Releases: open-telemetry/opentelemetry-java-instrumentation
Release list
Version 2.32.0
This release targets the OpenTelemetry SDK 1.66.0.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.
⚠️ Breaking changes to non-stable APIs
- Remove the deprecated
HostIdResource.REGISTRY_QUERYconstant. (#19778) - The
ExperimentalJmxMetricHandlerSPI now requires implementations to providegetMetricNames(). (#19781) - Add the required
isRequestStreaming(REQUEST)method toGenAiAttributesGetter. (#19879) - The experimental
java.common.messaging.headers/developmentYAML selector no longer configures header capture. Usejava.common.messaging.headersinstead. (#20260)
🚫 Deprecations
- Deprecate
otel.jmx.target.systemin favor ofotel.jmx.metrics.experimental.included. (#19783) - Deprecate
otel.instrumentation.elasticsearch.capture-search-query. It will be removed in 3.0, when search query bodies are always captured. There is no replacement. (#19675) - Deprecate
otel.instrumentation.opensearch.capture-search-query. It will be removed in 3.0, when search query bodies are always captured. There is no replacement. Sanitization remains enabled by default and configurable withotel.instrumentation.opensearch.query-sanitization.enabled. (#19837) - Deprecate
otel.jmx.enabledin favor ofotel.instrumentation.jmx.enabledto align with other instrumentation enablement properties. (#19945) - Deprecate automatic rewriting of
VirtualField.find(Class, Class)calls in inlined javaagent advice. Instead, look up theVirtualFieldonce and store it in a helper class'sstatic finalfield. Thefindmethod itself remains supported. (#19980) - Deprecate the Elasticsearch REST library instrumentation. Use the Elasticsearch Java API Client's native OpenTelemetry support, or the Java agent for direct
RestClientusage. Java agent instrumentation is unaffected. (#19995) - Deprecate
otel.instrumentation.messaging.experimental.receive-telemetry.enabledin favor ofotel.instrumentation.common.messaging.experimental.receive-telemetry.enabled. For headers, replaceotel.instrumentation.messaging.experimental.headers.includedand.excludedwithotel.instrumentation.common.messaging.headers.includedand.excluded. Also deprecateotel.instrumentation.messaging.experimental.capture-headersin favor ofotel.instrumentation.common.messaging.headers.included. Stable selectors take precedence per leaf. (#20060, #20260) - Deprecate the
.included/.excludedproperties underotel.instrumentation.log4j-appender.experimental.map-message-attributes,otel.instrumentation.logback-appender.experimental.key-value-pair-attributes,otel.instrumentation.logback-appender.experimental.logstash-marker-attributes, andotel.instrumentation.logback-appender.experimental.logstash-structured-argument-attributesin favor of the stable and unifiedotel.instrumentation.common.logging.structured-attributes.included/.excluded. (#20066) - Deprecate
otel.instrumentation.couchbase.experimental-span-attributesin favor ofotel.instrumentation.couchbase.emit-experimental-telemetry, a broader name for experimental attributes and internal spans from the underlying Couchbase client. (#20117) - Deprecate
otel.traces.sampler=linksbased_parentbased_always_onwith no replacement and declarativerule_based_routingin favor of the SDK incubator composite/developmentrule_basedsampler, whose configuration and matching behavior differ. (#20249) - Promote controller and view telemetry configuration to the stable properties
otel.instrumentation.common.controller-telemetry.enabledandotel.instrumentation.common.view-telemetry.enabled, deprecatingotel.instrumentation.common.experimental.controller-telemetry.enabledandotel.instrumentation.common.experimental.view-telemetry.enabled. (#20258) - Promote Java agent span suppression configuration to the stable property
otel.instrumentation.common.span-suppression-strategy, deprecatingotel.instrumentation.experimental.span-suppression-strategy. (#20259) - Deprecate
otel.instrumentation.oshi.experimental-metrics.enabled,ProcessMetrics, and itsregisterObservers(...)methods in favor ofjvm.memory.usedandjvm.cpu.time. (#20323) - Deprecate
SystemMetrics.registerObservers(Meter)in the OSHI library instrumentation in favor ofSystemMetrics.registerObservers(OpenTelemetry). (#20263) - In declarative configuration YAML, deprecate dotted selectors in the
distribution.javaagent.instrumentation.enabledand.disabledlists. Usereactor_3_1instead ofreactor_3.1. Flat-property names such asotel.instrumentation.reactor-3.1.enabledare unchanged. (#20326)
🌟 New javaagent instrumentation
- Add Redisson database connection pool metrics for versions 2.3.0 through 3.25. (#19152, #19634)
- Add Java agent instrumentation for Pekko remoting so trace context propagates across remote calls. (#19823)
📈 Enhancements
- Expand the upcoming 3.0 database semantic conventions behind
otel.semconv-stability.opt-in=database, including configured server targets and span names, endpoint validation, network-peer attributes, Redis namespaces, operation names, error types, query text, and connection pool metric names and database identity for Cassandra, ClickHouse, Couchbase, Elasticsearch, Geode, HBase, JDBC, Redis clients, MongoDB, OpenSearch, R2DBC, Spymemcached, and Vert.x. (#19728, #19747, #19749, #19753, #19757, #19795, #19830, #19831, #19832, #19834, #19838, #19839, #19844, #19845, #19846, #19848, #19850, #19864, #19868, #19872, #19877, #19883, #19901, #19902, #19903, #19904, #19981, ...
Version 2.31.1
This release targets the OpenTelemetry SDK 1.65.0.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.
🛠️ Bug fixes
- Restore stable semantic convention APIs to the compile classpaths of the Spring Boot autoconfigure and starter artifacts. (#19754)
Version 2.31.0
This release targets the OpenTelemetry SDK 1.65.0.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.
⚠️ Breaking changes to non-stable APIs
- Remove the deprecated
ConfigPropertiesBackedConfigProviderand itscreate(ConfigProperties)compatibility API from the declarative config bridge. (#19305) - Stop exposing
opentelemetry-instrumentation-api-incubatoron library instrumentation compile classpaths. (#19612)
🚫 Deprecations
- Deprecate
otel.instrumentation.experimental.span-suppression-strategyin favor ofExperimental.setSpanSuppressionStrategy(...). (#19180) - Deprecate
HostIdResource.REGISTRY_QUERYin favor of the absolute-pathreg.exelookup used byHostIdResource. (#19293) - Deprecate
MessageOperationin favor ofMessagingOperationType, and theMessageOperationoverloads ofMessagingAttributesExtractor,MessagingConsumerMetrics,MessagingProducerMetrics,MessagingSpanKindExtractor, andMessagingSpanNameExtractorin favor of the correspondingMessagingOperationTypeAPIs. (#19357) - Deprecate
otel.traces.exporter=zipkinin favor ofotel.traces.exporter=otlp, andotel.exporter.zipkin.endpointin favor ofotel.exporter.otlp.traces.endpoint. (#19400) - Deprecate
OpenTelemetryMeterRegistryBuilder#setMicrometerHistogramGaugesEnabled(boolean)in favor ofExperimental#setMicrometerHistogramGaugesEnabled(OpenTelemetryMeterRegistryBuilder, boolean). (#19404) - Deprecate legacy gRPC metadata, messaging header, and servlet request-parameter capture properties and APIs in favor of selector-based
.included/.excludedconfiguration andIncludeExcludeAPIs. (#19494, #19522, #19523, #19638) - Deprecate
otel.instrumentation.runtime-telemetry.experimental.prefer-jfrin favor ofotel.instrumentation.runtime-telemetry.experimental.jfr-metrics.included, andsetPreferJfrMetrics(...)in favor ofsetJfrMetrics(RuntimeTelemetryBuilder, IncludeExclude). (#19495) - Deprecate boolean and capture-list configuration for MDC/context data, map messages, key-value pairs, logger context, Logstash markers, and structured arguments in favor of
.included/.excludedselectors andIncludeExcludeAPIs. (#19519, #19520, #19521, #19599, #19600, #19605, #19609, #19610) - Deprecate the declarative configuration field
general.semconv_stability.opt_inin favor ofgeneral.stability_opt_in_list, andgeneral.sanitization.url.sensitive_query_parameters/developmentin favor ofgeneral.sanitization.url.sensitive_query_parameters. (#19561) - Deprecate
otel.instrumentation.graphql.add-operation-name-to-span-name.enabledin favor ofotel.instrumentation.graphql.operation-name-in-span-name.enabled, andotel.instrumentation.runtime-telemetry.package-emitter.enabled/jars-per-secondin favor ofotel.instrumentation.runtime-telemetry.experimental.package-emitter.enabled/jars-per-second. (#19573) - Deprecate captured request and response header builder methods across HTTP library instrumentations in favor of selector-based
requestHeaders(IncludeExclude)andresponseHeaders(IncludeExclude)APIs. (#19598, #19601, #19602, #19603, #19604, #19606, #19607, #19608) - Deprecate
otel.instrumentation.micrometer.histogram-gauges.enabledin favor ofotel.instrumentation.micrometer.experimental.histogram-gauges.enabled. (#19613)
🌟 New javaagent instrumentation
- Add Apache Commons Pool 2 instrumentation for object pool metrics. (#19091)
- Add Apache HBase client 1.0 javaagent instrumentation. (#19243)
- Add Redisson connection pool metrics for 3.26+. (#19392)
- Add support for OpenTelemetry API 1.65 incubator metrics in the Java agent. (#19456)
- Add Tomcat DBCP 8.0 javaagent instrumentation for database pool metrics. (#19472)
📈 Enhancements
- Add opt-in OSGi bundle metadata for selected instrumentation, API, and SDK extension artifacts so they can be consumed directly in OSGi runtimes. (#18995)
- Add
cassandra.compaction.progress.completedandcassandra.compaction.progress.sizegauges for in-flight Cassandra compactions. (#19290) - Preview the upcoming 3.0 messaging semantic conventions behind
otel.semconv-stability.opt-in=messagingacross AWS SQS and Lambda, JMS, Kafka, NATS, Pulsar, RabbitMQ, RocketMQ, Spring Integration, and Spring messaging instrumentations. (#19347, #19348, #19349, #19350, #19351, #19353, #19354, #19355, #19356, #19476, #19477, #19478, #19479, #19480, #19481, #19482, #19486, #19487, #19499, #19500, #19504, #19505, #19507, #19508, [#19535](https://github.com/open-telemetry/opentelemetry-java-instrumentati...
Version 2.30.0
This release targets the OpenTelemetry SDK 1.64.0.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.
⚠️ Breaking changes to non-stable APIs
- Remove
ExperimentalInstrumentationModule#getModuleGroup(). Built-in invokedynamic modules now share a singleInstrumentationModuleClassLoader, and each extension is isolated in its own. (#18859) - Remove the deprecated
InstrumentationModule.isIndyModule(); whether a module uses invokedynamic is now determined by the agent rather than declared per module. (#19140) - Remove deprecated query-related APIs from
SqlClientAttributesGetter,CassandraRequest, andExperimental. (#19165) - Remove the deprecated
Enduser*attribute-capturing APIs from the Spring Security 6.0 library; use theUser*replacements instead. (#19168)
🚫 Deprecations
- Deprecate only the Spring Boot starter
ConfigPropertiescompatibility bean used with experimental declarative configuration, in favor of the newConfigProviderbean; it will be removed in 3.0. TheConfigPropertiesbean remains supported for non-declarative configuration. (#19175) - Deprecate
DeclarativeConfigPropertiesBridgeandDeclarativeConfigPropertiesBridgeBuilder. UseDeclarativeConfigPropertiesdirectly orDeclarativeConfigBridgeinstead. Will be removed in 3.0. (#19202) - Deprecate
ConfigPropertiesBackedConfigProviderin favor ofDeclarativeConfigBridge. It will be removed in 2.31.0. (#19220)
🌟 New javaagent instrumentation
- Add Javaagent instrumentation for HBase client 1.4. (#19087)
🌟 New library instrumentation
- Add library instrumentation (
ThriftTelemetry) for the Apache Thrift 0.13 async server. (#19062)
📈 Enhancements
- Add async server tracing to the Apache Thrift 0.13 javaagent instrumentation; async server handlers were previously uninstrumented. (#18994)
- Support
database=as an alias fordatabaseNamewhen extractingdb.namefrom MSSQL JDBC URLs. (#19029) - Add batch-operation support to the experimental stable database semantic-convention opt-in (
otel.semconv-stability.opt-in=database) across database instrumentations, including batch span names,db.operation.batch.size(including empty batches), anddb.query.summary. (#19034, #19037, #19054, #19055, #19056, #19057, #19143, #19147, #19161, #19162, #19164, #19172, #19189, #19199) - Add tracing for Lettuce 4.0 reactive commands, including exceptional completion and cancellation. (#19071)
- Add the experimental Cassandra JMX metrics target system. (#19080)
- Add experimental JFR-based
jvm.thread.virtual.pinnedandjvm.thread.virtual.submit_failedmetrics for Java 19+ virtual threads; enable withotel.instrumentation.runtime-telemetry.emit-experimental-jfr-metrics=true. (#19092) - Capture custom object values passed to
PreparedStatement.setObject()in query parameter attributes. (#19093) InstrumentationModulenow exposesinjectedClassNames()andexposedClassNames()for indy instrumentations, so module authors no longer needExperimentalInstrumentationModulefor those helper-class declarations. (#19142)- Add
captureTemplateandcaptureArgumentsoptions to the log4j, java-util-logging, and jboss-logmanager logging instrumentations, capturing the log message template and arguments as separatelog.body.template/log.body.parametersattributes; logback already supported these options (#15423). (#19154) - Add
server.addressandserver.portattributes to Redisson client spans. (#19191) - Add
server.addressandserver.portattributes to Lettuce Redis client spans. (#19192) - Add
server.addressandserver.portattributes to Rediscala client spans. (#19193) - Set
server.addresson registry-backed Dubbo client spans to the registry address plus the service target (registry://host:port/interface:version:group) and leaveserver.portunset, gated behind the stable rpc semconv opt-in (otel.semconv-stability.opt-in=rpc); the resolved provider host and port are kept under the default semconv. (#17244, #19285)
🛠️ Bug fixes
- Fix a spurious duplicate warning when the application logger bridge is installed multiple times during startup. (#19088)
- Fix MySQL and MariaDB
db.connection_stringvalues so IPv6 hosts stay bracketed instead of becoming ambiguous. (#19078) - Fix multi-topic Pulsar consumers so the internal background receive no longer creates a spurious extra receive span. (#19095)
SpringConfigProperties.getMap()no longer evaluates map property values as SpEL expressions; non-special-cased map properties now parse as comma-delimitedkey=valuepairs via the SDK'sDefaultConfigProperties, so settings likeotel.instrumentation.common.peer-service-mappingwork without SpEL syntax. (#19113)- Fix JMS destination extraction so an unreadable destination now leaves
messaging.destination.nameunset instead of reporting it asunknown. (#19115) - Fix the JMX Metric Insight
jvm.class.loadedandjvm.class.unloadedmetrics to use counter instruments. (#19141)
🙇 Thank you
This release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:
@alokmajumder
@bhuvan-somisetty
@breedx-splk
@carlosalberto
@CodingFabian
@FrankSpitulski
@heyams
@hwxy233
@imavroukakis
@inssein
@ishg
@jaydeluca
@jkoronaAtCisco
@johnbley
@JonasKunz
@laurit
@maryliag
@maxxedev
@mmanciop
@opentelemetry-pr-dashboard
@opentelemetrybot
@pavolloffay
@philsttr
@robsunday
@ryanrupp
@steverao
@SylvainJuge
@trask
@tsawada
@xiangtianyu
@YaoYingLong
@zeitlinger
Version 2.29.0
This release targets the OpenTelemetry SDK 1.63.0.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.
⚠️ Breaking changes to non-stable APIs
- Change the return type for
JmxTelemetry.start(...)APIs. (#18782) - Experimental runtime package telemetry now emits
package.checksum_algorithm=SHA-256and 64-characterpackage.checksumvalues instead of SHA1 checksums. (#18846)
🚫 Deprecations
- Rename the common logging context keys to
otel.instrumentation.common.logging.trace-id-key,otel.instrumentation.common.logging.span-id-key, andotel.instrumentation.common.logging.trace-flags-key, while keeping the old property names deprecated. (#18851) - Rename the
kafka-brokerandkafka-connectJMX target systems toexperimental-kafka-brokerandexperimental-kafka-connect; the old names still work for now and log a warning. (#18971)
🌟 New javaagent instrumentation
- Add SOFARPC 5.4 instrumentation that emits RPC client and server spans and metrics. (#15589)
- Add Javaagent instrumentation for HBase client 2.0.0 through 2.5.0. (#18253)
📈 Enhancements
- Add opt-in support for emitting HTTP request exceptions as log signals with
otel.semconv.exception.signal.preview=logs. (#16259) - Add
opentelemetry-api-1.63Javaagent instrumentation for OpenTelemetry API 1.63 andopentelemetry-api-incubator1.63. (#18911) - Add
otel.semconv-stability.v3-previewas a fallback for the declarativev3_previewsemconv stability setting. (#18936) - Update the experimental stable database semantic-convention opt-in (
otel.semconv-stability.opt-in=database) across database instrumentations, including span names anddb.*attributes. (#18808, #18853, #18920, #18922, #18926, #18930, #18970, #18979, #18980, #18984, #18985, #18986, #18987, #18989, #18990, #18992, #18993, #19004, #19005) - Capture query text and parameterization for Cassandra batch statements. (#18964)
- Keep
opentelemetry-apiandopentelemetry-instrumentation-annotationsenabled underotel.instrumentation.common.v3-previeweven whendefault-enabled=false. (#18792) - When
otel.instrumentation.common.v3-previewis enabled, affected instrumentations emituser.*identity attributes instead ofenduser.*ones. (#18795) - Disable Kafka client metrics by default when
otel.instrumentation.common.v3-preview=true. (#18828) - Recognize Amazon Aurora DSQL and AWS wrapper JDBC URL prefixes when parsing JDBC connection metadata. (#18831)
- Set instrumentation versions on emitted Meter scopes. (#18866)
- Run
@WithSpaninstrumentation after other instrumentations so other advice can attach attributes to the active span. (#18874) - Emit database client failures as
db.client.operation.exceptionlogs whenotel.semconv.exception.signal.previewis enabled. (#18889) - Emit RPC exceptions as log records when
otel.semconv.exception.signal.preview=logsis enabled. (#18890) - Emit messaging exceptions as log records under
otel.semconv.exception.signal.preview. (#18891) - Emit
faas.invocation.exceptionlog records for FaaS exceptions whenotel.semconv.exception.signal.preview=logsis enabled. (#18892) - Emit
gen_ai.client.operation.exceptionlogs for OpenAI chat and embeddings failures whenotel.semconv.exception.signal.preview=logsis enabled. (#18893) - Emit AWS SDK request failures as
rpc.client.call.exceptionlog records whenotel.semconv.exception.signal.preview=logsis enabled. (#18894) - Declarative configuration now supports per-domain semantic-convention selection using
semconv.version,semconv.experimental, andsemconv.dual_emitsettings. (#18908) - When
otel.instrumentation.common.v3-previewis enabled, useotel.semconv-stability.previewinstead ofotel.semconv-stability.opt-into opt in to the nonstableservice.peerandrpcsemantic conventions. (#18914) - Disable Kotlin coroutines
@WithSpaninstrumentation by default whenotel.instrumentation.common.v3-preview=true. (#18919) - Use the summary-aware path in
SqlQueryAnalyzer.analyze()whenotel.instrumentation.common.v3-previewis enabled. (#18921) - When
otel.instrumentation.common.v3-previewis enabled, deprecated JDBC/db sanitization config names are ignored in favor ofdb.query_sanitization.enabled. (#18934) - Include
jvm.gc.causeon GC duration metrics whenotel.instrumentation.common.v3-previewis enabled. (#18967) - Emit duration metrics for JDBC transaction operations
COMMITandROLLBACK. (#19003) - Use a generated
InstrumentationVersionclass in OkHttp 3.0 instead of reading embedded version properties, avoiding Android StrictMode disk-read violations. (#19006) - Add thread details span attributes for declarative Spring starter configuration when
distribution.spring_starter.thread_details_enabledis set. (#19008)
🛠️ Bug fixes
- Preserve the current context for Redisson command execution futures so async operations continue the active trace. (#18701)
- Stop the Pulsar agent from creating duplicate receive spans for multi-topic consumers. (#18771)
- Fix a hang in Ktor client streaming requests so spans end promptly with Ktor 3.5.0. (#18781)
- Fix a
BedrockconverseStreamNullPointerExceptionwhen a tool call has empty arguments. ([#18783](https://github.com/open-telemetry/opentelemetry-java-instrumentation/pull/...
Version 2.28.1
This release targets the OpenTelemetry SDK 1.62.0.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.
🛠️ Bug fixes
- Fix javaagent startup failures when declarative configuration uses bundled contrib components, such as the rule-based routing sampler. (#18813)
Version 2.28.0
This release targets the OpenTelemetry SDK 1.62.0.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.
⚠️ Breaking changes to non-stable APIs
- Removed the obsolete internal
ClassInjector/ProxyInjectionBuilderAPI used by the oldExperimentalInstrumentationModule.injectClasses(ClassInjector)path; useExperimentalInstrumentationModule.exposedClassNames()instead. (#18112) - Removed previously deprecated non-stable API methods and the deprecated
opentelemetry-runtime-telemetry-java8andopentelemetry-runtime-telemetry-java17library aliases. (#18136) - Removed the previously deprecated
captureEventNamelibrary builder setting from the logback-appender-1.0 and log4j-appender-2.17OpenTelemetryAppender, and the correspondingotel.instrumentation.{logback-appender,log4j-appender,jboss-logmanager}.experimental.capture-event-namejavaagent properties. Use theotel.event.namekey in MDC / context data / key-value pairs / Logstash markers / structured arguments instead. (#18223) - Removed previously deprecated experimental config properties
otel.instrumentation.http.client.experimental.redact-query-parametersandotel.instrumentation.common.experimental.db-sqlcommenter.enabled; useotel.instrumentation.sanitization.url.experimental.sensitive-query-parametersandotel.instrumentation.common.db.experimental.sqlcommenter.enabledinstead. (#18229) - Removed the deprecated
otel.instrumentation.servlet.experimental.add-trace-id-request-attributeproperty; useotel.instrumentation.servlet.experimental.trace-id-request-attribute.enabledinstead. (#18237) - Reshaped the ktor
Experimentalhelper from a class with acompanion objectto a top-levelobject. Kotlin source callers (Experimental.emitExperimentalTelemetry(...)) are unaffected, but pre-compiled consumers must be recompiled against the new artifact. (#18343)
🚫 Deprecations
- Deprecate
otel.instrumentation.jaxws-cxf-3.0.enabledin favor ofotel.instrumentation.jaxws-2.0-cxf-3.0.enabled, andotel.instrumentation.jaxws-metro-2.2.enabledin favor ofotel.instrumentation.jaxws-2.0-metro-2.2.enabled. (#18184)
🌟 New javaagent instrumentation
- Add Apache Thrift 0.13 instrumentation for RPC client and server spans and metrics. (#18405)
🌟 New library instrumentation
- Add Apache Thrift 0.13 library instrumentation for RPC client and server spans and metrics. (#18405)
📈 Enhancements
- Couchbase 3.1 javaagent instrumentation now emits the more conventional instrumentation scope name
io.opentelemetry.couchbase-3.1instead ofio.opentelemetry.javaagent.couchbase-3.1whenotel.instrumentation.common.v3-previewis enabled. (#18426) - Wicket resource requests now use the resource reference class name in the server span name when
otel.instrumentation.common.v3-previewis enabled. (#18312, #18775) - Decide whether javaagent helper classes are injected into the application class loader or isolated based on the advice classes used by an instrumentation. (#17815)
- Improve cgroup v2 container ID detection for Podman by supporting additional
mountinfolayouts and warning when multiple candidate IDs are found. (#18272)
🛠️ Bug fixes
- Fix Pekko HTTP and Tapir server route tracking so server span names and
http.routepreserve the most specific matched route across nested directives, exceptions, and timeouts; this may change span names andhttp.routevalues for affected routes. (#16390) - Fix context loss in Finagle HTTP instrumentation across Netty-to-Finagle request conversion and
twitter-utilFuture/Promise asynchronous boundaries. (#17867) - Fix virtual-thread pinning caused by weak-map stale-entry cleanup running on virtual threads; cleanup now runs from the background thread instead. (#18113)
- Avoid linking batch consumer spans to the ambient consumer span when records or messages have no propagation headers. (#18154)
- Fix
resetOnEachOperator()for Reactor 3.1 so it also removes the scheduler hook when instrumentation is disabled. (#18258) - End spans when RxJava 1.0 subscriptions throw synchronously. (#18265)
- Fix Spring Boot service version auto-detection so
META-INF/build-info.propertiesis read from the jar root instead ofBOOT-INF/classes/. (#18292) - Clear the Netty
VirtualFieldafter finishing a response in the Netty 3.8 server instrumentation. (#18358) - Fix
JarDetailsto closeJarFilehandles while reading archives and embedded jars, preventing resource leaks during runtime telemetry collection. (#18385) - Fix a
NullPointerExceptionwhen converting an agent context without an associated application context to an application context. (#18444) - Fix Ktor server instrumentation to prevent OpenTelemetry context leaks caused by incomplete coroutine context restoration. (#18456)
- Fix Vert.x sub-router
http.routeattributes by prepending the mount point to the relative route path; this may change server span names andhttp.routevalues for mounted sub-routes. (#18462) - Fix oshi metrics startup and RSS memory reporting with
oshi7.0.0. (#18478) - Fix Play MVC and Play WS instrumentation on Play 3.x applications. (#18624)
- Record an error receive span when a wrapped Kafka consumer
poll()fails. (#18625) - Fix weak-map cleanup during agent startup by starting
WeakConcurrentMapCleanerbefore Byte Buddy installation. (#18628) - Fix indy instrumentation so it works with the security manager without recursive bootstrap failures. (#18634)
- Avoid a deadlock in weak caches when stale entries are expunged during
computeIfAbsent. (#18635) - Declarative config customizers now handle missing processor and detector lists without throwing
NullPointerExceptionduring startup. (#18641) - Fix a race that could prevent HTTP server spans from ending correctly in Netty 3.8 and 4.0 instrumentation. (#18645)
- Avoid
NumberFormatExceptionwhen a JDBC URL port is null. (#18708) - Fix Vert.x
TaskQueueandOrderedExecutorFactorytask execution so span context propagates to queued runnables. (#18709) - Limit Redisson batch query text length to avoid oversized
db.statementvalues for large batches. (#18744) - Fix SQL query sanitization so password clauses in SAP HANA administrative statements are redacted without redacting
passwordidentifiers. (#18754)
🙇 Thank you
This release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:
@anuraaga
@Ari4ka
@asvanberg
@breedx-splk
@Channyboy
@chatgpt-codex-connector
@deejay1
@dengliming
@dmarkwat
@dta...
Version 2.27.0
This release targets the OpenTelemetry SDK 1.61.0.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.
⚠️ Breaking changes to non-stable APIs
- Make
AbstractKtorServerTelemetryBuilder.isOpenTelemetryInitialized()protected (previously public). (#17509) - Replace
ExperimentalInstrumentationModule.injectClasses(ClassInjector)withexposedClassNames()for exposing helper classes to the application class loader. (#17765) - Moved
WebApplicationContextInstrumentationfrom thespring-webinstrumentation module tospring-webmvc; users who disabled it viaotel.instrumentation.spring-web.enabled=falsemust now useotel.instrumentation.spring-webmvc.enabled=false. (#17856)
🚫 Deprecations
- Deprecated
KafkaTelemetryBuilder.setMessagingReceiveInstrumentationEnabled(boolean)in favor ofsetMessagingReceiveTelemetryEnabled(boolean). (#17092) - Deprecated GraphQL builder methods
setSanitizeQuery()andsetAddOperationNameToSpanName(), and deprecated config keyotel.instrumentation.graphql.add-operation-name-to-span-name.enabledin favor ofsetQuerySanitizationEnabled(),setOperationNameInSpanNameEnabled(), andotel.instrumentation.graphql.operation-name-in-span-name.enabled. (#17093) - Deprecate
Experimental.setEnableSqlCommenter()in JDBC and R2DBC instrumentation in favor ofExperimental.setSqlCommenterEnabled(). (#17094) - Rename
otel.instrumentation.servlet.capture-request-parameterstootel.instrumentation.servlet.experimental.capture-request-parametersandotel.instrumentation.servlet.add-trace-id-request-attributetootel.instrumentation.servlet.experimental.trace-id-request-attribute.enabled; old property names are deprecated. (#17113) - Deprecated the declarative config name
statement_sanitizerin favor ofquery_sanitization, and the declarative config groupcommon.databasein favor ofcommon.db. (#17116) - Deprecated the GraphQL declarative config name
query_sanitizerin favor ofquery_sanitization. (#17455) - Deprecated the DB query sanitization system property names
otel.instrumentation.common.db-statement-sanitizer.enabled,otel.instrumentation.jdbc.statement-sanitizer.enabled,otel.instrumentation.mongo.statement-sanitizer.enabled, andotel.instrumentation.r2dbc.statement-sanitizer.enabledin favor of the corresponding*.query-sanitization.enablednames, deprecatedotel.instrumentation.common.experimental.db-sqlcommenter.enabledin favor ofotel.instrumentation.common.db.experimental.sqlcommenter.enabled, and deprecatedotel.instrumentation.graphql.query-sanitizer.enabledin favor ofotel.instrumentation.graphql.query-sanitization.enabled. (#17464) - Deprecate
InstrumentationModule.isIndyModule(); indy mode is now determined by the agent distribution configuration instead of per-module overrides. (#17713)
📈 Enhancements
- Remove
log4j.map_message.prefix from MapMessage attributes whenotel.instrumentation.common.v3-previewis enabled. (#13871) - Stop normalizing messaging header names (dash to underscore) when
otel.instrumentation.common.v3-previewis enabled, so captured header attribute keys now preserve the original header name. (#14554) - Add
db.system.nameattribute to Vertx SQL client instrumentation when stable database semantic conventions are enabled (otel.semconv-stability.opt-in=database). (#16254) - JDBC instrumentation now supports the
db.system.nameattribute with stable semantic convention values (e.g.,postgresql,oracle.db,ibm.db2,sap.hana) when stable database semantic conventions are enabled (otel.semconv-stability.opt-in=database). (#16277) - Add
otel.instrumentation.common.v3-previewflag that enables upcoming 3.0 breaking changes early. (#16459) - Optimized log event MDC attribute mapping in jboss-logmanager, log4j, and logback appenders by pre-computing attribute keys at initialization. (#16765)
- Add
messaging.kafka.bootstrap.serversattribute to Kafka producer spans whenotel.instrumentation.kafka.experimental-span-attributesis enabled. (#17065) - Disable servlet trace-id request attribute by default when
otel.instrumentation.common.v3-previewis enabled. (#17173) - Disable thread details span processor (
otel.javaagent.add-thread-details) by default whenotel.instrumentation.common.v3-previewis enabled. (#17215) - Improved javaagent startup optimization by decomposing disjunction matchers, allowing more transformations to be skipped during class loading. (#17227)
- Add stable
messaging.kafka.offsetattribute to Kafka instrumentation, gated behindotel.semconv-stability.preview=messaging. (#17785) - Preserve original casing of servlet request parameter names in attribute keys when
otel.instrumentation.common.v3-previewis enabled. (#17822) - Replace reflective mutation of Byte Buddy's
AgentBuilder.Default.transformationswith aClassFileTransformerhook, avoiding a JDK 26 JEP 500 warning about writing to a final field via reflection. (#17824) - Add javaagent bridging support for OpenTelemetry API 1.61 stable methods including
Tracer.isEnabled(), metric instrumentisEnabled(), andLogger.setBody(Body). (#17849)
🛠️ Bug fixes
- Fix
WebClientBeanPostProcessorandRestClientBeanPostProcessorto avoid replacing user-customized builder beans when the OpenTelemetry tracing filter/interceptor is already registered. (#15546) - Fix memory leak where bridged observable metric callbacks were never closed when the application-side instrument was garbage collected. (#16219)
- Fix Ktor server instrumentation leaking scope across requests due to
restoreThreadContextnot always being called by Ktor coroutine machinery. (#16487) - Add missing
schemaUrlto servlet response instrumenter. (#16560) - Fix
OpenTelemetryContextDataProvidercallingGlobalOpenTelemetry.get()during class initialization, which could interfere with SDK setup ordering. (#16638) - Fix ZIO instrumentation destroying caller thread context on fiber suspend, which caused spans created after
unsafe.runto lose their parent. (#16647) - Fix Spring Boot starter adding a duplicate OpenTelemetry logback appender when the appender is nested inside another appender. (#16697)
- Fix bridging of
VALUE-type attributes set viaAttributeKey.valueKey()on spans and log records through the javaagent API bridge. (#16750) - Fix unsafe deserialization in RMI instrumentation that could lead to remote code execution (CVE-2026-33701, #16986, also released in 2.26.1)
- Fix boot loader class injection for
httpurlconnection,methods, andrmiinstrumentations to useMethodHandles.Lookupinstead of unsafe fallback on JDK 23+. (#17050) - Fix runtime-telem...
Version 2.26.1
This is a patch release on the previous 2.26.0 release, fixing the issue(s) below.
🔒 Security fixes
- Fix unsafe deserialization in RMI instrumentation that could lead to remote code execution (CVE-2026-33701, #16979)
Version 2.26.0
This release targets the OpenTelemetry SDK 1.60.1.
Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they are still alpha quality and will continue to have breaking changes. Please see the VERSIONING.md for more details.
⚠️ Breaking changes to non-stable APIs
- Remove deprecated AWS Lambda v2.2 wrappers and
forceFlush(int, TimeUnit)overload (#16170) - Remove deprecated HTTP client/server methods (#16167)
- Remove deprecated database instrumentation methods and classes (#16164)
- Remove deprecated peer-service mapping APIs (#16165)
- Make runtime-telemetry deprecated classes now internal (#16173)
- Remove
AttributesExtractorUtil(#16152) - Remove marker interface from
SqlClientAttributesGetter(#16205) - Merge network/server getter methods into DB attribute getters (#16264, #16268)
- Rename SQL sanitizer classes to SQL analyzer (#16269)
- Rename internal common module packages to follow new naming convention (#16284, #16308, #16327, #16341, #16373)
🚫 Deprecations
- Deprecated individual runtime-telemetry module classes in favor of unified module (#16087)
- Deprecated old HTTP server query parameter methods in favor of sensitive query param handling (#16097)
- Deprecated old RPC attributes getter methods in favor of new ones supporting stable semantic conventions (#16130)
- Deprecated old ClickHouse instrumentation methods as part of simplification (#16206)
- Deprecated old R2DBC methods in favor of ones supporting
db.system.name(#16251) - Deprecated old
DbClientAttributesGettermethods; addedgetErrorType()with implementations (#16276) - Deprecated old RPC metrics methods in favor of ones supporting stable semantic conventions (#16298)
- Deprecated old
DbClientAttributesGettermethods; addedgetDbName()to better support old/stable semconv split (#16318)
📈 Enhancements
- Add server address and port attributes for Spymemcached (#15242)
- Add Kafka Connect as a built-in JMX metrics target (#15561)
- Convert Lettuce instrumentation to use
Instrumenter(#15838) - OpenSearch Java client: capture sanitized search query bodies (#15634)
- Apply stable semantic conventions to Camel JMX metrics (#16088)
- Add
jvm.file_descriptor.limitmetric (#16174) - Run gRPC client callbacks with parent context (#16175)
- SQL summary: handle
EXPLAINstatements (#16184) - Simplify InfluxDB instrumentation (#16207)
- Update histogram buckets for
db.client.operation.duration(#16222) - SQL summary: support Oracle dblink syntax (#16230)
- Add instrumentation for ZIO HTTP server route (#16232)
- Remove network attributes under database stable semconv flag (#16257)
- Support Javalin 7 (#16261)
- gRPC: initial stable semconv support (#16304)
- Populate
os.versionresource attribute (#16311) - Camel: don't emit db spans under stable semconv (#16275)
- Dubbo: stable semconv support (#16352)
- Update the OpenTelemetry SDK version to 1.60.0 (#16407)
- Use new stable
LogRecordBuilder.setException()(#16423) - Configure
semconv-stability.opt-inwith declarative config API (#16443) - Support
otel.event.name(#16220)
🛠️ Bug fixes
- SQL sanitizer now treats double-quoted fragments as string literals by default (#15582)
- Clear recorded exception when request completes (#16138)
- Clear URL connection state after ending span (#16155)
- Fix Spring declarative config with environment variable substitution (#15775)
- Fix Ktor server send pipeline error handling (#16192)
- Logging appenders:
KeyValueattributes should take priority over MDC (#16239) - Create new
PekkoRouteHolderfor each request (#16258) - Tomcat JMX: ignore negative thread and session limits (#16355)
server.portis required on HTTP client spans (#16388)- Fix Ktor server instrumentation resolving peer address (#16392)
- Fix class cast exception in servlet instrumentation (#16403)
- Fix empty response body on Jetty HttpClient 9.4.24–9.4.43 (#16406)
🙇 Thank you
This release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:
@aaaugustine29
@Arpan200502
@breedx-splk
@filipl
@fuleow
@hilmarf
@huange7
@imrahul23
@jack-berg
@jaydeluca
@jonasplaum
@laurit
@lmolkova
@lucacavenaghi97
@minwoox
@mznet
@pepeshore
@richard-salac
@robsunday
@samwright
@self-sasi
@steverao
@SylvainJuge
@trask
@zeitlinger