fix(openai-agents): bump @opentelemetry/core to ^2.8.0 to resolve W3C Baggage DoS advisory - #3377
Merged
Conversation
… Baggage DoS advisory
@arizeai/openinference-core
@arizeai/openinference-genai
@arizeai/openinference-instrumentation-anthropic
@arizeai/openinference-instrumentation-bedrock
@arizeai/openinference-instrumentation-bedrock-agent-runtime
@arizeai/openinference-instrumentation-beeai
@arizeai/openinference-instrumentation-claude-agent-sdk
@arizeai/openinference-instrumentation-langchain
@arizeai/openinference-instrumentation-langchain-v0
@arizeai/openinference-instrumentation-mcp
@arizeai/openinference-instrumentation-openai
@arizeai/openinference-instrumentation-openai-agents
@arizeai/openinference-semantic-conventions
@arizeai/openinference-tanstack-ai
@arizeai/openinference-vercel
commit: |
| "@arizeai/openinference-semantic-conventions": "workspace:*", | ||
| "@opentelemetry/api": "^1.9.0", | ||
| "@opentelemetry/core": "^1.25.1", | ||
| "@opentelemetry/core": "^2.8.0", |
Contributor
There was a problem hiding this comment.
Missing changeset file
This PR modifies js/packages/openinference-instrumentation-openai-agents/package.json but does not include a .changeset/*.md file. Per js/CLAUDE.md:
pnpm changeset # before merging PRs
Without a changeset, the automated release tooling cannot determine the version bump or generate a changelog entry for this security fix. Please run pnpm changeset locally, select openinference-instrumentation-openai-agents as a patch bump, add a brief description (e.g. "bump @opentelemetry/core to ^2.8.0 to resolve CVE-2026-54285"), and commit the generated .changeset/*.md file.
``` fix(openai-agents): bump @opentelemetry/core to ^2.8.0 to resolve W3C Baggage DoS advisory ```
mikeldking
deleted the
claude/dependabot-security-strumentation-openai-agents-package-json-f7ecc2e2--29027770327-1
branch
July 24, 2026 23:36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves the open Dependabot security alert affecting
js/packages/openinference-instrumentation-openai-agents/package.json.—
@opentelemetry/coreUnbounded memory allocation in W3C Baggagepropagation (GHSA-8988-4f7v-96qf / CVE-2026-54285). Vulnerable range
< 2.8.0, first patched2.8.0.Changes
js/packages/openinference-instrumentation-openai-agents/package.json: bumpedthe direct runtime dependency
@opentelemetry/corefrom^1.25.1to^2.8.0.js/pnpm-lock.yaml: regenerated withpnpm install --lockfile-onlyfor thetarget package.
@opentelemetry/core@2.8.0already existed in the lockfile(used by sibling packages such as
anthropicandlangchain-v0), so only thetarget importer's specifier/resolution changed — no broad churn.
This mirrors the fix already applied for
langchain-v0in commit d5a24f2, whichkeeps
@opentelemetry/coreat^2.8.0alongside@opentelemetry/api@^1.9.0andthe other
1.xOpenTelemetry packages.@opentelemetry/core@2.8.0is compatiblewith
@opentelemetry/api@1.9.0.Validation
Run from
js/:pnpm install --frozen-lockfile -r— lockfile consistent with the manifest.pnpm run -r build— all workspace packages build, including the target.pnpm --filter @arizeai/openinference-instrumentation-openai-agents run type:check— passes.pnpm --filter @arizeai/openinference-instrumentation-openai-agents run test -- --reporter=default— 53/53 tests pass. (The trailingEROFSmessage is only the GitHub Actions Vitest reporter trying to write a job summary from the sandbox; it does not affect the test result.)Follow-up
None. The single alert for this manifest is fully resolved.