Skip to content

chore(deps): bump the opentelemetry group across 1 directory with 10 updates - #17999

Open
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/pip/autobot-backend/main/opentelemetry-e83226c48b
Open

dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/pip/autobot-backend/main/opentelemetry-e83226c48b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on opentelemetry-api, opentelemetry-sdk, opentelemetry-exporter-otlp, opentelemetry-exporter-otlp-proto-grpc, opentelemetry-exporter-otlp-proto-http, opentelemetry-proto, opentelemetry-instrumentation-fastapi, opentelemetry-propagator-b3, opentelemetry-instrumentation-redis and opentelemetry-instrumentation-aiohttp-client to permit the latest version.
Updates opentelemetry-api from 1.44.0 to 1.45.0

Release notes

Sourced from opentelemetry-api's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the enabled method (#5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport packages and switch default HTTP backend to urllib3 (#5389)
  • opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • opentelemetry-python: enable Ruff default ruleset and fix auto-fixable lint issues (#5491)
  • opentelemetry-sdk: SimpleSpanProcessor now drops spans ended after shutdown() instead of passing them to the exporter, and counts them on otel.sdk.processor.span.processed with error.type=already_shutdown. (#5512)
  • Bump pytest to 9.0.3 (#5518)
  • opentelemetry-exporter-otlp-proto-http: clarify that the endpoint= kwarg requires the full signal path (#5633)
  • opentelemetry-sdk: fix typos in SpanLimits docstring (#5658)

Fixed

  • opentelemetry-configuration: perform environment variable substitution on scalar values after parsing the configuration file, so ${VAR} references inside comments and mapping keys are no longer substituted and undefined references in comments no longer abort loading (#5407)
  • opentelemetry-configuration: declarative config environment variable substitution now replaces an unset variable that has no default with an empty value instead of raising an error, per the configuration spec. Resource attributes whose value resolves to null (an unset ${VAR} with no default) are skipped with a warning instead of being inserted as a null value. (#5408)
  • 'scripts/build.sh: add opentelemetry-configurationandopentelemetry-proto-json` to the package to release (#5425)
  • opentelemetry-sdk: fix View instrument-name matching so a view configured with an instrument's real (mixed-case) name is applied; matching is now case-insensitive and platform-independent instead of relying on fnmatch's OS-dependent case handling (#5430)
  • opentelemetry-sdk: fix missing f-prefix in exponential histogram error messages (#5434)
  • opentelemetry-configuration: resolve false-positive warning logs for newer schema minor version (#5436)
  • opentelemetry-sdk: make methods on FixedSizeExemplarReservoirABC thread safe (#5437)
  • opentelemetry-propagator-jaeger: fix typing issues and enable pyright typechecking for the package opentelemetry-propagator-jaeger: skip uberctx- baggage headers with an empty value on extraction instead of raising TypeError (#5440)
  • opentelemetry-sdk: fix TypeError when instantiating a _BaseConfigurator subclass whose __init__ takes arguments (#5441)
  • opentelemetry-sdk: fix TypeError in os.fork() when a BatchProcessor or PeriodicExportingMetricReader is garbage collected (#5453)
  • opentelemetry-configuration: a declarative config key present with an empty (null) value on an object-typed node (e.g. always_on:, a - service: detector, or a metric console: exporter) is now treated the same as an explicit empty config (always_on: {}) instead of failing type dispatch or silently skipping the node. Both dict-typed nodes and dataclasses constructible with no arguments are covered. (#5454)
  • opentelemetry-api: fix copy-pasted log message in SpanContext.__delattr__ (#5455)
  • opentelemetry-sdk: reject views with ExponentialBucketHistogramAggregation for asynchronous instruments instead of silently producing no data (#5461)
  • opentelemetry-sdk: fill every bucket of SimpleFixedSizeExemplarReservoir before random sampling (#5462)

... (truncated)

Changelog

Sourced from opentelemetry-api's changelog.

Version 1.45.0/0.66b0 (2026-09-25)

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions

... (truncated)

Commits
  • 4f0fcfa Prepare release 1.45.0/0.66b0 (#5690)
  • 9406f34 opentelemetry-test-utils: add CapturingSampler for instrumentation tests (#5681)
  • 1fe31a9 fix: update W3CBaggagePropagator to properly handle whitespace (#5680)
  • 008b5b0 feat(config): wire top-level attribute_limits into per-signal providers (#5365)
  • edfad0c [opentelemetry-sdk] Fix overwriting of the service.instance.id which has been...
  • f5e0f62 opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • e4021aa chore(ci): update ci (#5677)
  • 0c6508c ci: restrict checkout credential persistence (#5589)
  • 2e88971 Add host.id to host resource attributes (#5653)
  • 5f851d2 opentelemetry-exporter-otlp-proto-grpc: fix incorrect default port for gRPC i...
  • Additional commits viewable in compare view

Updates opentelemetry-sdk from 1.44.0 to 1.45.0

Release notes

Sourced from opentelemetry-sdk's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the enabled method (#5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport packages and switch default HTTP backend to urllib3 (#5389)
  • opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • opentelemetry-python: enable Ruff default ruleset and fix auto-fixable lint issues (#5491)
  • opentelemetry-sdk: SimpleSpanProcessor now drops spans ended after shutdown() instead of passing them to the exporter, and counts them on otel.sdk.processor.span.processed with error.type=already_shutdown. (#5512)
  • Bump pytest to 9.0.3 (#5518)
  • opentelemetry-exporter-otlp-proto-http: clarify that the endpoint= kwarg requires the full signal path (#5633)
  • opentelemetry-sdk: fix typos in SpanLimits docstring (#5658)

Fixed

  • opentelemetry-configuration: perform environment variable substitution on scalar values after parsing the configuration file, so ${VAR} references inside comments and mapping keys are no longer substituted and undefined references in comments no longer abort loading (#5407)
  • opentelemetry-configuration: declarative config environment variable substitution now replaces an unset variable that has no default with an empty value instead of raising an error, per the configuration spec. Resource attributes whose value resolves to null (an unset ${VAR} with no default) are skipped with a warning instead of being inserted as a null value. (#5408)
  • 'scripts/build.sh: add opentelemetry-configurationandopentelemetry-proto-json` to the package to release (#5425)
  • opentelemetry-sdk: fix View instrument-name matching so a view configured with an instrument's real (mixed-case) name is applied; matching is now case-insensitive and platform-independent instead of relying on fnmatch's OS-dependent case handling (#5430)
  • opentelemetry-sdk: fix missing f-prefix in exponential histogram error messages (#5434)
  • opentelemetry-configuration: resolve false-positive warning logs for newer schema minor version (#5436)
  • opentelemetry-sdk: make methods on FixedSizeExemplarReservoirABC thread safe (#5437)
  • opentelemetry-propagator-jaeger: fix typing issues and enable pyright typechecking for the package opentelemetry-propagator-jaeger: skip uberctx- baggage headers with an empty value on extraction instead of raising TypeError (#5440)
  • opentelemetry-sdk: fix TypeError when instantiating a _BaseConfigurator subclass whose __init__ takes arguments (#5441)
  • opentelemetry-sdk: fix TypeError in os.fork() when a BatchProcessor or PeriodicExportingMetricReader is garbage collected (#5453)
  • opentelemetry-configuration: a declarative config key present with an empty (null) value on an object-typed node (e.g. always_on:, a - service: detector, or a metric console: exporter) is now treated the same as an explicit empty config (always_on: {}) instead of failing type dispatch or silently skipping the node. Both dict-typed nodes and dataclasses constructible with no arguments are covered. (#5454)
  • opentelemetry-api: fix copy-pasted log message in SpanContext.__delattr__ (#5455)
  • opentelemetry-sdk: reject views with ExponentialBucketHistogramAggregation for asynchronous instruments instead of silently producing no data (#5461)
  • opentelemetry-sdk: fill every bucket of SimpleFixedSizeExemplarReservoir before random sampling (#5462)

... (truncated)

Changelog

Sourced from opentelemetry-sdk's changelog.

Version 1.45.0/0.66b0 (2026-09-25)

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions

... (truncated)

Commits
  • 4f0fcfa Prepare release 1.45.0/0.66b0 (#5690)
  • 9406f34 opentelemetry-test-utils: add CapturingSampler for instrumentation tests (#5681)
  • 1fe31a9 fix: update W3CBaggagePropagator to properly handle whitespace (#5680)
  • 008b5b0 feat(config): wire top-level attribute_limits into per-signal providers (#5365)
  • edfad0c [opentelemetry-sdk] Fix overwriting of the service.instance.id which has been...
  • f5e0f62 opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • e4021aa chore(ci): update ci (#5677)
  • 0c6508c ci: restrict checkout credential persistence (#5589)
  • 2e88971 Add host.id to host resource attributes (#5653)
  • 5f851d2 opentelemetry-exporter-otlp-proto-grpc: fix incorrect default port for gRPC i...
  • Additional commits viewable in compare view

Updates opentelemetry-exporter-otlp from 1.44.0 to 1.45.0

Release notes

Sourced from opentelemetry-exporter-otlp's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the enabled method (#5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport packages and switch default HTTP backend to urllib3 (#5389)
  • opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • opentelemetry-python: enable Ruff default ruleset and fix auto-fixable lint issues (#5491)
  • opentelemetry-sdk: SimpleSpanProcessor now drops spans ended after shutdown() instead of passing them to the exporter, and counts them on otel.sdk.processor.span.processed with error.type=already_shutdown. (#5512)
  • Bump pytest to 9.0.3 (#5518)
  • opentelemetry-exporter-otlp-proto-http: clarify that the endpoint= kwarg requires the full signal path (#5633)
  • opentelemetry-sdk: fix typos in SpanLimits docstring (#5658)

Fixed

  • opentelemetry-configuration: perform environment variable substitution on scalar values after parsing the configuration file, so ${VAR} references inside comments and mapping keys are no longer substituted and undefined references in comments no longer abort loading (#5407)
  • opentelemetry-configuration: declarative config environment variable substitution now replaces an unset variable that has no default with an empty value instead of raising an error, per the configuration spec. Resource attributes whose value resolves to null (an unset ${VAR} with no default) are skipped with a warning instead of being inserted as a null value. (#5408)
  • 'scripts/build.sh: add opentelemetry-configurationandopentelemetry-proto-json` to the package to release (#5425)
  • opentelemetry-sdk: fix View instrument-name matching so a view configured with an instrument's real (mixed-case) name is applied; matching is now case-insensitive and platform-independent instead of relying on fnmatch's OS-dependent case handling (#5430)
  • opentelemetry-sdk: fix missing f-prefix in exponential histogram error messages (#5434)
  • opentelemetry-configuration: resolve false-positive warning logs for newer schema minor version (#5436)
  • opentelemetry-sdk: make methods on FixedSizeExemplarReservoirABC thread safe (#5437)
  • opentelemetry-propagator-jaeger: fix typing issues and enable pyright typechecking for the package opentelemetry-propagator-jaeger: skip uberctx- baggage headers with an empty value on extraction instead of raising TypeError (#5440)
  • opentelemetry-sdk: fix TypeError when instantiating a _BaseConfigurator subclass whose __init__ takes arguments (#5441)
  • opentelemetry-sdk: fix TypeError in os.fork() when a BatchProcessor or PeriodicExportingMetricReader is garbage collected (#5453)
  • opentelemetry-configuration: a declarative config key present with an empty (null) value on an object-typed node (e.g. always_on:, a - service: detector, or a metric console: exporter) is now treated the same as an explicit empty config (always_on: {}) instead of failing type dispatch or silently skipping the node. Both dict-typed nodes and dataclasses constructible with no arguments are covered. (#5454)
  • opentelemetry-api: fix copy-pasted log message in SpanContext.__delattr__ (#5455)
  • opentelemetry-sdk: reject views with ExponentialBucketHistogramAggregation for asynchronous instruments instead of silently producing no data (#5461)
  • opentelemetry-sdk: fill every bucket of SimpleFixedSizeExemplarReservoir before random sampling (#5462)

... (truncated)

Changelog

Sourced from opentelemetry-exporter-otlp's changelog.

Version 1.45.0/0.66b0 (2026-09-25)

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions

... (truncated)

Commits
  • 4f0fcfa Prepare release 1.45.0/0.66b0 (#5690)
  • 9406f34 opentelemetry-test-utils: add CapturingSampler for instrumentation tests (#5681)
  • 1fe31a9 fix: update W3CBaggagePropagator to properly handle whitespace (#5680)
  • 008b5b0 feat(config): wire top-level attribute_limits into per-signal providers (#5365)
  • edfad0c [opentelemetry-sdk] Fix overwriting of the service.instance.id which has been...
  • f5e0f62 opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • e4021aa chore(ci): update ci (#5677)
  • 0c6508c ci: restrict checkout credential persistence (#5589)
  • 2e88971 Add host.id to host resource attributes (#5653)
  • 5f851d2 opentelemetry-exporter-otlp-proto-grpc: fix incorrect default port for gRPC i...
  • Additional commits viewable in compare view

Updates opentelemetry-exporter-otlp-proto-grpc from 1.44.0 to 1.45.0

Release notes

Sourced from opentelemetry-exporter-otlp-proto-grpc's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] Description has been truncated

@dependabot
dependabot Bot requested a review from mrveiss as a code owner October 5, 2026 10:56
@dependabot dependabot Bot added backend dependencies Pull requests that update a dependency file labels Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: mrveiss/AutoBot-AI/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 0bd6d7ca-858f-47b6-bc59-f39cd6a8aed3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Retargeted to main (main-first flow, #11696). Dependabot security updates always open against the default branch; this workflow re-applies the retarget after every Dependabot push, so rebases cannot revert it.

@dependabot dependabot Bot changed the title chore(deps): bump the opentelemetry group in /autobot-backend with 10 updates chore(deps): bump the opentelemetry group across 1 directory with 10 updates Oct 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/autobot-backend/main/opentelemetry-e83226c48b branch from 69d2868 to f15116f Compare October 5, 2026 17:55
@mrveiss

mrveiss commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Why this is red, and it is not the security gate

The security scan gate failure on this PR is fixed on main as of #18037 — a rebase clears it. What remains is real, and a rebase will not clear it.

python-suite fails before any test runs, in the dependency-floor gate:

dependency floors [GATE]: 4 of 163 compared versions are below their declared floor
  opentelemetry-api: installed 1.44.0, declared ==1.45.0 (requirements.txt:51)
  opentelemetry-sdk: installed 1.44.0, declared ==1.45.0 (requirements.txt:52)

This PR raises requirements.txt to ==1.45.0, but CI installs from requirements-ci/*, and:

requirements-ci/storage.txt:32  opentelemetry-api==1.44.0
requirements-ci/storage.txt:33  opentelemetry-sdk==1.44.0

So the declared floor moves and the installed version does not. The gate is correct to fail — it is reporting exactly the inconsistency the bump created.

What landing this needs

requirements-ci/storage.txt has to move with requirements.txt. That is not a mechanical edit: the file's own comment at line 14 says the pin is there because chromadb==1.5.9 requires opentelemetry-api, so raising it is a chromadb-compatibility question, not a formatting one. Whoever takes it should check that chromadb 1.5.9 tolerates opentelemetry 1.45.0 before moving the pin.

This is a class, not one PR

Any dependabot bump to a package pinned in both requirements.txt and requirements-ci/* fails the same way, because dependabot updates the first and not the second. Three other open PRs are red on python-suite after the same bump shape — #18026 (autobot-backend/code_analysis, requirements-media, requirements-modal), #18000 (autobot-slm-backend/requirements.txt + constraints/shared.txt), #18027 (frontend). I have not confirmed the same mechanism in those; what is confirmed is that all four fail python-suite or frontend-tests on top of the gate, so none of them is unblocked by #18037 alone.

There is already a pre-commit hook for the adjacent rule — "A requirements file and its include must not pin a package differently (#14228)" — which did not fire here, since the two pins live in files dependabot touches separately. Worth checking whether its scope should cover requirements-ci/* against the root, which would turn this from a CI-time surprise into a commit-time one.

Diagnosed while serialising the PR queue; not fixed here because pushing to a dependabot branch makes dependabot close and recreate the PR.

@mrveiss

mrveiss commented Oct 6, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

…updates

Updates the requirements on [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-instrumentation-fastapi](https://github.com/open-telemetry/opentelemetry-python-contrib), [opentelemetry-propagator-b3](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-instrumentation-redis](https://github.com/open-telemetry/opentelemetry-python-contrib) and [opentelemetry-instrumentation-aiohttp-client](https://github.com/open-telemetry/opentelemetry-python-contrib) to permit the latest version.

Updates `opentelemetry-api` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-sdk` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-exporter-otlp` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-exporter-otlp-proto-grpc` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-exporter-otlp-proto-http` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-proto` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-instrumentation-fastapi` to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-propagator-b3` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-instrumentation-redis` to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-aiohttp-client` to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

---
updated-dependencies:
- dependency-name: opentelemetry-api
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: opentelemetry
- dependency-name: opentelemetry-exporter-otlp
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: opentelemetry
- dependency-name: opentelemetry-exporter-otlp-proto-grpc
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: opentelemetry
- dependency-name: opentelemetry-exporter-otlp-proto-http
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: opentelemetry
- dependency-name: opentelemetry-instrumentation-aiohttp-client
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: opentelemetry
- dependency-name: opentelemetry-instrumentation-fastapi
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: opentelemetry
- dependency-name: opentelemetry-instrumentation-redis
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: opentelemetry
- dependency-name: opentelemetry-propagator-b3
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: opentelemetry
- dependency-name: opentelemetry-proto
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: opentelemetry
- dependency-name: opentelemetry-sdk
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: opentelemetry
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/autobot-backend/main/opentelemetry-e83226c48b branch from f15116f to 96524c3 Compare October 6, 2026 09:51
@mrveiss

mrveiss commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Root cause: CI pin and service constraint can resolve to different releases

python-suite shard 5/12 fails on the constraint-drift guard (#17448), not on anything the bump broke at runtime:

AssertionError: 4 package(s) whose CI and service constraints can resolve to
different releases and are not recorded in
repo_tests/requirements_constraint_drift_baseline.txt:
    autobot-backend/requirements.txt::opentelemetry-api
    autobot-backend/requirements.txt::opentelemetry-exporter-otlp-proto-grpc
    autobot-backend/requirements.txt::opentelemetry-proto
    autobot-backend/requirements.txt::opentelemetry-sdk

CI pins what production runs; an unbounded service constraint takes whatever
published last. Make the two agree, or record the pair with its reason.

The bump moved the CI pin for these four and left the service manifest's constraint loose, so CI would validate one release while production installs another.

Fix: make the two agree. These four are shared, so the durable form is a single declaration in constraints/shared.txt (the SSOT, #10524) with the literals removed from the manifests — one package declared once, rather than re-pinned per file. Recording the pair in the drift baseline is explicitly not the fix; the guard says so itself.

Related: #18060 tracks that a version currently has up to seven homes in this repo.

Not actioned yet: one PR runs CI at a time here and #18082 holds the lane.

@mrveiss

mrveiss commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Shard 5/12 here is not the same cause as #18105's shard 5 — the shared shard number is a coincidence of sharding, which is worth saying because it reads like one shared failure across two PRs.

This one is requirements_ci_drift_test.py::test_the_constraint_audit_is_clean_on_the_real_tree:

4 package(s) whose CI and service constraints can resolve to different releases
and are not recorded in repo_tests/requirements_constraint_drift_baseline.txt

That is the class tracked by #17448 (open) — CI pins what production runs, while an unbounded service constraint takes whatever published last. So the fix is either making each pair agree or recording the pair with its reason; the baseline is not a place to silence it.

Not claiming this PR as owned work, and not updating the branch: it is 20 behind, and re-measuring it against a base that #18130 is about to move would spend a CI run on an answer that expires. Recorded here so the cause is known before someone re-runs it and reads the shard number as the #18105 failure.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant