Skip to content

Bump EDOT .NET to 1.6.0 and drop the Resources.Host pin - #4306

Merged
akira28 merged 1 commit into
mainfrom
chore/edot-dotnet-1.6.0
Oct 5, 2026
Merged

akira28 merged 1 commit into
mainfrom
chore/edot-dotnet-1.6.0

Conversation

@akira28

@akira28 akira28 commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This PR moves Elastic.OpenTelemetry to 1.6.0 and the core OpenTelemetry packages to 1.19.x. It also removes the security pin for OpenTelemetry.Resources.Host, which EDOT now resolves to a patched version on its own.

Affects: Docs API, MCP, CLI

Prompt summary: EDOT .NET 1.6.0 ships with the 1.19.1 OpenTelemetry SDK and components. The ask is to upgrade from 1.5.0 and drop the OpenTelemetry.Resources.Host pin, which should no longer be needed.

Why

#4128 pinned OpenTelemetry.Resources.Host to 1.16.0-beta.2 to clear GHSA-v8pv-4842-x354. EDOT 1.6.0 depends on OpenTelemetry.Resources.Host 1.19.1-beta.1, which is outside the vulnerable range. The pin is now dead weight that we would have to keep bumping by hand.

What

EDOT upgrade and pin removal

Elastic.OpenTelemetry goes from 1.5.0 to 1.6.0. The OpenTelemetry.Resources.Host entry and its comment leave the transitive security-pin group in Directory.Packages.props. Restore now resolves OpenTelemetry.Resources.Host 1.19.1-beta.1 through EDOT.

OpenTelemetry versions aligned with EDOT

EDOT 1.6.0 requires OpenTelemetry 1.19.1 and the instrumentation packages at 1.19.0. This repo enables CentralPackageTransitivePinningEnabled, so leaving our direct pins at 1.16.0 would fail restore with a downgrade error. OpenTelemetry, Exporter.OpenTelemetryProtocol, Extensions.Hosting, and Exporter.InMemory move to 1.19.1. Instrumentation.Http, Instrumentation.Runtime, and Instrumentation.AspNetCore move to 1.19.0.

Verify

dotnet restore   # no NU1903 or NU1109 errors
./build.sh unit-test

🤖 Generated with Claude Code

EDOT .NET 1.6.0 depends on OpenTelemetry 1.19.1 and pulls in a patched
OpenTelemetry.Resources.Host, so the GHSA-v8pv-4842-x354 pin is no longer
needed. Transitive pinning requires the core OpenTelemetry packages to move
to 1.19.x as well, or restore fails with a downgrade error.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@akira28
akira28 requested a review from a team as a code owner October 5, 2026 13:37
@akira28
akira28 requested a review from Mpdreamz October 5, 2026 13:37
@akira28
akira28 enabled auto-merge (squash) October 5, 2026 13:38
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Docs preview (local build)

Handbook preview: https://docs-v3-preview.elastic.dev/elastic/docs-builder/pull/4306/

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blocking issues found.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • d31bhlox0wglh.cloudfront.net

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "d31bhlox0wglh.cloudfront.net"

See Network Configuration for more information.


What is this? | From workflow: PR Review

Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

@akira28
akira28 merged commit db925b1 into main Oct 5, 2026
43 checks passed
@akira28
akira28 deleted the chore/edot-dotnet-1.6.0 branch October 5, 2026 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants