Commit 7f470fa
chore(deps): raise the OpenTelemetry floor to 1.12.0 (#5588)
* feat(otel): raise the OpenTelemetry floor to 1.12.0 (#5560)
Sentry.OpenTelemetry floored OpenTelemetry at 1.6.0 and
Sentry.OpenTelemetry.Exporter floored OpenTelemetry.Exporter.OpenTelemetryProtocol
at 1.10.0. The latter resolved OpenTelemetry.Api 1.10.0 by default, which is
delisted from nuget.org over GHSA-8785-wc3w-h8q6 - a DoS triggered simply by
receiving a traceparent/tracestate header, with no opt-in. Nothing warned
consumers, because the exporter package itself is still listed.
1.12.0 rather than the 1.11.0 the issue asks for: 1.11.0 and 1.11.1 are delisted
too, and 1.11.1/1.11.2 pull the deprecated Grpc.Core on net462. 1.12.0 is the
lowest floor that is both listed and free of that. It also drops the
Google.Protobuf and Grpc.Net.Client dependencies the exporter carried at 1.10.0.
OpenTelemetry 1.12.0 no longer brings System.Net.Http in transitively on .NET
Framework, so Sentry.OpenTelemetry now references it explicitly, matching the
pattern already in Sentry.csproj.
Closes #4931
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit 74e84fb)
* ci: allowlist GHSA-4625-4j76-fww9 for the OTLP exporter
The advisory needs opt-in experimental disk retry without a configured
directory, plus a local attacker, and is fixed only in 1.15.3. Also
refresh the GHSA-g94r-2vxg-569j reason for the new 1.12.0 floor.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>1 parent c76fbdb commit 7f470fa
4 files changed
Lines changed: 23 additions & 7 deletions
File tree
- scripts
- src
- Sentry.OpenTelemetry.Exporter
- Sentry.OpenTelemetry
- test/Sentry.OpenTelemetry.Tests
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
40 | | - | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
41 | 47 | | |
42 | 48 | | |
43 | 49 | | |
Lines changed: 4 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
17 | 20 | | |
18 | 21 | | |
19 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
26 | | - | |
27 | | - | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
28 | 35 | | |
29 | 36 | | |
30 | 37 | | |
| |||
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
10 | | - | |
11 | | - | |
| 10 | + | |
| 11 | + | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| |||
0 commit comments