Skip to content

Conversation

@renovate-sh-app
Copy link

@renovate-sh-app renovate-sh-app bot commented Oct 17, 2025

This PR contains the following updates:

Package Change Age Confidence
github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension v0.96.0 -> v0.107.0 age confidence

GitHub Vulnerability Alerts

CVE-2024-42368

Summary

The bearertokenauth extension's server authenticator performs a simple, non-constant time string comparison of the received & configured bearer tokens.

Details

https://github.com/open-telemetry/opentelemetry-collector-contrib/blob/9128a9258fe1fee36f198f97b1e3371fc7b77a93/extension/bearertokenauthextension/bearertokenauth.go#L189-L196

For background on the type of vulnerability, see https://ropesec.com/articles/timing-attacks/.

Impact

This impacts anyone using the bearertokenauth server authenticator. Malicious clients with network access to the collector may perform a timing attack against a collector with this authenticator to guess the configured token, by iteratively sending tokens and comparing the response time. This would allow an attacker to introduce fabricated or bad data into the collector's telemetry pipeline.

Fix

The observable timing vulnerability was fixed by @​axw in v0.107.https://github.com/open-telemetry/opentelemetry-collector-contrib/pull/34516/34516) by using constant-time comparison.

Workarounds

  • upgrade to v0.107.0 or above, or, if you're unable to upgrade at this time,
  • don't expose the receiver using bearertokenauth to network segments accessible by potential attackers, or
  • change the receiver to use a different authentication extension instead, or
  • disable the receiver relying on bearertokenauth

open-telemetry has an Observable Timing Discrepancy

CVE-2024-42368 / GHSA-rfxf-mf63-cpqv / GO-2024-3066

More information

Details

Summary

The bearertokenauth extension's server authenticator performs a simple, non-constant time string comparison of the received & configured bearer tokens.

Details

https://github.com/open-telemetry/opentelemetry-collector-contrib/blob/9128a9258fe1fee36f198f97b1e3371fc7b77a93/extension/bearertokenauthextension/bearertokenauth.go#L189-L196

For background on the type of vulnerability, see https://ropesec.com/articles/timing-attacks/.

Impact

This impacts anyone using the bearertokenauth server authenticator. Malicious clients with network access to the collector may perform a timing attack against a collector with this authenticator to guess the configured token, by iteratively sending tokens and comparing the response time. This would allow an attacker to introduce fabricated or bad data into the collector's telemetry pipeline.

Fix

The observable timing vulnerability was fixed by @​axw in v0.107.https://github.com/open-telemetry/opentelemetry-collector-contrib/pull/34516/34516) by using constant-time comparison.

Workarounds
  • upgrade to v0.107.0 or above, or, if you're unable to upgrade at this time,
  • don't expose the receiver using bearertokenauth to network segments accessible by potential attackers, or
  • change the receiver to use a different authentication extension instead, or
  • disable the receiver relying on bearertokenauth

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


open-telemetry has an Observable Timing Discrepancy in github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension

CVE-2024-42368 / GHSA-rfxf-mf63-cpqv / GO-2024-3066

More information

Details

open-telemetry has an Observable Timing Discrepancy in github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Release Notes

open-telemetry/opentelemetry-collector-contrib (github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension)

v0.107.0

This release fixes CVE-2024-42368 on the bearerauthtokenextension (#​34516)

🛑 Breaking changes 🛑
  • clickhouseexporter: Add compress option to ClickHouse exporter, with default value of lz4 (#​34365)
    This change adds a new compress option to the config field and enables it by default.
    Prior to this change, compression was not enabled by default.
    The only way to enable compression prior to this change was via the DSN URL.
    With this change, lz4 compression will be enabled by default.
    The list of valid options is provided by the underlying clickhouse-go driver.
    While this change is marked as breaking, there should be no effect to existing deployments by enabling compression.
    Compression should improve network performance on most deployments that have a remote ClickHouse server.

  • Update the scope name for telemetry produce by components. The following table summarizes the changes:

Component name Previous scope New scope PR number
azureeventhubreceiver otelcol/azureeventhubreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/azureeventhubreceiver #​34611
cloudfoundryreceiver otelcol/cloudfoundry github.com/open-telemetry/opentelemetry-collector-contrib/receiver/cloudfoundryreceiver #​34612
cloudflarereceiver otelcol/cloudflare github.com/open-telemetry/opentelemetry-collector-contrib/receiver/cloudflarereceiver #​34613
azuremonitorreceiver otelcol/azuremonitorreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/azuremonitorreceiver #​34618
fileconsumer otelcol/fileconsumer github.com/open-telemetry/opentelemetry-collector-contrib/pkg/stanza/fileconsumer #​34619
loadbalancingexporter otelcol/loadbalancing github.com/open-telemetry/opentelemetry-collector-contrib/exporter/loadbalancingexporter #​34429
sumologicexporter otelcol/sumologic github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sumologicexporter #​34438
prometheusremotewriteexporter otelcol/prometheusremotewrite github.com/open-telemetry/opentelemetry-collector-contrib/exporter/prometheusremotewriteexporter #​34440
activedirectorydsreceiver otelcol/activedirectorydsreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/activedirectorydsreceiver #​34492
aerospikereceiver otelcol/aerospikereceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/aerospikereceiver #​34518
apachereceiver otelcol/apachereceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/apachereceiver #​34517
apachesparkreceiver otelcol/apachesparkreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/apachesparkreceiver #​34519
bigipreceiver otelcol/bigipreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/bigipreceiver #​34520
chronyreceiver otelcol/chronyreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/chronyreceiver #​34524
couchdbreceiver otelcol/couchdbreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/couchdbreceiver #​34525
countconnector otelcol/countconnector github.com/open-telemetry/opentelemetry-collector-contrib/connector/countconnector #​34583
deltatocumulativeprocessor otelcol/deltatocumulative github.com/open-telemetry/opentelemetry-collector-contrib/processor/deltatocumulativeprocessor #​34550
dockerstatsreceiver otelcol/dockerstatsreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/dockerstatsreceiver #​34528
elasticsearchreceiver otelcol/elasticsearchreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/elasticsearchreceiver #​34529
expvarreceiver otelcol/expvarreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/expvarreceiver #​34530
filestatsreceiver otelcol/filestatsreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/filestatsreceiver #​34429
filterprocessor otelcol/filter github.com/open-telemetry/opentelemetry-collector-contrib/processor/filterprocessor #​34550
flinkmetricsreceiver otelcol/flinkmetricsreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/flinkmetricsreceiver #​34533
fluentforwardreceiver otelcol/fluentforwardreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/fluentforwardreceiver #​34534
gitproviderreceiver otelcol/gitproviderreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/gitproviderreceiver #​34496
googlespannerreceiver otelcol/googlecloudspannermetrics github.com/open-telemetry/opentelemetry-collector-contrib/receiver/googlespannerreceiver #​34593
grafanacloudconnector otelcol/grafanacloud github.com/open-telemetry/opentelemetry-collector-contrib/connector/grafanacloudconnector #​34552
groupbyattrsprocessor otelcol/groupbyattrs github.com/open-telemetry/opentelemetry-collector-contrib/processor/groupbyattrsprocessor #​34550
groupbytraceprocessor otelcol/groupbytrace github.com/open-telemetry/opentelemetry-collector-contrib/processor/groupbytraceprocessor #​34550
haproxyreceiver otelcol/haproxyreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/haproxyreceiver #​34498
hostmetricsreceiver receiver's scrapers otelcol/hostmetricsreceiver/* github.com/open-telemetry/opentelemetry-collector-contrib/receiver/hostmetricsreceiver/internal/scraper/* #​34526
httpcheckreceiver otelcol/httpcheckreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/httpcheckreceiver #​34497
iisreceiver otelcol/iisreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/iisreceiver #​34535
k8sattributesprocessor otelcol/k8sattributes github.com/open-telemetry/opentelemetry-collector-contrib/processor/k8sattributesprocessor #​34550
k8sclusterreceiver otelcol/k8sclusterreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/k8sclusterreceiver #​34536
kafkametricsreceiver otelcol/kafkametricsreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/kafkametricsreceiver #​34538
kafkareceiver otelcol/kafkareceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/kafkareceiver #​34539
kubeletstatsreceiver otelcol/kubeletstatsreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/kubeletstatsreceiver #​34537
memcachedreceiver otelcol/memcachedreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/memcachedreceiver #​34542
mongodbatlasreceiver otelcol/mongodbatlasreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/mongodbatlasreceiver #​34543
mongodbreceiver otelcol/mongodbreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/mongodbreceiver #​34544
mysqlreceiver otelcol/mysqlreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/mysqlreceiver #​34545
nginxreceiver otelcol/nginxreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/nginxreceiver #​34493
nsxtreceiver otelcol/nsxtreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/nsxtreceiver #​34429
oracledbreceiver otelcol/oracledbreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/oracledbreceiver #​34491
otelarrowreceiver otelcol/otelarrowreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/otelarrowreceiver #​34546
podmanreceiver otelcol/podmanreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/podmanreceiver #​34429
postgresqlreceiver otelcol/postgresqlreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/postgresqlreceiver #​34476
probabilisticsamplerprocessor otelcol/probabilisticsampler github.com/open-telemetry/opentelemetry-collector-contrib/processor/probabilisticsamplerprocessor #​34550
prometheusreceiver otelcol/prometheusreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/prometheusreceiver #​34589
rabbitmqreceiver otelcol/rabbitmqreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/rabbitmqreceiver #​34475
sshcheckreceiver otelcol/sshcheckreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/sshcheckreceiver #​34448
vcenterreceiver otelcol/vcenter github.com/open-telemetry/opentelemetry-collector-contrib/receiver/vcenterreceiver #​34449
zookeeperreceiver otelcol/zookeeper github.com/open-telemetry/opentelemetry-collector-contrib/receiver/zookeeperreceiver #​34450
redisreceiver otelcol/redisreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/redisreceiver #​34470
riakreceiver otelcol/riakreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/riakreceiver #​34469
routingprocessor otelcol/routing github.com/open-telemetry/opentelemetry-collector-contrib/processor/routingprocessor #​34550
saphanareceiver otelcol/saphanareceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/saphanareceiver #​34468
servicegraphconnector otelcol/servicegraph github.com/open-telemetry/opentelemetry-collector-contrib/connector/servicegraphconnector #​34552
snmpreceiver otelcol/snmpreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/snmpreceiver #​34592
snowflakereceiver otelcol/snowflakereceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/snowflakereceiver #​34467
solacereceiver otelcol/solacereceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/solacereceiver #​34466
splunkenterprisereceiver otelcol/splunkenterprisereceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/splunkenterprisereceiver #​34452
statsdreceiver otelcol/statsdreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/statsdreceiver #​34547
tailsamplingprocessor otelcol/tailsampling github.com/open-telemetry/opentelemetry-collector-contrib/processor/tailsamplingprocessor #​34550
sqlserverreceiver otelcol/sqlserverreceiver github.com/open-telemetry/opentelemetry-collector-contrib/receiver/sqlserverreceiver #​34451
  • elasticsearchreceiver: Enable more index metrics by default (#​34396)
    This enables the following metrics by default:
    elasticsearch.index.documents
    elasticsearch.index.operations.merge.current
    elasticsearch.index.segments.count
    To preserve previous behavior, update your Elasticsearch receiver configuration to disable these metrics.
  • vcenterreceiver: Enables all of the vSAN metrics by default. (#​34409)
    The following metrics will be enabled by default now:
    • vcenter.cluster.vsan.throughput
    • vcenter.cluster.vsan.operations
    • vcenter.cluster.vsan.latency.avg
    • vcenter.cluster.vsan.congestions
    • vcenter.host.vsan.throughput
    • vcenter.host.vsan.operations
    • vcenter.host.vsan.latency.avg
    • vcenter.host.vsan.congestions
    • vcenter.host.vsan.cache.hit_rate
    • vcenter.vm.vsan.throughput
    • vcenter.vm.vsan.operations
    • vcenter.vm.vsan.latency.avg
🚩 Deprecations 🚩
  • exporter/datadog: Deprecates logs::dump_payloads since it is invalid with the Datadog Agent logs pipeline, which will be enabled by default in the v0.108.0 release. (#​34490)
🚀 New components 🚀
  • logdedupprocessor: Add new logdedupprocessor processor that deduplicates log entries. (#​34118)
  • coralogixprocessor: creating new component for coralogix features (#​33090)
  • googlecloudmonitoringreceiver: Adding new component - Google Cloud monitoring receiver to fetch GCP Cloud Metrics and transform to OpenTelemetry compatible format. (#​33762)
💡 Enhancements 💡
  • awsemfexporter: AWS EMF Exporter to update ApplicationSignals log group name and namespace, and adjust AWS service name prefix logic in spans (#​33798)

  • azureeventhubreceiver: Added traces support in azureeventhubreceiver (#​33583)

  • exporter/prometheusremotewrite: Reduce unnecessary memory allocation by removing buffer that was not used by Snappy encoding function. (#​34273)

  • exporter/prometheusremotewrite: Reduce memory allocations of prometheus remote write exporter "batchtimeseries" when large batch sizes are used (#​34269)

  • clickhouseexporter: Updated the default logs table to a more optimized schema (#​34203)
    Improved partitioning and time range queries.

  • bearertokenauthextension: use constant time comparison. This fixes CVE-2024-42368 (#​34516)

  • processor/k8sattributes: Add support for container.image.repo_digests metadata (#​34029)

  • datadogconnector: Move feature gate connector.datadogconnector.NativeIngest to beta (#​34549)
    When this feature gate is enabled (default), the datadog connector uses the new API to produce APM stats under the hood. | The new API has better throughput when your spans have many attributes (especially container related attributes). Functional-wise the new API should have no user-facing change compared to the old API. | However if you observe any unexpected behaviors, you can disable this feature gate to revert to the old stats processing APIs.

  • elasticsearchexporter: Add opt-in support for the experimental batcher config (#​32377)
    By enabling (or explicitly disabling) the batcher, the Elasticsearch exporter's
    existing batching/buffering logic will be disabled, and the batch sender will be used.

  • elasticsearchexporter: Add summary support for metrics (#​34560)

  • hostmetricsreceiver: add reporting interval to entity event (#​34240)

  • elasticsearchreceiver: Add metric for active index merges (#​34387)

  • kafkaexporter: add an ability to partition logs based on resource attributes. (#​33229)

  • logdedupprocessor: Adds a histogram metric to record the number of aggregated log records. (#​34579)

  • logdedupprocessor: Updates stability level to alpha. (#​34575)

  • logdedup: Make the name of the log deduplication component consistent (#​34571)

  • logdedupprocessor: Ensures any pending aggregated logs are processed and sent to the next consumer before shutting down. (#​34615)

  • logdedupprocessor: Adds a scope aggregator to the logdedup processor enabling the aggregation of logs per scope. (#​34606)

  • logdedupprocessor: Simplifies the processor shutdown behaviour by removing the unnecessary done channel. (#​34478)

  • pkg/ottl: Add support for map literals in OTTL (#​32388)

  • pkg/ottl: Introduce ExtractGrokPatterns converter (#​32593)

  • pkg/ottl: Add the MD5 function to convert the value into a MD5 hash/digest (#​33792)

  • pkg/ottl: Introduce sha512 converter to generate SHA-512 hash/digest from given payload. (#​34007)

  • kafkametricsreceiver: Add option to configure cluster alias name and add new metrics for kafka topic configurations (#​34148)

  • receiver/splunkhec: Add a regex to enforce metrics naming for Splunk events fields based on metrics documentation. (#​34275)

  • telemetrygen: Support boolean values in --telemetry-attributes and --otlp-attributes flag (#​18928)

  • filelogreceiver: Check for unsupported fractional seconds directive when converting strptime time layout to native format (#​34390)

  • windowseventlogreceiver: Add remote collection support to Stanza operator windows pkg to support remote log collect for the Windows Event Log receiver. (#​33100)

🧰 Bug fixes 🧰
  • configauth: Fix unmarshaling of authentication in HTTP servers. (#​34325)
    This brings in a bug fix from the core collector. See open-telemetry/opentelemetry-collector#10750.

  • docker_observer: Change default endpoint for docker_observer on Windows to npipe:////./pipe/docker_engine (#​34358)

  • pkg/translator/jaeger: Change the translation to jaeger spans to match semantic conventions. (#​34368)
    otel.library.name is deprecated and replaced by otel.scope.name
    otel.library.version is deprecated and replaced by otel.scope.version

  • pkg/stanza: Ensure that errors from Process and Write do not break for loops (#​34295)

  • cmd/opampsupervisor: Start even if the OpAMP server cannot be contacted, and continually retry connecting. (#​33408, #​33799)

  • cmd/opampsupervisor: Write the generated effective config and agent log files to the user-defined storage directory. (#​34341)

  • azuremonitorreceiver: Add Azure China as a cloud option. (#​34315)

  • postgresqlreceiver: Support unix socket based replication by handling null values in the client_addr field (#​33107)

  • splunkhecexporter: Copy the bytes to be placed in the request body to avoid corruption on reuse (#​34357)
    This bug is a manifestation of golang/go#51907.
    Under high load, the pool of buffers used to send requests is reused enough
    that the same buffer is used concurrently to process data and be sent as request body.
    The fix is to copy the payload into a new byte array before sending it.

  • syslogexporter: Fix issue where exporter may hang indefinitely while dialing. (#​34393)

  • clickhouseexporter: Use observed timestamp if timestamp is zero (#​34150)
    Some OpenTelemetry libraries do not send timestamp for logs, but they should always send | the observed timestamp. In these cases the ClickHouse exporter just stored a zero timestamp | to the database. This changes the behavior to look into the observed timestamp if the timestamp | is zero.

  • webhookeventreceiver: added a timestamp to the logs generated from incoming events. (#​33702)

v0.106.1

🧰 Bug fixes 🧰

v0.106.0

🛑 Breaking changes 🛑
  • vcenterreceiver: Enables various vCenter metrics that were disabled by default until v0.106.0 (#​33607)
    The following metrics will be enabled by default "vcenter.datacenter.cluster.count", "vcenter.datacenter.vm.count", "vcenter.datacenter.datastore.count",
    "vcenter.datacenter.host.count", "vcenter.datacenter.disk.space", "vcenter.datacenter.cpu.limit", "vcenter.datacenter.memory.limit",
    "vcenter.resource_pool.memory.swapped", "vcenter.resource_pool.memory.ballooned", and "vcenter.resource_pool.memory.granted". The
    "resourcePoolMemoryUsageAttribute" has also been bumped up to release v.0.107.0

  • googlemanagedprometheusexporter: Fix typo in exporter.googlemanagedpromethues.intToDouble feature gate (#​34232)

🚩 Deprecations 🚩
  • k8sattributesprocessor: Deprecate extract.annotations.regex and extract.labels.regex config fields in favor of the ExtractPatterns function in the transform processor. The FieldExtractConfig.Regex parameter will be removed in version v0.111.0. (#​25128)
    Deprecating of FieldExtractConfig.Regex parameter means that it is recommended to use the ExtractPatterns function from the transform processor instead. To convert your current configuration please check the ExtractPatterns function documentation. You should use the pattern parameter of ExtractPatterns instead of using the FieldExtractConfig.Regex parameter.
🚀 New components 🚀
  • otlpjsonconnector: New component that will allow extracting otlpjson data from incoming Logs. (#​34239, #​34208)
  • redis_storage: Adds a new storage extension using Redis to store data in transit (#​31682)
💡 Enhancements 💡
  • processor/transform: Add scale_metric function that scales all data points in a metric. (#​16214)

  • vcenterreceiver: Adds vCenter vSAN host metrics. (#​33556)
    Introduces the following vSAN host metrics to the vCenter receiver:

    • vcenter.host.vsan.throughput
    • vcenter.host.vsan.iops
    • vcenter.host.vsan.congestions
    • vcenter.host.vsan.cache.hit_rate
    • vcenter.host.vsan.latency.avg
  • transformprocessor: Support aggregating metrics based on their attributes. (#​16224)

  • metricstransformprocessor: Adds the 'median' aggregation type to the Metrics Transform Processor. Also uses the refactored aggregation business logic from internal/core package. (#​16224)

  • telemetrygen: uses the go logging SDK instead of pdata (#​18902)

  • elasticsearchexporter: Add explicit bounds histogram support to metrics (#​34045)

  • hostmetricsreceiver: allow configuring log pipeline to send host EntityState event (#​33927)

  • elasticsearchexporter: Introduce an experimental OTel native mapping mode for logs (#​33290)

  • extension/healthcheckv2: Add extension/subcomponent management logic. (#​26661)

  • otlpjsonconnector: Add connector's implementations (#​34249, #​34208)

  • windowsperfcountersreceiver: Improve handling of non-existing instances for Windows Performance Counters (#​33815)
    It is an expected that when querying Windows Performance Counters the targeted instances may not be present.
    The receiver will no longer require the use of recreate_query to handle non-existing instances.
    As soon as the instances are available, the receiver will start collecting metrics for them.
    There won't be warning log messages when there are no matches for the configured instances.

  • kafkareceiver: Add settings session_timeout and heartbeat_interval to Kafka Receiver for group management facilities (#​28630)

  • otelarrowreceiver, otelarrowexporter: OTel-Arrow internal packages moved into this repository. (#​33567)
    New integration testing between otelarrowexporter and otelarrowreceiver.

  • otlpjsonconnector: Move connector's stability to alpha. (#​34208, #​34253)

  • pkg/ottl: Adds an Format function to OTTL that calls fmt.Sprintf (#​33405)

  • vcenterreceiver: Adds a number of default disabled vSAN metrics for Clusters. (#​33556)

  • vcenterreceiver: Adds a number of default disabled vSAN metrics for Virtual Machines. (#​33556)

🧰 Bug fixes 🧰
  • clickhouseexporter: Increase the default number of queue consumers to 10 (#​34176)
  • opencensusreceiver: Do not report an error into resource status during receiver shutdown when the listener connection was closed. (#​33865)
  • datadogconnector: Produce stats for non-root client and producer spans when connector.datadogconnector.NativeIngest and compute_top_level_by_span_kind are enabled (#​34197)
    You should have only run into this bug when ALL the conditions below are met | 1. feature gate connector.datadogconnector.NativeIngest is enabled | 2. config compute_top_level_by_span_kind is set to true | 3. config compute_stats_by_span_kind is unset or set to false | 4. you have child spans with client or producer span kind
  • datadogconnector: Respect _dd.measured when connector.datadogconnector.NativeIngest is enabled (#​34197)
    Spans with attribute _dd.measured set to 1 will always get Datadog APM stats
  • deltatocumulativeprocessor: fix bucket counts when downscaling exp histograms with odd offsets (#​33831)
  • otelarrowreceiver: Fix potential goroutine leak when in stream-shutdown. (#​34236)
  • otelarrowreceiver: Eliminate one spurious span error. (#​34175)
  • pkg/ottl: Handle JSON array provided to ParseJSON function (#​33535)
  • exporter/datadog: Fixes a bug where otelcol_exporter_sent_log_records was reporting double as many logs sent when using the logs agent feature gate. (#​33887)
  • statsdeceiver: Log only non-EOF errors when reading payload received via TCP. (#​33951)
  • vcenterreceiver: Adds destroys to the ContainerViews in the client. (#​34254)
    This may not be necessary, but it should be better practice than not.

v0.105.0

🛑 Breaking changes 🛑
  • skywalkingexporter: Remove unmaintained component (#​23796)
  • elasticsearchexporter: Make "dedup" option no-op, always de-duplicate. (#​33773)
    Elasticsearch does not permit duplicate keys in JSON objects, so there is no value in being able to configure deduplication.
  • elasticsearchexporter: Remove defunct "file" and "fields" configuration settings. (#​33803)
    This is a breaking change only because removing the attributes would prevent collector startup if those attributes are specified, but otherwise there is no functional change. These configuration attributes have never done anything.
  • stanza: errors from Operator.Process are returned instead of silently ignored. (#​33783)
    This public function is affected: https://pkg.go.dev/github.com/open-telemetry/opentelemetry-collector-contrib/pkg/stanza@v0.104.0/operator/helper#WriterOperator.Write
  • vcenterreceiver: Enables various vCenter metrics that were disabled by default until v0.105 (#​34022)
    The following metrics will be enabled by default "vcenter.host.network.packet.drop.rate",
    "vcenter.vm.cpu.readiness", "vcenter.host.cpu.capacity", and "vcenter.host.cpu.reserved".
🚩 Deprecations 🚩
  • lokiexporter: Deprecate component (#​33916)
🚀 New components 🚀
  • sumconnector: creates a wireframe and initial pr to develop from (#​32669)
  • extensions/observer/cfgardenobserver: Add a new observer that discovers containers through the Garden API (#​33618)
💡 Enhancements 💡
  • pkg/ottl: Added Hex() converter function (#​31929)

  • pkg/ottl: Add IsRootSpan() converter function. (#​32918)
    Converter IsRootSpan() returns true if the span in the corresponding context is root, that means its parent_span_id equals the hexadecimal representation of zero. In all other scenarios function returns false.

  • vcenterreceiver: Adds additional vCenter resource pool metrics and a memory_usage_type attribute for vcenter.resource_pool.memory.usage metric to use. (#​33607)
    Added "vcenter.resource_pool.memory.swapped", "vcenter.resource_pool.memory.ballooned", and "vcenter.resource_pool.memory.granted"
    metrics. Also added an additional attribute, "memory_usage_type" for "vcenter.resource_pool.memory.usage" metric, which is
    currently under a feature gate.

  • kubeletstatsreceiver: Add k8s.pod.memory.node.utilization and k8s.container.memory.node.utilization metrics (#​33591)

  • vcenterreceiver: Adds vCenter metrics at the datacenter level. (#​33607)
    Introduces various datacenter metrics which work by aggregating stats from datastores, clusters, hosts, and VM's.

  • processor/resource, processor/attributes: Add an option to extract value from a client address by specifying client.address value in the from_context field. (#​34051)

  • awss3receiver: Add support for retrieving logs and metrics to the AWS S3 Receiver. (#​30750)

  • receiver/azuremonitorreceiver: Add support for Managed Identity and Default Credential auth (#​31268, #​33584)

  • azuremonitorreceiver: Add maximum_number_of_records_per_resource config parameter in order to overwrite default (#​32165)

  • clickhouseexporter: Upgrading stability for logs to beta (#​33615)
    The logs exporter has been proven to be stable for large scale production deployments.
    Configuration options specific to logs are unlikely to change.

  • cloudfoundryreceiver: Add support to receive CloudFoundry Logs (#​32671)

  • datadogreceiver: Add support for metrics in Datadog receiver (#​18278)

  • datadogexporter: Add a feature gate exporter.datadogexporter.TraceExportUseCustomHTTPClient that allows a custom HTTP client to be used in trace export (#​34025)
    This is an experimental feature. By default the feature gate is disabled and trace export uses a default HTT


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

@renovate-sh-app
Copy link
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: github.com/prometheus/mysqld_exporter@v0.14.0 (replaced by github.com/grafana/mysqld_exporter@v0.12.2-0.20231005125903-364b9c41e595): version "v0.12.2-0.20231005125903-364b9c41e595" invalid: unknown revision 364b9c41e595

@CLAassistant
Copy link

CLAassistant commented Oct 17, 2025

CLA assistant check
All committers have signed the CLA.

@renovate-sh-app renovate-sh-app bot force-pushed the renovate/go-github.com-open-telemetry-opentelemetry-collector-contrib-extension-bearertokenauthextension-vulnerability branch from 9a2fc34 to cf9e54c Compare November 5, 2025 00:13
@renovate-sh-app renovate-sh-app bot force-pushed the renovate/go-github.com-open-telemetry-opentelemetry-collector-contrib-extension-bearertokenauthextension-vulnerability branch 2 times, most recently from 7e5a3e5 to 10d4191 Compare November 21, 2025 18:18
…ector-contrib/extension/bearertokenauthextension to v0.107.0 [security]

| datasource | package                                                                                      | from    | to       |
| ---------- | -------------------------------------------------------------------------------------------- | ------- | -------- |
| go         | github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension | v0.96.0 | v0.107.0 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@renovate-sh-app renovate-sh-app bot force-pushed the renovate/go-github.com-open-telemetry-opentelemetry-collector-contrib-extension-bearertokenauthextension-vulnerability branch from 10d4191 to de59fed Compare November 21, 2025 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant