From 62d2443f639e2f643f04c0073920cb2b2c416116 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Wed, 29 Jul 2026 15:43:11 +0200
Subject: [PATCH 01/54] chore(deps): update dependency aqua:grafana/oats to
v0.9.0 (#2352)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [aqua:grafana/oats](https://redirect.github.com/grafana/oats) | minor
| `0.8.0` â `0.10.0` |
---
### Release Notes
grafana/oats (aqua:grafana/oats)
###
[`v0.10.0`](https://redirect.github.com/grafana/oats/blob/HEAD/CHANGELOG.md#0100-2026-07-28)
[Compare
Source](https://redirect.github.com/grafana/oats/compare/v0.9.0...v0.10.0)
##### Features
- add opt-in HTTP input retries
([#453](https://redirect.github.com/grafana/oats/issues/453))
([82a973d](https://redirect.github.com/grafana/oats/commit/82a973d528a9dab8b8ac69091db53e41b92cf8b6))
##### Bug Fixes
- **release:** ensure gcx updates trigger releases
([#454](https://redirect.github.com/grafana/oats/issues/454))
([8e52488](https://redirect.github.com/grafana/oats/commit/8e52488956da7273f36937a8cbdfe97918e67278))
###
[`v0.9.0`](https://redirect.github.com/grafana/oats/blob/HEAD/CHANGELOG.md#090-2026-07-28)
[Compare
Source](https://redirect.github.com/grafana/oats/compare/v0.8.0...v0.9.0)
##### Features
- support one-shot Compose inputs
([#451](https://redirect.github.com/grafana/oats/issues/451))
([c43e6cb](https://redirect.github.com/grafana/oats/commit/c43e6cb6964d486c8a27df9f2d43b821f5a1ac62))
##### Bug Fixes
- **deps:** update module go.opentelemetry.io/collector/pdata to v1.63.0
([#438](https://redirect.github.com/grafana/oats/issues/438))
([6f3524a](https://redirect.github.com/grafana/oats/commit/6f3524a215886baf03e78e2493d235d1fb8ac131))
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
mise.lock | 44 ++++++++++++++++++++++----------------------
mise.toml | 2 +-
2 files changed, 23 insertions(+), 23 deletions(-)
diff --git a/mise.lock b/mise.lock
index f09cb34a5..ba618bcba 100644
--- a/mise.lock
+++ b/mise.lock
@@ -126,49 +126,49 @@ url = "https://github.com/grafana/gcx/releases/download/v1.0.0/gcx_1.0.0_windows
url_api = "https://api.github.com/repos/grafana/gcx/releases/assets/492677462"
[[tools."aqua:grafana/oats"]]
-version = "0.8.0"
+version = "0.10.0"
backend = "aqua:grafana/oats"
[tools."aqua:grafana/oats"."platforms.linux-arm64"]
-checksum = "sha256:82eaf1e836cea916b96cef6745423efd8256ceab64bbabd1fa8f13b3883a1212"
-url = "https://github.com/grafana/oats/releases/download/v0.8.0/oats_0.8.0_linux_arm64.tar.gz"
-url_api = "https://api.github.com/repos/grafana/oats/releases/assets/487171323"
+checksum = "sha256:be195aeeafce644c8a59438bbc8c472f5ca51df6f9570c6b646373a703d686b0"
+url = "https://github.com/grafana/oats/releases/download/v0.10.0/oats_0.10.0_linux_arm64.tar.gz"
+url_api = "https://api.github.com/repos/grafana/oats/releases/assets/493772122"
provenance = "github-attestations"
[tools."aqua:grafana/oats"."platforms.linux-arm64-musl"]
-checksum = "sha256:82eaf1e836cea916b96cef6745423efd8256ceab64bbabd1fa8f13b3883a1212"
-url = "https://github.com/grafana/oats/releases/download/v0.8.0/oats_0.8.0_linux_arm64.tar.gz"
-url_api = "https://api.github.com/repos/grafana/oats/releases/assets/487171323"
+checksum = "sha256:be195aeeafce644c8a59438bbc8c472f5ca51df6f9570c6b646373a703d686b0"
+url = "https://github.com/grafana/oats/releases/download/v0.10.0/oats_0.10.0_linux_arm64.tar.gz"
+url_api = "https://api.github.com/repos/grafana/oats/releases/assets/493772122"
provenance = "github-attestations"
[tools."aqua:grafana/oats"."platforms.linux-x64"]
-checksum = "sha256:ea4368c6d7f62244ce959ba60512f271d46d133b50350077257e2bb81c03a5ca"
-url = "https://github.com/grafana/oats/releases/download/v0.8.0/oats_0.8.0_linux_amd64.tar.gz"
-url_api = "https://api.github.com/repos/grafana/oats/releases/assets/487171351"
+checksum = "sha256:b72a7a587148d1eaa15ccea3ce1adfd67e040d1cd9f9e267c850154035ef9a18"
+url = "https://github.com/grafana/oats/releases/download/v0.10.0/oats_0.10.0_linux_amd64.tar.gz"
+url_api = "https://api.github.com/repos/grafana/oats/releases/assets/493772131"
provenance = "github-attestations"
[tools."aqua:grafana/oats"."platforms.linux-x64-musl"]
-checksum = "sha256:ea4368c6d7f62244ce959ba60512f271d46d133b50350077257e2bb81c03a5ca"
-url = "https://github.com/grafana/oats/releases/download/v0.8.0/oats_0.8.0_linux_amd64.tar.gz"
-url_api = "https://api.github.com/repos/grafana/oats/releases/assets/487171351"
+checksum = "sha256:b72a7a587148d1eaa15ccea3ce1adfd67e040d1cd9f9e267c850154035ef9a18"
+url = "https://github.com/grafana/oats/releases/download/v0.10.0/oats_0.10.0_linux_amd64.tar.gz"
+url_api = "https://api.github.com/repos/grafana/oats/releases/assets/493772131"
provenance = "github-attestations"
[tools."aqua:grafana/oats"."platforms.macos-arm64"]
-checksum = "sha256:156bb14787a09093de8ad0370c95e8104b771ca0b3ede382541f9837db797f27"
-url = "https://github.com/grafana/oats/releases/download/v0.8.0/oats_0.8.0_darwin_arm64.tar.gz"
-url_api = "https://api.github.com/repos/grafana/oats/releases/assets/487171322"
+checksum = "sha256:570d5c3b43c0cbe0d88c527d2fcecb9ee565e2f9d1a4d49fb4b6bbf5c3fa47e5"
+url = "https://github.com/grafana/oats/releases/download/v0.10.0/oats_0.10.0_darwin_arm64.tar.gz"
+url_api = "https://api.github.com/repos/grafana/oats/releases/assets/493772124"
provenance = "github-attestations"
[tools."aqua:grafana/oats"."platforms.macos-x64"]
-checksum = "sha256:034bc120d0d8bbf8aff05f61a6b569efec821df19bd25bb602ee77d4a6368235"
-url = "https://github.com/grafana/oats/releases/download/v0.8.0/oats_0.8.0_darwin_amd64.tar.gz"
-url_api = "https://api.github.com/repos/grafana/oats/releases/assets/487171352"
+checksum = "sha256:c3579f73928df56d1cf6d6bbb90d20424649ff08c228daa4810914017f8620d8"
+url = "https://github.com/grafana/oats/releases/download/v0.10.0/oats_0.10.0_darwin_amd64.tar.gz"
+url_api = "https://api.github.com/repos/grafana/oats/releases/assets/493772123"
provenance = "github-attestations"
[tools."aqua:grafana/oats"."platforms.windows-x64"]
-checksum = "sha256:166a5577c66efa9e4d677856ae1780212ee27c081042c8d54db0c996019adbc0"
-url = "https://github.com/grafana/oats/releases/download/v0.8.0/oats_0.8.0_windows_amd64.zip"
-url_api = "https://api.github.com/repos/grafana/oats/releases/assets/487171324"
+checksum = "sha256:b52112bf0932ea8dea1fb051bc04e29efa5ef138f67d09d775c4eb716d3d92f9"
+url = "https://github.com/grafana/oats/releases/download/v0.10.0/oats_0.10.0_windows_amd64.zip"
+url_api = "https://api.github.com/repos/grafana/oats/releases/assets/493772125"
provenance = "github-attestations"
[[tools."aqua:jonwiggins/xmloxide"]]
diff --git a/mise.toml b/mise.toml
index 569a2f3bd..eb899bbe5 100644
--- a/mise.toml
+++ b/mise.toml
@@ -1,6 +1,6 @@
[tools]
"aqua:grafana/gcx" = "v1.0.0"
-"aqua:grafana/oats" = "0.8.0"
+"aqua:grafana/oats" = "0.10.0"
hugo = "0.164.0"
java = "temurin-25.0.3+9.0.LTS"
node = "24.18.0"
From 23ae29aa71825c2a83abf249fc45cca2a46e3c8b Mon Sep 17 00:00:00 2001
From: Subhramit Basu
Date: Thu, 30 Jul 2026 05:13:15 +0530
Subject: [PATCH 02/54] docs: add API design guideline to contributing docs
(#2350)
---
AGENTS.md | 7 +++++++
CONTRIBUTING.md | 7 +++++++
2 files changed, 14 insertions(+)
diff --git a/AGENTS.md b/AGENTS.md
index 24481b8e5..9c229117a 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -125,6 +125,13 @@ commits. CI will fail if these checks fail.
- Build succeeds (tests are skipped;
run `mise run test` or `mise run test-all` for tests)
+## API Design
+
+- For internal or SDK-facing classes, prefer static factories and builders
+ over adding new public constructors.
+- Keep constructors non-public unless they are intentionally part of the
+ stable API.
+
## Testing
- JUnit 5 (Jupiter) with `@Test` annotations
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 519b98fea..ece7e11e5 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -73,6 +73,13 @@ This requires native lint tools,
which you can install with `mise run setup:native-lint-tools`.
These are optional but catch formatting and lint issues before CI.
+## API Design
+
+For internal or SDK-facing classes, prefer static factories and builders over
+adding new public constructors. Constructors are difficult to evolve
+compatibly, so keep them non-public unless they are intentionally part of the
+stable API.
+
## Running Tests
If you're getting errors when running tests:
From ee64917c53c0c8698a2b70ad48342f3bb2ca535d Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Wed, 29 Jul 2026 19:43:44 -0400
Subject: [PATCH 03/54] chore(deps): update dependency
org.mock-server:mockserver-netty-no-dependencies to v7.5.0 (#2354)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
> âšī¸ **Note**
>
> This PR body was truncated due to platform limits.
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[org.mock-server:mockserver-netty-no-dependencies](https://www.mock-server.com)
([source](https://redirect.github.com/mock-server/mockserver-monorepo))
| `7.4.0` â `7.5.0` |

|

|
---
### Release Notes
mock-server/mockserver-monorepo
(org.mock-server:mockserver-netty-no-dependencies)
###
[`v7.5.0`](https://redirect.github.com/mock-server/mockserver-monorepo/blob/HEAD/changelog.md#750---2026-07-29)
##### Security
- **BREAKING: response templates can no longer reach arbitrary Java
classes by default, closing the
template remote-code-execution path reported as
[GHSA-7pwj-xvc2-hfpc](https://redirect.github.com/mock-server/mockserver-monorepo/security/advisories/GHSA-7pwj-xvc2-hfpc).**
A caller who can reach the management API can register an expectation,
and a response template was able
to load `java.lang.Runtime` and execute OS commands in the MockServer
process. Both engines that could
do this are now sandboxed out of the box:
- `velocityDisallowClassLoading` now defaults to **`true`** (was
`false`), installing Velocity's
`SecureUberspector` so a template cannot reach classes through
`$request.class.classLoader.loadClass(...)`.
This is the more exposed half of the issue, and the half the report did
not cover: Velocity ships in
the DEFAULT distribution, whereas the JavaScript engine does not.
- JavaScript templates now resolve **no** Java classes unless an
operator grants them. Previously an
empty `javascriptAllowedClasses` *and* empty
`javascriptDisallowedClasses` meant unrestricted
`Java.type(...)` access; that combination â the out-of-the-box state â
now denies every class.
- The GraalJS guest context no longer grants access to the members of
`java.lang.Class` or
`java.lang.ClassLoader`. Denying classes at `Java.type(...)` alone was
**not** sufficient: real host
objects are bound into the context (`faker` and the other built-in
helpers), and under the previous
`HostAccess.ALL` a template could walk from one of them to a classloader
â
`faker.getClass().getClassLoader().loadClass('java.lang.Runtime')` â
reaching `Runtime` without the
class filter ever being consulted. That walk is now closed, so
host-class lookup is the single complete
gate; a regression test drives four such walks (including through
`request`) and fails if any resolves.
Velocity's `SecureUberspector` already blocked the equivalent walk
through its own bound helpers, which
is now covered by a test too.
Both flips are fully reversible with one property and remove no
functionality: set
`mockserver.velocityDisallowClassLoading=false`, or list the classes
your templates need in
`mockserver.javascriptAllowedClasses` (the single entry `*` lets any
class resolve again). Templates that
do not touch Java classes are unaffected, which is the overwhelming
majority â JavaScript templates have
the full ES2023 standard library available regardless of this setting. A
refused class is logged once at
WARN naming the class and the property to set, because GraalJS otherwise
surfaces a refusal only as the
class being undefined ("... is not a function"); the log is bounded and
de-duplicated so a hostile
template cannot flood it. `mockserver.javascriptAllowedClasses` is now
also settable through the Spring
test listener's `@MockServerTest` properties, which it was not before â
it was a nice-to-have while the
default was unrestricted, and is the only way to grant a class now that
it is not. The insecure-mode WARN
now fires when an operator has explicitly opened the
sandbox rather than when it is closed. Proven end-to-end by a Netty
integration test that registers the
reported payload through the real management API and asserts the OS
command creates no marker file, with
a negative control on a deliberately unsandboxed server that DOES create
it â so a regression cannot pass
as an inert payload. This lands DEF-2 and DEF-3 of
`docs/plans/later/security-defaults.md` ahead of the
other default flips listed there; JavaScript went further than that plan
proposed (deny everything, not a
built-in "safe types" allow-list) because deny-by-default is the only
form that stays safe as the JDK
grows new reachable classes.
##### Fixed
- **A property file that cannot be read is now reported instead of
ignored in silence
([#2358](https://redirect.github.com/mock-server/mockserver-monorepo/issues/2358)).**
When a
`mockserver.propertyFile` an operator had explicitly configured could
not be read, MockServer applied
none of its properties and said nothing about it â at any log level. The
only symptom was that every
property in the file appeared to be at its default, which surfaces far
downstream as unexplained
behaviour: in the reported case an unreadable (but present) mounted file
meant `initializationJsonPath`
was never set, so no expectations loaded, no `loading JSON
initialization file:` line appeared, and no
error was logged either. The message existed but was unreachable in
practice â gated at DEBUG *and*
emitted during static initialisation, before any log level has been
applied, so neither
`-Dmockserver.logLevel=DEBUG` nor a `-logLevel` argument could surface
it. Such a file is now logged at
WARN, naming the path and the underlying reason verbatim; because
`FileNotFoundException` covers "not
there" and "not allowed to read it" alike, that reason is usually the
whole answer (`Permission denied`
in the reported case, typically SELinux labelling or a
rootless/user-namespace UID mismatch). A property
file that is merely absent at its default location stays quiet, as does
the Docker image's built-in
`-Dmockserver.propertyFile=/config/mockserver.properties`, which the
entrypoint always passes and which
therefore expresses no intent â otherwise every container started
without a mounted config would warn.
Inside the image, only `MOCKSERVER_PROPERTY_FILE` can express that
intent, and it does.
- **The `mockserver-node` launcher suite no longer fails intermittently
on a TLS handshake reset.** The
two tests that exercise `jvmOptions` did so over HTTPS against a server
started with
`dynamicallyCreateCertificateAuthorityCertificate=true`, and issued that
HTTPS request as soon as
`start_mockserver` resolved. `start_mockserver` only proves the HTTP
control plane is answering â it
polls `PUT /mockserver/retrieve` over plain HTTP â but with a
dynamically created certificate
authority the server still has to generate a CA key pair and a leaf
certificate before it can serve
TLS on that same (port-unified) port. A handshake arriving in that
window was closed mid-negotiation
and surfaced as `ECONNRESET` "Client network socket disconnected before
secure TLS connection was
established", failing whichever of the two tests lost the race. This
accounted for every
`mockserver-node` failure on `master` over the preceding 40 builds (5 of
40, \~12%), so it was the sole
cause of the pipeline's intermittent red. Both tests now wait for an
actual TLS handshake to complete
before asserting, which gates them on the condition they really depend
on rather than retrying the
assertions. The new `waitForTlsReady` helper is verified to reject â not
resolve â both when nothing
is listening and when a listener accepts the TCP connection then
destroys it mid-handshake, which is
exactly the failure signature it exists to absorb. The readiness budget
is deliberately generous
(120s): waiting costs nothing when the server is healthy, since a ready
server completes the
handshake on the first attempt in milliseconds, so the limit only
decides how much CI contention is
tolerated before a slow start is misreported as a fault. An earlier 30s
budget went green five builds
running and then expired on a loaded agent â the same flake wearing a
clearer error message. A start
that takes over 5s is now reported even when it passes, because
readiness creeping towards the limit
is the signal that the next run will not make it.
- **`archiver.glob()` works again in `@mockserver/testcontainers`
(Node), and CVE-2026-14257 stays
closed.** The previous remedy for the `brace-expansion` denial of
service (GHSA-mh99-v99m-4gvg,
patched only in 5.0.8) was a blanket `"brace-expansion": "^5.0.8"`
override. That resolved the whole
tree to a single hoisted 5.0.8 and `npm audit` reported zero
vulnerabilities â but 5.x changed the
CommonJS export from a callable function to an object (`{ expand,
EXPANSION_MAX, ... }`), while the
minimatch copies actually installed (3.1.5, 5.1.9, 9.0.9) all call it as
`expand(pattern)`. Every
glob containing a brace therefore threw `TypeError: expand is not a
function`, crashing
`archiver.glob()`. The blast radius is narrower than it first looks â
`testcontainers` copies files
with `archiver.directory()`/`.append()`, which pass no brace pattern and
still work â so what broke
is brace globbing for anything in this module's runtime tree that does
use it. The failure was
invisible because minimatch short-circuits patterns with no `{`, so
plain globs kept working and the
unit suite stayed green. The override is now targeted: `readdir-glob`
and `archiver-utils`' `glob`
take `minimatch@^10.2.5`, which depends on `brace-expansion@^5.0.5` and
is written against the new
API, so both runtime copies land on the patched 5.0.8 with a matching
minimatch. jest keeps its own
`minimatch@3.1.5` + `brace-expansion@1.1.16` pairing and is untouched.
`npm audit --omit=dev` still
reports 0 vulnerabilities, and a new `dependency-integrity` unit test
drives a brace pattern through
both runtime minimatch copies and through a real `archiver.glob()` tar,
plus asserts expansion stays
bounded â it fails against the blanket override, so the silent half of
this cannot return.
- **A forward `responseOverride` that replaces the body no longer
inherits the upstream response's
`Content-Length`, which truncated the response on the wire.** The
override swapped the body but left the
upstream header in place, so the client read only as many bytes as the
body it replaced â a 34-byte
override behind an upstream `Content-Length: 13` arrived as 13 bytes â
or hung waiting for bytes that
never came. The stale header is now dropped so the encoder recomputes it
from what is actually written;
a `Content-Length` set by the override itself, and
`connectionOptions.contentLengthHeaderOverride`, are
still honoured, and a header-only override (one that sets no body) is
untouched. This affects every body
override, and it was the remaining reason a `FILE` response body
returned from a `responseOverride`
still reached the client wrong after
[#2450](https://redirect.github.com/mock-server/mockserver-monorepo/issues/2450):
the file was materialised
correctly and then cut short by the stale length. Covered by a Netty
integration test that drives a real
forward-with-override through a real upstream and asserts the bytes the
client receives.
- **The JetBrains plugin's LLM tool window now sends a valid expectation
([#2455](https://redirect.github.com/mock-server/mockserver-monorepo/issues/2455)).**
"Load into Server" was
rejected with `400 incorrect expectation json format` because the
builder emitted a shape that never
existed on the server: a flat `completion` string, a top-level
`finishReason`, `stream`, and `usage`,
and a `provider` of `OPEN_AI`. The completion text, streaming flag, stop
reason, and token usage
belong INSIDE the `completion` object (`text`, `streaming`,
`stopReason`, `usage.inputTokens` /
`usage.outputTokens`), and providers are the `Provider` enum names
(`OPENAI`, `AZURE_OPENAI`, âĻ). The
provider and field catalogues shared with the VS Code extension are
corrected the same way â they
offered `OPEN_AI`, `VERTEX_AI`, `messages`, `stream`, `finishReason` and
a top-level `usage`, none of
which the server accepts â and completion inside a `completion` object
now offers the nested fields.
The plugin has always bundled the correct schema; it simply never
validated its own output against it,
and the previous tests asserted the builder matched the same invented
shape it produced. Both editors
now validate against the bundled schema in their test suites.
- **`httpLlmResponse.provider` now accepts every provider MockServer
implements.** The JSON Schema enum
listed 9 of the 14 `org.mockserver.model.Provider` constants, so
`MISTRAL`, `XAI`, `DEEPSEEK`, `GROQ`,
and `OPENROUTER` were rejected with `400 incorrect expectation json
format` even though each has a
fully registered response codec. The five missing values are added to
the core schema, the generated
VS Code and JetBrains schemas, and both copies of the OpenAPI
specification, and a new parity test
fails if the enum and `Provider` ever diverge again in either direction.
The provider list on the
LLM response mocking documentation and in the Rust client's field docs
is updated to match.
- **The cloud blob-store, async-broker and transparent-proxy CI steps no
longer OOM-kill their own build
before any test runs.** Each ran its Docker container with
`--memory=4g`, but `mockserver/.mvn/jvm.config`
pins the Maven JVM to `-Xmx6144m` and the wrapper prepends it to
`MAVEN_OPTS`, so the `-am` dependency
build was permitted a 6 GB heap inside a 4 GB cgroup and the kernel
intermittently killed it with exit 137
â losing the very coverage those fail-closed steps exist to guarantee.
Raised each to `--memory=7g`, the
value every other `./mvnw` step already uses and which fits the
single-agent `c5.2xlarge`/`m5.2xlarge`
default-queue instances with margin.
##### Added
- **A cassette is now auto-registered when a fixture is loaded or
recorded via the MCP tools, so it
appears under `GET /mockserver/cassettes` without a separate `PUT
/mockserver/cassettes` call.**
Previously the server-side cassette registry was populated only by an
explicit
`PUT /mockserver/cassettes`, so a fixture loaded with the
`load_expectations_from_file` MCP tool, or
written with `record_llm_fixtures`, never showed up in the dashboard's
Cassettes tab unless the
caller also registered it by hand. Both MCP tool handlers now register
the fixture in
`CassetteRegistry` at the point the file is loaded/written â the file
path as the key, the loaded/
written expectation count, and an `origin` of `loaded` or `recorded`
respectively â so
`GET /mockserver/cassettes` (which serialises that registry) lists it
automatically. Re-loading or
re-recording the same path updates the existing entry in place rather
than duplicating it.
- **Clustered (Infinispan) expectation reload-on-startup is now proven
end-to-end.** A new test
(`ClusteredExpectationPersistenceReloadTest` in
`mockserver-state-infinispan`) forms an in-JVM
JGroups cluster consisting of a bare "fleet keeper"
`InfinispanStateBackend` that stays up for the
whole test plus a full MockServer node started with
`stateBackend=infinispan`,
`clusterEnabled=true` and `persistExpectations=true`. An expectation is
created on that node over
the wire, the persisted document is polled for through the *keeper's*
backend (proving it really
replicated across the REPL\_SYNC blob cache), the node is then stopped
completely, and a fresh node
is started against the same cluster and the same
`persistedExpectationsPath` â which must restore
the expectation and MATCH a real HTTP request with it. The local
persisted file is asserted to be
empty first, so the restore cannot be coming from the
filesystem-initializer route. The reload path
in `ExpectationFileSystemPersistence` was already covered at unit level
in `mockserver-core`
(`ExpectationBlobStoreRestoreTest`, against an `InMemoryBlobStore`, with
no server and no cluster)
and end-to-end only against S3/MinIO behind a Docker gate; what no test
proved is that a clustered
node's `InfinispanBlobStore` is the store `HttpState` wires into that
restore, nor that a real
restarted member of a live cluster recovers the fleet's shared
expectations. A second test sets
`blobStoreRestoreTimeoutSeconds=0` (the documented way to skip the
restore) and asserts the fresh
node does NOT serve the expectation, which permanently pins the fact
that no other mechanism â
JGroups state transfer of the expectations cache, a stray invalidation
event, or the local file â
restores expectations when a node starts. Verified by a positive
control: disabling the reload
path in production makes the restarted node answer with an empty body
and turns the test red.
- **The response-aware arm of the eviction false-green guard is now
proven end-to-end over HTTP.** A new
Netty integration test (`EvictedResponseVerificationIntegrationTest`)
boots a real server with
`maxLogEntries=2` and `failVerificationOnEvictedLog=true`, registers an
expectation so a `GET
/was-responded` exchange is recorded as a real `EXPECTATION_RESPONSE`
request-response pair, then floods
the bounded event log with further unmatched traffic so that pair is
evicted. A subsequent
`verify(request("/was-responded"), response().withStatusCode(418),
never())` through the Java client must
throw an `AssertionError` saying the **response** "could not be
verified" because entries were discarded
after reaching `maxLogEntries`. `MockServerEventLog` implements this
guard twice â once in `verifyRequest`
and once, through a completely separate counting path over recorded
pairs, in `verifyResponse` â and only
the request arm had an `*IntegrationTest`; the response arm was covered
solely by an engine-level test
against an in-process event log. The test uses `never()` because it is
the simplest shape that reaches
the guard: the guard sits on the PASS branch behind any asserted upper
bound (`getAtMost() != -1` â so
`atMost(n)`, `between(0,n)` and `exactly(0)` reach it too), whereas an
`atLeast(1)`/`once()` verification
of an evicted pair fails earlier with an ordinary "Response not found"
message and proves nothing.
`never()` is exactly the case a guard-less server would answer with a
silent false green. The assertion pins the message to `Response could
not be verified` so it cannot be
satisfied by the request-side arm. Verified by a positive control
(disabling only the response-side guard
in production makes the verification pass silently and turns the test
red).
- **The eviction false-green guard is now proven end-to-end over HTTP.**
A new Netty integration test
(`EvictedLogVerificationIntegrationTest`) boots a real server with
`maxLogEntries=2` and
`failVerificationOnEvictedLog=true`, records a `GET /was-called`
request, then floods the bounded
request-log ring with further traffic so the `/was-called` entry is
evicted. A subsequent
`verify(request("/was-called"), never())` through the Java client must
throw an `AssertionError` whose
message says the log "could not be verified" because entries were
discarded after reaching
`maxLogEntries` â proving the guard refuses to certify absence it can no
longer see, rather than
silently passing. Previously the guard was only covered by an
engine-level test against an in-process
`MockServerEventLog` and no `*IntegrationTest` exercised it across the
wire. Verified by a positive
control (disabling the guard in production makes `verify(never())` pass
silently and turns the test
red).
