Skip to content

chore(deps): bump the go-deps group across 1 directory with 17 updates - #173

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-deps-829e3d539a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go-deps-829e3d539a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-deps group with 17 updates in the / directory:

Package From To
github.com/anthropics/anthropic-sdk-go 1.73.0 1.79.0
github.com/quic-go/quic-go 0.62.0 0.63.0
github.com/redis/go-redis/v9 9.22.0 9.23.0
go.opentelemetry.io/otel 1.46.0 1.47.0
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp 0.22.0 0.23.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp 1.46.0 1.47.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace 1.46.0 1.47.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp 1.46.0 1.47.0
go.opentelemetry.io/otel/log 0.22.0 1.47.0
go.opentelemetry.io/otel/metric 1.46.0 1.47.0
go.opentelemetry.io/otel/sdk 1.46.0 1.47.0
go.opentelemetry.io/otel/sdk/log 0.22.0 1.47.0
go.opentelemetry.io/otel/sdk/metric 1.46.0 1.47.0
go.opentelemetry.io/otel/trace 1.46.0 1.47.0
golang.org/x/sys 0.48.0 0.49.0
google.golang.org/genai 1.71.0 1.73.0
modernc.org/sqlite 1.59.0 1.60.1

Updates github.com/anthropics/anthropic-sdk-go from 1.73.0 to 1.79.0

Release notes

Sourced from github.com/anthropics/anthropic-sdk-go's releases.

v1.79.0

1.79.0 (2026-10-07)

Full Changelog: v1.78.0...v1.79.0

Features

  • api: add claude-haiku-5-5 and typed computer and browser toolset tool calls (1930a5e)
  • api: add disabled to thinking types in model capabilities (3b88a46)
  • api: add display_name to RBAC roles and deprecate name (e568369)
  • api: add include_default parameter to list workspaces (a2acfc6)
  • api: add lifecycle stage fields and filter to /v1/models (2b3ea06)
  • api: add line to model objects (24b1d56)
  • api: add url_sources to the Managed Agents web_fetch tool config (3b88a46)
  • api: add web search and code execution support to model capabilities (3b88a46)
  • client: add All() iterators to SSE streams and auto-pagers (b0d7423)

Bug Fixes

  • api: send the beta header by default when listing spend limits (b8bcfc7)
  • auth: require https or loopback at every token endpoint (#431) (3b88a46)
  • client: percent-encode path params and reject dot-segment values (3b88a46)
  • client: return the field error when a param union variant fails to decode (a59fef2)
  • client: send array header params as a single comma-separated header (dace66e)
  • client: send default and caller-provided array header values in a single header (1ca109c)
  • environments: keep a local edit made after a memory upload whose response was lost (#441) (3b88a46)
  • return unmodeled content blocks and citations from ToParam instead of panicking (#436) (3b88a46)

Chores

  • api: keep the MessageParam name and drop generated constructors (3b88a46)
  • api: mark the Text Completions API as deprecated (3b88a46)
  • docs: correct example groups in rate limit list description (a489eb3)
  • docs: correct when usage and cost report data becomes final (3b88a46)
  • docs: describe a federation rule's target by its type (3b88a46)
  • docs: fix example IDs in sessions, agents and vault credentials (3b88a46)
  • docs: update Managed Agents multiagent and thread descriptions (3b88a46)
  • docs: update the activity summaries endpoint description (86f2da1)
  • docs: update the description of the Model line field (ad2ed3e)
  • internal: add REVIEW.md with review instructions (3b88a46)
  • internal: make mock server spec updates smaller in git history (3b88a46)
  • internal: move the custom unmarshaler test into the param decode tests (#444) (3b88a46)
  • tests: run tests skipped for a query param bug that is now fixed (3a8025b)
  • tests: run tests that an older mock server could not serve (4735a5a)

Documentation

... (truncated)

Changelog

Sourced from github.com/anthropics/anthropic-sdk-go's changelog.

1.79.0 (2026-10-07)

Full Changelog: v1.78.0...v1.79.0

Features

  • api: add claude-haiku-5-5 and typed computer and browser toolset tool calls (1930a5e)
  • api: add disabled to thinking types in model capabilities (3b88a46)
  • api: add display_name to RBAC roles and deprecate name (e568369)
  • api: add include_default parameter to list workspaces (a2acfc6)
  • api: add lifecycle stage fields and filter to /v1/models (2b3ea06)
  • api: add line to model objects (24b1d56)
  • api: add url_sources to the Managed Agents web_fetch tool config (3b88a46)
  • api: add web search and code execution support to model capabilities (3b88a46)
  • client: add All() iterators to SSE streams and auto-pagers (b0d7423)

Bug Fixes

  • api: send the beta header by default when listing spend limits (b8bcfc7)
  • auth: require https or loopback at every token endpoint (#431) (3b88a46)
  • client: percent-encode path params and reject dot-segment values (3b88a46)
  • client: return the field error when a param union variant fails to decode (a59fef2)
  • client: send array header params as a single comma-separated header (dace66e)
  • client: send default and caller-provided array header values in a single header (1ca109c)
  • environments: keep a local edit made after a memory upload whose response was lost (#441) (3b88a46)
  • return unmodeled content blocks and citations from ToParam instead of panicking (#436) (3b88a46)

Chores

  • api: keep the MessageParam name and drop generated constructors (3b88a46)
  • api: mark the Text Completions API as deprecated (3b88a46)
  • docs: correct example groups in rate limit list description (a489eb3)
  • docs: correct when usage and cost report data becomes final (3b88a46)
  • docs: describe a federation rule's target by its type (3b88a46)
  • docs: fix example IDs in sessions, agents and vault credentials (3b88a46)
  • docs: update Managed Agents multiagent and thread descriptions (3b88a46)
  • docs: update the activity summaries endpoint description (86f2da1)
  • docs: update the description of the Model line field (ad2ed3e)
  • internal: add REVIEW.md with review instructions (3b88a46)
  • internal: make mock server spec updates smaller in git history (3b88a46)
  • internal: move the custom unmarshaler test into the param decode tests (#444) (3b88a46)
  • tests: run tests skipped for a query param bug that is now fixed (3a8025b)
  • tests: run tests that an older mock server could not serve (4735a5a)

Documentation

  • api: list streaming-only methods in api.md under their real names (3b88a46)

... (truncated)

Commits
  • a45273b Merge pull request #476 from anthropics/release-please--branches--main--chang...
  • e41c58e release: 1.79.0
  • a59fef2 fix(client): return the field error when a param union variant fails to decode
  • 2b3ea06 feat(api): add lifecycle stage fields and filter to /v1/models
  • 86f2da1 chore(docs): update the activity summaries endpoint description
  • 1930a5e feat(api): add claude-haiku-5-5 and typed computer and browser toolset tool c...
  • 3b88a46 docs(beta): point structured-output helper docs at output_config.format (#429)
  • e568369 feat(api): add display_name to RBAC roles and deprecate name
  • cfd31a5 docs(api): state the agent tools limit as 256
  • ad2ed3e chore(docs): update the description of the Model line field
  • Additional commits viewable in compare view

Updates github.com/quic-go/quic-go from 0.62.0 to 0.63.0

Release notes

Sourced from github.com/quic-go/quic-go's releases.

v0.63.0

This release improves HTTP/3 request handling and error reporting.

Breaking Changes

  • http3: non-CONNECT server requests now leave URL.Scheme and URL.Host empty, matching net/http: #5839
  • http3: Extended CONNECT now leaves URL.Scheme and URL.Host empty and sets RequestURI to :path: #5841
  • http3: stream APIs now return QUIC stream and application errors as *http3.Error: #5852

Notable Fixes

  • http3: :path must start with /; only OPTIONS allows *: #5842
  • quicvarint: complete varints now decode successfully when returned alongside io.EOF or another reader error: #5876

Notable Changes

  • http3.Error now supports unwrapping the underlying QUIC stream or application error: #5873
  • http3.ClientConn now exposes LocalAddr and RemoteAddr: #5871

Changelog

Full Changelog: quic-go/quic-go@v0.62.0...v0.63.0

Commits
  • 9d085cc quicvarint: handle data returned with errors when reading and peeking (#5876)
  • 02fba56 http3: allow unwrapping stream and application errors (#5873)
  • 3c2c36b fix issue and pull request template (#5874)
  • 9f98c6a add an AI policy (#5870)
  • 43213a3 http3: add LocalAddr and RemoteAddr to ClientConn (#5871)
  • 7ff87de use more specific require assertions for errors (#5872)
  • 418c938 fix flaky TestDial by closing transports in server tests (#5869)
  • 4edf5ee use more specific require assertions in tests (#5855)
  • 510e6fa http3: return consistent error types from stream APIs (#5852)
  • aeeb231 ci: bump docker/setup-buildx-action from 4.3.0 to 4.4.1 (#5866)
  • Additional commits viewable in compare view

Updates github.com/redis/go-redis/v9 from 9.22.0 to 9.23.0

Release notes

Sourced from github.com/redis/go-redis/v9's releases.

9.23.0

This is a minor release. It contains everything from 9.23.0-beta.1, so these notes cover the full 9.22.0 → 9.23.0 upgrade.

⚠️ Changes to check when you upgrade from 9.22.0:

  • Go 1.26 is now the minimum Go version (#4060). The go directive of the root module and of the submodules moved from 1.24 to 1.26, as part of the dependency bumps for govulncheck findings. Projects that build with Go 1.24 or 1.25 must upgrade the toolchain.
  • Each Client has a dedicated pipeline connection pool (#4002). This includes failover clients and cluster node clients. Pipeline, TxPipeline, and autopipeline operations use this pool, so they do not compete with regular commands for main-pool connections. The pool is for burst capacity only: it dials only when necessary, an unused pool holds zero connections, and if the pool is full an operation uses the main pool. Set PipelinePoolSize: -1 to get the previous single-pool behavior.
  • AutoPipelineOptions.MaxBatchBytes has a default of 128 KiB (before, there was no limit). The default prevents a write/reply deadlock; it is not a throughput control. The buffers of the pipeline pool also have a default of 128 KiB.

⚠️ Changes to experimental APIs since 9.23.0-beta.1 (no effect if you upgrade from 9.22.0):

  • AutoPipelineOptions.FullDuplexFastSubmit is removed (#4018). The submit channel is replaced by a queue that takes a full wave of commands in one lock, so the separate fast path is not necessary. Remove the field from your options.
  • Options.ClientSideCacheRefreshRecencyWindow is removed (#4034). Refresh-on-invalidate now reads again every cached entry of an invalidated key and does not look at how recently the entry was read. On a write-heavy keyspace this means refresh traffic across the full resident cache. Remove the field from your options.
  • LocalCache.LRUClock() is removed (#4034). It returned the recency token that the removed recency window used, and has no replacement. Remove calls to it.
  • ClientSideCacheInvalidationBatchWindow served stale values in beta.1 (#4033). Under load the batcher applied only ~15% of invalidations, and the cache served invalidated values with a ~100% hit rate. 9.23.0 applies all of them. If you used this option on beta.1, upgrade.

🚀 Highlights

Full-Duplex Auto-Pipelining (Experimental)

Set AutoPipelineOptions.FullDuplex to enable the full-duplex mode of the automatic pipeliner. The default mode sends one batch per round trip. In full-duplex mode the engine holds one pipeline-pool connection, and a writer goroutine and a reader goroutine move the ordered command stream in both directions at the same time. On a high-latency link each command completes in approximately one round-trip time (RTT) on a single connection. On a 50 ms WAN profile: ~389k ops/s at 52 ms p50, against ~207k ops/s at 116 ms on the half-duplex ordered path.

The mode works on both faces of a standalone Client (AutoPipeline() and AsyncAutoPipeline()), and natively on a ClusterClient when routing goes to masters only. On a cluster, one child engine per master sends each command to the node that owns its slot, and follows MOVED / ASK redirects and retryable replies (LOADING, READONLY, ...) through the usual cluster redirect path. With replica routing (ReadOnly, RouteByLatency, or RouteRandomly), the autopipeliner uses the half-duplex shard flushers, which obey the shard picker. Config().FullDuplex reports the mode in effect.

Options:

  • FullDuplexWindow — the maximum number of commands in flight (backpressure).
  • FullDuplexIdleTimeout and FullDuplexMaxHold — when the engine returns the held connection to the pool. The pool hooks then do re-authentication and maintenance-notification handoffs.
  • MaxFlushDelay — now also used in full-duplex mode (#4014). The writer waits only when enough commands are in flight, so low-concurrency callers keep the 1×RTT behavior. With MaxFlushDelay=250µs at 1024 callers: +22% ops/s and −26% p99. The default is 0, so this is opt-in.
  • NumShards — on a standalone Client, the number of full-duplex engines (#4022). See below.

Pipeline() on the full-duplex connection (#4021). Standalone Client only. Before, ap.Pipeline() used a pooled connection for each Exec. It now submits the batch to the engine as one contiguous run (FDPipelined), so replies come back in submit order, as on a dedicated connection. At 256–1024 callers with 10 commands per Exec: +49% to +52% throughput on one socket instead of ~150. Errors, retries, hooks, and metrics behave like an ordinary pipeline. A batch that cannot use the stream (a blocking command, a per-command read timeout, a diverted command, or a batch larger than the queue) falls back to the ordinary pipeline. TxPipeline stays on a pooled connection, because MULTI/EXEC needs connection affinity. On a ClusterClient, ap.Pipeline() is still the ordinary cluster pipeline. A batch that the queue cannot admit now reserves its slots and waits in a first-come line, so single commands cannot starve a long pipeline (#4057, merged as part of #4021) by @​vlady-kotsev.

Several engines on one client (#4022). With FullDuplex, NumShards > 1 now means N engines on one client: one pool, one hook chain, N held connections. Commands route by a hash of their first key, so commands on the same key stay on one connection and keep their order without Unordered. Keyless commands are distributed round-robin. An FDPipelined batch stays on one engine. The pipeline pool must hold at least NumShards connections for each full-duplex autopipeliner. More engines help only under high concurrency: with 10-command pipelines, 8 engines were 30% slower than 1 at 8 callers, equal at about 128 callers, and 2.2× faster at 1024 callers.

The full-duplex path supports blocking commands, Options.Limiter (one admission per written batch), per-command and pipeline hooks, OTel metrics, retry budgets (a NoRetry command is never sent again after it is on the wire), and seamless maintenance handoffs. Limits of the stream model:

  • A hook can observe a command, but cannot stop it. A ProcessHook that returns without calling next does not cancel the command on the full-duplex path; the command is already queued on the held connection. Run policy or kill-switch hooks on a plain client or on the half-duplex autopipeliner.
  • Diverted commands are not ordered with the stream. The engine diverts blocking commands, connection-hostile commands, and managed HIMPORT commands. On the async face, wait for the result of a diverted command before you submit a command that depends on it.
  • Single commands on the full-duplex stream do not use the client-side cache. If CSC is enabled, a cacheable command on the stream does not read or write the cache.
  • Duration metrics are recorded per reply. A command that fails before it reaches the reader (lease failure, limiter denial, retry exhaustion, close) calls the error callback but records no operation-duration sample.
rdb := redis.NewClient(&redis.Options{
	Addr: "localhost:6379",
	AutoPipelineOptions: &redis.AutoPipelineOptions{
		FullDuplex: true, // stream commands on one held connection, ~1 RTT each
	},
})
defer rdb.Close()
</tr></table> 

... (truncated)

Changelog

Sourced from github.com/redis/go-redis/v9's changelog.

9.23.0 (2026-10-05)

This is a minor release. It contains everything from 9.23.0-beta.1, so these notes cover the full 9.22.0 → 9.23.0 upgrade. The release adds:

  • An experimental full-duplex mode for the automatic pipeliner, now with Pipeline() on the full-duplex connection and several engines on one client.
  • Refresh-on-invalidate and miss coalescing for client-side caching, and a faster cache read path.
  • Better distribution of cluster reads under latency-based routing.
  • Client.EphemeralConn, an opt-in limit on queued autopipeline commands, and many stability fixes.

⚠️ Changes to check when you upgrade from 9.22.0:

  • Go 1.26 is now the minimum Go version (#4060). The go directive of the root module and of the submodules moved from 1.24 to 1.26, as part of the dependency bumps for govulncheck findings. Projects that build with Go 1.24 or 1.25 must upgrade the toolchain.
  • Each Client has a dedicated pipeline connection pool (#4002). This includes failover clients and cluster node clients. Pipeline, TxPipeline, and autopipeline operations use this pool, so they do not compete with regular commands for main-pool connections. The pool is for burst capacity only: it dials only when necessary, an unused pool holds zero connections, and if the pool is full an operation uses the main pool. Set PipelinePoolSize: -1 to get the previous single-pool behavior.
  • AutoPipelineOptions.MaxBatchBytes has a default of 128 KiB (before, there was no limit). The default prevents a write/reply deadlock; it is not a throughput control. The buffers of the pipeline pool also have a default of 128 KiB.

⚠️ Changes to experimental APIs since 9.23.0-beta.1 (no effect if you upgrade from 9.22.0):

  • AutoPipelineOptions.FullDuplexFastSubmit is removed (#4018). The submit channel is replaced by a queue that takes a full wave of commands in one lock, so the separate fast path is not necessary. Remove the field from your options.
  • Options.ClientSideCacheRefreshRecencyWindow is removed (#4034). Refresh-on-invalidate now reads again every cached entry of an invalidated key and does not look at how recently the entry was read. On a write-heavy keyspace this means refresh traffic across the full resident cache. Remove the field from your options.
  • LocalCache.LRUClock() is removed (#4034). It returned the recency token that the removed recency window used, and has no replacement. Remove calls to it.
  • ClientSideCacheInvalidationBatchWindow served stale values in beta.1 (#4033). Under load the batcher applied only ~15% of invalidations, and the cache served invalidated values with a ~100% hit rate. 9.23.0 applies all of them. If you used this option on beta.1, upgrade.

🚀 Highlights

Full-Duplex Auto-Pipelining (Experimental)

Set AutoPipelineOptions.FullDuplex to enable the full-duplex mode of the automatic pipeliner. The default mode sends one batch per round trip. In full-duplex mode the engine holds one pipeline-pool connection, and a writer goroutine and a reader goroutine move the ordered command stream in both directions at the same time. On a high-latency link each command completes in approximately one round-trip time (RTT) on a single connection. On a 50 ms WAN profile: ~389k ops/s at 52 ms p50, against ~207k ops/s at 116 ms on the half-duplex ordered path.

The mode works on both faces of a standalone Client (AutoPipeline() and AsyncAutoPipeline()), and natively on a ClusterClient when routing goes to masters only. On a cluster, one child engine per master sends each command to the node that owns its slot, and follows MOVED / ASK redirects and retryable replies (LOADING, READONLY, ...) through the usual cluster redirect path. With replica routing (ReadOnly, RouteByLatency, or RouteRandomly), the autopipeliner uses the half-duplex shard flushers, which obey the shard picker. Config().FullDuplex reports the mode in effect.

Options:

  • FullDuplexWindow — the maximum number of commands in flight (backpressure).
  • FullDuplexIdleTimeout and FullDuplexMaxHold — when the engine returns the held connection to the pool. The pool hooks then do re-authentication and maintenance-notification handoffs.
  • MaxFlushDelay — now also used in full-duplex mode (#4014). The writer waits only when enough commands are in flight, so low-concurrency callers keep the 1×RTT behavior. With MaxFlushDelay=250µs at 1024 callers: +22% ops/s and −26% p99. The default is 0, so this is opt-in.
  • NumShards — on a standalone Client, the number of full-duplex engines (#4022). See below.

Pipeline() on the full-duplex connection (#4021). Standalone Client only. Before, ap.Pipeline() used a pooled connection for each Exec. It now submits the batch to the engine as one contiguous run (FDPipelined), so replies come back in submit order, as on a dedicated connection. At 256–1024 callers with 10 commands per Exec: +49% to +52% throughput on one socket instead of ~150. Errors, retries, hooks, and metrics behave like an ordinary pipeline. A batch that cannot use the stream (a blocking command, a per-command read timeout, a diverted command, or a batch larger than the queue) falls back to the ordinary pipeline. TxPipeline stays on a pooled connection, because MULTI/EXEC needs connection affinity. On a ClusterClient, ap.Pipeline() is still the ordinary cluster pipeline. A batch that the queue cannot admit now reserves its slots and waits in a first-come line, so single commands cannot starve a long pipeline (#4057, merged as part of #4021) by @​vlady-kotsev.

Several engines on one client (#4022). With FullDuplex, NumShards > 1 now means N engines on one client: one pool, one hook chain, N held connections. Commands route by a hash of their first key, so commands on the same key stay on one connection and keep their order without Unordered. Keyless commands are distributed round-robin. An FDPipelined batch stays on one engine. The pipeline pool must hold at least NumShards connections for each full-duplex autopipeliner. More engines help only under high concurrency: with 10-command pipelines, 8 engines were 30% slower than 1 at 8 callers, equal at about 128 callers, and 2.2× faster at 1024 callers.

The full-duplex path supports blocking commands, Options.Limiter (one admission per written batch), per-command and pipeline hooks, OTel metrics, retry budgets (a NoRetry command is never sent again after it is on the wire), and seamless maintenance handoffs. Limits of the stream model:

  • A hook can observe a command, but cannot stop it. A ProcessHook that returns without calling next does not cancel the command on the full-duplex path; the command is already queued on the held connection. Run policy or kill-switch hooks on a plain client or on the half-duplex autopipeliner.
  • Diverted commands are not ordered with the stream. The engine diverts blocking commands, connection-hostile commands, and managed HIMPORT commands. On the async face, wait for the result of a diverted command before you submit a command that depends on it.
  • Single commands on the full-duplex stream do not use the client-side cache. If CSC is enabled, a cacheable command on the stream does not read or write the cache.
  • Duration metrics are recorded per reply. A command that fails before it reaches the reader (lease failure, limiter denial, retry exhaustion, close) calls the error callback but records no operation-duration sample.
rdb := redis.NewClient(&redis.Options{
</tr></table> 

... (truncated)

Commits
  • 6f2b263 chore(release): v9.23.0 (#4074)
  • ec50c69 feat(conn): add DisposableConn to discard on Close (#4039)
  • e3d2548 fix(pool): fix ConnStateMachine waiter races (#4072)
  • 2ee6d86 fix(pool): wake waiters when a connection is released to the pool (#4028)
  • 83d45ed fix:(proto): support uintptr in WriteArg (#4054)
  • c2002af docs(example): add full-duplex examples (#4061)
  • b5f8864 feat(autopipeline): add MaxQueuedCommands hard limit (#4070)
  • 89ecbc5 fix(options): reject invalid skip_verify values in ParseURL (#4064)
  • f813adc feat(autopipeline): run N full-duplex engines on one client (#4022)
  • 349bcf4 feat(autopipeline): run Pipeline on the full-duplex connection (#4021)
  • Additional commits viewable in compare view

Updates go.opentelemetry.io/otel from 1.46.0 to 1.47.0

Release notes

Sourced from go.opentelemetry.io/otel's releases.

v1.47.0/v0.69.0/v0.23.0/v0.1.0

This release contains the first stable release of the OpenTelemetry Go Logs API and SDK. Our project stability guarantees now apply to the following modules:

  • go.opentelemetry.io/otel/log
  • go.opentelemetry.io/otel/sdk/log

See our versioning policy for more information about these stability guarantees.

Added

  • Add String method for KeyValue type in go.opentelemetry.io/otel/attribute. (#8205)
  • Add String method for Set type in go.opentelemetry.io/otel/attribute. (#8347)
  • Add WithMaxExportBatchSize to go.opentelemetry.io/otel/sdk/metric to configure the maximum export batch size for PeriodicReader. (#8960)
  • Add WithAttributeValueDepthLimit, DefaultAttributeValueDepthLimit, and SpanLimits.AttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/trace to configure the maximum depth of span, event, link, and instrumentation scope attribute values. (#8938)
  • Add WithAttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/log to configure the maximum depth of log record and instrumentation scope attribute values. (#8938)
  • Add WithMaxResponseSize to go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, and go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8941)
  • Add experimental ProbabilitySampler in go.opentelemetry.io/otel/sdk/trace/x that conforms to the OpenTelemetry specification's threshold-based sampling algorithm. (#8123)
  • Add experimental *Binder extension interfaces in go.opentelemetry.io/otel/metric/x for instruments that support binding attributes ahead of time. (#8760)
  • Add the experimental Finisher synchronous metric instrument extension interface to go.opentelemetry.io/otel/metric/x. (#8906)

Changed

  • Use the OpenTelemetry Attribute Collection representation for non-OTLP protocols for metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8993)
  • Apply a maximum depth of 64 by default to span, event, link, log record, and instrumentation scope attribute values in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log. (#8938)
  • Reduce allocations when applying attribute value length limits in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log by rebuilding composite values only when truncation is needed. (#8912)
  • Decode traceparent using a hex lookup table in go.opentelemetry.io/otel/propagation, which rejects the specification-disallowed upper-case characters without a separate scan of the header. (#8739)
  • Decode all characters at constant indices in TraceIDFromHex and SpanIDFromHex in go.opentelemetry.io/otel/trace to eliminate bounds checks. (#8740)

Fixed

  • Count valid U+FFFD replacement characters toward attribute value length limits in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log.
  • Truncate string attribute values to empty strings when the configured length limit is zero, including malformed UTF-8, in go.opentelemetry.io/otel/trace, go.opentelemetry.io/otel/sdk/trace, and go.opentelemetry.io/otel/sdk/log. (#9054)
  • Fix a data race in NewPeriodicReader where r.inst was assigned after the background goroutine was launched in go.opentelemetry.io/otel/sdk/metric. (#9028)
  • Prevent precision loss for large int64 values in Sum, Histogram, and ExponentialHistogram aggregations in go.opentelemetry.io/otel/sdk/metric. (#8981)
  • Ensure grpc.DialOption values passed via WithDialOption take precedence over conflicting internally-computed defaults in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc, and go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc. (#8805, #8834, #8836)
  • Treat overflowing OTEL_METRIC_EXPORT_INTERVAL and OTEL_METRIC_EXPORT_TIMEOUT values as invalid in go.opentelemetry.io/otel/sdk/metric. (#8800)
  • Prevent a panic in NewFixedSizeReservoir and FixedSizeReservoirProvider when given a negative size in go.opentelemetry.io/otel/sdk/metric/exemplar; negative sizes are now clamped to zero, consistent with a size of zero. (#8832)
  • Preserve exponential histogram ZeroThreshold during OTLP metric export in go.opentelemetry.io/otel/exporters/otlp/otlpmetric. (#8801)
  • Ensure metric helpers in go.opentelemetry.io/otel/semconv/v1.32.0, go.opentelemetry.io/otel/semconv/v1.33.0, and go.opentelemetry.io/otel/semconv/v1.34.0 record measurements only once when no attributes are provided. (#8849)
  • Treat empty OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG values as unset in go.opentelemetry.io/otel/sdk/trace. (#8873)
  • Normalize global OTEL_EXPORTER_OTLP_ENDPOINT path joining in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp so trailing-slash base URLs do not produce double-slash log export paths. (#8864)
  • Prevent a deadlock when formatting an error passed to RecordError calls back into the span in go.opentelemetry.io/otel/sdk/trace. (#8815)
  • Prevent SimpleSpanProcessor.Shutdown from panicking when constructed with a nil exporter in go.opentelemetry.io/otel/sdk/trace. (#8844)
  • Propagate invalid exponential histogram scale errors to Prometheus exporter self-observability metrics in go.opentelemetry.io/otel/exporters/prometheus. (#8839)

... (truncated)

Changelog

Sourced from go.opentelemetry.io/otel's changelog.

[1.47.0/0.69.0/0.23.0/0.1.0] - 2026-10-02

This release contains the first stable release of the OpenTelemetry Go Logs API and SDK. Our project stability guarantees now apply to the following modules:

  • go.opentelemetry.io/otel/log
  • go.opentelemetry.io/otel/sdk/log

See our versioning policy for more information about these stability guarantees.

Added

  • Add String method for KeyValue type in go.opentelemetry.io/otel/attribute. (#8205)
  • Add String method for Set type in go.opentelemetry.io/otel/attribute. (#8347)
  • Add WithMaxExportBatchSize to go.opentelemetry.io/otel/sdk/metric to configure the maximum export batch size for PeriodicReader. (#8960)
  • Add WithAttributeValueDepthLimit, DefaultAttributeValueDepthLimit, and SpanLimits.AttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/trace to configure the maximum depth of span, event, link, and instrumentation scope attribute values. (#8938)
  • Add WithAttributeValueDepthLimit in go.opentelemetry.io/otel/sdk/log to configure the maximum depth of log record and instrumentation scope attribute values. (#8938)
  • Add WithMaxResponseSize to go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, and go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp. (#8941)
  • Add experimental ProbabilitySampler in go.opentelemetry.io/otel/sdk/trace/x that conforms to the OpenTelemetry specification's threshold-based sampling algorithm. (#8123)
  • Add experimental *Binder extension interfaces in go.opentelemetry.io/otel/metric/x for instruments that support binding attributes ahead of time. (#8760)
  • Add the experimental Finisher synchronous metric instrument extension interface to go.opentelemetry.io/otel/metric/x. (#8906)

Changed

  • Use the OpenTelemetry Attribute Collection representation for non-OTLP protocols for metric data diffs in go.opentelemetry.io/otel/sdk/metric/metricdata/metricdatatest. (#8993)
  • Apply a maximum depth of 64 by default to span, event, link, log record, and instrumentation scope attribute values in go.opentelemetry.io/otel/sdk/trace and go.opentelemetry.io/otel/sdk/log. (#8938)
  • Reduce allocations when applying attribute value length limits in go.opentelemetry.io/otel/sdk/trace and go.opentelemet...

    Description has been truncated

Bumps the go-deps group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/anthropics/anthropic-sdk-go](https://github.com/anthropics/anthropic-sdk-go) | `1.73.0` | `1.79.0` |
| [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) | `0.62.0` | `0.63.0` |
| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) | `9.22.0` | `9.23.0` |
| [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp](https://github.com/open-telemetry/opentelemetry-go) | `0.22.0` | `0.23.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/log](https://github.com/open-telemetry/opentelemetry-go) | `0.22.0` | `1.47.0` |
| [go.opentelemetry.io/otel/metric](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/sdk/log](https://github.com/open-telemetry/opentelemetry-go) | `0.22.0` | `1.47.0` |
| [go.opentelemetry.io/otel/sdk/metric](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.46.0` | `1.47.0` |
| [golang.org/x/sys](https://github.com/golang/sys) | `0.48.0` | `0.49.0` |
| [google.golang.org/genai](https://github.com/googleapis/go-genai) | `1.71.0` | `1.73.0` |
| [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) | `1.59.0` | `1.60.1` |



Updates `github.com/anthropics/anthropic-sdk-go` from 1.73.0 to 1.79.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-go/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-go/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-go@v1.73.0...v1.79.0)

Updates `github.com/quic-go/quic-go` from 0.62.0 to 0.63.0
- [Release notes](https://github.com/quic-go/quic-go/releases)
- [Commits](quic-go/quic-go@v0.62.0...v0.63.0)

Updates `github.com/redis/go-redis/v9` from 9.22.0 to 9.23.0
- [Release notes](https://github.com/redis/go-redis/releases)
- [Changelog](https://github.com/redis/go-redis/blob/master/RELEASE-NOTES.md)
- [Commits](redis/go-redis@v9.22.0...v9.23.0)

Updates `go.opentelemetry.io/otel` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` from 0.22.0 to 0.23.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@log/v0.22.0...metric/v0.23.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/log` from 0.22.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@log/v0.22.0...v1.47.0)

Updates `go.opentelemetry.io/otel/metric` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/sdk` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/sdk/log` from 0.22.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@log/v0.22.0...v1.47.0)

Updates `go.opentelemetry.io/otel/sdk/metric` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `go.opentelemetry.io/otel/trace` from 1.46.0 to 1.47.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.46.0...v1.47.0)

Updates `golang.org/x/sys` from 0.48.0 to 0.49.0
- [Commits](golang/sys@v0.48.0...v0.49.0)

Updates `google.golang.org/genai` from 1.71.0 to 1.73.0
- [Release notes](https://github.com/googleapis/go-genai/releases)
- [Changelog](https://github.com/googleapis/go-genai/blob/main/CHANGELOG.md)
- [Commits](googleapis/go-genai@v1.71.0...v1.73.0)

Updates `modernc.org/sqlite` from 1.59.0 to 1.60.1
- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.59.0...v1.60.1)

---
updated-dependencies:
- dependency-name: github.com/anthropics/anthropic-sdk-go
  dependency-version: 1.79.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/quic-go/quic-go
  dependency-version: 0.63.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: github.com/redis/go-redis/v9
  dependency-version: 9.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/log
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/metric
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/sdk
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/sdk/log
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/sdk/metric
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: go.opentelemetry.io/otel/trace
  dependency-version: 1.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: golang.org/x/sys
  dependency-version: 0.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: google.golang.org/genai
  dependency-version: 1.73.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
- dependency-name: modernc.org/sqlite
  dependency-version: 1.60.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from eser as a code owner October 10, 2026 23:54
@dependabot dependabot Bot added dependencies Dependency updates go Go service changes labels Oct 10, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates go Go service changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants