chore(deps): bump @opentelemetry/instrumentation-aws-sdk from 0.59.0 to 0.77.0 - #1288
Conversation
Coverage Report for CI Build 34986970763Coverage remained the same at 82.751%Details
Uncovered ChangesNo uncovered changes found. Coverage RegressionsNo coverage regressions found. Coverage Stats💛 - Coveralls |
There was a problem hiding this comment.
LGTM. Standard automated dependency bump; the inline nit about the nested 0.75.0 shadow copy is informational and doesn't block merging.
Extended reasoning...
Overview
This is a Dependabot PR that bumps @opentelemetry/instrumentation-aws-sdk from ^0.59.0 to ^0.76.0 in package.json, with the corresponding package-lock.json regeneration. No application source code is touched.
Security risks
None. This is a transitive OpenTelemetry instrumentation package used only for AWS SDK tracing spans; it has no auth, crypto, or data-handling logic in this codebase. The lockfile diff is a mechanical, tool-generated update.
Level of scrutiny
Low. This is the class of PR (automated, mechanical dependency bump, lockfile-only) that fits the approval bar for straightforward changes. The one inline finding is a nit noting the bump doesn't actually take effect at runtime due to a nested dependency shadow from @opentelemetry/auto-instrumentations-node still requiring ^0.75.0 — it's a no-op, not a regression, so it doesn't change the risk profile of merging.
Other factors
No behavior changes, no tests needed beyond what CI already covers for dependency installs. Nothing in the PR timeline indicates unresolved discussion.
d2b8c41 to
d774942
Compare
08f9a5d to
4942317
Compare
|
@dependabot recreate |
Bumps [@opentelemetry/instrumentation-aws-sdk](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-aws-sdk) from 0.59.0 to 0.77.0. - [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/instrumentation-aws-sdk/CHANGELOG.md) - [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/instrumentation-aws-sdk-v0.77.0/packages/instrumentation-aws-sdk) --- updated-dependencies: - dependency-name: "@opentelemetry/instrumentation-aws-sdk" dependency-version: 0.76.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
4942317 to
3792762
Compare
Bumps @opentelemetry/instrumentation-aws-sdk from 0.59.0 to 0.77.0.
Release notes
Sourced from @opentelemetry/instrumentation-aws-sdk's releases.
... (truncated)
Changelog
Sourced from @opentelemetry/instrumentation-aws-sdk's changelog.
... (truncated)
Commits
932fc96chore: release main (#3638)015582afeat(deps): update deps matching '@opentelemetry/*' (#3716)b26d7f2docs: fix sdk-node README links (#3676)27e172achore: release main (#3596)466d5defeat(deps): update deps matching '@opentelemetry/*' (#3629)b7efd7bchore(*): migrate to sdk-trace (#3599)5b7dd0efeat!: only emit stable http, network and database attributes (#3585)8d7daeachore: release main (#3568)6dfb532feat(deps): update deps matching '@opentelemetry/*' (#3593)4e52a90chore: release main (#3524)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@opentelemetry/instrumentation-aws-sdksince your current version.