Repository navigation
Bump EDOT .NET to 1.6.0 and drop the Resources.Host pin - #4306
Merged
Merged
Conversation
EDOT .NET 1.6.0 depends on OpenTelemetry 1.19.1 and pulls in a patched OpenTelemetry.Resources.Host, so the GHSA-v8pv-4842-x354 pin is no longer needed. Transitive pinning requires the core OpenTelemetry packages to move to 1.19.x as well, or restore fails with a downgrade error. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Docs preview (local build)Handbook preview: https://docs-v3-preview.elastic.dev/elastic/docs-builder/pull/4306/ |
Contributor
There was a problem hiding this comment.
No blocking issues found.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
d31bhlox0wglh.cloudfront.net
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "d31bhlox0wglh.cloudfront.net"See Network Configuration for more information.
What is this? | From workflow: PR Review
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.
Mpdreamz
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR moves
Elastic.OpenTelemetryto 1.6.0 and the core OpenTelemetry packages to 1.19.x. It also removes the security pin forOpenTelemetry.Resources.Host, which EDOT now resolves to a patched version on its own.Affects: Docs API, MCP, CLI
Prompt summary: EDOT .NET 1.6.0 ships with the 1.19.1 OpenTelemetry SDK and components. The ask is to upgrade from 1.5.0 and drop the
OpenTelemetry.Resources.Hostpin, which should no longer be needed.Why
#4128 pinned
OpenTelemetry.Resources.Hostto1.16.0-beta.2to clear GHSA-v8pv-4842-x354. EDOT 1.6.0 depends onOpenTelemetry.Resources.Host1.19.1-beta.1, which is outside the vulnerable range. The pin is now dead weight that we would have to keep bumping by hand.What
EDOT upgrade and pin removal
Elastic.OpenTelemetrygoes from 1.5.0 to 1.6.0. TheOpenTelemetry.Resources.Hostentry and its comment leave the transitive security-pin group inDirectory.Packages.props. Restore now resolvesOpenTelemetry.Resources.Host1.19.1-beta.1through EDOT.OpenTelemetry versions aligned with EDOT
EDOT 1.6.0 requires
OpenTelemetry1.19.1 and the instrumentation packages at 1.19.0. This repo enablesCentralPackageTransitivePinningEnabled, so leaving our direct pins at 1.16.0 would fail restore with a downgrade error.OpenTelemetry,Exporter.OpenTelemetryProtocol,Extensions.Hosting, andExporter.InMemorymove to 1.19.1.Instrumentation.Http,Instrumentation.Runtime, andInstrumentation.AspNetCoremove to 1.19.0.Verify
dotnet restore # no NU1903 or NU1109 errors ./build.sh unit-test🤖 Generated with Claude Code