Skip to content

Bump the npm-minor-and-patch-updates group across 1 directory with 30 updates - #279

Merged
cmenon12 merged 5 commits into
mainfrom
dependabot/npm_and_yarn/npm-minor-and-patch-updates-dca6681ee6
Sep 18, 2026
Merged

cmenon12 merged 5 commits into
mainfrom
dependabot/npm_and_yarn/npm-minor-and-patch-updates-dca6681ee6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-and-patch-updates group with 30 updates in the / directory:

Package From To
@opentelemetry/auto-instrumentations-node 0.78.0 0.80.0
@opentelemetry/instrumentation-express 0.68.0 0.70.0
@opentelemetry/instrumentation-http 0.220.0 0.222.0
@opentelemetry/sdk-metrics 2.9.0 2.11.0
@opentelemetry/sdk-node 0.220.0 0.222.0
@opentelemetry/sdk-trace-node 2.9.0 2.11.0
ace-linters 2.2.0 2.2.1
client-zip 2.5.0 2.5.1
compression 1.8.1 1.8.2
express-rate-limit 8.5.2 8.7.0
govuk-frontend 6.3.0 6.5.1
helmet 8.2.0 8.3.0
hmrc-frontend 7.23.0 7.35.0
marked 18.0.6 18.0.13
moment 2.30.1 2.31.0
mongoose 9.7.3 9.10.1
tsx 4.23.0 4.23.13
@cspell/dict-en-gb 5.0.29 5.0.34
@cspell/eslint-plugin 10.0.1 10.3.2
@playwright/test 1.61.1 1.63.0
@types/supertest 7.2.0 7.2.1
cspell 10.0.1 10.3.2
eslint 10.6.0 10.10.0
eslint-plugin-perfectionist 5.9.1 5.11.1
jest 30.4.2 30.5.1
node-mocks-http 1.17.2 1.18.1
prettier 3.9.4 3.9.6
ts-jest 29.4.11 29.4.12
typescript-eslint 8.62.1 8.70.0
undici 8.10.0 8.10.2

Updates @opentelemetry/auto-instrumentations-node from 0.78.0 to 0.80.0

Release notes

Sourced from @opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.80.0

0.80.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @opentelemetry/instrumentation-amqplib bumped from ^0.68.0 to ^0.69.0
      • @opentelemetry/instrumentation-aws-lambda bumped from ^0.73.0 to ^0.74.0
      • @opentelemetry/instrumentation-aws-sdk bumped from ^0.76.0 to ^0.77.0
      • @opentelemetry/instrumentation-bunyan bumped from ^0.66.0 to ^0.67.0
      • @opentelemetry/instrumentation-cassandra-driver bumped from ^0.66.0 to ^0.67.0
      • @opentelemetry/instrumentation-connect bumped from ^0.64.0 to ^0.65.0
      • @opentelemetry/instrumentation-cucumber bumped from ^0.37.0 to ^0.38.0
      • @opentelemetry/instrumentation-dataloader bumped from ^0.38.0 to ^0.39.0
      • @opentelemetry/instrumentation-dns bumped from ^0.64.0 to ^0.65.0
      • @opentelemetry/instrumentation-express bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-fs bumped from ^0.40.0 to ^0.41.0
      • @opentelemetry/instrumentation-generic-pool bumped from ^0.64.0 to ^0.65.0
      • @opentelemetry/instrumentation-graphql bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-hapi bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-host-metrics bumped from ^0.4.0 to ^0.5.0
      • @opentelemetry/instrumentation-ioredis bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-kafkajs bumped from ^0.30.0 to ^0.31.0
      • @opentelemetry/instrumentation-knex bumped from ^0.65.0 to ^0.66.0
      • @opentelemetry/instrumentation-koa bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-lru-memoizer bumped from ^0.65.0 to ^0.66.0
      • @opentelemetry/instrumentation-memcached bumped from ^0.64.0 to ^0.65.0
      • @opentelemetry/instrumentation-mongodb bumped from ^0.74.0 to ^0.75.0
      • @opentelemetry/instrumentation-mongoose bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-mysql bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-mysql2 bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-nestjs-core bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-net bumped from ^0.65.0 to ^0.66.0
      • @opentelemetry/instrumentation-openai bumped from ^0.19.0 to ^0.20.0
      • @opentelemetry/instrumentation-oracledb bumped from ^0.46.0 to ^0.47.0
      • @opentelemetry/instrumentation-pg bumped from ^0.73.0 to ^0.74.0
      • @opentelemetry/instrumentation-pino bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-redis bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-restify bumped from ^0.66.0 to ^0.67.0
      • @opentelemetry/instrumentation-router bumped from ^0.65.0 to ^0.66.0
      • @opentelemetry/instrumentation-runtime-node bumped from ^0.34.0 to ^0.35.0
      • @opentelemetry/instrumentation-socket.io bumped from ^0.68.0 to ^0.69.0
      • @opentelemetry/instrumentation-tedious bumped from ^0.40.0 to ^0.41.0

... (truncated)

Changelog

Sourced from @opentelemetry/auto-instrumentations-node's changelog.

0.80.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @opentelemetry/instrumentation-amqplib bumped from ^0.68.0 to ^0.69.0
      • @opentelemetry/instrumentation-aws-lambda bumped from ^0.73.0 to ^0.74.0
      • @opentelemetry/instrumentation-aws-sdk bumped from ^0.76.0 to ^0.77.0
      • @opentelemetry/instrumentation-bunyan bumped from ^0.66.0 to ^0.67.0
      • @opentelemetry/instrumentation-cassandra-driver bumped from ^0.66.0 to ^0.67.0
      • @opentelemetry/instrumentation-connect bumped from ^0.64.0 to ^0.65.0
      • @opentelemetry/instrumentation-cucumber bumped from ^0.37.0 to ^0.38.0
      • @opentelemetry/instrumentation-dataloader bumped from ^0.38.0 to ^0.39.0
      • @opentelemetry/instrumentation-dns bumped from ^0.64.0 to ^0.65.0
      • @opentelemetry/instrumentation-express bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-fs bumped from ^0.40.0 to ^0.41.0
      • @opentelemetry/instrumentation-generic-pool bumped from ^0.64.0 to ^0.65.0
      • @opentelemetry/instrumentation-graphql bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-hapi bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-host-metrics bumped from ^0.4.0 to ^0.5.0
      • @opentelemetry/instrumentation-ioredis bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-kafkajs bumped from ^0.30.0 to ^0.31.0
      • @opentelemetry/instrumentation-knex bumped from ^0.65.0 to ^0.66.0
      • @opentelemetry/instrumentation-koa bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-lru-memoizer bumped from ^0.65.0 to ^0.66.0
      • @opentelemetry/instrumentation-memcached bumped from ^0.64.0 to ^0.65.0
      • @opentelemetry/instrumentation-mongodb bumped from ^0.74.0 to ^0.75.0
      • @opentelemetry/instrumentation-mongoose bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-mysql bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-mysql2 bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-nestjs-core bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-net bumped from ^0.65.0 to ^0.66.0
      • @opentelemetry/instrumentation-openai bumped from ^0.19.0 to ^0.20.0
      • @opentelemetry/instrumentation-oracledb bumped from ^0.46.0 to ^0.47.0
      • @opentelemetry/instrumentation-pg bumped from ^0.73.0 to ^0.74.0
      • @opentelemetry/instrumentation-pino bumped from ^0.67.0 to ^0.68.0
      • @opentelemetry/instrumentation-redis bumped from ^0.69.0 to ^0.70.0
      • @opentelemetry/instrumentation-restify bumped from ^0.66.0 to ^0.67.0
      • @opentelemetry/instrumentation-router bumped from ^0.65.0 to ^0.66.0
      • @opentelemetry/instrumentation-runtime-node bumped from ^0.34.0 to ^0.35.0
      • @opentelemetry/instrumentation-socket.io bumped from ^0.68.0 to ^0.69.0
      • @opentelemetry/instrumentation-tedious bumped from ^0.40.0 to ^0.41.0
      • @opentelemetry/instrumentation-undici bumped from ^0.31.0 to ^0.32.0

... (truncated)

Commits

Updates @opentelemetry/instrumentation-express from 0.68.0 to 0.70.0

Release notes

Sourced from @opentelemetry/instrumentation-express's releases.

instrumentation-redis: v0.70.0

0.70.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • devDependencies
      • @opentelemetry/contrib-test-utils bumped from ^0.68.0 to ^0.69.0
Changelog

Sourced from @opentelemetry/instrumentation-express's changelog.

