Skip to content

Commit 7f470fa

Browse files
chore(deps): raise the OpenTelemetry floor to 1.12.0 (#5588)
* feat(otel): raise the OpenTelemetry floor to 1.12.0 (#5560) Sentry.OpenTelemetry floored OpenTelemetry at 1.6.0 and Sentry.OpenTelemetry.Exporter floored OpenTelemetry.Exporter.OpenTelemetryProtocol at 1.10.0. The latter resolved OpenTelemetry.Api 1.10.0 by default, which is delisted from nuget.org over GHSA-8785-wc3w-h8q6 - a DoS triggered simply by receiving a traceparent/tracestate header, with no opt-in. Nothing warned consumers, because the exporter package itself is still listed. 1.12.0 rather than the 1.11.0 the issue asks for: 1.11.0 and 1.11.1 are delisted too, and 1.11.1/1.11.2 pull the deprecated Grpc.Core on net462. 1.12.0 is the lowest floor that is both listed and free of that. It also drops the Google.Protobuf and Grpc.Net.Client dependencies the exporter carried at 1.10.0. OpenTelemetry 1.12.0 no longer brings System.Net.Http in transitively on .NET Framework, so Sentry.OpenTelemetry now references it explicitly, matching the pattern already in Sentry.csproj. Closes #4931 Co-authored-by: Claude Opus 5 <noreply@anthropic.com> (cherry picked from commit 74e84fb) * ci: allowlist GHSA-4625-4j76-fww9 for the OTLP exporter The advisory needs opt-in experimental disk retry without a configured directory, plus a local attacker, and is fixed only in 1.15.3. Also refresh the GHSA-g94r-2vxg-569j reason for the new 1.12.0 floor. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
1 parent c76fbdb commit 7f470fa

4 files changed

Lines changed: 23 additions & 7 deletions

File tree

‎scripts/vulnerability-allowlist.json‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,8 +36,14 @@
3636
{
3737
"advisory": "https://github.com/advisories/GHSA-g94r-2vxg-569j",
3838
"package": "OpenTelemetry.Api",
39-
"reviewed": "2026-09-10",
40-
"reason": "Sentry.OpenTelemetry floors the OpenTelemetry package at 1.6.0, the minimum version without trim warnings. The advisory is fixed only in 1.15.3, so clearing it means forcing every consumer up nine minor versions. The impact is excessive allocation while parsing oversized baggage/B3/Jaeger headers, and the advisory's own mitigation - HTTP request header size limits - is applied by default by IIS (16KB) and nginx (8KB)."
39+
"reviewed": "2026-09-17",
40+
"reason": "Sentry.OpenTelemetry and Sentry.OpenTelemetry.Exporter floor OpenTelemetry at 1.12.0, the lowest listed version clear of GHSA-8785-wc3w-h8q6. The advisory is fixed only in 1.15.3, so clearing it means forcing every consumer up three more minor versions. The impact is excessive allocation while parsing oversized baggage/B3/Jaeger headers, and the advisory's own mitigation - HTTP request header size limits - is applied by default by IIS (16KB) and nginx (8KB)."
41+
},
42+
{
43+
"advisory": "https://github.com/advisories/GHSA-4625-4j76-fww9",
44+
"package": "OpenTelemetry.Exporter.OpenTelemetryProtocol",
45+
"reviewed": "2026-09-17",
46+
"reason": "Sentry.OpenTelemetry.Exporter floors the OTLP exporter at 1.12.0; the advisory is fixed only in 1.15.3. It requires the user to opt in to the experimental disk retry (OTEL_DOTNET_EXPERIMENTAL_OTLP_RETRY=disk) without setting OTEL_DOTNET_EXPERIMENTAL_OTLP_DISK_RETRY_DIRECTORY_PATH, plus a local attacker with access to the shared temp directory. Sentry never enables disk retry, and setting the directory path is a complete workaround, so it does not justify forcing every consumer up three more minor versions."
4147
}
4248
]
4349
}

‎src/Sentry.OpenTelemetry.Exporter/Sentry.OpenTelemetry.Exporter.csproj‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,10 @@
1313
</ItemGroup>
1414

1515
<ItemGroup>
16-
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.10.0" />
16+
<!-- 1.12.0 is the lowest floor we can offer: 1.10.0-1.11.1 are delisted from nuget.org over
17+
GHSA-8785-wc3w-h8q6, and 1.11.1/1.11.2 pull the deprecated Grpc.Core on net462. 1.12.0 also
18+
drops the Google.Protobuf and Grpc.Net.Client dependencies 1.10.0 carried. -->
19+
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.12.0" />
1720
</ItemGroup>
1821

1922
<ItemGroup>

‎src/Sentry.OpenTelemetry/Sentry.OpenTelemetry.csproj‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,15 @@
2323
</ItemGroup>
2424

2525
<ItemGroup>
26-
<!-- Version 1.6.0 is the minimum version that does not have trim warnings -->
27-
<PackageReference Include="OpenTelemetry" Version="1.6.0" />
26+
<!-- 1.6.0 was the lowest version without trim warnings; 1.12.0 is the lowest that also avoids
27+
the delisted 1.10.0-1.11.1 range (GHSA-8785-wc3w-h8q6). -->
28+
<PackageReference Include="OpenTelemetry" Version="1.12.0" />
29+
</ItemGroup>
30+
31+
<!-- On .NET Framework, we need an assembly reference to System.Net.Http. OpenTelemetry 1.6.0 pulled
32+
one in transitively; 1.12.0 dropped those dependencies, so reference it explicitly. -->
33+
<ItemGroup Condition="'$(TargetFrameworkIdentifier)' == '.NETFramework'">
34+
<Reference Include="System.Net.Http" />
2835
</ItemGroup>
2936

3037
<ItemGroup>

‎test/Sentry.OpenTelemetry.Tests/Sentry.OpenTelemetry.Tests.csproj‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,8 +7,8 @@
77
</PropertyGroup>
88

99
<ItemGroup>
10-
<PackageReference Include="OpenTelemetry" Version="1.6.0" />
11-
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.6.0" />
10+
<PackageReference Include="OpenTelemetry" Version="1.12.0" />
11+
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.12.0" />
1212
</ItemGroup>
1313

1414
<ItemGroup Condition="'$(TargetFramework)' == '$(PreviousTfm)'">

0 commit comments

Comments
 (0)