Skip to content

Commit 409f58a

Browse files
committed
fix: upgrade OpenTelemetry OTLP deps to 0.209.0 to resolve protobufjs@7.5.5 vulnerability
Updates @opentelemetry OTLP exporter packages from 0.203.0 to 0.209.0 and their co-dependencies (core, resources, SDK packages) to matching versions. This pulls in @opentelemetry/otlp-transformer@0.209.0 which depends on protobufjs@8.0.0, resolving the protobufjs@7.5.5 vulnerability. Affected packages: - packages/core/package.json (10 deps bumped) - packages/cli-v3/package.json (6 deps bumped) - apps/webapp/package.json (12 deps bumped) - references/d3-chat/package.json (6 deps bumped)
1 parent 9cb6fd1 commit 409f58a

4 files changed

Lines changed: 36 additions & 36 deletions

File tree

apps/webapp/package.json

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -70,23 +70,23 @@
7070
"@kapaai/react-sdk": "^0.1.3",
7171
"@lezer/highlight": "^1.1.6",
7272
"@opentelemetry/api": "1.9.0",
73-
"@opentelemetry/api-logs": "0.203.0",
74-
"@opentelemetry/core": "2.0.1",
75-
"@opentelemetry/exporter-logs-otlp-http": "0.203.0",
76-
"@opentelemetry/exporter-metrics-otlp-proto": "0.203.0",
77-
"@opentelemetry/exporter-trace-otlp-http": "0.203.0",
73+
"@opentelemetry/api-logs": "0.209.0",
74+
"@opentelemetry/core": "2.3.0",
75+
"@opentelemetry/exporter-logs-otlp-http": "0.209.0",
76+
"@opentelemetry/exporter-metrics-otlp-proto": "0.209.0",
77+
"@opentelemetry/exporter-trace-otlp-http": "0.209.0",
7878
"@opentelemetry/host-metrics": "^0.37.0",
79-
"@opentelemetry/instrumentation": "0.203.0",
79+
"@opentelemetry/instrumentation": "0.209.0",
8080
"@opentelemetry/instrumentation-aws-sdk": "^0.57.0",
8181
"@opentelemetry/instrumentation-express": "^0.52.0",
82-
"@opentelemetry/instrumentation-http": "0.203.0",
82+
"@opentelemetry/instrumentation-http": "0.209.0",
8383
"@opentelemetry/resource-detector-aws": "^2.3.0",
84-
"@opentelemetry/resources": "2.0.1",
85-
"@opentelemetry/sdk-logs": "0.203.0",
86-
"@opentelemetry/sdk-metrics": "2.0.1",
87-
"@opentelemetry/sdk-node": "0.203.0",
88-
"@opentelemetry/sdk-trace-base": "2.0.1",
89-
"@opentelemetry/sdk-trace-node": "2.0.1",
84+
"@opentelemetry/resources": "2.3.0",
85+
"@opentelemetry/sdk-logs": "0.209.0",
86+
"@opentelemetry/sdk-metrics": "2.3.0",
87+
"@opentelemetry/sdk-node": "0.209.0",
88+
"@opentelemetry/sdk-trace-base": "2.3.0",
89+
"@opentelemetry/sdk-trace-node": "2.3.0",
9090
"@opentelemetry/semantic-conventions": "1.36.0",
9191
"@popperjs/core": "^2.11.8",
9292
"@prisma/instrumentation": "^6.14.0",

packages/cli-v3/package.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -87,12 +87,12 @@
8787
"@depot/cli": "0.0.1-cli.2.80.0",
8888
"@modelcontextprotocol/sdk": "^1.25.2",
8989
"@opentelemetry/api": "1.9.0",
90-
"@opentelemetry/api-logs": "0.203.0",
91-
"@opentelemetry/exporter-trace-otlp-http": "0.203.0",
92-
"@opentelemetry/instrumentation": "0.203.0",
93-
"@opentelemetry/instrumentation-fetch": "0.203.0",
94-
"@opentelemetry/resources": "2.0.1",
95-
"@opentelemetry/sdk-trace-node": "2.0.1",
90+
"@opentelemetry/api-logs": "0.209.0",
91+
"@opentelemetry/exporter-trace-otlp-http": "0.209.0",
92+
"@opentelemetry/instrumentation": "0.209.0",
93+
"@opentelemetry/instrumentation-fetch": "0.209.0",
94+
"@opentelemetry/resources": "2.3.0",
95+
"@opentelemetry/sdk-trace-node": "2.3.0",
9696
"@opentelemetry/semantic-conventions": "1.36.0",
9797
"@s2-dev/streamstore": "^0.22.5",
9898
"@trigger.dev/build": "workspace:4.5.0-rc.2",

packages/core/package.json

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -193,18 +193,18 @@
193193
"@google-cloud/precise-date": "^4.0.0",
194194
"@jsonhero/path": "^1.0.21",
195195
"@opentelemetry/api": "1.9.0",
196-
"@opentelemetry/api-logs": "0.203.0",
197-
"@opentelemetry/core": "2.0.1",
198-
"@opentelemetry/exporter-logs-otlp-http": "0.203.0",
199-
"@opentelemetry/exporter-metrics-otlp-http": "0.203.0",
200-
"@opentelemetry/exporter-trace-otlp-http": "0.203.0",
196+
"@opentelemetry/api-logs": "0.209.0",
197+
"@opentelemetry/core": "2.3.0",
198+
"@opentelemetry/exporter-logs-otlp-http": "0.209.0",
199+
"@opentelemetry/exporter-metrics-otlp-http": "0.209.0",
200+
"@opentelemetry/exporter-trace-otlp-http": "0.209.0",
201201
"@opentelemetry/host-metrics": "^0.37.0",
202-
"@opentelemetry/instrumentation": "0.203.0",
203-
"@opentelemetry/resources": "2.0.1",
204-
"@opentelemetry/sdk-logs": "0.203.0",
205-
"@opentelemetry/sdk-metrics": "2.0.1",
206-
"@opentelemetry/sdk-trace-base": "2.0.1",
207-
"@opentelemetry/sdk-trace-node": "2.0.1",
202+
"@opentelemetry/instrumentation": "0.209.0",
203+
"@opentelemetry/resources": "2.3.0",
204+
"@opentelemetry/sdk-logs": "0.209.0",
205+
"@opentelemetry/sdk-metrics": "2.3.0",
206+
"@opentelemetry/sdk-trace-base": "2.3.0",
207+
"@opentelemetry/sdk-trace-node": "2.3.0",
208208
"@opentelemetry/semantic-conventions": "1.36.0",
209209
"@s2-dev/streamstore": "0.22.5",
210210
"dequal": "^2.0.3",

references/d3-chat/package.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -23,13 +23,13 @@
2323
"@ai-sdk/openai": "2.0.14",
2424
"@e2b/code-interpreter": "^1.1.0",
2525
"@opentelemetry/api": "^1.9.0",
26-
"@opentelemetry/api-logs": "^0.203.0",
27-
"@opentelemetry/exporter-logs-otlp-http": "0.203.0",
28-
"@opentelemetry/exporter-trace-otlp-http": "0.203.0",
29-
"@opentelemetry/instrumentation-http": "0.203.0",
26+
"@opentelemetry/api-logs": "^0.209.0",
27+
"@opentelemetry/exporter-logs-otlp-http": "0.209.0",
28+
"@opentelemetry/exporter-trace-otlp-http": "0.209.0",
29+
"@opentelemetry/instrumentation-http": "0.209.0",
3030
"@opentelemetry/instrumentation-undici": "0.14.0",
31-
"@opentelemetry/instrumentation": "^0.203.0",
32-
"@opentelemetry/sdk-logs": "^0.203.0",
31+
"@opentelemetry/instrumentation": "^0.209.0",
32+
"@opentelemetry/sdk-logs": "^0.209.0",
3333
"@radix-ui/react-avatar": "^1.1.3",
3434
"@slack/web-api": "7.9.1",
3535
"@trigger.dev/python": "workspace:*",

0 commit comments

Comments
 (0)