0.70.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • devDependencies
      • @opentelemetry/contrib-test-utils bumped from ^0.68.0 to ^0.69.0

0.69.0 (2026-07-23)

Features

  • deps: update deps matching '@opentelemetry/*' (#3629) (466d5de)

Dependencies

  • The following workspace dependencies were updated
    • devDependencies
      • @opentelemetry/contrib-test-utils bumped from ^0.67.0 to ^0.68.0
Commits

Updates @opentelemetry/instrumentation-http from 0.220.0 to 0.222.0

Release notes

Sourced from @opentelemetry/instrumentation-http's releases.

experimental/v0.222.0

0.222.0

💥 Breaking Changes

  • fix(sdk-node)!: fail-fast on Propagator creation from config file #6930 @trentm
  • fix(sdk-node)!: fail-fast on MeterProvider creation from config file #6954 @trentm
  • fix(sdk-node)!: fail-fast on TracerProvider creation from config file #6962 @trentm
  • fix(sdk-node)!: fail-fast on Resource creation from config file #6989 @trentm
    • This also breaks some usage of startNodeSDK() for environment-based config, i.e. when not using a config file. For example with OTEL_NODE_RESOURCE_DETECTORS=all, it results in an error message and a no-op SDK. (This does not impact users of new NodeSDK() -- the currently recommended mechanism to start an SDK using this package.)

      Could not create OpenTelemetry SDK from configuration, SDK will not be setup: unknown ExperimentalResourceDetector name in configuration: "container"

🚀 Features

  • feat(sdk-logs): deprecate SdkLogRecord in favor of ReadWriteLogRecord #6939 @pichlermarc

🐛 Bug Fixes

  • fix(instrumentation-http): redact sensitive query parameters on incoming (server) spans; add redactedQueryParamsServer config option @dyladan
  • fix(sdk-node): support headers_list when creating OTLP exporters from declarative configuration #6953 @JacksonWeber

📚 Documentation

  • docs(sdk-logs): mark logger configuration as experimental #6996 @LarryHu0217
  • docs(configuration): document the ConfigModel suffix naming convention for exported types #6612 @vedantchalke36

🏠 Internal

  • refactor(sampler-jaeger-remote): remove axios dependency and use fetch to get the sampler configuration from Jaeger API #6963 @david-luna

experimental/v0.221.0

0.221.0

💥 Breaking Changes

  • feat(sdk-logs)!: configure the force flush timeout per call #6931 @LarryHu0217
    • (user-facing): LoggerProviderOptions.forceFlushTimeoutMillis has been removed; pass timeoutMillis to LoggerProvider.forceFlush() instead.
  • feat(instrumentation-http)!: emit only stable HTTP semantic conventions. The OTEL_SEMCONV_STABILITY_OPT_IN environment variable no longer changes HTTP attribute or metric emission — old (v1.7.0) and duplicate (http/http/dup) semconv outputs have been removed. #6819 @maryliag
  • feat(instrumentation-fetch)!: emit only stable HTTP semantic conventions. The semconvStabilityOptIn instrumentation config option has been removed; old (v1.7.0) and duplicate semconv outputs are no longer emitted. #6819 @maryliag
  • feat(instrumentation-xml-http-request)!: emit only stable HTTP semantic conventions. The semconvStabilityOptIn instrumentation config option has been removed; old (v1.7.0) and duplicate semconv outputs are no longer emitted. #6819 @maryliag
  • feat(instrumentation-grpc)!: emit only stable network semantic conventions. The OTEL_SEMCONV_STABILITY_OPT_IN environment variable no longer changes attribute emission — net.peer.name and net.peer.port (old) are no longer set; only server.address and server.port (stable). #6819 @maryliag

🚀 Features

  • feat(sdk-logs): allow modifying ReadWriteLogRecord properties (including hrTime, hrTimeObserved, and spanContext) in accordance with the OpenTelemetry Logs specification #6923 @Babul422

... (truncated)

Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-metrics from 2.9.0 to 2.11.0

Release notes

Sourced from @opentelemetry/sdk-metrics's releases.

v2.11.0

2.11.0

🚀 Features

  • feat(context-async-hooks): implement attach() on AsyncLocalStorageContextManager #6845 @pichlermarc
    • On Node.js 25.9+, delegates to AsyncLocalStorage.withScope() returning a native RunScope. On older Node.js, falls back to enterWith() with a manual disposable wrapper.
  • feat(sdk-trace): allow configuring the force flush timeout per call #6929 @LarryHu0217

🐛 Bug Fixes

  • fix(sdk-metrics): ignore Infinity in exponential histograms #7015 @mwear

🏠 Internal

  • perf(sdk-metrics): reuse a single DataView for exponential histogram bit reads #6998 @mwear
  • chore(ci): run documentation tests on a weekly schedule #6920 @LarryHu0217
  • feat(ci): support pre-releases and major version bumps in the release workflow #6768 @pichlermarc
  • chore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the same value for service.instance.id

v2.10.0

2.10.0

🚀 Features

  • feat(sdk-logs): implement log processor metrics #6554 @anuraaga
  • feat(otlp-exporter): implement exporter metrics #6480 @anuraaga
  • feat(propagator-jaeger): Notice: The @opentelemetry/propagator-jaeger package will be removed in SDK 3.x, planned for approximately September 2026. @pichlermarc
    • The Jaeger propagator has been deprecated by the OpenTelemetry specification in favor of W3CTraceContextPropagator. This package will be removed in a future release.

🐛 Bug Fixes

  • fix(sdk-trace): reject SimpleSpanProcessor.forceFlush() when a pending export fails #6771 @LarryHu0217
  • fix(sdk-trace): include trace IDs at the ratio 1 upper bound in TraceIdRatioBasedSampler #6890 @LarryHu0217

🏠 Internal

Changelog

Sourced from @opentelemetry/sdk-metrics's changelog.

2.11.0

🚀 Features

  • feat(context-async-hooks): implement attach() on AsyncLocalStorageContextManager #6845 @pichlermarc
    • On Node.js 25.9+, delegates to AsyncLocalStorage.withScope() returning a native RunScope. On older Node.js, falls back to enterWith() with a manual disposable wrapper.
  • feat(sdk-trace): allow configuring the force flush timeout per call #6929 @LarryHu0217

🐛 Bug Fixes

  • fix(sdk-trace-base): avoid a Webpack self-reference error in CommonJS output #6981 @sansynx
  • fix(sdk-metrics): ignore Infinity in exponential histograms #7015 @mwear

🏠 Internal

  • perf(sdk-metrics): reuse a single DataView for exponential histogram bit reads #6998 @mwear
  • chore(ci): run documentation tests on a weekly schedule #6920 @LarryHu0217
  • feat(ci): support pre-releases and major version bumps in the release workflow #6768 @pichlermarc
  • chore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the same value for service.instance.id

2.10.0

🚀 Features

  • feat(sdk-logs): implement log processor metrics #6554 @anuraaga
  • feat(otlp-exporter): implement exporter metrics #6480 @anuraaga
  • feat(propagator-jaeger): Notice: The @opentelemetry/propagator-jaeger package will be removed in SDK 3.x, planned for approximately September 2026. @pichlermarc
    • The Jaeger propagator has been deprecated by the OpenTelemetry specification in favor of W3CTraceContextPropagator. This package will be removed in a future release.

🐛 Bug Fixes

  • fix(sdk-trace): reject SimpleSpanProcessor.forceFlush() when a pending export fails #6771 @LarryHu0217
  • fix(sdk-trace): include trace IDs at the ratio 1 upper bound in TraceIdRatioBasedSampler #6890 @LarryHu0217

🏠 Internal

Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-node from 0.220.0 to 0.222.0

Release notes

Sourced from @opentelemetry/sdk-node's releases.

experimental/v0.222.0

0.222.0

💥 Breaking Changes

  • fix(sdk-node)!: fail-fast on Propagator creation from config file #6930 @trentm
  • fix(sdk-node)!: fail-fast on MeterProvider creation from config file #6954 @trentm
  • fix(sdk-node)!: fail-fast on TracerProvider creation from config file #6962 @trentm
  • fix(sdk-node)!: fail-fast on Resource creation from config file #6989 @trentm
    • This also breaks some usage of startNodeSDK() for environment-based config, i.e. when not using a config file. For example with OTEL_NODE_RESOURCE_DETECTORS=all, it results in an error message and a no-op SDK. (This does not impact users of new NodeSDK() -- the currently recommended mechanism to start an SDK using this package.)

      Could not create OpenTelemetry SDK from configuration, SDK will not be setup: unknown ExperimentalResourceDetector name in configuration: "container"

🚀 Features

  • feat(sdk-logs): deprecate SdkLogRecord in favor of ReadWriteLogRecord #6939 @pichlermarc

🐛 Bug Fixes

  • fix(instrumentation-http): redact sensitive query parameters on incoming (server) spans; add redactedQueryParamsServer config option @dyladan
  • fix(sdk-node): support headers_list when creating OTLP exporters from declarative configuration #6953 @JacksonWeber

📚 Documentation

  • docs(sdk-logs): mark logger configuration as experimental #6996 @LarryHu0217
  • docs(configuration): document the ConfigModel suffix naming convention for exported types #6612 @vedantchalke36

🏠 Internal

  • refactor(sampler-jaeger-remote): remove axios dependency and use fetch to get the sampler configuration from Jaeger API #6963 @david-luna

experimental/v0.221.0

0.221.0

💥 Breaking Changes

  • feat(sdk-logs)!: configure the force flush timeout per call #6931 @LarryHu0217
    • (user-facing): LoggerProviderOptions.forceFlushTimeoutMillis has been removed; pass timeoutMillis to LoggerProvider.forceFlush() instead.
  • feat(instrumentation-http)!: emit only stable HTTP semantic conventions. The OTEL_SEMCONV_STABILITY_OPT_IN environment variable no longer changes HTTP attribute or metric emission — old (v1.7.0) and duplicate (http/http/dup) semconv outputs have been removed. #6819 @maryliag
  • feat(instrumentation-fetch)!: emit only stable HTTP semantic conventions. The semconvStabilityOptIn instrumentation config option has been removed; old (v1.7.0) and duplicate semconv outputs are no longer emitted. #6819 @maryliag
  • feat(instrumentation-xml-http-request)!: emit only stable HTTP semantic conventions. The semconvStabilityOptIn instrumentation config option has been removed; old (v1.7.0) and duplicate semconv outputs are no longer emitted. #6819 @maryliag
  • feat(instrumentation-grpc)!: emit only stable network semantic conventions. The OTEL_SEMCONV_STABILITY_OPT_IN environment variable no longer changes attribute emission — net.peer.name and net.peer.port (old) are no longer set; only server.address and server.port (stable). #6819 @maryliag

🚀 Features

  • feat(sdk-logs): allow modifying ReadWriteLogRecord properties (including hrTime, hrTimeObserved, and spanContext) in accordance with the OpenTelemetry Logs specification #6923 @Babul422

... (truncated)

Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-trace-node from 2.9.0 to 2.11.0

Release notes

Sourced from @opentelemetry/sdk-trace-node's releases.

v2.11.0

2.11.0

🚀 Features

  • feat(context-async-hooks): implement attach() on AsyncLocalStorageContextManager #6845 @pichlermarc
    • On Node.js 25.9+, delegates to AsyncLocalStorage.withScope() returning a native RunScope. On older Node.js, falls back to enterWith() with a manual disposable wrapper.
  • feat(sdk-trace): allow configuring the force flush timeout per call #6929 @LarryHu0217

🐛 Bug Fixes

  • fix(sdk-metrics): ignore Infinity in exponential histograms #7015 @mwear

🏠 Internal

  • perf(sdk-metrics): reuse a single DataView for exponential histogram bit reads #6998 @mwear
  • chore(ci): run documentation tests on a weekly schedule #6920 @LarryHu0217
  • feat(ci): support pre-releases and major version bumps in the release workflow #6768 @pichlermarc
  • chore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the same value for service.instance.id

v2.10.0

2.10.0

🚀 Features

  • feat(sdk-logs): implement log processor metrics #6554 @anuraaga
  • feat(otlp-exporter): implement exporter metrics #6480 @anuraaga
  • feat(propagator-jaeger): Notice: The @opentelemetry/propagator-jaeger package will be removed in SDK 3.x, planned for approximately September 2026. @pichlermarc
    • The Jaeger propagator has been deprecated by the OpenTelemetry specification in favor of W3CTraceContextPropagator. This package will be removed in a future release.

🐛 Bug Fixes

  • fix(sdk-trace): reject SimpleSpanProcessor.forceFlush() when a pending export fails #6771 @LarryHu0217
  • fix(sdk-trace): include trace IDs at the ratio 1 upper bound in TraceIdRatioBasedSampler #6890 @LarryHu0217

🏠 Internal

Changelog

Sourced from @opentelemetry/sdk-trace-node's changelog.

2.11.0

🚀 Features

  • feat(context-async-hooks): implement attach() on AsyncLocalStorageContextManager #6845 @pichlermarc
    • On Node.js 25.9+, delegates to AsyncLocalStorage.withScope() returning a native RunScope. On older Node.js, falls back to enterWith() with a manual disposable wrapper.
  • feat(sdk-trace): allow configuring the force flush timeout per call #6929 @LarryHu0217

🐛 Bug Fixes

  • fix(sdk-trace-base): avoid a Webpack self-reference error in CommonJS output #6981 @sansynx
  • fix(sdk-metrics): ignore Infinity in exponential histograms #7015 @mwear

🏠 Internal

  • perf(sdk-metrics): reuse a single DataView for exponential histogram bit reads #6998 @mwear
  • chore(ci): run documentation tests on a weekly schedule #6920 @LarryHu0217
  • feat(ci): support pre-releases and major version bumps in the release workflow #6768 @pichlermarc
  • chore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the same value for service.instance.id

2.10.0

🚀 Features

  • feat(sdk-logs): implement log processor metrics #6554 @anuraaga
  • feat(otlp-exporter): implement exporter metrics #6480 @anuraaga
  • feat(propagator-jaeger): Notice: The @opentelemetry/propagator-jaeger package will be removed in SDK 3.x, planned for approximately September 2026. @pichlermarc
    • The Jaeger propagator has been deprecated by the OpenTelemetry specification in favor of W3CTraceContextPropagator. This package will be removed in a future release.

🐛 Bug Fixes

  • fix(sdk-trace): reject SimpleSpanProcessor.forceFlush() when a pending export fails #6771 @LarryHu0217
  • fix(sdk-trace): include trace IDs at the ratio 1 upper bound in TraceIdRatioBasedSampler #6890 @LarryHu0217

🏠 Internal

Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates ace-linters from 2.2.0 to 2.2.1

Release notes

Sourced from ace-linters's releases.

v2.2.1

What's Changed

  • Feat: add XML namespace diagnostics and tests by @mkslanc in mkslanc/ace-linters#216
  • Workspace build/config updates related to moving packages to the newer Vite 8-based setup
  • Handle empty and whitespace-only XML documents
  • Fix #218

Full Changelog: mkslanc/ace-linters@v2.1.1...v2.2.1

Commits

Updates client-zip from 2.5.0 to 2.5.1

Changelog

Sourced from client-zip's changelog.

2.5.1:

  • bugfix: the error from aborting the input stream is now passed on by the output stream.
Commits
  • f16ccbe Merge branch 'no-zip64' (after backporting input stream error catching)
  • 680fbc2 1.7.1
  • e3a2c85 Backport async iterator cancellation catching to nozip64
  • a23113d Merge pull request #96 from 1vivy/codex/await-iterator-cancellation
  • 792c547 Await upstream iterator cancellation
  • 7fcc01b fix merge error in README
  • See full diff in compare view

Updates compression from 1.8.1 to 1.8.2

Release notes

Sourced from compres...

Description has been truncated

… updates

Bumps the npm-minor-and-patch-updates group with 30 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node) | `0.78.0` | `0.80.0` |
| [@opentelemetry/instrumentation-express](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/instrumentation-express) | `0.68.0` | `0.70.0` |
| [@opentelemetry/instrumentation-http](https://github.com/open-telemetry/opentelemetry-js) | `0.220.0` | `0.222.0` |
| [@opentelemetry/sdk-metrics](https://github.com/open-telemetry/opentelemetry-js) | `2.9.0` | `2.11.0` |
| [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) | `0.220.0` | `0.222.0` |
| [@opentelemetry/sdk-trace-node](https://github.com/open-telemetry/opentelemetry-js) | `2.9.0` | `2.11.0` |
| [ace-linters](https://github.com/mkslanc/ace-linters) | `2.2.0` | `2.2.1` |
| [client-zip](https://github.com/Touffy/client-zip) | `2.5.0` | `2.5.1` |
| [compression](https://github.com/expressjs/compression) | `1.8.1` | `1.8.2` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.5.2` | `8.7.0` |
| [govuk-frontend](https://github.com/alphagov/govuk-frontend/tree/HEAD/packages/govuk-frontend) | `6.3.0` | `6.5.1` |
| [helmet](https://github.com/helmetjs/helmet) | `8.2.0` | `8.3.0` |
| [hmrc-frontend](https://github.com/hmrc/hmrc-frontend) | `7.23.0` | `7.35.0` |
| [marked](https://github.com/markedjs/marked) | `18.0.6` | `18.0.13` |
| [moment](https://github.com/moment/moment) | `2.30.1` | `2.31.0` |
| [mongoose](https://github.com/Automattic/mongoose) | `9.7.3` | `9.10.1` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.0` | `4.23.13` |
| [@cspell/dict-en-gb](https://github.com/streetsidesoftware/cspell-dicts/tree/HEAD/dictionaries/en_GB) | `5.0.29` | `5.0.34` |
| [@cspell/eslint-plugin](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell-eslint-plugin) | `10.0.1` | `10.3.2` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.63.0` |
| [@types/supertest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest) | `7.2.0` | `7.2.1` |
| [cspell](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell) | `10.0.1` | `10.3.2` |
| [eslint](https://github.com/eslint/eslint) | `10.6.0` | `10.10.0` |
| [eslint-plugin-perfectionist](https://github.com/azat-io/eslint-plugin-perfectionist) | `5.9.1` | `5.11.1` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.4.2` | `30.5.1` |
| [node-mocks-http](https://github.com/eugef/node-mocks-http) | `1.17.2` | `1.18.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.4` | `3.9.6` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.11` | `29.4.12` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.62.1` | `8.70.0` |
| [undici](https://github.com/nodejs/undici) | `8.10.0` | `8.10.2` |



Updates `@opentelemetry/auto-instrumentations-node` from 0.78.0 to 0.80.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.80.0/packages/auto-instrumentations-node)

Updates `@opentelemetry/instrumentation-express` from 0.68.0 to 0.70.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/instrumentation-express/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/instrumentation-pg-v0.70.0/packages/instrumentation-express)

Updates `@opentelemetry/instrumentation-http` from 0.220.0 to 0.222.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.220.0...experimental/v0.222.0)

Updates `@opentelemetry/sdk-metrics` from 2.9.0 to 2.11.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.9.0...v2.11.0)

Updates `@opentelemetry/sdk-node` from 0.220.0 to 0.222.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.220.0...experimental/v0.222.0)

Updates `@opentelemetry/sdk-trace-node` from 2.9.0 to 2.11.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.9.0...v2.11.0)

Updates `ace-linters` from 2.2.0 to 2.2.1
- [Release notes](https://github.com/mkslanc/ace-linters/releases)
- [Commits](https://github.com/mkslanc/ace-linters/commits/v2.2.1)

Updates `client-zip` from 2.5.0 to 2.5.1
- [Release notes](https://github.com/Touffy/client-zip/releases)
- [Changelog](https://github.com/Touffy/client-zip/blob/master/CHANGES.md)
- [Commits](Touffy/client-zip@v2.5.0...v2.5.1)

Updates `compression` from 1.8.1 to 1.8.2
- [Release notes](https://github.com/expressjs/compression/releases)
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md)
- [Commits](expressjs/compression@v1.8.1...v1.8.2)

Updates `express-rate-limit` from 8.5.2 to 8.7.0
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](express-rate-limit/express-rate-limit@v8.5.2...v8.7.0)

Updates `govuk-frontend` from 6.3.0 to 6.5.1
- [Release notes](https://github.com/alphagov/govuk-frontend/releases)
- [Changelog](https://github.com/alphagov/govuk-frontend/blob/main/CHANGELOG.md)
- [Commits](https://github.com/alphagov/govuk-frontend/commits/v6.5.1/packages/govuk-frontend)

Updates `helmet` from 8.2.0 to 8.3.0
- [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md)
- [Commits](helmetjs/helmet@v8.2.0...v8.3.0)

Updates `hmrc-frontend` from 7.23.0 to 7.35.0
- [Release notes](https://github.com/hmrc/hmrc-frontend/releases)
- [Changelog](https://github.com/hmrc/hmrc-frontend/blob/main/CHANGELOG.md)
- [Commits](hmrc/hmrc-frontend@v7.23.0...v7.35.0)

Updates `marked` from 18.0.6 to 18.0.13
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.6...v18.0.13)

Updates `moment` from 2.30.1 to 2.31.0
- [Release notes](https://github.com/moment/moment/releases)
- [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md)
- [Commits](moment/moment@2.30.1...2.31.0)

Updates `mongoose` from 9.7.3 to 9.10.1
- [Release notes](https://github.com/Automattic/mongoose/releases)
- [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md)
- [Commits](Automattic/mongoose@9.7.3...9.10.1)

Updates `tsx` from 4.23.0 to 4.23.13
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.0...v4.23.13)

Updates `@cspell/dict-en-gb` from 5.0.29 to 5.0.34
- [Release notes](https://github.com/streetsidesoftware/cspell-dicts/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell-dicts/blob/main/dictionaries/en_GB/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell-dicts/commits/@cspell/dict-en-gb@5.0.34/dictionaries/en_GB)

Updates `@cspell/eslint-plugin` from 10.0.1 to 10.3.2
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell-eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.2/packages/cspell-eslint-plugin)

Updates `@playwright/test` from 1.61.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.61.1...v1.63.0)

Updates `@types/supertest` from 7.2.0 to 7.2.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/supertest)

Updates `cspell` from 10.0.1 to 10.3.2
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.2/packages/cspell)

Updates `eslint` from 10.6.0 to 10.10.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.6.0...v10.10.0)

Updates `eslint-plugin-perfectionist` from 5.9.1 to 5.11.1
- [Release notes](https://github.com/azat-io/eslint-plugin-perfectionist/releases)
- [Changelog](https://github.com/azat-io/eslint-plugin-perfectionist/blob/main/changelog.md)
- [Commits](azat-io/eslint-plugin-perfectionist@v5.9.1...v5.11.1)

Updates `jest` from 30.4.2 to 30.5.1
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.1/packages/jest)

Updates `node-mocks-http` from 1.17.2 to 1.18.1
- [Release notes](https://github.com/eugef/node-mocks-http/releases)
- [Changelog](https://github.com/eugef/node-mocks-http/blob/master/HISTORY.md)
- [Commits](eugef/node-mocks-http@v1.17.2...v1.18.1)

Updates `prettier` from 3.9.4 to 3.9.6
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.4...3.9.6)

Updates `ts-jest` from 29.4.11 to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.4.11...v29.4.12)

Updates `typescript-eslint` from 8.62.1 to 8.70.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/typescript-eslint)

Updates `undici` from 8.10.0 to 8.10.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v8.10.0...v8.10.2)

---
updated-dependencies:
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.80.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@opentelemetry/instrumentation-express"
  dependency-version: 0.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@opentelemetry/instrumentation-http"
  dependency-version: 0.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@opentelemetry/sdk-metrics"
  dependency-version: 2.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@opentelemetry/sdk-trace-node"
  dependency-version: 2.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: ace-linters
  dependency-version: 2.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: client-zip
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: compression
  dependency-version: 1.8.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: express-rate-limit
  dependency-version: 8.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: govuk-frontend
  dependency-version: 6.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: helmet
  dependency-version: 8.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: hmrc-frontend
  dependency-version: 7.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: marked
  dependency-version: 18.0.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: moment
  dependency-version: 2.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: mongoose
  dependency-version: 9.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: tsx
  dependency-version: 4.23.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@cspell/dict-en-gb"
  dependency-version: 5.0.34
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@cspell/eslint-plugin"
  dependency-version: 10.3.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: "@types/supertest"
  dependency-version: 7.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: cspell
  dependency-version: 10.3.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: eslint
  dependency-version: 10.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: eslint-plugin-perfectionist
  dependency-version: 5.11.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: jest
  dependency-version: 30.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: node-mocks-http
  dependency-version: 1.18.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: prettier
  dependency-version: 3.9.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
- dependency-name: typescript-eslint
  dependency-version: 8.70.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-and-patch-updates
- dependency-name: undici
  dependency-version: 8.10.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-and-patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from cmenon12 as a code owner September 18, 2026 18:34
@dependabot dependabot Bot added the dependencies Updates to dependencies label Sep 18, 2026
Co-authored-by: dependabot[bot] <support@github.com>
@cmenon12
cmenon12 force-pushed the dependabot/npm_and_yarn/npm-minor-and-patch-updates-dca6681ee6 branch from 5596466 to 6e99c18 Compare September 18, 2026 19:07
Since the dependency update that took mongoose to 9.10.1, every test run
fails in the global beforeAll hook with:

    MongooseServerSelectionError: Missing required sub-document 'driver'
    in the client metadata document

mongoose 9.10.0 upgraded the MongoDB Node driver to 7.6.0. That release
changed resolveRuntimeAdapters() from synchronous to async, replacing
require('os') with await import('os') so the driver would survive being
bundled into ESM output. Under Jest's module runtime that import does not
resolve as expected, and appendMetadata() swallows the rejection via
.then(undefined, squashError), falling back to empty client metadata. The
server then rejects the handshake with code 183 (ClientMetadataMissingField).

Supply the os module explicitly via the runtimeAdapters client option so
the driver never takes the dynamic import path. This passes the driver the
same module it would otherwise load itself, and affects handshake metadata
generation only.

Scoped to the test setup, as the failure does not occur outside Jest.

Note: runtimeAdapters is documented but marked experimental, and the driver
rejects unknown options outright, so this needs rechecking on every driver
upgrade. Revert once a patched driver is released.

Refs: NODE-7832, Automattic/mongoose#16499,
      typegoose/mongodb-memory-server#1026
@cmenon12
cmenon12 merged commit 4b12e63 into main Sep 18, 2026
13 checks passed
@cmenon12
cmenon12 deleted the dependabot/npm_and_yarn/npm-minor-and-patch-updates-dca6681ee6 branch September 18, 2026 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Updates to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant