Skip to content

deps: bump go.opentelemetry.io/contrib/exporters/autoexport from 0.63.0 to 0.72.0 - #1248

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go.opentelemetry.io/contrib/exporters/autoexport-0.72.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go.opentelemetry.io/contrib/exporters/autoexport-0.72.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps go.opentelemetry.io/contrib/exporters/autoexport from 0.63.0 to 0.72.0.

Changelog

Sourced from go.opentelemetry.io/contrib/exporters/autoexport's changelog.

[1.47.0/2.6.0/0.72.0/0.38.0/0.27.0/0.21.0/0.17.0/0.19.0] - 2026-10-03

Added

  • Add NewResourceDetectorWithOptions and the WithAWSLogger option to go.opentelemetry.io/contrib/detectors/aws/ec2/v2, allowing a custom AWS SDK logging.Logger to be supplied to the EC2 resource detector. (#9132)
  • Add go.opentelemetry.io/contrib/detectors/openshift, a new resource detector for OpenShift 4 clusters, ported from processor/resourcedetectionprocessor/internal/openshift in opentelemetry-collector-contrib. Detects k8s.cluster.name, and cloud.provider, cloud.platform and cloud.region for clusters running on AWS, Google Cloud and IBM Cloud; Azure clusters report cloud.provider and cloud.platform only. (#9499)
  • Add go.opentelemetry.io/contrib/detectors/kubeadm, a new resource detector for kubeadm-provisioned Kubernetes clusters, ported from processor/resourcedetectionprocessor/internal/kubeadm in opentelemetry-collector-contrib. Detects k8s.cluster.name from the ClusterConfiguration document in the kube-system/kubeadm-config ConfigMap and k8s.cluster.uid from the kube-system namespace UID. (#9500)

Changed

  • Client metrics in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp no longer include attributes from the server-side Labeler, preventing attributes such as http.route from leaking into outbound requests. This is a breaking change for applications that use ContextWithLabeler to add custom client metric attributes: use ContextWithClientLabeler / ClientLabelerFromContext or the WithMetricAttributesFn option instead. Server-side use of ContextWithLabeler / LabelerFromContext is unchanged. (#8924)
  • Stop emitting the legacy http.read_bytes and http.wrote_bytes attributes on the per-operation span events enabled by WithMessageEvents in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp. The read and write events remain, while total body sizes continue to be recorded on the server span as http.request.body.size and http.response.body.size according to HTTP semantic conventions. (#9624)

Deprecated

  • Deprecate go.opentelemetry.io/contrib/instrumentation/github.com/aws/aws-sdk-go-v2/otelaws. (#9707)
  • Deprecate go.opentelemetry.io/contrib/propagators/aws. (#9706)
  • Deprecate go.opentelemetry.io/contrib/samplers/probability/consistent. (#9633)
  • Deprecate ReadBytesKey, ReadErrorKey, WroteBytesKey, and WriteErrorKey in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp. The identifiers remain available and their values are unchanged, but WithMessageEvents no longer emits http.read_bytes or http.wrote_bytes. There is no semantic-convention replacement for per-read or per-write byte counts or the human-readable error fields. Use HTTPRequestBodySizeKey and HTTPResponseBodySizeKey from go.opentelemetry.io/otel/semconv/v1.43.0 to record total body sizes on the span. If an error causes the HTTP request to fail, set the span status to Error and record ErrorType(err) from go.opentelemetry.io/otel/semconv/v1.43.0 on the span. (#9624)

Fixed

  • Treat empty Prometheus exporter environment variable values as unset in go.opentelemetry.io/contrib/exporters/autoexport, restoring the documented defaults. (#9636)
  • Bound converter-owned recursive map, slice, array, and pointer traversal in go.opentelemetry.io/contrib/bridges/otellogr, go.opentelemetry.io/contrib/bridges/otellogrus, go.opentelemetry.io/contrib/bridges/otelslog, and go.opentelemetry.io/contrib/bridges/otelzap. A field requiring more than 100 such levels is replaced with <max-depth-exceeded> and the record continues to be emitted. Existing fmt and user-method behavior remains unchanged. (#9691)
  • Format span attributes in go.opentelemetry.io/contrib/zpages using attribute.Value.String instead of the deprecated attribute.Value.Emit, following the OpenTelemetry AnyValue representation for non-OTLP protocols. (#9453)
  • Set error.type on the span and on the request-duration, request-body-size, and response-body-size metrics when a client disconnects mid-request in go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin, using the request context's cancellation error as the classification source when the handler has not already recorded an error via c.Error. Previously a disconnect was recorded with span status Error and no error.type, indistinguishable from a genuine server fault. (#9394)
  • Report Prometheus metrics HTTP server errors in go.opentelemetry.io/contrib/otelconf when using the v0.2.0 configuration schema. The error check was inverted, so a clean shutdown (http.ErrServerClosed) was reported as unexpected while real Serve errors were ignored. (#9653)
  • Fix temporary file cleanup for multipart requests in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp by copying the parsed multipart form back to the original request during deferred cleanup, preserving net/http cleanup during panic unwinding for HTTP/2 panic handling and outer recovery middleware paths. Unrecovered HTTP/1 handler panics remain uncleaned because net/http skips finishRequest in that path. (#9685)
  • Fix http.client.request.body.size recording for streaming request bodies in go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp. (#8684)
  • Bound Kubernetes ConfigMap requests in go.opentelemetry.io/contrib/detectors/aws/eks with a 10-second timeout so Detect cannot hang indefinitely when the caller-provided context has no deadline. (#9419)

Removed

  • Drop support for [Go 1.25]. (#9584)
  • Remove go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho. Use github.com/labstack/echo-opentelemetry instead. (#9613)

[1.46.0/2.5.3/0.71.0/0.37.3/0.26.0/0.20.1/0.16.3/0.18.0] - 2026-08-25

This release is the last to support [Go 1.25]. The next release will require at least [Go 1.26].

... (truncated)

Commits
  • 0c76f61 Release v1.47.0/v2.6.0/v0.72.0/v0.38.0/v0.27.0/v0.21.0/v0.17.0/v0.19.0 (#9802)
  • 318f5f9 Add timeout on Kubernetes API calls for EKS detector (#9419)
  • f848a15 test(detector/ecs): increase unit test coverage (#9774)
  • c0d84de Restore gofumpt clothe-returns and balance-calls (#9793)
  • 6215054 fix(deps): update aws-sdk-go-v2 monorepo (#9785)
  • 9a2e8ea fix(deps): update kubernetes monorepo to v0.37.1
  • 3d8e338 chore(deps): update sigs.k8s.io/json digest to 11ed52e
  • be5b688 chore(deps): update go-openapi packages
  • e382b4d chore(deps): update module github.com/fxamacker/cbor/v2 to v2.9.4
  • 97f9e88 fix(deps): update module github.com/moby/moby/client to v0.6.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [go.opentelemetry.io/contrib/exporters/autoexport](https://github.com/open-telemetry/opentelemetry-go-contrib) from 0.63.0 to 0.72.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-go-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go-contrib@zpages/v0.63.0...zpages/v0.72.0)

---
updated-dependencies:
- dependency-name: go.opentelemetry.io/contrib/exporters/autoexport
  dependency-version: 0.72.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Update project dependencies go Pull requests that update go code labels Oct 7, 2026
@dependabot
dependabot Bot requested a review from a team October 7, 2026 15:47
@dependabot dependabot Bot added the dependencies Update project dependencies label Oct 7, 2026
@dependabot
dependabot Bot requested review from a team and a balanced review from Copilot October 7, 2026 15:47
@dependabot dependabot Bot added the go Pull requests that update go code label Oct 7, 2026
@netlify

netlify Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for kpt-porch ready!

Name Link
🔨 Latest commit aeae858
🔍 Latest deploy log https://app.netlify.com/projects/kpt-porch/deploys/6ac6699656cdd30008ae3185
😎 Deploy Preview https://deploy-preview-1248--kpt-porch.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The broad telemetry dependency upgrade includes upstream breaking behavioral changes that warrant human validation.

0 open findings

What changed in this PR

Updates OpenTelemetry autoexport and its dependency graph to current compatible releases.

Changes:

  • Bumps autoexport from v0.63.0 to v0.72.0.
  • Updates related OpenTelemetry, Prometheus, gRPC, and transitive dependencies.
  • Refreshes module checksums.
File Description
go.mod Updates dependency versions.
go.sum Refreshes dependency checksums.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Update project dependencies go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant