Skip to content

chore(build): resolve OpenTelemetry instrumentation BOM from the version catalog - #217

Open
adityamparikh wants to merge 1 commit into
apache:mainfrom
adityamparikh:chore/otel-bom-version-catalog
Open

adityamparikh wants to merge 1 commit into
apache:mainfrom
adityamparikh:chore/otel-bom-version-catalog

Conversation

@adityamparikh

Copy link
Copy Markdown
Contributor

Summary

opentelemetry-instrumentation-bom and opentelemetry-spring-boot-starter were hardcoded string literals in build.gradle.kts, invisible to catalog-driven dependency tooling. #82 bumped gradle/libs.versions.toml's opentelemetry-instrumentation-bom to 2.26.1 (a CVE fix) but that bump never took effect, because build.gradle.kts still pinned the literal 2.11.0 — the catalog entry was silently orphaned.

This wires both dependencies through the version catalog (libs.opentelemetry.instrumentation.bom, libs.opentelemetry.spring.boot.starter) so future catalog bumps actually apply.

The catalog version stays at 2.11.0 — this is a build-wiring fix only, no functional version change. 2.26.1 needs io.opentelemetry.common.ComponentLoader, which Spring Boot 3.5.x's managed OTel SDK doesn't ship yet, and breaks native AOT (documented in dev-docs/graalvm-native-image.md, "Why not just bump OTel?"). I added a comment on the catalog entry pointing at that doc so the pin doesn't look like an oversight again.

Test plan

  • ./gradlew assemble — builds clean
  • ./gradlew build -x rat (JDK 25 on PATH) — full build, all tests, spotlessApply all pass
  • Confirmed :rat failure is pre-existing/local-only (untracked .playwright-mcp/*.yml files), unrelated to this change

…ion catalog

opentelemetry-instrumentation-bom and opentelemetry-spring-boot-starter were
hardcoded string literals in build.gradle.kts, invisible to catalog-driven
dependency tooling. PR #82 bumped gradle/libs.versions.toml's
opentelemetry-instrumentation-bom to 2.26.1 (a CVE fix) but never took
effect, because build.gradle.kts still pinned the literal 2.11.0.

Wire both through libs.versions.toml so future bumps to the catalog entry
actually apply. The catalog version stays at 2.11.0: 2.26.1 needs
io.opentelemetry.common.ComponentLoader, which Spring Boot 3.5.x's managed
OTel SDK doesn't ship, and breaks native AOT (see
dev-docs/graalvm-native-image.md, "Why not just bump OTel?"). This is a
build-wiring fix only, no functional version change.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
@adityamparikh
adityamparikh force-pushed the chore/otel-bom-version-catalog branch from 61364f3 to 943b7d0 Compare September 26, 2026 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant