Skip to content

build(deps): bump io.opentelemetry:opentelemetry-api from 1.57.0 to 1.62.0#13222

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/maven/grpc-gcp-java/io.opentelemetry-opentelemetry-api-1.62.0
Closed

build(deps): bump io.opentelemetry:opentelemetry-api from 1.57.0 to 1.62.0#13222
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/maven/grpc-gcp-java/io.opentelemetry-opentelemetry-api-1.62.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 18, 2026

Copy link
Copy Markdown
Contributor

Bumps io.opentelemetry:opentelemetry-api from 1.57.0 to 1.62.0.

Release notes

Sourced from io.opentelemetry:opentelemetry-api's releases.

Version 1.62.0

API

Context

  • Fix GHSA-rcgg-9c38-7xpx: Apply limits to baggage entries for W3CBaggagePropagator, OtTracePropagator, JaegerPropagator (#8378)

SDK

Traces

  • Avoid parentContext allocation on span start for the common case (#8332)

Metrics

  • Add setMaxExportBatchSize to PeriodicMetricReaderBuilder (#8296)
  • Fix PeriodicMetricReader shutdown race that could drop the final flush (#8299)

Exporters

  • BREAKING Prometheus: Change default server host from 0.0.0.0 to localhost (#8298)
  • BREAKING Prometheus: Stop converting unit "1" to "ratio" (#8252)
  • OTLP: Fix null input handling in StringEncoder (#8312)
  • OTLP: Align proto field types and wire tag names in marshalers (#8293)
  • OTLP: Fix MarshalerUtil sizeRepeatedString calculation (#8284)
  • OTLP: Bound JdkHttpSender thread pool size to prevent unbounded thread creation (#8276)
  • OTLP Profiles: Split profiles data model into separate sdk-profiles and JFR shim modules (#8207)
  • OTLP Profiles: Publish alpha release of opentelemetry-sdk-profiles and opentelemetry-exporter-otlp-profiles (#8351)

Extensions

  • BREAKING Declarative config: Extract to new opentelemetry-sdk-extension-declarative-config artifact with new package io.opentelemetry.sdk.autoconfigure.declarativeconfig (#8265)
  • Autoconfigure: Add file size validation in OtlpConfigUtil to avoid unsafe cast to int (#8287)
  • Declarative config: Fix collection fields to not be initialized to empty by default (#8356)
  • Incubator: Add EventToSpanEventBridge to bridge log-based events to span events (#8372)

Testing

  • Add @Nullable to equalTo value argument in OpenTelemetryAssertions (#8301)
  • Add hasValueSatisfying to LongPointAssert and DoublePointAssert for fuzzy value matching (#8328)
  • Add containsPointsSatisfying to metric data asserts for "each given assertion must be satisfied by at least one point, extras allowed" checks on sum, gauge, histogram, exponential histogram, and summary data (#8329)

Project tooling

  • Add initial OSGi support (#7964)
  • Promote ApiUsageLogger to opentelemetry-common public API (#8318)
  • Establish exception logging guidelines and fix inconsistent patterns across exporters and SDK (#8231)
  • Add *.impl.* package naming convention for internal code with japicmp compatibility (#8325)
  • Add Sonatype dependency audit to build (#8365)

... (truncated)

Changelog

Sourced from io.opentelemetry:opentelemetry-api's changelog.

Version 1.62.0 (2026-05-08)

API

Context

  • Fix GHSA-rcgg-9c38-7xpx: Apply limits to baggage entries for W3CBaggagePropagator, OtTracePropagator, JaegerPropagator (#8378)

SDK

Traces

  • Avoid parentContext allocation on span start for the common case (#8332)

Metrics

  • Add setMaxExportBatchSize to PeriodicMetricReaderBuilder (#8296)
  • Fix PeriodicMetricReader shutdown race that could drop the final flush (#8299)

Exporters

  • BREAKING Prometheus: Change default server host from 0.0.0.0 to localhost (#8298)
  • BREAKING Prometheus: Stop converting unit "1" to "ratio" (#8252)
  • OTLP: Fix null input handling in StringEncoder (#8312)
  • OTLP: Align proto field types and wire tag names in marshalers (#8293)
  • OTLP: Fix MarshalerUtil sizeRepeatedString calculation (#8284)
  • OTLP: Bound JdkHttpSender thread pool size to prevent unbounded thread creation (#8276)
  • OTLP Profiles: Split profiles data model into separate sdk-profiles and JFR shim modules (#8207)
  • OTLP Profiles: Publish alpha release of opentelemetry-sdk-profiles and opentelemetry-exporter-otlp-profiles (#8351)

Extensions

  • BREAKING Declarative config: Extract to new opentelemetry-sdk-extension-declarative-config artifact with new package io.opentelemetry.sdk.autoconfigure.declarativeconfig (#8265)
  • Autoconfigure: Add file size validation in OtlpConfigUtil to avoid unsafe cast to int (#8287)

... (truncated)

Commits
  • d03621f [release/v1.62.x] Prepare release 1.62.0 (#8385)
  • 3a62b7a Prepare 1.62.0 (#8378)
  • 893910b docs: Expand SIG meeting welcoming language (#8383)
  • 03837d3 Apply baggage limits (#8380)
  • cdadad6 Update dependency org.osgi:org.osgi.test.bom to v1.3.0 (#8376)
  • 8e0f196 Update error-prone monorepo to v2.49.0 (#8259)
  • 2923430 Add initial OSGi support (#7964)
  • 3f3780c Add guidance for null checking, promote ApiUsageLogger to opentelemetry-commo...
  • e224e19 Port event span event bridge from contrib (#8372)
  • b29f3df Update dependency com.google.api.grpc:proto-google-common-protos to v2.71.0 (...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies java Pull requests that update java code labels May 18, 2026
@dependabot dependabot Bot requested review from a team as code owners May 18, 2026 21:16
@dependabot dependabot Bot added dependencies java Pull requests that update java code labels May 18, 2026
@lqiu96

lqiu96 commented May 26, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [io.opentelemetry:opentelemetry-api](https://github.com/open-telemetry/opentelemetry-java) from 1.57.0 to 1.62.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-java/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java@v1.57.0...v1.62.0)

---
updated-dependencies:
- dependency-name: io.opentelemetry:opentelemetry-api
  dependency-version: 1.62.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/maven/grpc-gcp-java/io.opentelemetry-opentelemetry-api-1.62.0 branch from effa781 to f5b66cf Compare May 26, 2026 14:59
@lqiu96 lqiu96 added the kokoro:force-run Add this label to force Kokoro to re-run the tests. label May 26, 2026
@yoshi-kokoro yoshi-kokoro removed the kokoro:force-run Add this label to force Kokoro to re-run the tests. label May 26, 2026
@lqiu96

lqiu96 commented May 26, 2026

Copy link
Copy Markdown
Member

Error:

Error:  Failed to execute goal org.apache.maven.plugins:maven-enforcer-plugin:3.5.0:enforce (enforce) on project google-cloud-spanner-executor: 
Error:  Rule 2: org.apache.maven.enforcer.rules.dependency.RequireUpperBoundDeps failed with message:
Error:  Failed while enforcing RequireUpperBoundDeps. The error(s) are [
Error:  Require upper bound dependencies error for io.opentelemetry:opentelemetry-api:1.57.0 paths to dependency are:
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-io.opentelemetry:opentelemetry-api:1.57.0
Error:  and
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-io.opentelemetry:opentelemetry-sdk:1.57.0
Error:      +-io.opentelemetry:opentelemetry-api:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-api:1.57.0
Error:  and
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-io.opentelemetry:opentelemetry-sdk-common:1.57.0
Error:      +-io.opentelemetry:opentelemetry-api:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-api:1.57.0
Error:  and
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-io.opentelemetry:opentelemetry-sdk-trace:1.57.0
Error:      +-io.opentelemetry:opentelemetry-api:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-api:1.57.0
Error:  and
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-com.google.cloud.opentelemetry:exporter-trace:0.36.0
Error:      +-io.opentelemetry:opentelemetry-api:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-api:1.49.0
Error:  and
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-com.google.cloud:grpc-gcp:1.11.0-SNAPSHOT
Error:      +-io.opentelemetry:opentelemetry-api:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-api:1.62.0
Error:  and
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-com.google.cloud:google-cloud-spanner:6.118.0-SNAPSHOT
Error:      +-io.opentelemetry:opentelemetry-api:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-api:1.57.0
Error:  and
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-io.opentelemetry:opentelemetry-sdk:1.57.0
Error:      +-io.opentelemetry:opentelemetry-sdk-metrics:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-sdk-metrics:1.57.0
Error:        +-io.opentelemetry:opentelemetry-api:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-api:1.57.0
Error:  and
Error:  +-com.google.cloud:google-cloud-spanner-executor:6.118.0-SNAPSHOT
Error:    +-io.opentelemetry:opentelemetry-sdk:1.57.0
Error:      +-io.opentelemetry:opentelemetry-sdk-logs:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-sdk-logs:1.57.0
Error:        +-io.opentelemetry:opentelemetry-api:1.57.0 (managed) <-- io.opentelemetry:opentelemetry-api:1.57.0
Error:  ]
Error:  -> [Help 1]

Interestingly, this only proposes bumping otel-api in the grpc-gcp-java module. I think we should also be bumping this isn shared-deps to keep it consistent in the Java SDK. Going to try and update that it in a new commit to test if that resolves the enforcer error, but bumping an otel version will require team approval.

@lqiu96 lqiu96 added the do not merge Indicates a pull request not ready for merge, due to either quality or timing. label May 26, 2026
@lqiu96 lqiu96 requested a review from a team as a code owner May 26, 2026 16:48
@sonarqubecloud

Copy link
Copy Markdown

@sonarqubecloud

Copy link
Copy Markdown

@lqiu96 lqiu96 added kokoro:force-run Add this label to force Kokoro to re-run the tests. and removed kokoro:force-run Add this label to force Kokoro to re-run the tests. labels May 26, 2026
@lqiu96 lqiu96 changed the title build(deps): bump io.opentelemetry:opentelemetry-api from 1.57.0 to 1.62.0 in /grpc-gcp-java build(deps): bump io.opentelemetry:opentelemetry-api from 1.57.0 to 1.62.0 May 26, 2026
@yoshi-kokoro yoshi-kokoro removed the kokoro:force-run Add this label to force Kokoro to re-run the tests. label May 26, 2026
@lqiu96

lqiu96 commented May 29, 2026

Copy link
Copy Markdown
Member

Closing in favor of #13304

@lqiu96 lqiu96 closed this May 29, 2026
@dependabot @github

dependabot Bot commented on behalf of github May 29, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/maven/grpc-gcp-java/io.opentelemetry-opentelemetry-api-1.62.0 branch May 29, 2026 20:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies do not merge Indicates a pull request not ready for merge, due to either quality or timing. java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants