This is an automated email from the ASF dual-hosted git repository.

CurtHagenlocher pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-adbc.git


The following commit(s) were added to refs/heads/main by this push:
     new dcf54f380 fix(csharp): Bump 
OpenTelemetry.Exporter.OpenTelemetryProtocol to 1.15.3 (#4291)
dcf54f380 is described below

commit dcf54f3803255a5c8b6b8dde8e1e4b513615ed9b
Author: Bryce Mecum <[email protected]>
AuthorDate: Sun May 3 21:30:15 2026 -0700

    fix(csharp): Bump OpenTelemetry.Exporter.OpenTelemetryProtocol to 1.15.3 
(#4291)
    
    Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol to 1.15.3 to fix the
    csharp build. 1.15.3 is the oldest patched version according to
    https://github.com/advisories/GHSA-4625-4j76-fww9. I see this locally
    and in CI:
    
    ```
    $dotnet build
    
/Users/bryce/src/apache/arrow-adbc/csharp/src/Telemetry/Traces/Exporters/Apache.Arrow.Adbc.Telemetry.Traces.Exporters.csproj
 : error [NU1902](https://go.microsoft.com/fwlink/?LinkId=NU1902): Warning As 
Error: Package 'OpenTelemetry.Exporter.OpenTelemetryProtocol' 1.12.0 has a 
known moderate severity vulnerability, 
https://github.com/advisories/GHSA-4625-4j76-fww9
    
    Restore failed with 1 error(s) in 2.6s
    ```
    
    The changelog for OpenTelemetry.Exporter.OpenTelemetryProtocol is here:
    
https://github.com/open-telemetry/opentelemetry-dotnet/blob/main/RELEASENOTES.md#1153.
---
 csharp/Directory.Packages.props | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/csharp/Directory.Packages.props b/csharp/Directory.Packages.props
index d54792743..277f78e5f 100644
--- a/csharp/Directory.Packages.props
+++ b/csharp/Directory.Packages.props
@@ -42,7 +42,7 @@
     <PackageVersion Include="Moq" Version="4.20.72" />
     <PackageVersion Include="OpenTelemetry" Version="1.12.0" />
     <PackageVersion Include="OpenTelemetry.Exporter.Console" Version="1.12.0" 
/>
-    <PackageVersion Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" 
Version="1.12.0" />
+    <PackageVersion Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" 
Version="1.15.3" />
     <PackageVersion Include="System.Diagnostics.DiagnosticSource" 
Version="9.0.6" />
     <PackageVersion Include="System.Net.Http" Version="4.3.4" />
     <PackageVersion Include="System.Net.Http.WinHttpHandler" Version="8.0.2" />

Reply via email to