Skip to content

deps: bump grpc-gateway to v2.30.0 and move otelgrpc to the stats.Handler API - #1258

Merged
psbrar99 merged 1 commit into
envoyproxy:mainfrom
zhaohuabing:otelgrpc-stats-handler
Sep 30, 2026
Merged

psbrar99 merged 1 commit into
envoyproxy:mainfrom
zhaohuabing:otelgrpc-stats-handler

Conversation

@zhaohuabing

@zhaohuabing zhaohuabing commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Bumps grpc-gateway from v2.29.0 to v2.30.0, which carries the fix for CVE-2026-37236. It is an indirect dependency via the OTLP exporter, but scanners flag the image on v2.29.0.

v2.30.0 requires otelgrpc v0.70.0, which removed the deprecated interceptor constructors, so the server and client CLI move to the stats.Handler API. That is what has kept the dependabot otelgrpc bumps failing since v0.68.0 (#1127, #1159, #1207, #1229), so this unblocks #1229. The otel API, SDK, OTLP exporters and b3 propagator all move to v1.45.0 so they stay on one release.

Behavior change: otelgrpc v0.70.0 emits the stable RPC span attributes by default. rpc.grpc.status_code is replaced by the string rpc.response.status_code in every mode, and rpc.method becomes fully qualified. OTEL_SEMCONV_STABILITY_OPT_IN=rpc/old keeps the old service and short method attributes; the README tracing section documents the details. Tracing is off by default and metrics are unaffected.

@zhaohuabing
zhaohuabing marked this pull request as ready for review September 30, 2026 04:41
@zhaohuabing
zhaohuabing force-pushed the otelgrpc-stats-handler branch 2 times, most recently from a40ace9 to fa4915e Compare September 30, 2026 04:58
…dler API

grpc-gateway v2.30.0 carries the fix for CVE-2026-37236. It requires
otelgrpc v0.70.0, which removed the deprecated interceptor constructors,
so the server and the client CLI switch to otelgrpc.NewServerHandler and
otelgrpc.NewClientHandler. With the otel interceptor gone the server's
unary chain has a single element, so it is installed with
grpc.UnaryInterceptor. The otel API, SDK, OTLP trace exporters and b3
propagator all move to the matching v1.45.0 release so the set stays
aligned.

otelgrpc v0.70.0 emits the stable RPC semantic conventions by default,
which renames the gRPC span attributes. The README documents
OTEL_SEMCONV_STABILITY_OPT_IN for keeping the previous attributes.

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: Huabing (Robin) Zhao <huabing@tetrate.io>
@zhaohuabing
zhaohuabing force-pushed the otelgrpc-stats-handler branch from fa4915e to 3ed97f2 Compare September 30, 2026 05:05
@zhaohuabing

zhaohuabing commented Sep 30, 2026 •

Copy link
Copy Markdown
Member Author

cc @nacx @psbrar99 @ysawa0

@psbrar99
psbrar99 merged commit 29ed276 into envoyproxy:main Sep 30, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants