERVAL and OTEL_METRIC_EXPORT_TIMEOUT values as invalid in go.opentelemetry.io/otel/sdk/metric. (#8800)
  • Prevent a panic in NewFixedSizeReservoir and FixedSizeReservoirProvider when given a negative size in go.opentelemetry.io/otel/sdk/metric/exemplar; negative sizes are now clamped to zero, consistent with a size of zero. (#8832)
  • Preserve exponential histogram ZeroThreshold during OTLP metric export in go.opentelemetry.io/otel/exporters/otlp/otlpmetric. (#8801)
  • Ensure metric helpers in go.opentelemetry.io/otel/semconv/v1.32.0, go.opentelemetry.io/otel/semconv/v1.33.0, and go.opentelemetry.io/otel/semconv/v1.34.0 record measurements only once when no attributes are provided. (#8849)
  • Treat empty OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG values as unset in go.opentelemetry.io/otel/sdk/trace. (#8873)
  • Normalize global OTEL_EXPORTER_OTLP_ENDPOINT path joining in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp so trailing-slash base URLs do not produce double-slash log export paths. (#8864)
  • Prevent a deadlock when formatting an error passed to RecordError calls back into the span in go.opentelemetry.io/otel/sdk/trace. (#8815)
  • Prevent SimpleSpanProcessor.Shutdown from panicking when constructed with a nil exporter in go.opentelemetry.io/otel/sdk/trace. (#8844)
  • Propagate invalid exponential histogram scale errors to Prometheus exporter self-observability metrics in go.opentelemetry.io/otel/exporters/prometheus. (#8839)

... (truncated)

Changelog

Sourced from go.opentelemetry.io/otel's changelog.

[1.47.0/0.69.0/0.23.0/0.1.0] - 2026-10-02

This release contains the first stable release of the OpenTelemetry Go Logs API and SDK. Our project stability guarantees now apply to the following modules:

  • go.opentelemetry.io/otel/log
  • go.opentelemetry.io/otel/sdk/log

See our versioning policy for more information about these stability guarantees.

Added

  • Add String method for KeyValue type in go.opentelemetry.io/otel/attribute. (#8205)
  • Add String method for Set type in go.opentelemetry.io/otel/attribute. (#8347)
  • Add WithMaxExportBatchSize to go.opentelemetry.io/otel/sdk/metric to configure the maximum export batch size for PeriodicReader. (#8960)
  • Add WithAttributeValueDepthLimit, DefaultAttributeValueDepthLimit, and SpanLimits.AttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/trace to configure the maximum depth of span, event, link, and instrumentation scope attribute values. (#8938)
  • Add WithAttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/log to configure the maximum depth of log record and instrumentation scope attribute values. (#8938)
  • Add WithMaxResponseSize to go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, and go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8941)
  • Add experimental ProbabilitySampler in go.opentelemetry.io/otel/sdk/trace/x that conforms to the OpenTelemetry specification's threshold-based sampling algorithm. (#8123)
  • Add experimental *Binder extension interfaces in go.opentelemetry.io/otel/metric/x for instruments that support binding attributes ahead of time. (#8760)
  • Add the experimental Finisher synchronous metric instrument extension interface to go.opentelemetry.io/otel/metric/x. (#8906)

Changed

  • Use the OpenTelemetry Attribute Collection representation for non-OTLP protocols for metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8993)
  • Apply a maximum depth of 64 by default to span, event, link, log record, and instrumentation scope attribute values in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log. (#8938)
  • Reduce allocations when applying attribute value length limits in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log by rebuilding composite values only when truncation is needed. (#8912)
  • Decode traceparent using a hex lookup table in go.opentelemetry.io/otel/propagation, which rejects the specification-disallowed upper-case characters without a separate scan of the header. (#8739)
  • Decode all characters at constant indices in TraceIDFromHex and SpanIDFromHex in go.opentelemetry.io/otel/trace to eliminate bounds checks. (#8740)

Fixed

  • Count valid U+FFFD replacement characters toward attribute value length limits in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log.
  • Truncate string attribute values to empty strings when the configured length limit is zero, including malformed UTF-8, in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log. (#9054)
  • Fix a data race in NewPeriodicReader where r.inst was assigned after the background goroutine was launched in go.opentelemetry.io/otel/sdk/metric. (#9028)
  • Prevent precision loss for large int64 values in Sum, Histogram, and ExponentialHistogram aggregations in go.opentelemetry.io/otel/sdk/metric. (#8981)
  • Ensure grpc.DialOption values passed via WithDialOption take precedence over conflicting internally-computed defaults in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc, and go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#8805, #8834, #8836)
  • Treat overflowing OTEL_METRIC_EXPORT_INTERVAL and OTEL_METRIC_EXPORT_TIMEOUT values as invalid in go.opentelemetry.io/otel/sdk/metric. (#8800)
  • Prevent a panic in NewFixedSizeReservoir and FixedSizeReservoirProvider when given a negative size in go.opentelemetry.io/otel/sdk/metric/exemplar; negative sizes are now clamped to zero, consistent with a size of zero. (#8832)
  • Preserve exponential histogram ZeroThreshold during OTLP metric export in go.opentelemetry.io/otel/exporters/otlp/otlpmetric. (#8801)
  • Ensure metric helpers in go.opentelemetry.io/otel/semconv/v1.32.0, go.opentelemetry.io/otel/semconv/v1.33.0, and go.opentelemetry.io/otel/semconv/v1.34.0 record measurements only once when no attributes are provided. (#8849)
  • Treat empty OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG values as unset in go.opentelemetry.io/otel/sdk/trace. (#8873)
  • Normalize global OTEL_EXPORTER_OTLP_ENDPOINT path joining in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp so trailing-slash base URLs do not produce double-slash log export paths. (#8864)
  • Prevent a deadlock when formatting an error passed to RecordError calls back into the span in go.opentelemetry.io/otel/sdk/trace. (#8815)
  • Prevent SimpleSpanProcessor.Shutdown from panicking when constructed with a nil exporter in go.opentelemetry.io/otel/sdk/trace. (#8844)

... (truncated)

Commits
  • 66cfc95 Release 1.47.0/0.69.0/0.23.0/0.1.0 (#9024)
  • f09d1de Merge commit from fork
  • 017b08c Merge commit from fork
  • d9d3ac2 Update ubuntu:26.04 Docker digest to 88a381d
  • b240391 Update module github.com/uudashr/iface to v1.5.3
  • 55899e3 Fix zero attribute value length for malformed UTF-8 (#9054)
  • 75b1fe3 Update github.com/charmbracelet/ultraviolet digest to 8786532
  • cce78ad Update github.com/golangci/rowserrcheck digest to f772fe6 (#9066)
  • cdc6ee4 Update module github.com/pjbgf/sha1cd to v0.7.0
  • ef11bfc chore: Replace deprecated gofumpt extra-rules with extra options (#9062)
  • Additional commits viewable in compare view

Updates go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc from 1.46.0 to 1.47.0

Release notes

Sourced from go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc's releases.

v1.47.0/v0.69.0/v0.23.0/v0.1.0

This release contains the first stable release of the OpenTelemetry Go Logs API and SDK. Our project stability guarantees now apply to the following modules:

  • go.opentelemetry.io/otel/log
  • go.opentelemetry.io/otel/sdk/log

See our versioning policy for more information about these stability guarantees.

Added

  • Add String method for KeyValue type in go.opentelemetry.io/otel/attribute. (#8205)
  • Add String method for Set type in go.opentelemetry.io/otel/attribute. (#8347)
  • Add WithMaxExportBatchSize to go.opentelemetry.io/otel/sdk/metric to configure the maximum export batch size for PeriodicReader. (#8960)
  • Add WithAttributeValueDepthLimit, DefaultAttributeValueDepthLimit, and SpanLimits.AttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/trace to configure the maximum depth of span, event, link, and instrumentation scope attribute values. (#8938)
  • Add WithAttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/log to configure the maximum depth of log record and instrumentation scope attribute values. (#8938)
  • Add WithMaxResponseSize to go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, and go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8941)
  • Add experimental ProbabilitySampler in go.opentelemetry.io/otel/sdk/trace/x that conforms to the OpenTelemetry specification's threshold-based sampling algorithm. (#8123)
  • Add experimental *Binder extension interfaces in go.opentelemetry.io/otel/metric/x for instruments that support binding attributes ahead of time. (#8760)
  • Add the experimental Finisher synchronous metric instrument extension interface to go.opentelemetry.io/otel/metric/x. (#8906)

Changed

  • Use the OpenTelemetry Attribute Collection representation for non-OTLP protocols for metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8993)
  • Apply a maximum depth of 64 by default to span, event, link, log record, and instrumentation scope attribute values in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log. (#8938)
  • Reduce allocations when applying attribute value length limits in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log by rebuilding composite values only when truncation is needed. (#8912)
  • Decode traceparent using a hex lookup table in go.opentelemetry.io/otel/propagation, which rejects the specification-disallowed upper-case characters without a separate scan of the header. (#8739)
  • Decode all characters at constant indices in TraceIDFromHex and SpanIDFromHex in go.opentelemetry.io/otel/trace to eliminate bounds checks. (#8740)

Fixed

  • Count valid U+FFFD replacement characters toward attribute value length limits in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log.
  • Truncate string attribute values to empty strings when the configured length limit is zero, including malformed UTF-8, in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log. (#9054)
  • Fix a data race in NewPeriodicReader where r.inst was assigned after the background goroutine was launched in go.opentelemetry.io/otel/sdk/metric. (#9028)
  • Prevent precision loss for large int64 values in Sum, Histogram, and ExponentialHistogram aggregations in go.opentelemetry.io/otel/sdk/metric. (#8981)
  • Ensure grpc.DialOption values passed via WithDialOption take precedence over conflicting internally-computed defaults in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc, and go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#8805, #8834, #8836)
  • Treat overflowing OTEL_METRIC_EXPORT_INTERVAL and OTEL_METRIC_EXPORT_TIMEOUT values as invalid in go.opentelemetry.io/otel/sdk/metric. (#8800)
  • Prevent a panic in NewFixedSizeReservoir and FixedSizeReservoirProvider when given a negative size in go.opentelemetry.io/otel/sdk/metric/exemplar; negative sizes are now clamped to zero, consistent with a size of zero. (#8832)
  • Preserve exponential histogram ZeroThreshold during OTLP metric export in go.opentelemetry.io/otel/exporters/otlp/otlpmetric. (#8801)
  • Ensure metric helpers in go.opentelemetry.io/otel/semconv/v1.32.0, go.opentelemetry.io/otel/semconv/v1.33.0, and go.opentelemetry.io/otel/semconv/v1.34.0 record measurements only once when no attributes are provided. (#8849)
  • Treat empty OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG values as unset in go.opentelemetry.io/otel/sdk/trace. (#8873)
  • Normalize global OTEL_EXPORTER_OTLP_ENDPOINT path joining in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp so trailing-slash base URLs do not produce double-slash log export paths. (#8864)
  • Prevent a deadlock when formatting an error passed to RecordError calls back into the span in go.opentelemetry.io/otel/sdk/trace. (#8815)
  • Prevent SimpleSpanProcessor.Shutdown from panicking when constructed with a nil exporter in go.opentelemetry.io/otel/sdk/trace. (#8844)
  • Propagate invalid exponential histogram scale errors to Prometheus exporter self-observability metrics in go.opentelemetry.io/otel/exporters/prometheus. (#8839)

... (truncated)

Changelog

Sourced from go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc's changelog.

[1.47.0/0.69.0/0.23.0/0.1.0] - 2026-10-02

This release contains the first stable release of the OpenTelemetry Go Logs API and SDK. Our project stability guarantees now apply to the following modules:

  • go.opentelemetry.io/otel/log
  • go.opentelemetry.io/otel/sdk/log

See our versioning policy for more information about these stability guarantees.

Added

  • Add String method for KeyValue type in go.opentelemetry.io/otel/attribute. (#8205)
  • Add String method for Set type in go.opentelemetry.io/otel/attribute. (#8347)
  • Add WithMaxExportBatchSize to go.opentelemetry.io/otel/sdk/metric to configure the maximum export batch size for PeriodicReader. (#8960)
  • Add WithAttributeValueDepthLimit, DefaultAttributeValueDepthLimit, and SpanLimits.AttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/trace to configure the maximum depth of span, event, link, and instrumentation scope attribute values. (#8938)
  • Add WithAttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/log to configure the maximum depth of log record and instrumentation scope attribute values. (#8938)
  • Add WithMaxResponseSize to go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, and go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8941)
  • Add experimental ProbabilitySampler in go.opentelemetry.io/otel/sdk/trace/x that conforms to the OpenTelemetry specification's threshold-based sampling algorithm. (#8123)
  • Add experimental *Binder extension interfaces in go.opentelemetry.io/otel/metric/x for instruments that support binding attributes ahead of time. (#8760)
  • Add the experimental Finisher synchronous metric instrument extension interface to go.opentelemetry.io/otel/metric/x. (#8906)

Changed

  • Use the OpenTelemetry Attribute Collection representation for non-OTLP protocols for metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8993)
  • Apply a maximum depth of 64 by default to span, event, link, log record, and instrumentation scope attribute values in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log. (#8938)
  • Reduce allocations when applying attribute value length limits in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log by rebuilding composite values only when truncation is needed. (#8912)
  • Decode traceparent using a hex lookup table in go.opentelemetry.io/otel/propagation, which rejects the specification-disallowed upper-case characters without a separate scan of the header. (#8739)
  • Decode all characters at constant indices in TraceIDFromHex and SpanIDFromHex in go.opentelemetry.io/otel/trace to eliminate bounds checks. (#8740)

Fixed

  • Count valid U+FFFD replacement characters toward attribute value length limits in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log.
  • Truncate string attribute values to empty strings when the configured length limit is zero, including malformed UTF-8, in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log. (#9054)
  • Fix a data race in NewPeriodicReader where r.inst was assigned after the background goroutine was launched in go.opentelemetry.io/otel/sdk/metric. (#9028)
  • Prevent precision loss for large int64 values in Sum, Histogram, and ExponentialHistogram aggregations in go.opentelemetry.io/otel/sdk/metric. (#8981)
  • Ensure grpc.DialOption values passed via WithDialOption take precedence over conflicting internally-computed defaults in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc, and go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#8805, #8834, #8836)
  • Treat overflowing OTEL_METRIC_EXPORT_INTERVAL and OTEL_METRIC_EXPORT_TIMEOUT values as invalid in go.opentelemetry.io/otel/sdk/metric. (#8800)
  • Prevent a panic in NewFixedSizeReservoir and FixedSizeReservoirProvider when given a negative size in go.opentelemetry.io/otel/sdk/metric/exemplar; negative sizes are now clamped to zero, consistent with a size of zero. (#8832)
  • Preserve exponential histogram ZeroThreshold during OTLP metric export in go.opentelemetry.io/otel/exporters/otlp/otlpmetric. (#8801)
  • Ensure metric helpers in go.opentelemetry.io/otel/semconv/v1.32.0, go.opentelemetry.io/otel/semconv/v1.33.0, and go.opentelemetry.io/otel/semconv/v1.34.0 record measurements only once when no attributes are provided. (#8849)
  • Treat empty OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG values as unset in go.opentelemetry.io/otel/sdk/trace. (#8873)
  • Normalize global OTEL_EXPORTER_OTLP_ENDPOINT path joining in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp so trailing-slash base URLs do not produce double-slash log export paths. (#8864)
  • Prevent a deadlock when formatting an error passed to RecordError calls back into the span in go.opentelemetry.io/otel/sdk/trace. (#8815)
  • Prevent SimpleSpanProcessor.Shutdown from panicking when constructed with a nil exporter in go.opentelemetry.io/otel/sdk/trace. (#8844)

... (truncated)

Commits
  • 66cfc95 Release 1.47.0/0.69.0/0.23.0/0.1.0 (#9024)
  • f09d1de Merge commit from fork
  • 017b08c Merge commit from fork
  • d9d3ac2 Update ubuntu:26.04 Docker digest to 88a381d
  • b240391 Update module github.com/uudashr/iface to v1.5.3
  • 55899e3 Fix zero attribute value length for malformed UTF-8 (#9054)
  • 75b1fe3 Update github.com/charmbracelet/ultraviolet digest to 8786532
  • cce78ad Update github.com/golangci/rowserrcheck digest to f772fe6 (#9066)
  • cdc6ee4 Update module github.com/pjbgf/sha1cd to v0.7.0
  • ef11bfc chore: Replace deprecated gofumpt extra-rules with extra options (#9062)
  • Additional commits viewable in compare view

Updates go.opentelemetry.io/otel/sdk from 1.46.0 to 1.47.0

Release notes

Sourced from go.opentelemetry.io/otel/sdk's releases.

v1.47.0/v0.69.0/v0.23.0/v0.1.0

This release contains the first stable release of the OpenTelemetry Go Logs API and SDK. Our project stability guarantees now apply to the following modules:

  • go.opentelemetry.io/otel/log
  • go.opentelemetry.io/otel/sdk/log

See our versioning policy for more information about these stability guarantees.

Added

  • Add String method for KeyValue type in go.opentelemetry.io/otel/attribute. (#8205)
  • Add String method for Set type in go.opentelemetry.io/otel/attribute. (#8347)
  • Add WithMaxExportBatchSize to go.opentelemetry.io/otel/sdk/metric to configure the maximum export batch size for PeriodicReader. (#8960)
  • Add WithAttributeValueDepthLimit, DefaultAttributeValueDepthLimit, and SpanLimits.AttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/trace to configure the maximum depth of span, event, link, and instrumentation scope attribute values. (#8938)
  • Add WithAttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/log to configure the maximum depth of log record and instrumentation scope attribute values. (#8938)
  • Add WithMaxResponseSize to go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, and go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8941)
  • Add experimental ProbabilitySampler in go.opentelemetry.io/otel/sdk/trace/x that conforms to the OpenTelemetry specification's threshold-based sampling algorithm. (#8123)
  • Add experimental *Binder extension interfaces in go.opentelemetry.io/otel/metric/x for instruments that support binding attributes ahead of time. (#8760)
  • Add the experimental Finisher synchronous metric instrument extension interface to go.opentelemetry.io/otel/metric/x. (#8906)

Changed

  • Use the OpenTelemetry Attribute Collection representation for non-OTLP protocols for metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8993)
  • Apply a maximum depth of 64 by default to span, event, link, log record, and instrumentation scope attribute values in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log. (#8938)
  • Reduce allocations when applying attribute value length limits in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log by rebuilding composite values only when truncation is needed. (#8912)
  • Decode traceparent using a hex lookup table in go.opentelemetry.io/otel/propagation, which rejects the specification-disallowed upper-case characters without a separate scan of the header. (#8739)
  • Decode all characters at constant indices in TraceIDFromHex and SpanIDFromHex in go.opentelemetry.io/otel/trace to eliminate bounds checks. (#8740)

Fixed

  • Count valid U+FFFD replacement characters toward attribute value length limits in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log.
  • Truncate string attribute values to empty strings when the configured length limit is zero, including malformed UTF-8, in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log. (#9054)
  • Fix a data race in NewPeriodicReader where r.inst was assigned after the background goroutine was launched in go.opentelemetry.io/otel/sdk/metric. (#9028)
  • Prevent precision loss for large int64 values in Sum, Histogram, and ExponentialHistogram aggregations in go.opentelemetry.io/otel/sdk/metric. (#8981)
  • Ensure grpc.DialOption values passed via WithDialOption take precedence over conflicting internally-computed defaults in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc, and go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#8805, #8834, #8836)
  • Treat overflowing OTEL_METRIC_EXPORT_INTERVAL and OTEL_METRIC_EXPORT_TIMEOUT values as invalid in go.opentelemetry.io/otel/sdk/metric. (#8800)
  • Prevent a panic in NewFixedSizeReservoir and FixedSizeReservoirProvider when given a negative size in go.opentelemetry.io/otel/sdk/metric/exemplar; negative sizes are now clamped to zero, consistent with a size of zero. (#8832)
  • Preserve exponential histogram ZeroThreshold during OTLP metric export in go.opentelemetry.io/otel/exporters/otlp/otlpmetric. (#8801)
  • Ensure metric helpers in go.opentelemetry.io/otel/semconv/v1.32.0, go.opentelemetry.io/otel/semconv/v1.33.0, and go.opentelemetry.io/otel/semconv/v1.34.0 record measurements only once when no attributes are provided. (#8849)
  • Treat empty OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG values as unset in go.opentelemetry.io/otel/sdk/trace. (#8873)
  • Normalize global OTEL_EXPORTER_OTLP_...

    Description has been truncated

Bumps the go-deps group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/grafana/pyroscope-go](https://github.com/grafana/pyroscope-go) | `1.4.2` | `1.4.3` |
| [github.com/neo4j/neo4j-go-driver/v6](https://github.com/neo4j/neo4j-go-driver) | `6.2.0` | `6.3.0` |
| [github.com/qdrant/go-client](https://github.com/qdrant/go-client) | `1.19.0` | `1.19.3` |
| [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [golang.org/x/crypto](https://github.com/golang/crypto) | `0.55.0` | `0.57.0` |
| [golang.org/x/net](https://github.com/golang/net) | `0.58.0` | `0.59.0` |
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.83.2` | `1.84.0` |



Updates `github.com/grafana/pyroscope-go` from 1.4.2 to 1.4.3
- [Release notes](https://github.com/grafana/pyroscope-go/releases)
- [Commits](grafana/pyroscope-go@v1.4.2...v1.4.3)

Updates `github.com/neo4j/neo4j-go-driver/v6` from 6.2.0 to 6.3.0
- [Release notes](https://github.com/neo4j/neo4j-go-driver/releases)
- [Commits](neo4j/neo4j-go-driver@v6.2.0...v6.3.0)

Updates `github.com/qdrant/go-client` from 1.19.0 to 1.19.3
- [Release notes](https://github.com/qdrant/go-client/releases)
- [Commits](qdrant/go-client@v1.19.0...v1.19.3)

Updates `go.opentelemetry.io/otel` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/sdk` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/trace` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `golang.org/x/crypto` from 0.55.0 to 0.57.0
- [Commits](golang/crypto@v0.55.0...v0.57.0)

Updates `golang.org/x/net` from 0.58.0 to 0.59.0
- [Commits](golang/net@v0.58.0...v0.59.0)

Updates `google.golang.org/grpc` from 1.83.2 to 1.84.0
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.83.2...v1.84.0)

---
updated-dependencies:
- dependency-name: github.com/grafana/pyroscope-go
  dependency-version: 1.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: github.com/neo4j/neo4j-go-driver/v6
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/qdrant/go-client
  dependency-version: 1.19.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/sdk
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/trace
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/crypto
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/net
  dependency-version: 0.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: google.golang.org/grpc
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <[email protected]>
@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Security Evidence

Commit: b5ef5e2f2aae027bdc868693d8f06dd1b546d9b7

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 2 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / PR Risk Taxonomy

Commit: b5ef5e2f2aae027bdc868693d8f06dd1b546d9b7

PR taxonomy clear (success)

Scanned 2 changed file(s). No taxonomy bucket signals were detected.

Scanned 2 changed file(s).

No PR taxonomy bucket signals were detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Reference Set Readiness

Commit: b5ef5e2f2aae027bdc868693d8f06dd1b546d9b7

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 2 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Hosted Promotion Readiness

Commit: b5ef5e2f2aae027bdc868693d8f06dd1b546d9b7

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 2 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@cloudflare-workers-and-pages

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
agent-memory b5ef5e2 Oct 05 2026, 02:11 PM

@cloudflare-workers-and-pages

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
hystersis-docs b5ef5e2 Oct 05 2026, 02:11 PM

@cloudflare-workers-and-pages

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
hystersis-app b5ef5e2 Oct 05 2026, 02:12 PM

@cloudflare-workers-and-pages

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
agent-memorydash b5ef5e2 Oct 05 2026, 02:13 PM

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants