Bump go.opentelemetry.io/otel/sdk/metric from 1.36.0 to 1.38.0#2753
Bump go.opentelemetry.io/otel/sdk/metric from 1.36.0 to 1.38.0#2753dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Kusari Analysis Results:
Both dependency and code security analyses independently confirm this is a safe OpenTelemetry SDK update from v1.36.0 to v1.38.0. The dependency analysis validates excellent maintenance scores (10/10), permissive licensing, and zero known vulnerabilities in a well-established CNCF project. The code analysis confirms zero security issues, no exposed secrets, successful govulncheck validation, and appropriate file modifications limited to go.mod and go.sum. All security scans passed cleanly with no conflicting findings. This represents a routine, low-risk dependency update with strong security validation from multiple perspectives. Note View full detailed analysis result for more information on the output and the checks that were run.
Found this helpful? Give it a 👍 or 👎 reaction! |
|
@dependabot rebase |
053eb27 to
635d9bd
Compare
|
Kusari PR Analysis rerun based on - 635d9bd performed at: 2025-09-16T17:17:26Z - link to updated analysis |
635d9bd to
93ce94b
Compare
|
Kusari PR Analysis rerun based on - 93ce94b performed at: 2025-09-17T16:36:52Z - link to updated analysis |
93ce94b to
3724a52
Compare
|
Kusari PR Analysis rerun based on - 3724a52 performed at: 2025-09-17T23:39:55Z - link to updated analysis |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
@dependabot rebase |
3724a52 to
39bf567
Compare
|
Kusari PR Analysis rerun based on - 39bf567 performed at: 2025-09-18T15:42:46Z - link to updated analysis |
39bf567 to
c81b556
Compare
|
Kusari PR Analysis rerun based on - c81b556 performed at: 2025-10-02T13:40:41Z - link to updated analysis |
|
@dependabot rebase |
1 similar comment
|
@dependabot rebase |
c81b556 to
f16952d
Compare
|
@dependabot rebase |
f16952d to
c790aa2
Compare
|
@dependabot recreate |
c790aa2 to
755370f
Compare
|
@dependabot rebase |
755370f to
06e4f64
Compare
|
@dependabot rebase |
06e4f64 to
eeab627
Compare
|
@dependabot recreate |
eeab627 to
3949150
Compare
|
@dependabot recreate |
Bumps [go.opentelemetry.io/otel/sdk/metric](https://github.com/open-telemetry/opentelemetry-go) from 1.36.0 to 1.38.0. - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.36.0...v1.38.0) --- updated-dependencies: - dependency-name: go.opentelemetry.io/otel/sdk/metric dependency-version: 1.38.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
3949150 to
57a78b4
Compare
Bumps go.opentelemetry.io/otel/sdk/metric from 1.36.0 to 1.38.0.
Changelog
Sourced from go.opentelemetry.io/otel/sdk/metric's changelog.
... (truncated)
Commits
84e3f3aRelease v1.38.0 (#7271)18424a4Add tests for attribute JSON marshalling (#7268)9798759Statically define trace observability attributes (#7263)be1e57fRefactor BSP observability setup (#7264)d99c68cchore(deps): update module github.com/mgechev/revive to v1.12.0 (#7269)0724539Add benchmark for set equality (#7262)5358fd7Upgrade semconv dependencies to v1.37.0 (#7260)25d0274fix(deps): update module github.com/stretchr/testify to v1.11.1 (#7261)d0cab86prometheus: Add support for setting Translation Strategy config option (#7111)3342341Generate thesemconv/v1.37.0packages (#7254)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)