Skip to content

Bump OpenTelemetry dependencies to fix vulnerabilities#1685

Merged
bart-vmware merged 5 commits into
mainfrom
bump-vulnerable-otel
Apr 29, 2026
Merged

Bump OpenTelemetry dependencies to fix vulnerabilities#1685
bart-vmware merged 5 commits into
mainfrom
bump-vulnerable-otel

Conversation

@bart-vmware
Copy link
Copy Markdown
Member

@bart-vmware bart-vmware commented Apr 29, 2026

Description

Bump OpenTelemetry dependencies to v15.* to resolve reported vulnerabilities in older versions.

Quality checklist

  • Your code complies with our Coding Style.
  • You've updated unit and/or integration tests for your change, where applicable.
  • You've updated documentation for your change, where applicable.
    If your change affects other repositories, such as Documentation, Samples and/or MainSite, add linked PRs here.
  • There's an open issue for the PR that you are making. If you'd like to propose a new feature or change, please open an issue to discuss the change or find an existing issue.
  • You've added required license files and/or file headers (explaining where the code came from with proper attribution), where code is copied from StackOverflow, a blog, or OSS.

@bart-vmware bart-vmware marked this pull request as ready for review April 29, 2026 12:19
@bart-vmware bart-vmware requested a review from TimHess April 29, 2026 12:19
@github-actions
Copy link
Copy Markdown
Contributor

Summary - All Code Coverage (ubuntu-latest)

Line coverage Branch coverage

Assembly Line coverage Branch coverage
Steeltoe.Bootstrap.AutoConfiguration 97.4% 100%
Steeltoe.Common 84.5% 77.8%
Steeltoe.Common.Certificates 97.2% 85.9%
Steeltoe.Common.Hosting 83.5% 65%
Steeltoe.Common.Http 100% 85.2%
Steeltoe.Common.Logging 81.1% 56.2%
Steeltoe.Common.Net 64.5% 66.6%
Steeltoe.Configuration.Abstractions 96.1% 90.7%
Steeltoe.Configuration.CloudFoundry 98.3% 93.9%
Steeltoe.Configuration.ConfigServer 90.7% 85.9%
Steeltoe.Configuration.Encryption 97.6% 92.4%
Steeltoe.Configuration.Kubernetes.ServiceBindings 95.1% 89.3%
Steeltoe.Configuration.Placeholder 93.8% 84.7%
Steeltoe.Configuration.RandomValue 93.2% 90%
Steeltoe.Configuration.SpringBoot 98.3% 95%
Steeltoe.Connectors 94.5% 89.7%
Steeltoe.Connectors.EntityFrameworkCore 81.5% 75%
Steeltoe.Discovery.Configuration 96.3% 75%
Steeltoe.Discovery.Consul 97.6% 96.5%
Steeltoe.Discovery.Eureka 92.2% 86.5%
Steeltoe.Discovery.HttpClients 94.6% 96.1%
Steeltoe.Logging.Abstractions 99.4% 96.9%
Steeltoe.Logging.DynamicConsole 100% 95.4%
Steeltoe.Logging.DynamicSerilog 99.1% 95.4%
Steeltoe.Management.Abstractions 100% 100%
Steeltoe.Management.Endpoint 95.8% 89%
Steeltoe.Management.Prometheus 95.8% 91.6%
Steeltoe.Management.Tasks 100% ****
Steeltoe.Management.Tracing 100% 75%
Steeltoe.Security.Authentication.JwtBearer 100% 100%
Steeltoe.Security.Authentication.OpenIdConnect 73.8% 59%
Steeltoe.Security.Authorization.Certificate 96.7% 75%
Steeltoe.Security.DataProtection.Redis 100% ****

TimHess
TimHess previously approved these changes Apr 29, 2026
Base automatically changed from fix-broken-build to main April 29, 2026 13:38
@bart-vmware bart-vmware dismissed TimHess’s stale review April 29, 2026 13:38

The base branch was changed.

@bart-vmware bart-vmware requested a review from TimHess April 29, 2026 13:39
@sonarqubecloud
Copy link
Copy Markdown

@bart-vmware bart-vmware merged commit ef661b4 into main Apr 29, 2026
25 checks passed
@bart-vmware bart-vmware deleted the bump-vulnerable-otel branch April 29, 2026 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants