Skip to content

Bump io.opentelemetry.contrib:opentelemetry-aws-xray from 1.39.0 to 1.57.0 in /auth-service#281

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/auth-service/io.opentelemetry.contrib-opentelemetry-aws-xray-1.57.0
Open

Bump io.opentelemetry.contrib:opentelemetry-aws-xray from 1.39.0 to 1.57.0 in /auth-service#281
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/auth-service/io.opentelemetry.contrib-opentelemetry-aws-xray-1.57.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jun 3, 2026

Bumps io.opentelemetry.contrib:opentelemetry-aws-xray from 1.39.0 to 1.57.0.

Release notes

Sourced from io.opentelemetry.contrib:opentelemetry-aws-xray's releases.

Version 1.57.0

This release targets the OpenTelemetry Java Instrumentation 2.28.0.

Baggage processor

  • Delegate baggage filtering to IncludeExcludePredicate and allow wildcards in auto-configuration (#2802)

Dynamic control

  • Initialize pipeline configuration from declarative configuration or a fallback file (#2766)
  • Add policy pipeline initialization manager (#2826)

IBM MQ metrics

  • Add expired message metric for IBM MQ queues (#2809)

JFR events

  • Add support for JFR contextual information (#2739)

OpAMP client

  • Remove CompletableFuture usage (#2810)

Telemetry processors

  • Deprecate EventToSpanEventBridge (#2822)

Span stack traces

  • Ignore inferred spans in span stack traces by default (#2803)

🙇 Thank you

This release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:

@​atoulme @​breedx-splk @​egahlin @​jack-berg @​jackshirazi @​jaydeluca @​JonasKunz @​laurit @​LikeTheSalad @​marschall @​MikeGoldsmith @​psx95 @​sfriberg @​SylvainJuge

... (truncated)

Changelog

Sourced from io.opentelemetry.contrib:opentelemetry-aws-xray's changelog.

Version 1.57.0 (2026-05-20)

Baggage processor

  • Delegate baggage filtering to IncludeExcludePredicate and allow wildcards in auto-configuration (#2802)

Dynamic control

  • Initialize pipeline configuration from declarative configuration or a fallback file (#2766)
  • Add policy pipeline initialization manager (#2826)

IBM MQ metrics

  • Add expired message metric for IBM MQ queues (#2809)

JFR events

  • Add support for JFR contextual information (#2739)

OpAMP client

  • Remove CompletableFuture usage (#2810)

Telemetry processors

  • Deprecate EventToSpanEventBridge (#2822)

Span stack traces

  • Ignore inferred spans in span stack traces by default (#2803)

Version 1.56.0 (2026-04-28)

Dynamic control

  • Add SourceFormat string to enum conversion (#2737)
  • Add policy config model classes (record-style structure) (#2736)
  • Add config parsing for both JSON and YAML (#2738)
  • Add OpampPolicyProvider for the policy pipeline

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jun 3, 2026
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High Software Management Finding - Software License

Code library with Restrictive license

More Details

Code library com.sun.mail:jakarta.mail version 2.0.2 has GPL-2.0-with-classpath-exception license, categorized as Restrictive, its use may cause a supply chain licensing issue.

Remediation guidance

  • Review the license terms to understand its specific rules.
  • If needed, Replace this component immediately with an alternative using a permissive license (e.g., MIT, Apache 2.0).
  • Consult your legal team if the component is business-critical or the terms are unclear.

To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason

If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).


To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate

Bumps [io.opentelemetry.contrib:opentelemetry-aws-xray](https://github.com/open-telemetry/opentelemetry-java-contrib) from 1.39.0 to 1.57.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-java-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java-contrib/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java-contrib@v1.39.0...v1.57.0)

---
updated-dependencies:
- dependency-name: io.opentelemetry.contrib:opentelemetry-aws-xray
  dependency-version: 1.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump io.opentelemetry.contrib:opentelemetry-aws-xray from 1.52.0 to 1.57.0 in /auth-service Bump io.opentelemetry.contrib:opentelemetry-aws-xray from 1.39.0 to 1.57.0 in /auth-service Jun 3, 2026
@dependabot dependabot Bot force-pushed the dependabot/gradle/auth-service/io.opentelemetry.contrib-opentelemetry-aws-xray-1.57.0 branch from c546abd to e9ac19a Compare June 3, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants