Update all patch and minor versions - #3093
Merged
Merged
Conversation
github-actions
Bot
requested review from
atoulme,
breedx-splk,
jeanbisutti,
jsuereth,
psx95,
srprash and
wangzlei
September 8, 2026 02:56
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The Weaver bump does not update the image actually used by the build tasks.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Updates patch and minor dependency versions across build tooling, runtime libraries, and integration-test infrastructure.
Changes:
- Updates Java dependencies, including SLF4J, Google Auth, and Byte Buddy.
- Updates Copilot CLI and Markdown lint tooling.
- Updates pinned OpenTelemetry Collector and Weaver images.
File summaries
| File | Description |
|---|---|
runtime-attach/runtime-attach-core/build.gradle.kts |
Updates Byte Buddy Agent. |
mise.toml |
Updates rumdl. |
ibm-mq-metrics/weaver.Dockerfile |
Updates the tracked Weaver image. |
ibm-mq-metrics/build.gradle.kts |
Updates SLF4J dependencies. |
gcp-auth-extension/build.gradle.kts |
Updates Google Auth. |
dependencyManagement/build.gradle.kts |
Updates managed SLF4J versions. |
aws-xray/src/awsTest/java/io/opentelemetry/contrib/aws/xray/AwsXrayRemoteSamplerIntegrationTest.java |
Updates the Collector test image. |
.github/scripts/copilot-cli/package.json |
Updates Copilot CLI. |
.github/scripts/copilot-cli/package-lock.json |
Refreshes the Copilot CLI lockfile. |
Review details
Files not reviewed (1)
- .github/scripts/copilot-cli/package-lock.json: Generated file
- Files reviewed: 8/9 changed files
- Comments generated: 1
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
||
| # Weaver is used to generate markdown docs, and enforce policies on the model and run integration tests. | ||
| FROM otel/weaver:v0.25.1@sha256:9ad46ca9cd4fa5974b121f886aa3e9946a8ef8ea905001a96c018d21f9db87ca AS weaver No newline at end of file | ||
| FROM otel/weaver:v0.26.1@sha256:9094862c0ab261bdbcb079bb981f9a573b3659b130a6d2ab8616eca6ba37aaec AS weaver No newline at end of file |
laurit
approved these changes
Sep 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.0.81→1.0.830.159.0→0.160.0v0.25.1→v0.26.10.2.62→0.2.682.0.18→2.0.192.0.18→2.0.192.0.18→2.0.192.0.18→2.0.192.0.18→2.0.191.51.0→1.52.01.18.12→1.18.13Release Notes
github/copilot-cli (@github/copilot)
v1.0.83Compare Source
model, tried in order until one is available to you, andmodel-policy: requiredkeeps model changes on that list/copyand notifications work in herdr panesConnection: closeghcommands now authenticate as the account configured for the repository instead of the Copilot CLI login--add-diror--plugin-dirpath now resolves against the session's working directory under--resume=<id>and--worktree, instead of the directory the CLI was launched from. Relative values are also resolved after-Cis applied, so-Cno longer has to precede either option on the command line/mcp configand the MCP add/edit/authenticate forms now open in the plugins dashboard instead of a separate MCP manager, so closing a form returns to the server list.v1.0.82Compare Source
open-telemetry/opentelemetry-collector-releases (otel/opentelemetry-collector-contrib)
v0.160.0Compare Source
🚀 New components 🚀
spanpruningprocessor: Added missing spanpruningprocessor to otelcol-contrib (#1608)💡 Enhancements 💡
otelcol-contrib: Upgrade go.opentelemetry.io/obi to v0.11.0. (#1604)open-telemetry/weaver (otel/weaver)
v0.26.1: 0.26.1 - 2026-09-02Compare Source
Release Notes
weaver-installer.shfailing to detect Unix platforms due to missing bash shell in release workflow. (#1744)Install weaver 0.26.1
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.26.1/weaver-installer.ps1 | iex"Download weaver 0.26.1
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
You can also download the attestation from GitHub and verify against that directly:
v0.26.0: 0.26.0 - 2026-09-02Compare Source
Release Notes
registry live-checkandregistry infernow bind their OTLP and HTTP admin listeners to127.0.0.1instead of0.0.0.0, so they no longer listen on every local address by default. Pass--otlp-grpc-address(live-check) or--grpc-address(infer) to bind a specific interface, or0.0.0.0for all of them. The admin listener now binds to the same address as the OTLP listener rather than always to0.0.0.0. (#1740 by @lmolkova)crypto-ring,crypto-aws-lc,crypto-openssl,crypto-openssl-vendored,crypto-symcrypt), withcrypto-ringas the default. (#1712 by @lquerel)weaver.yamland.weaver.toml. (#1693 by @jsuereth)entity_refsandlookup_entityto thesemconvRego library, so anafter_resolutionpolicy can read the entity definition that anentity_associationsleaf names, including one a dependency defines.entity_refswalks theone_ofandall_oflevels of an association. (#1719 by @jerbly)lookup_entityJinja function, which turns anentity_associationsleaf into the entity definition it names, forweaver registry generateon a v2 registry. (#1718 by @jerbly)entity_associationsreference into a dependency, or to an entity refinement, neither of which the checker could see before: those entities went unchecked, so a resource missing their required attributes passed clean. A Rego advice policy can read the same v2 definitions, asdata.entities. (#1716 by @jerbly)entity_associationsleaf in the materialized schema now says which registry defines the entity, as the published schema already did. A leaf that was the bare namehostis now{ type: host, provenance: { source: <schema url> } }, and a leaf with no provenance means this registry defines it. A template, jq filter or Rego policy that read the leaf as a string reads.typeinstead, and theserveUI and its API are updated too. (#1710 by @jerbly)dependenciesin the materialized (forge) schema is now a map keyed by schema url holding each registry once, and thedependency_graphgives the direct dependencies of each. (#1730 by @jerbly)type: resourcegroup converting to a v2 entity whose type carried the group-id prefix. The entity type now comes from the group'sname, as it always did for imports, and falls back to the id when the group has none. Everyresourcegroup of semconv v1.33.0 has this shape, soresource.hostbecame the entityresource.hostrather thanhost, and anentity_associationsentry naminghostmatched nothing. (#1704 by @jerbly)entity.orspan.prefix from the type. I.e. an entity authored astype: entity.testnow keeps the typeentity.testinstead oftest. (#1704 by @jerbly)entity.hostandhostboth become the entityhostand the second silently replaced the first. (#1704 by @jerbly)entity_associationsentry, and record which registry defines the entity it names. A name that nothing in scope defines now fails resolution, as does one that two dependencies each declare an unrelated entity under. A private entity (dependency_resolution.exclude) satisfies an association only for a signal that is private too. In the v2 resolved schema an association leaf is now an object ({ type, provenance }) instead of a bare entity type;provenance.sourceindexesdependenciesand is absent for an entity of this registry. (#1704 by @jerbly)stabilityanddeprecatedon v2 attribute references. (#1720 by @lmolkova)importspattern that matched nothing in any dependency, as a warning. A typo or a stale name was previously dropped in silence. (#1701 by @jerbly)sampling_relevantsetting on its attributes. This is per-span state, held on the span's attribute reference rather than on the catalog attribute, so the import path never read it. Refining such a span was unaffected. (#1694 by @jerbly)importsnever matching a legacytype: resourceentity in a dependency. Such a group sets nonameand holds its entity type in the group id, so the matcher now matches the group id as well as the name. (#1694 by @jerbly)name+registry_pathin legacy (v1) manifests. (#1696 by @lmolkova)stabilityfrom the signal that declares it. The catalog lookup required the field to be present, so an entity could be published with an emptyidentity. A missing stability now converts todevelopment, the documented default, instead ofalpha. (#1695 by @jerbly)dependenciesset is the table thatDependencyRefprovenance indexes into, but it listed only direct dependencies, so anything reaching the registry through a dependency-of-a-dependency had no entry to point at. It now records the full closure. (#1655 by @jerbly)Install weaver 0.26.0
Install prebuilt binaries via shell script
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.26.0/weaver-installer.ps1 | iex"Download weaver 0.26.0
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
You can also download the attestation from GitHub and verify against that directly:
rvben/rumdl (rumdl)
v0.2.68Compare Source
Fixed
Performance
Downloads
Installation
Using uv (Recommended)
Using pip
Using pipx
Direct Download
Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
v0.2.67Compare Source
Fixed
Downloads
Installation
Using uv (Recommended)
Using pip
Using pipx
Direct Download
Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
v0.2.66Compare Source
Fixed
§in the heading and for an emoji not surrounded by spaces (#854) (d530737). A link written to the old slug is now reported, and MD073 regenerates the TOC entry of such a heading on its next fix; MD080 and the LSP heading rename use the same slug.Added
Downloads
Installation
Using uv (Recommended)
Using pip
Using pipx
Direct Download
Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
v0.2.65Compare Source
Added
--no-code-block-toolsand--only-code-block-toolsmode flags (#829) (fc410f7)rumdl config(#851) (4dc0d30)Fixed
[tool.rumdl.code-block-tools]in pyproject.toml (#851) (87b159d)rumdl configis empty (cac7b76)Downloads
Installation
Using uv (Recommended)
Using pip
Using pipx
Direct Download
Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
v0.2.64Compare Source
Added
gh-aw), including imports and current conditional branch syntax (39f7263)MarkdownFlavor::GhAw; downstream exhaustive matches must handle the new variantFixed
Downloads
Installation
Using uv (Recommended)
Using pip
Using pipx
Direct Download
Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
v0.2.63Compare Source
Added
Fixed
Configuration
📅 Schedule: (UTC)
* 0-7 * * 2)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.