- **Custom gRPC response metadata and trailing metadata are now proven
against a real `grpc-java`
client.** Two new tests in `GrpcUnaryClientIntegrationTest` register an
expectation whose gRPC
response carries both custom response metadata authored with
`withHeader(...)` and custom trailing
metadata authored with `withTrailer(...)`, drive it with a live
`grpc-java` client, and read the
values back off the real `io.grpc.Metadata` objects the client receives
(via a capturing
`ClientInterceptor`, and via `StatusRuntimeException.getTrailers()` on
the error path). The
assertions are deliberately discriminating: the response metadata must
arrive in the *initial
headers* and not in the trailers, the trailing metadata must arrive in
the *trailers* and not be
folded into the initial headers, and both values must round-trip
byte-for-byte including a value
carrying `=`, `;`, `,` and spaces. Previously this behaviour was
exercised only structurally
(`EmbeddedChannel` / model-level assertions, which cannot tell a trailer
emitted as a trailer from
one folded into the headers) and by the existing `-bin` metadata tests,
which deliberately accept
the value from either side because a body-less unary response may
legitimately collapse to
Trailers-Only. Verified by positive controls: dropping the user-authored
trailers turns both tests
red, and dropping the user-authored response headers turns the header
assertion red.
- **The `maxResponseBodySize` limit is now proven behaviourally against
a real upstream.** A new
integration test (`MaxResponseBodySizeIntegrationTest`) boots a
forwarding MockServer configured with a
4KB `maxResponseBodySize`, points it at a raw upstream socket that
returns a 64KB body, and drives it
over a plain client socket: the oversized body fails the forward and the
client receives **502 Bad
Gateway** with none of the payload relayed, while a control request
whose body sits under the limit is
forwarded intact. A third case repeats the oversized body with
`Transfer-Encoding: chunked` and no
`Content-Length`, proving the cap is enforced against the bytes actually
accumulated by the forward
client's aggregator rather than merely against a declared header.
Previously this documented,
memory-protecting bound â read whenever a forward-client pipeline is
built â had no behavioural
coverage at all, so a regression that dropped the wiring (or passed an
unbounded value) would have
removed the limit silently; only the inbound analogue
`maxRequestBodySize` was verified. The new test
covers the HTTP/1.1 forward aggregator; the HTTP/2 forward path reads
the same property (for the
per-stream aggregator and to derive the client's `maxFrameSize`) and
remains uncovered.
`maxResponseBodySize` accordingly moves from `ENFORCEMENT_EXEMPT` to
`ENFORCEMENT_VERIFIED` in
`ConfigurationEnforcementClassificationTest`. Verified by a positive
control (restoring an unbounded
aggregator lets the oversized body through with a 200 and turns both
over-limit assertions red).
- **The Ruby client now proves live SSE stream consumption over the
wire.** New integration examples
(`spec/integration_spec.rb` â `SSE streaming`) register an
`httpSseResponse` expectation via the Ruby
client against a running MockServer, then open a real streaming HTTP
consumer and assert every `data:`
frame arrives in order, that the reconstructed multi-delta message
matches, and that a multi-line
`data:` payload survives the framing intact (`Content-Type:
text/event-stream`). Previously the Ruby
suite only asserted the JSON keys of a built streaming expectation
(`a2a_spec`) and never consumed a
live SSE stream, so a silent server-emission or client-parsing drop
would have gone uncaught. Verified
by a positive control (dropping events from the emitted stream turns the
received-frames assertion red).
- **The `assumeAllRequestsAreHttp` protocol-detection fallback now has
direct unit coverage.** Two
paired `EmbeddedChannel` tests in `DirectProxyUnificationHandlerTest`
drive
`PortUnificationHandler.decode()` with an HTTP request using a
non-standard method (`PURGE`, which is
not one of GET/POST/PUT/HEAD/OPTIONS/PATCH/DELETE/TRACE/CONNECT): with
`assumeAllRequestsAreHttp=true` the full HTTP pipeline is added (rather
than falling to binary request
proxying), and with the flag disabled the HTTP codec is not added â
proving the flag is the only
difference. Previously the fallback branch was exercised only by a
live-socket integration test and
the config getter's own unit test, so the `EmbeddedChannel`
protocol-detection path for the flag was
unexercised.
- **HTTP/3 streaming response bodies are now proven end-to-end through
the action pipeline with a real
QUIC client.** A new integration test
(`Http3StreamingForwardIntegrationTest`) registers a `forward`
expectation on the HTTP/3 port (with `streamingResponsesEnabled`)
pointing at an upstream Server-Sent
Events stream that serves an early event immediately and withholds the
late event for 1.5s, then drives
it with a live Netty QUIC client and asserts both events arrive as
SEPARATE DATA frames spread across
that delay â proving the streaming relay funnels through
`HttpActionHandler` ->
`ResponseWriter.writeResponse` ->
`Http3ResponseWriter.writeStreamingResponse` and emits chunks
incrementally. Previously `Http3StreamingIntegrationTest` drove
`Http3ResponseWriter` directly from a
hand-built QUIC server (bypassing expectation matching), and
`Http3MockingMatrixIntegrationTest`
exercised the real pipeline over QUIC but only with non-streaming
actions, so incremental delivery of a
streamed body through the full pipeline was untested. QUIC-gated like
the sibling HTTP/3 tests so it
skips cleanly where the native transport is unavailable.
- **The dashboard's Monaco code editor is now proven in a real browser
end-to-end.** A new Playwright
e2e test (`mockserver-ui/e2e/dashboard.spec.ts`) drives the actual
bundled Monaco editor in the
served dashboard's composer against a live MockServer: it asserts
Monaco's own DOM
(`.monaco-editor` / `.view-lines`) renders, authors a JSON response body
via real editor input,
raises and clears a live validation marker from Monaco's JSON language
web worker, then registers
the mock and confirms the Monaco-authored body round-trips to the server
(present in
`PUT /mockserver/retrieve` and served verbatim on the matching request).
Previously the 178
jsdom/vitest specs globally replaced Monaco with a bare `
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
prometheus-metrics-exporter-pushgateway/pom.xml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/prometheus-metrics-exporter-pushgateway/pom.xml b/prometheus-metrics-exporter-pushgateway/pom.xml
index b83119bbb..b51d7c622 100644
--- a/prometheus-metrics-exporter-pushgateway/pom.xml
+++ b/prometheus-metrics-exporter-pushgateway/pom.xml
@@ -35,7 +35,7 @@
org.mock-server
mockserver-netty-no-dependencies
- 7.4.0
+ 7.5.0
test
From ed46db842f136bac47e29bd23fbc335e81eadd53 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Wed, 29 Jul 2026 20:39:34 -0400
Subject: [PATCH 04/54] chore(deps): update node.js to v24.18.1 (#2353)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [node](https://nodejs.org)
([source](https://redirect.github.com/nodejs/node)) | patch | `24.18.0`
â `24.18.1` |
---
### Release Notes
nodejs/node (node)
###
[`v24.18.1`](https://redirect.github.com/nodejs/node/releases/tag/v24.18.1):
2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol
[Compare
Source](https://redirect.github.com/nodejs/node/compare/v24.18.0...v24.18.1)
This is a security release.
##### Notable Changes
- (CVE-2026-56846) http2: retain header memory in session accounting
(Matteo Collina) â High
- (CVE-2026-56848) http2: defer rst stream while in scope (Matteo
Collina) â High
- (CVE-2026-58043) permission: avoid granting radix split nodes
(RafaelGSS) â High
- (CVE-2026-56850) https: distinguish PFX object-array agent keys
(RafaelGSS) â Medium
- (CVE-2026-58040) https: bind identity checks to session reuse (Matteo
Collina) â Medium
- (CVE-2026-58041) sqlite: invalidate tag store iterators on statement
reset (Matteo Collina) â Medium
- (CVE-2026-58042) dns: handle large resolveAny address replies
(RafaelGSS) â Medium
- (CVE-2026-58045) zlib: throw on out-of-bounds write buffers
(RafaelGSS) â Medium
- (CVE-2026-56847) permission: enforce fs write permission for trace
events (RafaelGSS) â Low
- (CVE-2026-58039) permission: check final report output path
(RafaelGSS) â Low
- (CVE-2026-58044) http: reject requests exceeding max header count
(Matteo Collina) â Low
- deps: update llhttp to 9.4.3 (Paolo Insogna)
- deps: update undici to 7.29.0 (Node.js GitHub Bot)
##### Commits
-
\[[`6cb0475751`](https://redirect.github.com/nodejs/node/commit/6cb0475751)]
- **deps**: update llhttp to 9.4.3 (Paolo Insogna)
[nodejs-private/node-private#935](https://redirect.github.com/nodejs-private/node-private/pull/935)
-
\[[`bcfe21d3dc`](https://redirect.github.com/nodejs/node/commit/bcfe21d3dc)]
- **deps**: update undici to 7.29.0 (Node.js GitHub Bot)
[#64713](https://redirect.github.com/nodejs/node/pull/64713)
-
\[[`9d0d36cffd`](https://redirect.github.com/nodejs/node/commit/9d0d36cffd)]
- **(CVE-2026-58042)** **dns**: handle large resolveAny address replies
(RafaelGSS)
[nodejs-private/node-private#929](https://redirect.github.com/nodejs-private/node-private/pull/929)
-
\[[`8a008fb523`](https://redirect.github.com/nodejs/node/commit/8a008fb523)]
- **(CVE-2026-58044)** **http**: reject requests exceeding max header
count (Matteo Collina)
[nodejs-private/node-private#922](https://redirect.github.com/nodejs-private/node-private/pull/922)
-
\[[`a77c7f7354`](https://redirect.github.com/nodejs/node/commit/a77c7f7354)]
- **(CVE-2026-56848)** **http2**: defer rst stream while in scope
(Matteo Collina)
[nodejs-private/node-private#921](https://redirect.github.com/nodejs-private/node-private/pull/921)
-
\[[`34ed88a069`](https://redirect.github.com/nodejs/node/commit/34ed88a069)]
- **(CVE-2026-56846)** **http2**: retain header memory in session
accounting (Matteo Collina)
[#63752](https://redirect.github.com/nodejs/node/pull/63752)
-
\[[`95ba2cfde7`](https://redirect.github.com/nodejs/node/commit/95ba2cfde7)]
- **(CVE-2026-58040)** **https**: bind identity checks to session reuse
(Matteo Collina)
[nodejs-private/node-private#904](https://redirect.github.com/nodejs-private/node-private/pull/904)
-
\[[`fcbdbe47ea`](https://redirect.github.com/nodejs/node/commit/fcbdbe47ea)]
- **(CVE-2026-56850)** **https**: distinguish PFX object-array agent
keys (RafaelGSS)
[nodejs-private/node-private#930](https://redirect.github.com/nodejs-private/node-private/pull/930)
-
\[[`ea26c12b56`](https://redirect.github.com/nodejs/node/commit/ea26c12b56)]
- **(CVE-2026-58043)** **permission**: avoid granting radix split nodes
(RafaelGSS)
[nodejs-private/node-private#911](https://redirect.github.com/nodejs-private/node-private/pull/911)
-
\[[`9a6b7e343a`](https://redirect.github.com/nodejs/node/commit/9a6b7e343a)]
- **(CVE-2026-58039)** **permission**: check final report output path
(RafaelGSS)
[nodejs-private/node-private#926](https://redirect.github.com/nodejs-private/node-private/pull/926)
-
\[[`6c0c990880`](https://redirect.github.com/nodejs/node/commit/6c0c990880)]
- **(CVE-2026-56847)** **permission**: enforce fs write permission for
trace events (RafaelGSS)
[nodejs-private/node-private#927](https://redirect.github.com/nodejs-private/node-private/pull/927)
-
\[[`af9ff0490c`](https://redirect.github.com/nodejs/node/commit/af9ff0490c)]
- **(CVE-2026-58041)** **sqlite**: invalidate tag store iterators on
statement reset (Matteo Collina)
[nodejs-private/node-private#896](https://redirect.github.com/nodejs-private/node-private/pull/896)
-
\[[`05f541b5c0`](https://redirect.github.com/nodejs/node/commit/05f541b5c0)]
- **(CVE-2026-58045)** **zlib**: throw on out-of-bounds write buffers
(RafaelGSS)
[nodejs-private/node-private#931](https://redirect.github.com/nodejs-private/node-private/pull/931)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
mise.lock | 28 +++++++++++++---------------
mise.toml | 2 +-
2 files changed, 14 insertions(+), 16 deletions(-)
diff --git a/mise.lock b/mise.lock
index ba618bcba..0dff26c57 100644
--- a/mise.lock
+++ b/mise.lock
@@ -480,36 +480,34 @@ url = "https://github.com/lycheeverse/lychee/releases/download/lychee-v0.24.2/ly
url_api = "https://api.github.com/repos/lycheeverse/lychee/releases/assets/409959491"
[[tools.node]]
-version = "24.18.0"
+version = "24.18.1"
backend = "core:node"
[tools.node."platforms.linux-arm64"]
-checksum = "sha256:6b4484c2190274175df9aa8f28e2d758a819cb1c1fe6ab481e2f95b463ab8508"
-url = "https://nodejs.org/dist/v24.18.0/node-v24.18.0-linux-arm64.tar.gz"
+checksum = "sha256:df224555a083b918e46260cc969838501b9f9a87140c1195e5b9597b56d5dae2"
+url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-linux-arm64.tar.gz"
[tools.node."platforms.linux-arm64-musl"]
-checksum = "sha256:b1c6c2dc31b46dd8fb2322f4fe75b07e775c5120bc37251deeea28f529d4567b"
-url = "https://unofficial-builds.nodejs.org/download/release/v24.18.0/node-v24.18.0-linux-arm64-musl.tar.gz"
+url = "https://unofficial-builds.nodejs.org/download/release/v24.18.1/node-v24.18.1-linux-arm64-musl.tar.gz"
[tools.node."platforms.linux-x64"]
-checksum = "sha256:783130984963db7ba9cbd01089eaf2c2efb055c7c1693c943174b967b3050cb8"
-url = "https://nodejs.org/dist/v24.18.0/node-v24.18.0-linux-x64.tar.gz"
+checksum = "sha256:9f5eb6ac21845a66c493c91a253b1da32fd684e89e9b7202d4936982336be4ca"
+url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-linux-x64.tar.gz"
[tools.node."platforms.linux-x64-musl"]
-checksum = "sha256:ea58409911e141ec6b19d9178efa2d9185a13295005b1cbf5521b3157eed1d95"
-url = "https://unofficial-builds.nodejs.org/download/release/v24.18.0/node-v24.18.0-linux-x64-musl.tar.gz"
+url = "https://unofficial-builds.nodejs.org/download/release/v24.18.1/node-v24.18.1-linux-x64-musl.tar.gz"
[tools.node."platforms.macos-arm64"]
-checksum = "sha256:e1a97e14c99c803e96c7339403282ea05a499c32f8d83defe9ef5ec66f979ed1"
-url = "https://nodejs.org/dist/v24.18.0/node-v24.18.0-darwin-arm64.tar.gz"
+checksum = "sha256:eb02f7fab96d3d67de40c5ec8566096fcb4c2026728787683ae5a97eb612b941"
+url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-darwin-arm64.tar.gz"
[tools.node."platforms.macos-x64"]
-checksum = "sha256:dfd0dbd3e721503434df7b7205e719f61b3a3a31b2bcf9729b8b91fea240f080"
-url = "https://nodejs.org/dist/v24.18.0/node-v24.18.0-darwin-x64.tar.gz"
+checksum = "sha256:6fb20fceacbb157c2f95825b80df4a454a0f6d81cdcd7bb81eeae9147e0e76ec"
+url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-darwin-x64.tar.gz"
[tools.node."platforms.windows-x64"]
-checksum = "sha256:0ae68406b42d7725661da979b1403ec9926da205c6770827f33aac9d8f26e821"
-url = "https://nodejs.org/dist/v24.18.0/node-v24.18.0-win-x64.zip"
+checksum = "sha256:ec56b84a7551893ab2324ebdfdc4ab974a63b4781162600b68a1293cc3e53765"
+url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-win-x64.zip"
[[tools."npm:renovate"]]
version = "43.279.1"
diff --git a/mise.toml b/mise.toml
index eb899bbe5..1ab071d68 100644
--- a/mise.toml
+++ b/mise.toml
@@ -3,7 +3,7 @@
"aqua:grafana/oats" = "0.10.0"
hugo = "0.164.0"
java = "temurin-25.0.3+9.0.LTS"
-node = "24.18.0"
+node = "24.18.1"
protoc = "35.1"
# Linters
From e5198bd5f89425c63a6c627d24d5ab349b933eeb Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Thu, 30 Jul 2026 07:16:55 -0400
Subject: [PATCH 05/54] chore(deps): update github/codeql-action action to
v4.37.4 (#2355)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[github/codeql-action](https://redirect.github.com/github/codeql-action)
| action | patch | `v4.37.3` â `v4.37.4` |
---
### Release Notes
github/codeql-action (github/codeql-action)
###
[`v4.37.4`](https://redirect.github.com/github/codeql-action/compare/v4.37.3...v4.37.4)
[Compare
Source](https://redirect.github.com/github/codeql-action/compare/v4.37.3...v4.37.4)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/workflows/codeql.yml | 4 ++--
.github/workflows/scorecard.yml | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index 4d0950bed..db005e80c 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -37,7 +37,7 @@ jobs:
path: ~/.m2/repository
key: ${{ runner.os }}-maven-codeql-${{ hashFiles('**/pom.xml') }}
- name: Initialize CodeQL
- uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
+ uses: github/codeql-action/init@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
with:
languages: java
tools: linked
@@ -56,6 +56,6 @@ jobs:
-Djavadoc.skip=true
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
+ uses: github/codeql-action/analyze@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
with:
category: /language:java
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index a2512f957..dd43bbaf5 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -41,6 +41,6 @@ jobs:
retention-days: 5
- name: Upload to code scanning
- uses: github/codeql-action/upload-sarif@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
+ uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
with:
sarif_file: results.sarif
From 34045542970750463b2956e426388fdaca0d3b07 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Thu, 30 Jul 2026 07:17:11 -0400
Subject: [PATCH 06/54] chore(deps): update dependency
org.apache.felix:maven-bundle-plugin to v6.1.0 (#2356)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[org.apache.felix:maven-bundle-plugin](http://felix.apache.org/components/bundle-plugin/)
([source](https://gitbox.apache.org/repos/asf?p=felix-dev.git)) |
`6.0.2` â `6.1.0` |

|

|
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
pom.xml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/pom.xml b/pom.xml
index d03c6cd6c..32e30634c 100644
--- a/pom.xml
+++ b/pom.xml
@@ -281,7 +281,7 @@
org.apache.felix
maven-bundle-plugin
- 6.0.2
+ 6.1.0
true
From 2d315426771022eb7d81e442767adb6183d98579 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Fri, 31 Jul 2026 08:42:48 -0400
Subject: [PATCH 07/54] chore(deps): update prom/prometheus docker tag to
v3.13.2 (#2357)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [prom/prometheus](https://redirect.github.com/prometheus/prometheus) |
patch | `v3.13.1` â `v3.13.2` |
---
### Release Notes
prometheus/prometheus (prom/prometheus)
###
[`v3.13.2`](https://redirect.github.com/prometheus/prometheus/compare/v3.13.1...v3.13.2)
[Compare
Source](https://redirect.github.com/prometheus/prometheus/compare/v3.13.1...v3.13.2)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
examples/example-custom-buckets/docker-compose.yaml | 2 +-
examples/example-exemplars-tail-sampling/docker-compose.yaml | 2 +-
examples/example-exporter-opentelemetry/docker-compose.yaml | 2 +-
examples/example-native-histogram/docker-compose.yaml | 2 +-
4 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/examples/example-custom-buckets/docker-compose.yaml b/examples/example-custom-buckets/docker-compose.yaml
index 509ef6f3d..4f7bdd5e6 100644
--- a/examples/example-custom-buckets/docker-compose.yaml
+++ b/examples/example-custom-buckets/docker-compose.yaml
@@ -10,7 +10,7 @@ services:
- -jar
- /example-custom-buckets.jar
prometheus:
- image: prom/prometheus:v3.13.1@sha256:3c42b892cf723fa54d2f262c37a0e1f80aa8c8ddb1da7b9b0df9455a35a7f893
+ image: prom/prometheus:v3.13.2@sha256:508729e0e2d18e11fd742a5a5ca70e557b940a93948c3c95fd0123a6fd538b69
network_mode: host
volumes:
- ./docker-compose/prometheus.yml:/prometheus.yml
diff --git a/examples/example-exemplars-tail-sampling/docker-compose.yaml b/examples/example-exemplars-tail-sampling/docker-compose.yaml
index f03204807..780431624 100644
--- a/examples/example-exemplars-tail-sampling/docker-compose.yaml
+++ b/examples/example-exemplars-tail-sampling/docker-compose.yaml
@@ -43,7 +43,7 @@ services:
command:
- --config=file:/config.yaml
prometheus:
- image: prom/prometheus:v3.13.1@sha256:3c42b892cf723fa54d2f262c37a0e1f80aa8c8ddb1da7b9b0df9455a35a7f893
+ image: prom/prometheus:v3.13.2@sha256:508729e0e2d18e11fd742a5a5ca70e557b940a93948c3c95fd0123a6fd538b69
network_mode: host
volumes:
- ./config/prometheus.yaml:/prometheus.yaml
diff --git a/examples/example-exporter-opentelemetry/docker-compose.yaml b/examples/example-exporter-opentelemetry/docker-compose.yaml
index 4e526c3fb..7ab385bb3 100644
--- a/examples/example-exporter-opentelemetry/docker-compose.yaml
+++ b/examples/example-exporter-opentelemetry/docker-compose.yaml
@@ -20,7 +20,7 @@ services:
command:
- --config=file:/config.yaml
prometheus:
- image: prom/prometheus:v3.13.1@sha256:3c42b892cf723fa54d2f262c37a0e1f80aa8c8ddb1da7b9b0df9455a35a7f893
+ image: prom/prometheus:v3.13.2@sha256:508729e0e2d18e11fd742a5a5ca70e557b940a93948c3c95fd0123a6fd538b69
network_mode: host
volumes:
- ./config/prometheus.yaml:/prometheus.yaml
diff --git a/examples/example-native-histogram/docker-compose.yaml b/examples/example-native-histogram/docker-compose.yaml
index 5e2d70398..899ff275c 100644
--- a/examples/example-native-histogram/docker-compose.yaml
+++ b/examples/example-native-histogram/docker-compose.yaml
@@ -10,7 +10,7 @@ services:
- -jar
- /example-native-histogram.jar
prometheus:
- image: prom/prometheus:v3.13.1@sha256:3c42b892cf723fa54d2f262c37a0e1f80aa8c8ddb1da7b9b0df9455a35a7f893
+ image: prom/prometheus:v3.13.2@sha256:508729e0e2d18e11fd742a5a5ca70e557b940a93948c3c95fd0123a6fd538b69
network_mode: host
volumes:
- ./docker-compose/prometheus.yml:/prometheus.yml
From 7e7e53364496a1dd6d21d2c01c59219166d7826d Mon Sep 17 00:00:00 2001
From: Gregor Zeitlinger
Date: Fri, 31 Jul 2026 14:45:13 +0200
Subject: [PATCH 08/54] fix: redact invalid configuration values (#2335)
---
.../config/ExporterPushgatewayProperties.java | 12 +++++-------
.../config/PrometheusPropertiesLoader.java | 3 +--
.../java/io/prometheus/metrics/config/Util.java | 14 +++++++++-----
.../metrics/config/ExporterPropertiesTest.java | 9 +++------
.../ExporterPushgatewayPropertiesTest.java | 4 ++--
.../config/OpenMetrics2PropertiesTest.java | 17 +++++------------
.../config/PrometheusPropertiesLoaderTest.java | 5 ++---
.../io/prometheus/metrics/config/UtilTest.java | 14 +++++++++++++-
.../exporter/pushgateway/PushGateway.java | 4 ++--
.../exporter/pushgateway/PushGatewayTest.java | 10 ++++++++++
10 files changed, 52 insertions(+), 40 deletions(-)
diff --git a/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/ExporterPushgatewayProperties.java b/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/ExporterPushgatewayProperties.java
index 10e8c0f33..e97ade191 100644
--- a/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/ExporterPushgatewayProperties.java
+++ b/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/ExporterPushgatewayProperties.java
@@ -94,9 +94,8 @@ static ExporterPushgatewayProperties load(PropertySource propertySource)
if (scheme != null) {
if (!scheme.equals("http") && !scheme.equals("https")) {
throw new PrometheusPropertiesException(
- String.format(
- "%s.%s: Illegal value. Expecting 'http' or 'https'. Found: %s",
- PREFIX, SCHEME, scheme));
+ Util.invalidValueMessage(
+ PREFIX + "." + SCHEME, "Illegal value. Expecting 'http' or 'https'."));
}
}
@@ -119,10 +118,9 @@ static ExporterPushgatewayProperties load(PropertySource propertySource)
return EscapingScheme.DOTS_ESCAPING;
default:
throw new PrometheusPropertiesException(
- String.format(
- "%s.%s: Illegal value. Expecting 'allow-utf-8', 'values', 'underscores', "
- + "or 'dots'. Found: %s",
- PREFIX, ESCAPING_SCHEME, scheme));
+ Util.invalidValueMessage(
+ PREFIX + "." + ESCAPING_SCHEME,
+ "Illegal value. Expecting 'allow-utf-8', 'values', 'underscores', or 'dots'."));
}
}
diff --git a/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/PrometheusPropertiesLoader.java b/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/PrometheusPropertiesLoader.java
index 6d52b71ef..04bbfe4a5 100644
--- a/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/PrometheusPropertiesLoader.java
+++ b/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/PrometheusPropertiesLoader.java
@@ -169,8 +169,7 @@ private static Properties loadPropertiesFromFile() throws PrometheusPropertiesEx
try (InputStream stream = Files.newInputStream(Paths.get(path))) {
properties.load(stream);
} catch (IOException e) {
- throw new PrometheusPropertiesException(
- "Failed to read Prometheus properties from " + path + ": " + e.getMessage(), e);
+ throw new PrometheusPropertiesException("Failed to read Prometheus properties file.", e);
}
}
return properties;
diff --git a/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/Util.java b/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/Util.java
index 20bd75699..d90810faf 100644
--- a/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/Util.java
+++ b/prometheus-metrics-config/src/main/java/io/prometheus/metrics/config/Util.java
@@ -24,7 +24,7 @@ static Boolean loadBoolean(String prefix, String propertyName, PropertySource pr
String fullKey = prefix.isEmpty() ? propertyName : prefix + "." + propertyName;
if (!"true".equalsIgnoreCase(property) && !"false".equalsIgnoreCase(property)) {
throw new PrometheusPropertiesException(
- String.format("%s: Expecting 'true' or 'false'. Found: %s", fullKey, property));
+ invalidValueMessage(fullKey, "Expecting 'true' or 'false'."));
}
return Boolean.parseBoolean(property);
}
@@ -88,7 +88,7 @@ static List loadDoubleList(
}
} catch (NumberFormatException e) {
throw new PrometheusPropertiesException(
- fullKey + "=" + property + ": Expecting comma separated list of double values");
+ invalidValueMessage(fullKey, "Expecting comma separated list of double values"));
}
}
return Arrays.asList(result);
@@ -130,7 +130,7 @@ static Integer loadInteger(String prefix, String propertyName, PropertySource pr
return Integer.parseInt(property);
} catch (NumberFormatException e) {
throw new PrometheusPropertiesException(
- fullKey + "=" + property + ": Expecting integer value");
+ invalidValueMessage(fullKey, "Expecting integer value"));
}
}
return null;
@@ -146,7 +146,7 @@ static Double loadDouble(String prefix, String propertyName, PropertySource prop
return Double.parseDouble(property);
} catch (NumberFormatException e) {
throw new PrometheusPropertiesException(
- fullKey + "=" + property + ": Expecting double value");
+ invalidValueMessage(fullKey, "Expecting double value"));
}
}
return null;
@@ -162,7 +162,7 @@ static Long loadLong(String prefix, String propertyName, PropertySource property
return Long.parseLong(property);
} catch (NumberFormatException e) {
throw new PrometheusPropertiesException(
- fullKey + "=" + property + ": Expecting long value");
+ invalidValueMessage(fullKey, "Expecting long value"));
}
}
return null;
@@ -197,4 +197,8 @@ static void assertValue(
throw new PrometheusPropertiesException(fullMessage);
}
}
+
+ static String invalidValueMessage(String fullKey, String message) {
+ return fullKey + ": " + message;
+ }
}
diff --git a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/ExporterPropertiesTest.java b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/ExporterPropertiesTest.java
index 514c5ff52..2f912ff77 100644
--- a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/ExporterPropertiesTest.java
+++ b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/ExporterPropertiesTest.java
@@ -27,8 +27,7 @@ void load() {
new HashMap<>(
Map.of("io.prometheus.exporter.include_created_timestamps", "invalid"))))
.withMessage(
- "io.prometheus.exporter.include_created_timestamps: Expecting 'true' or 'false'. Found:"
- + " invalid");
+ "io.prometheus.exporter.include_created_timestamps: Expecting 'true' or 'false'.");
assertThatExceptionOfType(PrometheusPropertiesException.class)
.isThrownBy(
() ->
@@ -36,8 +35,7 @@ void load() {
new HashMap<>(
Map.of("io.prometheus.exporter.exemplars_on_all_metric_types", "invalid"))))
.withMessage(
- "io.prometheus.exporter.exemplars_on_all_metric_types: Expecting 'true' or 'false'."
- + " Found: invalid");
+ "io.prometheus.exporter.exemplars_on_all_metric_types: Expecting 'true' or 'false'.");
}
private static ExporterProperties load(Map map) {
@@ -84,7 +82,6 @@ void prometheusTimestampsInMs() {
new HashMap<>(
Map.of("io.prometheus.exporter.prometheus_timestamps_in_ms", "invalid"))))
.withMessage(
- "io.prometheus.exporter.prometheus_timestamps_in_ms: Expecting 'true' or 'false'."
- + " Found: invalid");
+ "io.prometheus.exporter.prometheus_timestamps_in_ms: Expecting 'true' or 'false'.");
}
}
diff --git a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/ExporterPushgatewayPropertiesTest.java b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/ExporterPushgatewayPropertiesTest.java
index c92e6f2f9..4715662f3 100644
--- a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/ExporterPushgatewayPropertiesTest.java
+++ b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/ExporterPushgatewayPropertiesTest.java
@@ -27,7 +27,7 @@ void load() {
.isThrownBy(() -> load(Map.of("io.prometheus.exporter.pushgateway.scheme", "foo")))
.withMessage(
"io.prometheus.exporter.pushgateway.scheme: Illegal value. Expecting 'http' or 'https'."
- + " Found: foo");
+ + "");
}
@Test
@@ -60,7 +60,7 @@ void loadWithInvalidEscapingScheme() {
() -> load(Map.of("io.prometheus.exporter.pushgateway.escaping_scheme", "invalid")))
.withMessage(
"io.prometheus.exporter.pushgateway.escaping_scheme: Illegal value. Expecting"
- + " 'allow-utf-8', 'values', 'underscores', or 'dots'. Found: invalid");
+ + " 'allow-utf-8', 'values', 'underscores', or 'dots'.");
}
@Test
diff --git a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/OpenMetrics2PropertiesTest.java b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/OpenMetrics2PropertiesTest.java
index e7a273464..0546a138f 100644
--- a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/OpenMetrics2PropertiesTest.java
+++ b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/OpenMetrics2PropertiesTest.java
@@ -37,8 +37,7 @@ void loadInvalidValue() {
assertThatExceptionOfType(PrometheusPropertiesException.class)
.isThrownBy(
() -> load(new HashMap<>(Map.of("io.prometheus.openmetrics2.enabled", "invalid"))))
- .withMessage(
- "io.prometheus.openmetrics2.enabled: Expecting 'true' or 'false'. Found: invalid");
+ .withMessage("io.prometheus.openmetrics2.enabled: Expecting 'true' or 'false'.");
assertThatExceptionOfType(PrometheusPropertiesException.class)
.isThrownBy(
() ->
@@ -46,17 +45,14 @@ void loadInvalidValue() {
new HashMap<>(
Map.of("io.prometheus.openmetrics2.content_negotiation", "invalid"))))
.withMessage(
- "io.prometheus.openmetrics2.content_negotiation: Expecting 'true' or 'false'. Found:"
- + " invalid");
+ "io.prometheus.openmetrics2.content_negotiation: Expecting 'true' or 'false'.");
assertThatExceptionOfType(PrometheusPropertiesException.class)
.isThrownBy(
() ->
load(
new HashMap<>(
Map.of("io.prometheus.openmetrics2.composite_values", "invalid"))))
- .withMessage(
- "io.prometheus.openmetrics2.composite_values: Expecting 'true' or 'false'. Found:"
- + " invalid");
+ .withMessage("io.prometheus.openmetrics2.composite_values: Expecting 'true' or 'false'.");
assertThatExceptionOfType(PrometheusPropertiesException.class)
.isThrownBy(
() ->
@@ -64,17 +60,14 @@ void loadInvalidValue() {
new HashMap<>(
Map.of("io.prometheus.openmetrics2.exemplar_compliance", "invalid"))))
.withMessage(
- "io.prometheus.openmetrics2.exemplar_compliance: Expecting 'true' or 'false'. Found:"
- + " invalid");
+ "io.prometheus.openmetrics2.exemplar_compliance: Expecting 'true' or 'false'.");
assertThatExceptionOfType(PrometheusPropertiesException.class)
.isThrownBy(
() ->
load(
new HashMap<>(
Map.of("io.prometheus.openmetrics2.native_histograms", "invalid"))))
- .withMessage(
- "io.prometheus.openmetrics2.native_histograms: Expecting 'true' or 'false'. Found:"
- + " invalid");
+ .withMessage("io.prometheus.openmetrics2.native_histograms: Expecting 'true' or 'false'.");
}
private static OpenMetrics2Properties load(Map map) {
diff --git a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/PrometheusPropertiesLoaderTest.java b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/PrometheusPropertiesLoaderTest.java
index 532b00295..8f910cceb 100644
--- a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/PrometheusPropertiesLoaderTest.java
+++ b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/PrometheusPropertiesLoaderTest.java
@@ -31,9 +31,8 @@ void propertiesShouldBeLoadedFromPropertiesFile() {
void cantLoadPropertiesFile() {
assertThatExceptionOfType(PrometheusPropertiesException.class)
.isThrownBy(() -> PrometheusPropertiesLoader.load(new Properties()))
- .withMessage(
- "Failed to read Prometheus properties from nonexistent.properties:"
- + " nonexistent.properties");
+ .withMessage("Failed to read Prometheus properties file.")
+ .withMessageNotContaining("nonexistent.properties");
}
@Test
diff --git a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/UtilTest.java b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/UtilTest.java
index e4d7fa829..c3ed65ec7 100644
--- a/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/UtilTest.java
+++ b/prometheus-metrics-config/src/test/java/io/prometheus/metrics/config/UtilTest.java
@@ -51,6 +51,18 @@ void loadOptionalDuration_invalidNumber_throws() {
assertThatExceptionOfType(PrometheusPropertiesException.class)
.isThrownBy(() -> Util.loadOptionalDuration("", "foo", propertySource))
- .withMessage("foo=abc: Expecting long value");
+ .withMessage("foo: Expecting long value");
+ }
+
+ @Test
+ void invalidValueMessageRedactsRawValue() {
+ String secret = "bad\n\"secret-value";
+ Map regularProperties = new HashMap<>(Map.of("foo", secret));
+ PropertySource propertySource = new PropertySource(regularProperties);
+
+ assertThatExceptionOfType(PrometheusPropertiesException.class)
+ .isThrownBy(() -> Util.loadBoolean("", "foo", propertySource))
+ .withMessage("foo: Expecting 'true' or 'false'.")
+ .withMessageNotContaining(secret);
}
}
diff --git a/prometheus-metrics-exporter-pushgateway/src/main/java/io/prometheus/metrics/exporter/pushgateway/PushGateway.java b/prometheus-metrics-exporter-pushgateway/src/main/java/io/prometheus/metrics/exporter/pushgateway/PushGateway.java
index 5bf26b6c1..b7dd844ec 100644
--- a/prometheus-metrics-exporter-pushgateway/src/main/java/io/prometheus/metrics/exporter/pushgateway/PushGateway.java
+++ b/prometheus-metrics-exporter-pushgateway/src/main/java/io/prometheus/metrics/exporter/pushgateway/PushGateway.java
@@ -554,9 +554,9 @@ public PushGateway build() {
getEscapingScheme(properties),
getConnectionTimeout(properties),
getReadTimeout(properties));
- } catch (MalformedURLException e) {
+ } catch (MalformedURLException | IllegalArgumentException e) {
throw new PrometheusPropertiesException(
- address + ": Invalid address. Expecting :");
+ "Invalid Pushgateway address. Expecting :");
} catch (UnsupportedEncodingException e) {
throw new RuntimeException(e); // cannot happen, UTF-8 is always supported
}
diff --git a/prometheus-metrics-exporter-pushgateway/src/test/java/io/prometheus/metrics/exporter/pushgateway/PushGatewayTest.java b/prometheus-metrics-exporter-pushgateway/src/test/java/io/prometheus/metrics/exporter/pushgateway/PushGatewayTest.java
index bae8fdd91..8c33543f9 100644
--- a/prometheus-metrics-exporter-pushgateway/src/test/java/io/prometheus/metrics/exporter/pushgateway/PushGatewayTest.java
+++ b/prometheus-metrics-exporter-pushgateway/src/test/java/io/prometheus/metrics/exporter/pushgateway/PushGatewayTest.java
@@ -6,6 +6,7 @@
import static org.mockserver.model.HttpResponse.response;
import io.prometheus.metrics.config.EscapingScheme;
+import io.prometheus.metrics.config.PrometheusPropertiesException;
import io.prometheus.metrics.core.metrics.Gauge;
import io.prometheus.metrics.model.registry.PrometheusRegistry;
import java.io.IOException;
@@ -48,6 +49,15 @@ void testInvalidURLThrowsRuntimeException() {
});
}
+ @Test
+ void testInvalidURLDoesNotExposeCredentials() {
+ String secretAddress = "user:secret@[::";
+ assertThatExceptionOfType(PrometheusPropertiesException.class)
+ .isThrownBy(() -> PushGateway.builder().address(secretAddress).build())
+ .withMessage("Invalid Pushgateway address. Expecting :")
+ .withMessageNotContaining("secret");
+ }
+
@Test
void testMultipleSlashesAreStrippedFromURL() throws NoSuchFieldException, IllegalAccessException {
final PushGateway pushGateway =
From b6cd000a39f9bbf78cf0ae1209c60910219c9cbf Mon Sep 17 00:00:00 2001
From: Gregor Zeitlinger
Date: Fri, 31 Jul 2026 14:47:42 +0200
Subject: [PATCH 09/54] fix: prevent buffer stripe index overflow (#2331)
---
.../prometheus/metrics/core/metrics/Buffer.java | 6 +++++-
.../metrics/core/metrics/BufferTest.java | 15 +++++++++++++++
2 files changed, 20 insertions(+), 1 deletion(-)
create mode 100644 prometheus-metrics-core/src/test/java/io/prometheus/metrics/core/metrics/BufferTest.java
diff --git a/prometheus-metrics-core/src/main/java/io/prometheus/metrics/core/metrics/Buffer.java b/prometheus-metrics-core/src/main/java/io/prometheus/metrics/core/metrics/Buffer.java
index 1c47f867c..c2017995e 100644
--- a/prometheus-metrics-core/src/main/java/io/prometheus/metrics/core/metrics/Buffer.java
+++ b/prometheus-metrics-core/src/main/java/io/prometheus/metrics/core/metrics/Buffer.java
@@ -43,7 +43,7 @@ class Buffer {
}
boolean append(double value) {
- int index = Math.abs((int) Thread.currentThread().getId()) % stripedObservationCounts.length;
+ int index = stripeIndex(Thread.currentThread().getId(), stripedObservationCounts.length);
AtomicLong observationCountForThread = stripedObservationCounts[index];
long count = observationCountForThread.incrementAndGet();
if ((count & bufferActiveBit) == 0) {
@@ -54,6 +54,10 @@ boolean append(double value) {
}
}
+ static int stripeIndex(long threadId, int stripeCount) {
+ return (int) Math.floorMod(threadId, stripeCount);
+ }
+
private void doAppend(double amount) {
appendLock.lock();
try {
diff --git a/prometheus-metrics-core/src/test/java/io/prometheus/metrics/core/metrics/BufferTest.java b/prometheus-metrics-core/src/test/java/io/prometheus/metrics/core/metrics/BufferTest.java
new file mode 100644
index 000000000..dccd3b4eb
--- /dev/null
+++ b/prometheus-metrics-core/src/test/java/io/prometheus/metrics/core/metrics/BufferTest.java
@@ -0,0 +1,15 @@
+package io.prometheus.metrics.core.metrics;
+
+import static org.assertj.core.api.Assertions.assertThat;
+
+import org.junit.jupiter.api.Test;
+
+class BufferTest {
+
+ @Test
+ void stripeIndexDoesNotOverflowWhenThreadIdNarrowsToIntegerMinValue() {
+ assertThat(Buffer.stripeIndex(2_147_483_648L, 3)).isEqualTo(2);
+ assertThat(Buffer.stripeIndex(2_147_483_648L, 6)).isEqualTo(2);
+ assertThat(Buffer.stripeIndex(2_147_483_648L, 12)).isEqualTo(8);
+ }
+}
From af6a1e013135c0789b06978bd1b3bfc1180ce238 Mon Sep 17 00:00:00 2001
From: Gregor Zeitlinger
Date: Fri, 31 Jul 2026 14:48:22 +0200
Subject: [PATCH 10/54] ci: use shared pull request title lint (#2319)
---
.github/workflows/pr-title.yml | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/.github/workflows/pr-title.yml b/.github/workflows/pr-title.yml
index 5434323e0..8cc398ee0 100644
--- a/.github/workflows/pr-title.yml
+++ b/.github/workflows/pr-title.yml
@@ -14,6 +14,4 @@ jobs:
permissions:
pull-requests: read # action-semantic-pull-request reads the PR title
steps:
- - uses: amannn/action-semantic-pull-request@48f256284bd46cdaab1048c3721360e808335d50 # v6.1.1
- env:
- GITHUB_TOKEN: ${{ github.token }}
+ - uses: grafana/shared-workflows/actions/lint-pr-title@823ed150196915a86971ab4beb899b0c80d835fe # lint-pr-title/v1.2.3
From 10d274eed1015fe89e0a2ec63d4657750a9a59c5 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Fri, 31 Jul 2026 09:04:33 -0400
Subject: [PATCH 11/54] chore(deps): update dependency grafana/docker-otel-lgtm
to v0.30.0 (#2358)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
|
[grafana/docker-otel-lgtm](https://redirect.github.com/grafana/docker-otel-lgtm)
| minor | `0.29.2` â `0.30.0` |
---
### Release Notes
grafana/docker-otel-lgtm (grafana/docker-otel-lgtm)
###
[`v0.30.0`](https://redirect.github.com/grafana/docker-otel-lgtm/releases/tag/v0.30.0)
[Compare
Source](https://redirect.github.com/grafana/docker-otel-lgtm/compare/v0.29.2...v0.30.0)
#### What's Changed
##### OpenTelemetry & LGTM
- chore(deps): update dependency grafana to v13.1.1 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1634](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1634)
- chore(deps): update dependency pyroscope to v2.2.0 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1639](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1639)
- chore(deps): update dependency opentelemetry-collector to v0.157.0 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1643](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1643)
- chore(deps): update dependency loki to v3.7.4 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1653](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1653)
##### Other Changes
- Replace legacy OATS examples with the current CLI config by
[@zeitlinger](https://redirect.github.com/zeitlinger) in
[#1483](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1483)
- ci: lint Kubernetes manifests with Flint by
[@zeitlinger](https://redirect.github.com/zeitlinger) in
[#1635](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1635)
- test: validate one-shot OATS Compose inputs by
[@zeitlinger](https://redirect.github.com/zeitlinger) in
[#1661](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1661)
**Full Changelog**:
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
mise.toml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mise.toml b/mise.toml
index 1ab071d68..1fd2c3aa0 100644
--- a/mise.toml
+++ b/mise.toml
@@ -27,7 +27,7 @@ zizmor = "1.28.0"
[env]
FLINT_CONFIG_DIR = ".github/config"
# renovate: datasource=github-releases depName=grafana/docker-otel-lgtm
-LGTM_VERSION = "0.29.2"
+LGTM_VERSION = "0.30.0"
# Latest JMX Exporter release; used as the default ref for the compatibility job.
# renovate: datasource=github-tags depName=prometheus/jmx_exporter versioning=semver-coerced
DEFAULT_JMX_EXPORTER_VERSION = "v1.6.0"
From 922943cfe12acb5e373a0a6152384673c3c7b6dc Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Fri, 31 Jul 2026 19:14:18 -0400
Subject: [PATCH 12/54] chore(deps): update actions/setup-java digest to
b6effb0 (#2360)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/setup-java](https://redirect.github.com/actions/setup-java)
([changelog](https://redirect.github.com/actions/setup-java/compare/03ad4de0992f5dab5e18fcb136590ce7c4a0ac95..b6effb05e454b25005698d916606bdc6ffcbf961))
| action | digest | `03ad4de` â `b6effb0` |
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/workflows/codeql.yml | 2 +-
.github/workflows/multi-version-test.yml | 2 +-
.github/workflows/release.yml | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index db005e80c..5a34aaca4 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -26,7 +26,7 @@ jobs:
persist-credentials: false
- name: Set up Java
- uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5
+ uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5
with:
distribution: temurin
java-version: "25"
diff --git a/.github/workflows/multi-version-test.yml b/.github/workflows/multi-version-test.yml
index 9ab3ac0e3..f90251766 100644
--- a/.github/workflows/multi-version-test.yml
+++ b/.github/workflows/multi-version-test.yml
@@ -21,7 +21,7 @@ jobs:
- name: Set up Java ${{ matrix.java }}
id: setup-java
- uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5
+ uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5
with:
distribution: "temurin"
java-version: ${{ matrix.java }}
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 2970100fc..b0793ddc5 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -82,7 +82,7 @@ jobs:
run: mise run build-release
- name: Set up Apache Maven Central
- uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5
+ uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5
with:
distribution: "temurin"
java-version: "21"
From 6e9c7622db759e25b03b6a5b98efd47e01c734d9 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Tue, 4 Aug 2026 14:53:55 -0400
Subject: [PATCH 13/54] chore(deps): update flint to v0.22.10 (#2363)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [aqua:grafana/flint](https://redirect.github.com/grafana/flint) |
tools | patch | `0.22.9` â `0.22.10` |
| [grafana/flint](https://redirect.github.com/grafana/flint) | | patch |
`v0.22.9` â `v0.22.10` |
---
### Release Notes
grafana/flint (aqua:grafana/flint)
###
[`v0.22.10`](https://redirect.github.com/grafana/flint/blob/HEAD/CHANGELOG.md#02210---2026-07-27)
[Compare
Source](https://redirect.github.com/grafana/flint/compare/v0.22.9...v0.22.10)
##### Added
- add safe dotenv linting
([#436](https://redirect.github.com/grafana/flint/pull/436))
- add native Java formatting and regex replacements
([#407](https://redirect.github.com/grafana/flint/pull/407))
- add scoped Kubernetes manifest linting
([#437](https://redirect.github.com/grafana/flint/pull/437))
- add standalone Checkstyle linting
([#435](https://redirect.github.com/grafana/flint/pull/435))
- improve Flint init and setup migrations
([#428](https://redirect.github.com/grafana/flint/pull/428))
- define registry and execution contracts
([#427](https://redirect.github.com/grafana/flint/pull/427))
##### Fixed
- *(renovate)* avoid overlapping mise managers
([#446](https://redirect.github.com/grafana/flint/pull/446))
##### Other
- *(deps)* update dependency jdx/mise-action to v4.2.2
([#448](https://redirect.github.com/grafana/flint/pull/448))
- make Windows aube installs cacheable
([#447](https://redirect.github.com/grafana/flint/pull/447))
- *(deps)* update mise to v2026.7.12
([#444](https://redirect.github.com/grafana/flint/pull/444))
- *(deps)* update linters
([#443](https://redirect.github.com/grafana/flint/pull/443))
- move linter reference to dedicated pages
([#440](https://redirect.github.com/grafana/flint/pull/440))
- *(deps)* lock file maintenance
([#445](https://redirect.github.com/grafana/flint/pull/445))
- *(deps)* update taiki-e/install-action action to v2.85.0
([#442](https://redirect.github.com/grafana/flint/pull/442))
- *(deps)* update taiki-e/install-action action to v2.84.1
([#441](https://redirect.github.com/grafana/flint/pull/441))
- require silent happy paths for checks
([#439](https://redirect.github.com/grafana/flint/pull/439))
- *(deps)* update grafana/shared-workflows/lint-pr-title action to
v1.2.4
([#438](https://redirect.github.com/grafana/flint/pull/438))
- add Linux musl release artifacts
([#421](https://redirect.github.com/grafana/flint/pull/421))
- validate curated mise registry backends
([#429](https://redirect.github.com/grafana/flint/pull/429))
- *(deps)* update rust crate tokio to v1.53.1
([#434](https://redirect.github.com/grafana/flint/pull/434))
- *(deps)* update taiki-e/install-action action to v2.84.0
([#433](https://redirect.github.com/grafana/flint/pull/433))
- *(deps)* update rust crate clap to v4.6.3
([#432](https://redirect.github.com/grafana/flint/pull/432))
- *(deps)* update rust crate serde\_json to v1.0.151
([#431](https://redirect.github.com/grafana/flint/pull/431))
- record Flint v2 architecture decisions
([#426](https://redirect.github.com/grafana/flint/pull/426))
- *(deps)* update taiki-e/install-action action to v2.83.4
([#423](https://redirect.github.com/grafana/flint/pull/423))
- *(deps)* update actions/checkout digest to
[`3d3c42e`](https://redirect.github.com/grafana/flint/commit/3d3c42e)
([#422](https://redirect.github.com/grafana/flint/pull/422))
- *(deps)* update rust crate regex to v1.13.1
([#412](https://redirect.github.com/grafana/flint/pull/412))
- document semantic PR title guidance
([#420](https://redirect.github.com/grafana/flint/pull/420))
- *(deps)* update linters
([#418](https://redirect.github.com/grafana/flint/pull/418))
- *(deps)* update dependency mise to v2026.7.7
([#417](https://redirect.github.com/grafana/flint/pull/417))
- *(deps)* lock file maintenance
([#419](https://redirect.github.com/grafana/flint/pull/419))
- *(deps)* update taiki-e/install-action action to v2.83.3
([#415](https://redirect.github.com/grafana/flint/pull/415))
- *(deps)* update rust crate tokio to v1.52.4
([#414](https://redirect.github.com/grafana/flint/pull/414))
- *(deps)* update dependency jdx/mise-action to v4.2.1
([#416](https://redirect.github.com/grafana/flint/pull/416))
- *(deps)* update dependency rust to v1.97.1
([#413](https://redirect.github.com/grafana/flint/pull/413))
- *(deps)* update rust crate clap to v4.6.2
([#411](https://redirect.github.com/grafana/flint/pull/411))
- *(deps)* update rust crate globset to v0.4.19
([#410](https://redirect.github.com/grafana/flint/pull/410))
- *(deps)* update rust crate toml\_edit to v0.25.13
([#409](https://redirect.github.com/grafana/flint/pull/409))
- *(deps)* update rust crate toml to v1.1.3
([#408](https://redirect.github.com/grafana/flint/pull/408))
- document signed commit requirement
([#406](https://redirect.github.com/grafana/flint/pull/406))
- batch rumdl file checks
([#404](https://redirect.github.com/grafana/flint/pull/404))
- *(deps)* update taiki-e/install-action action to v2.83.2
([#405](https://redirect.github.com/grafana/flint/pull/405))
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- "before 4am on Monday"
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about these
updates again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/renovate.json5 | 2 +-
mise.lock | 38 ++++++++++++++++++++++----------------
mise.toml | 2 +-
3 files changed, 24 insertions(+), 18 deletions(-)
diff --git a/.github/renovate.json5 b/.github/renovate.json5
index 0dc002f19..720659e04 100644
--- a/.github/renovate.json5
+++ b/.github/renovate.json5
@@ -1,6 +1,6 @@
{
$schema: "https://docs.renovatebot.com/renovate-schema.json",
- extends: ["config:best-practices", "config:recommended", "github>grafana/flint#v0.22.9"],
+ extends: ["config:best-practices", "config:recommended", "github>grafana/flint#v0.22.10"],
platformCommit: "enabled",
automerge: true,
ignorePaths: [
diff --git a/mise.lock b/mise.lock
index 0dff26c57..c1a4b9364 100644
--- a/mise.lock
+++ b/mise.lock
@@ -47,43 +47,49 @@ url_api = "https://api.github.com/repos/rhysd/actionlint/releases/assets/3849249
provenance = "github-attestations"
[[tools."aqua:grafana/flint"]]
-version = "0.22.9"
+version = "0.22.10"
backend = "aqua:grafana/flint"
[tools."aqua:grafana/flint"."platforms.linux-arm64"]
-checksum = "sha256:aae323ea911f9a5012879b79fd3b913837d301098173684d5f9672b6d15c1193"
-url = "https://github.com/grafana/flint/releases/download/v0.22.9/flint-aarch64-unknown-linux-gnu.tar.gz"
-url_api = "https://api.github.com/repos/grafana/flint/releases/assets/476876537"
+checksum = "sha256:6dec82cb6486b7e645e0b1674493497191d92a8e28c5c79194e5553882d213de"
+url = "https://github.com/grafana/flint/releases/download/v0.22.10/flint-aarch64-unknown-linux-gnu.tar.gz"
+url_api = "https://api.github.com/repos/grafana/flint/releases/assets/491750275"
provenance = "github-attestations"
[tools."aqua:grafana/flint"."platforms.linux-arm64-musl"]
+checksum = "sha256:373060c08a4cdd905d6e8e83f62ef43da8778d9133cb66b7801f392587812e8f"
+url = "https://github.com/grafana/flint/releases/download/v0.22.10/flint-aarch64-unknown-linux-musl.tar.gz"
+url_api = "https://api.github.com/repos/grafana/flint/releases/assets/491750193"
provenance = "github-attestations"
[tools."aqua:grafana/flint"."platforms.linux-x64"]
-checksum = "sha256:e7b0597d82568e441dab13091f674f15c36914b0f412c8fcc19d3ed880da320a"
-url = "https://github.com/grafana/flint/releases/download/v0.22.9/flint-x86_64-unknown-linux-gnu.tar.gz"
-url_api = "https://api.github.com/repos/grafana/flint/releases/assets/476875905"
+checksum = "sha256:a9f7f3768ec02cdd082c12cea0e815fc142d3ee721f4d8485f4ba9fc2c7d0521"
+url = "https://github.com/grafana/flint/releases/download/v0.22.10/flint-x86_64-unknown-linux-gnu.tar.gz"
+url_api = "https://api.github.com/repos/grafana/flint/releases/assets/491749844"
provenance = "github-attestations"
[tools."aqua:grafana/flint"."platforms.linux-x64-musl"]
+checksum = "sha256:3b174b31f10b1ded2cf0a54e8b62e5526713a49816c1fd74b00073519044f7bb"
+url = "https://github.com/grafana/flint/releases/download/v0.22.10/flint-x86_64-unknown-linux-musl.tar.gz"
+url_api = "https://api.github.com/repos/grafana/flint/releases/assets/491750257"
provenance = "github-attestations"
[tools."aqua:grafana/flint"."platforms.macos-arm64"]
-checksum = "sha256:0370a9f0f16b262cb2c683cc2da539d39e131a3167ac44d3471b57135508b3b2"
-url = "https://github.com/grafana/flint/releases/download/v0.22.9/flint-aarch64-apple-darwin.tar.gz"
-url_api = "https://api.github.com/repos/grafana/flint/releases/assets/476875995"
+checksum = "sha256:f9aa1a95aa5953f7f5a64c0d72f86e634c4930e9cb73422a95e342c6cb9be5d5"
+url = "https://github.com/grafana/flint/releases/download/v0.22.10/flint-aarch64-apple-darwin.tar.gz"
+url_api = "https://api.github.com/repos/grafana/flint/releases/assets/491750245"
provenance = "github-attestations"
[tools."aqua:grafana/flint"."platforms.macos-x64"]
-checksum = "sha256:b14167a1e47ac34439518680ff5df16554056c5099bafd650f01a37cf29b4a3a"
-url = "https://github.com/grafana/flint/releases/download/v0.22.9/flint-x86_64-apple-darwin.tar.gz"
-url_api = "https://api.github.com/repos/grafana/flint/releases/assets/476878878"
+checksum = "sha256:b55731f1b74196afea675bdbd6ebbbd94171b4e9d31f79ecee36372bdf8818cf"
+url = "https://github.com/grafana/flint/releases/download/v0.22.10/flint-x86_64-apple-darwin.tar.gz"
+url_api = "https://api.github.com/repos/grafana/flint/releases/assets/491752660"
provenance = "github-attestations"
[tools."aqua:grafana/flint"."platforms.windows-x64"]
-checksum = "sha256:b5b9fb31413e11600ec0f8d4c0cf56c7698b1e38f156018364b3f1a2dcfbcbd0"
-url = "https://github.com/grafana/flint/releases/download/v0.22.9/flint-x86_64-pc-windows-msvc.zip"
-url_api = "https://api.github.com/repos/grafana/flint/releases/assets/476892021"
+checksum = "sha256:494f16ad4d2d8eae137438832e544675d196a2887086ab8070a5a346d70650be"
+url = "https://github.com/grafana/flint/releases/download/v0.22.10/flint-x86_64-pc-windows-msvc.zip"
+url_api = "https://api.github.com/repos/grafana/flint/releases/assets/491751016"
provenance = "github-attestations"
[[tools."aqua:grafana/gcx"]]
diff --git a/mise.toml b/mise.toml
index 1fd2c3aa0..d4a1ec530 100644
--- a/mise.toml
+++ b/mise.toml
@@ -8,7 +8,7 @@ protoc = "35.1"
# Linters
actionlint = "1.7.12"
-"aqua:grafana/flint" = "0.22.9"
+"aqua:grafana/flint" = "0.22.10"
"aqua:jonwiggins/xmloxide" = "v0.4.4"
"aqua:owenlamont/ryl" = "0.21.0"
biome = "2.5.5"
From 2a6f06b153b8a66b691d417a259f69dc0178dcdf Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Tue, 4 Aug 2026 14:54:11 -0400
Subject: [PATCH 14/54] chore(deps): update jdx/mise-action action to v4.2.4
(#2361)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [jdx/mise-action](https://redirect.github.com/jdx/mise-action) |
action | patch | `v4.2.3` â `v4.2.4` |
---
### Release Notes
jdx/mise-action (jdx/mise-action)
###
[`v4.2.4`](https://redirect.github.com/jdx/mise-action/releases/tag/v4.2.4):
: Reliable locking detection under forced color
[Compare
Source](https://redirect.github.com/jdx/mise-action/compare/v4.2.3...v4.2.4)
A small patch release that fixes locking-support detection when
workflows force colored output.
##### Fixed
##### Detect `mise install --locked` reliably under forced color
([#580](https://redirect.github.com/jdx/mise-action/pull/580) by
[@scop](https://redirect.github.com/scop))
When colored output was forced globally (for example via
`CLICOLOR_FORCE=1`), ANSI escape codes in `mise install --help`
prevented the action from matching `--locked` in the help text, so
locking support was reported as unavailable even on versions of mise
that supported it.
The help probe now runs with `NO_COLOR=1` in its environment, which
overrides `CLICOLOR_FORCE` and guarantees plain-text output for the
feature detection â regardless of the surrounding workflow's color
settings.
**Full Changelog**:
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/workflows/acceptance-tests.yml | 2 +-
.github/workflows/api-diff.yml | 2 +-
.github/workflows/build.yml | 2 +-
.github/workflows/bump-api-diff-baseline.yml | 2 +-
.github/workflows/generate-protobuf.yml | 2 +-
.github/workflows/github-pages.yaml | 2 +-
.github/workflows/java-version-matrix-tests.yml | 2 +-
.github/workflows/jmx-exporter-compatibility.yml | 2 +-
.github/workflows/lint.yml | 2 +-
.github/workflows/micrometer-compatibility.yml | 2 +-
.github/workflows/native-tests.yml | 2 +-
.github/workflows/nightly-benchmarks.yml | 2 +-
.github/workflows/pr-benchmarks.yml | 2 +-
.github/workflows/regenerate-api-diff-otel.yml | 2 +-
.github/workflows/release.yml | 2 +-
.github/workflows/test-release-build.yml | 2 +-
16 files changed, 16 insertions(+), 16 deletions(-)
diff --git a/.github/workflows/acceptance-tests.yml b/.github/workflows/acceptance-tests.yml
index 410da0c3f..420d8fba9 100644
--- a/.github/workflows/acceptance-tests.yml
+++ b/.github/workflows/acceptance-tests.yml
@@ -13,7 +13,7 @@ jobs:
with:
persist-credentials: false
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/api-diff.yml b/.github/workflows/api-diff.yml
index c7ad1f065..97171dd80 100644
--- a/.github/workflows/api-diff.yml
+++ b/.github/workflows/api-diff.yml
@@ -32,7 +32,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index 765b685f2..7877d56d3 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -12,7 +12,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/bump-api-diff-baseline.yml b/.github/workflows/bump-api-diff-baseline.yml
index edbf002f8..20623b920 100644
--- a/.github/workflows/bump-api-diff-baseline.yml
+++ b/.github/workflows/bump-api-diff-baseline.yml
@@ -33,7 +33,7 @@ jobs:
with:
ref: ${{ env.SNAPSHOT_BRANCH }}
persist-credentials: true
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/generate-protobuf.yml b/.github/workflows/generate-protobuf.yml
index 6c6e54495..dc9d2f133 100644
--- a/.github/workflows/generate-protobuf.yml
+++ b/.github/workflows/generate-protobuf.yml
@@ -18,7 +18,7 @@ jobs:
with:
ref: ${{ github.ref }}
persist-credentials: false
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/github-pages.yaml b/.github/workflows/github-pages.yaml
index a168df077..a03b03133 100644
--- a/.github/workflows/github-pages.yaml
+++ b/.github/workflows/github-pages.yaml
@@ -37,7 +37,7 @@ jobs:
persist-credentials: false
fetch-tags: "true"
fetch-depth: 0
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/java-version-matrix-tests.yml b/.github/workflows/java-version-matrix-tests.yml
index fbe49c90f..f3ea4a47d 100644
--- a/.github/workflows/java-version-matrix-tests.yml
+++ b/.github/workflows/java-version-matrix-tests.yml
@@ -31,7 +31,7 @@ jobs:
persist-credentials: false
- name: Set up mise
- uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/jmx-exporter-compatibility.yml b/.github/workflows/jmx-exporter-compatibility.yml
index 154c6f0a2..3f165a0a6 100644
--- a/.github/workflows/jmx-exporter-compatibility.yml
+++ b/.github/workflows/jmx-exporter-compatibility.yml
@@ -22,7 +22,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml
index a78b590f9..1d5a8e1d8 100644
--- a/.github/workflows/lint.yml
+++ b/.github/workflows/lint.yml
@@ -21,7 +21,7 @@ jobs:
fetch-depth: 0 # needed for git diff --merge-base in lint:links
- name: Setup mise
- uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/micrometer-compatibility.yml b/.github/workflows/micrometer-compatibility.yml
index a27f75048..5937d6344 100644
--- a/.github/workflows/micrometer-compatibility.yml
+++ b/.github/workflows/micrometer-compatibility.yml
@@ -30,7 +30,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/native-tests.yml b/.github/workflows/native-tests.yml
index 473a2935f..47b646358 100644
--- a/.github/workflows/native-tests.yml
+++ b/.github/workflows/native-tests.yml
@@ -13,7 +13,7 @@ jobs:
with:
persist-credentials: false
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/nightly-benchmarks.yml b/.github/workflows/nightly-benchmarks.yml
index 2aa5bf1aa..f5b9493d8 100644
--- a/.github/workflows/nightly-benchmarks.yml
+++ b/.github/workflows/nightly-benchmarks.yml
@@ -34,7 +34,7 @@ jobs:
fetch-depth: 0
- name: Setup mise
- uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/pr-benchmarks.yml b/.github/workflows/pr-benchmarks.yml
index 39f02cae9..ad89cc358 100644
--- a/.github/workflows/pr-benchmarks.yml
+++ b/.github/workflows/pr-benchmarks.yml
@@ -45,7 +45,7 @@ jobs:
fetch-depth: 0
- name: Setup mise
- uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/regenerate-api-diff-otel.yml b/.github/workflows/regenerate-api-diff-otel.yml
index da1db33b2..0d5abef26 100644
--- a/.github/workflows/regenerate-api-diff-otel.yml
+++ b/.github/workflows/regenerate-api-diff-otel.yml
@@ -18,7 +18,7 @@ jobs:
with:
ref: ${{ github.ref }}
persist-credentials: false
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index b0793ddc5..9dbf33cd1 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -72,7 +72,7 @@ jobs:
ref: ${{ inputs.tag }}
persist-credentials: false
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/test-release-build.yml b/.github/workflows/test-release-build.yml
index 64bc75b30..09bae5b4d 100644
--- a/.github/workflows/test-release-build.yml
+++ b/.github/workflows/test-release-build.yml
@@ -18,7 +18,7 @@ jobs:
persist-credentials: false
fetch-tags: "true"
fetch-depth: 0
- - uses: jdx/mise-action@9e7f7633ff6f6d6048a9418a68d48f288f50eb14 # v4.2.3
+ - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
From 80cf57dce18c0aa55201c0a123a7d040f787c1ae Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Tue, 4 Aug 2026 14:54:26 -0400
Subject: [PATCH 15/54] chore(deps): update github/codeql-action action to
v4.37.5 (#2365)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[github/codeql-action](https://redirect.github.com/github/codeql-action)
| action | patch | `v4.37.4` â `v4.37.5` |
---
### Release Notes
github/codeql-action (github/codeql-action)
###
[`v4.37.5`](https://redirect.github.com/github/codeql-action/compare/v4.37.4...v4.37.5)
[Compare
Source](https://redirect.github.com/github/codeql-action/compare/v4.37.4...v4.37.5)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/workflows/codeql.yml | 4 ++--
.github/workflows/scorecard.yml | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index 5a34aaca4..1ca3c4ac0 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -37,7 +37,7 @@ jobs:
path: ~/.m2/repository
key: ${{ runner.os }}-maven-codeql-${{ hashFiles('**/pom.xml') }}
- name: Initialize CodeQL
- uses: github/codeql-action/init@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
+ uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
languages: java
tools: linked
@@ -56,6 +56,6 @@ jobs:
-Djavadoc.skip=true
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
+ uses: github/codeql-action/analyze@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
category: /language:java
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index dd43bbaf5..604296434 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -41,6 +41,6 @@ jobs:
retention-days: 5
- name: Upload to code scanning
- uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
+ uses: github/codeql-action/upload-sarif@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
with:
sarif_file: results.sarif
From 60c2ab676b2cb86318779c08e78d9bfa04e7f625 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Tue, 4 Aug 2026 14:55:04 -0400
Subject: [PATCH 16/54] chore(deps): update eclipse-temurin:25.0.3_9-jre docker
digest to f19dbf0 (#2367)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin)
([source](https://redirect.github.com/adoptium/containers)) | final |
digest | `681c543` â `f19dbf0` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin)
([source](https://redirect.github.com/adoptium/containers)) | | digest |
`681c543` â `f19dbf0` |
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about these
updates again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
examples/example-custom-buckets/docker-compose.yaml | 2 +-
.../example-exporter-opentelemetry/oats-tests/agent/Dockerfile | 2 +-
.../example-exporter-opentelemetry/oats-tests/http/Dockerfile | 2 +-
examples/example-native-histogram/docker-compose.yaml | 2 +-
4 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/examples/example-custom-buckets/docker-compose.yaml b/examples/example-custom-buckets/docker-compose.yaml
index 4f7bdd5e6..77166969c 100644
--- a/examples/example-custom-buckets/docker-compose.yaml
+++ b/examples/example-custom-buckets/docker-compose.yaml
@@ -1,7 +1,7 @@
version: "3"
services:
example-application:
- image: eclipse-temurin:25.0.3_9-jre@sha256:681c543d6f36c50f45e9b5226930a46203dcfa351d3670e9d0bdf0dabae53539
+ image: eclipse-temurin:25.0.3_9-jre@sha256:f19dbf0a22d0b3658fda48ce7d7181df05ad14bda151dd5ad12cc09d1451c70e
network_mode: host
volumes:
- ./target/example-custom-buckets.jar:/example-custom-buckets.jar
diff --git a/examples/example-exporter-opentelemetry/oats-tests/agent/Dockerfile b/examples/example-exporter-opentelemetry/oats-tests/agent/Dockerfile
index 86fc52f9c..4fdc0e09c 100644
--- a/examples/example-exporter-opentelemetry/oats-tests/agent/Dockerfile
+++ b/examples/example-exporter-opentelemetry/oats-tests/agent/Dockerfile
@@ -1,4 +1,4 @@
-FROM eclipse-temurin:25.0.3_9-jre@sha256:681c543d6f36c50f45e9b5226930a46203dcfa351d3670e9d0bdf0dabae53539
+FROM eclipse-temurin:25.0.3_9-jre@sha256:f19dbf0a22d0b3658fda48ce7d7181df05ad14bda151dd5ad12cc09d1451c70e
COPY target/example-exporter-opentelemetry.jar ./app.jar
# check that the resource attributes from the agent are used, epsecially the service.instance.id should be the same
diff --git a/examples/example-exporter-opentelemetry/oats-tests/http/Dockerfile b/examples/example-exporter-opentelemetry/oats-tests/http/Dockerfile
index 89915692d..26ab27cf8 100644
--- a/examples/example-exporter-opentelemetry/oats-tests/http/Dockerfile
+++ b/examples/example-exporter-opentelemetry/oats-tests/http/Dockerfile
@@ -1,4 +1,4 @@
-FROM eclipse-temurin:25.0.3_9-jre@sha256:681c543d6f36c50f45e9b5226930a46203dcfa351d3670e9d0bdf0dabae53539
+FROM eclipse-temurin:25.0.3_9-jre@sha256:f19dbf0a22d0b3658fda48ce7d7181df05ad14bda151dd5ad12cc09d1451c70e
COPY target/example-exporter-opentelemetry.jar ./app.jar
diff --git a/examples/example-native-histogram/docker-compose.yaml b/examples/example-native-histogram/docker-compose.yaml
index 899ff275c..50062aed5 100644
--- a/examples/example-native-histogram/docker-compose.yaml
+++ b/examples/example-native-histogram/docker-compose.yaml
@@ -1,7 +1,7 @@
version: "3"
services:
example-application:
- image: eclipse-temurin:25.0.3_9-jre@sha256:681c543d6f36c50f45e9b5226930a46203dcfa351d3670e9d0bdf0dabae53539
+ image: eclipse-temurin:25.0.3_9-jre@sha256:f19dbf0a22d0b3658fda48ce7d7181df05ad14bda151dd5ad12cc09d1451c70e
network_mode: host
volumes:
- ./target/example-native-histogram.jar:/example-native-histogram.jar
From 3f555b0d1b349b9a710b1444ae64a327f75724b8 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Tue, 4 Aug 2026 14:55:38 -0400
Subject: [PATCH 17/54] chore(deps): update node.js to v24.19.0 (#2366)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [node](https://nodejs.org)
([source](https://redirect.github.com/nodejs/node)) | tools | minor |
`24.18.1` â `24.19.0` |
---
### Release Notes
nodejs/node (node)
###
[`v24.19.0`](https://redirect.github.com/nodejs/node/releases/tag/v24.19.0):
2026-08-03, Version 24.19.0 'Krypton' (LTS), @aduh95
[Compare
Source](https://redirect.github.com/nodejs/node/compare/v24.18.1...v24.19.0)
##### Notable Changes
-
\[[`d08872b530`](https://redirect.github.com/nodejs/node/commit/d08872b530)]
- **(SEMVER-MINOR)** **buffer**: implement `blob.textStream()` (Matthew
Aitken)
[#64036](https://redirect.github.com/nodejs/node/pull/64036)
-
\[[`35222948be`](https://redirect.github.com/nodejs/node/commit/35222948be)]
- **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support
compression (Tim Perry)
[#62217](https://redirect.github.com/nodejs/node/pull/62217)
-
\[[`d6ab039f24`](https://redirect.github.com/nodejs/node/commit/d6ab039f24)]
- **(SEMVER-MINOR)** **doc**: update `blockList` stability status to
release candidate (alphaleadership)
[#63050](https://redirect.github.com/nodejs/node/pull/63050)
-
\[[`1da05fb79d`](https://redirect.github.com/nodejs/node/commit/1da05fb79d)]
- **doc**: mark `stream.compose` stable (Matteo Collina)
[#62562](https://redirect.github.com/nodejs/node/pull/62562)
-
\[[`3c1636dabf`](https://redirect.github.com/nodejs/node/commit/3c1636dabf)]
- **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag
(Efe)
[#62300](https://redirect.github.com/nodejs/node/pull/62300)
-
\[[`e323e877be`](https://redirect.github.com/nodejs/node/commit/e323e877be)]
- **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()`
buffers (Matteo Collina)
[#63634](https://redirect.github.com/nodejs/node/pull/63634)
-
\[[`c1248c9544`](https://redirect.github.com/nodejs/node/commit/c1248c9544)]
- **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure
header value validation (RajeshKumar11)
[#61597](https://redirect.github.com/nodejs/node/pull/61597)
-
\[[`a534b65815`](https://redirect.github.com/nodejs/node/commit/a534b65815)]
- **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT`
in `setKeepAlive` (Guy Bedford)
[#63825](https://redirect.github.com/nodejs/node/pull/63825)
-
\[[`a23cdec683`](https://redirect.github.com/nodejs/node/commit/a23cdec683)]
- **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop
iteration (Pablo Erhard)
[#62935](https://redirect.github.com/nodejs/node/pull/62935)
-
\[[`7428b57a37`](https://redirect.github.com/nodejs/node/commit/7428b57a37)]
- **(SEMVER-MINOR)** **src**: allow empty `--experimental-config-file`
(Marco Ippolito)
[#61610](https://redirect.github.com/nodejs/node/pull/61610)
-
\[[`e57597173c`](https://redirect.github.com/nodejs/node/commit/e57597173c)]
- **(SEMVER-MINOR)** **stream**: expose `ReadableStreamTee` (Matteo
Collina)
[#64195](https://redirect.github.com/nodejs/node/pull/64195)
-
\[[`5396235993`](https://redirect.github.com/nodejs/node/commit/5396235993)]
- **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip
Skokan)
[#64119](https://redirect.github.com/nodejs/node/pull/64119)
-
\[[`5e901b5cd9`](https://redirect.github.com/nodejs/node/commit/5e901b5cd9)]
- **(SEMVER-MINOR)** **tls**: add `certificateCompression` option (Tim
Perry)
[#62217](https://redirect.github.com/nodejs/node/pull/62217)
##### Commits
-
\[[`676467fa9f`](https://redirect.github.com/nodejs/node/commit/676467fa9f)]
- **benchmark**: trim down the argon2 sets (Filip Skokan)
[#64218](https://redirect.github.com/nodejs/node/pull/64218)
-
\[[`a77a2000b7`](https://redirect.github.com/nodejs/node/commit/a77a2000b7)]
- **benchmark**: add child\_process async path baselines (Yagiz Nizipli)
[#63929](https://redirect.github.com/nodejs/node/pull/63929)
-
\[[`dd4482e915`](https://redirect.github.com/nodejs/node/commit/dd4482e915)]
- **buffer**: remove unreachable overflow check in atob (haramjeong)
[#60161](https://redirect.github.com/nodejs/node/pull/60161)
-
\[[`081c41eb86`](https://redirect.github.com/nodejs/node/commit/081c41eb86)]
- **buffer**: add fast api for isUtf8 and isAscii (GÃŧrgÃŧn DayÄąoÄlu)
[#64169](https://redirect.github.com/nodejs/node/pull/64169)
-
\[[`d08872b530`](https://redirect.github.com/nodejs/node/commit/d08872b530)]
- **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew
Aitken)
[#64036](https://redirect.github.com/nodejs/node/pull/64036)
-
\[[`6e2f7e6013`](https://redirect.github.com/nodejs/node/commit/6e2f7e6013)]
- **build**: remove redundant intermediate node\_aix\_shared (Chengzhong
Wu) [#63747](https://redirect.github.com/nodejs/node/pull/63747)
-
\[[`87e0675f51`](https://redirect.github.com/nodejs/node/commit/87e0675f51)]
- **build**: build codecache and snapshot with libnode (Chengzhong Wu)
[#63626](https://redirect.github.com/nodejs/node/pull/63626)
-
\[[`32174a7bae`](https://redirect.github.com/nodejs/node/commit/32174a7bae)]
- **build**: support setting an emulator from configure script (Ivan
Trubach)
[#53899](https://redirect.github.com/nodejs/node/pull/53899)
-
\[[`69cfb2f240`](https://redirect.github.com/nodejs/node/commit/69cfb2f240)]
- **build**: remove duplicated node\_use\_sqlite and node\_use\_ffi
conditions (Chengzhong Wu)
[#63629](https://redirect.github.com/nodejs/node/pull/63629)
-
\[[`37ac6e8cb5`](https://redirect.github.com/nodejs/node/commit/37ac6e8cb5)]
- **build**: add manually-dispatched stress-test workflow (Joyee Cheung)
[#64118](https://redirect.github.com/nodejs/node/pull/64118)
-
\[[`2424207191`](https://redirect.github.com/nodejs/node/commit/2424207191)]
- **build**: suppress compiler warnings for histogram (Richard Lau)
[#63980](https://redirect.github.com/nodejs/node/pull/63980)
-
\[[`63502b7404`](https://redirect.github.com/nodejs/node/commit/63502b7404)]
- **build,win**: fix VS2022 arm64 PGO build (Stefan Stojanovic)
[#63413](https://redirect.github.com/nodejs/node/pull/63413)
-
\[[`fe4e4055d0`](https://redirect.github.com/nodejs/node/commit/fe4e4055d0)]
- **child\_process**: fix permission model propagation via NODE\_OPTIONS
(Matteo Collina)
[#63972](https://redirect.github.com/nodejs/node/pull/63972)
-
\[[`aa2f3c066e`](https://redirect.github.com/nodejs/node/commit/aa2f3c066e)]
- **child\_process**: pass spawn options to the binding positionally
(Yagiz Nizipli)
[#63930](https://redirect.github.com/nodejs/node/pull/63930)
-
\[[`fcf32cf77a`](https://redirect.github.com/nodejs/node/commit/fcf32cf77a)]
- **child\_process**: serialize advanced IPC messages natively (Yagiz
Nizipli)
[#63933](https://redirect.github.com/nodejs/node/pull/63933)
-
\[[`7907134734`](https://redirect.github.com/nodejs/node/commit/7907134734)]
- **crypto**: reject small-order EdDSA points during verify (Filip
Skokan)
[#64026](https://redirect.github.com/nodejs/node/pull/64026)
-
\[[`b505cd5465`](https://redirect.github.com/nodejs/node/commit/b505cd5465)]
- **crypto**: support non-byte WebCrypto lengths and cSHAKE (Filip
Skokan)
[#63988](https://redirect.github.com/nodejs/node/pull/63988)
-
\[[`0f54a872e2`](https://redirect.github.com/nodejs/node/commit/0f54a872e2)]
- **crypto**: share WebCrypto method and usage helpers (Filip Skokan)
[#63975](https://redirect.github.com/nodejs/node/pull/63975)
-
\[[`824ec11c05`](https://redirect.github.com/nodejs/node/commit/824ec11c05)]
- **crypto**: refactor keyObject.toCryptoKey() and
SubtleCrypto.getPublicKey() (Filip Skokan)
[#63622](https://redirect.github.com/nodejs/node/pull/63622)
-
\[[`73aba92689`](https://redirect.github.com/nodejs/node/commit/73aba92689)]
- **crypto**: coerce -0 to +0 before native calls (Filip Skokan)
[#63556](https://redirect.github.com/nodejs/node/pull/63556)
-
\[[`c83b79874e`](https://redirect.github.com/nodejs/node/commit/c83b79874e)]
- **crypto**: reject invalid raw key imports (Filip Skokan)
[#63134](https://redirect.github.com/nodejs/node/pull/63134)
-
\[[`934fda64b9`](https://redirect.github.com/nodejs/node/commit/934fda64b9)]
- **crypto**: improve accuracy of SubtleCrypto.supports (Filip Skokan)
[#63104](https://redirect.github.com/nodejs/node/pull/63104)
-
\[[`e392e1f791`](https://redirect.github.com/nodejs/node/commit/e392e1f791)]
- **crypto**: fix large DH generator validation (Tobias NieÃen)
[#64092](https://redirect.github.com/nodejs/node/pull/64092)
-
\[[`e75a363e70`](https://redirect.github.com/nodejs/node/commit/e75a363e70)]
- **crypto**: use EVP\_MAC for HMAC on OpenSSL >=3 (Filip Skokan)
[#63942](https://redirect.github.com/nodejs/node/pull/63942)
-
\[[`adbaf7af9b`](https://redirect.github.com/nodejs/node/commit/adbaf7af9b)]
- **crypto**: make webcrypto aliasKeyFormat directional (Filip Skokan)
[#63910](https://redirect.github.com/nodejs/node/pull/63910)
-
\[[`bb1aea8897`](https://redirect.github.com/nodejs/node/commit/bb1aea8897)]
- **crypto**: fix unhandled error in Hash.\_transform (Haram Jeong)
[#63261](https://redirect.github.com/nodejs/node/pull/63261)
-
\[[`12c87732c1`](https://redirect.github.com/nodejs/node/commit/12c87732c1)]
- **crypto**: handle cipher context allocation failures (Tian Teng)
[#63542](https://redirect.github.com/nodejs/node/pull/63542)
-
\[[`858496b453`](https://redirect.github.com/nodejs/node/commit/858496b453)]
- **crypto**: deduplicate X509 subject matching logic (Tobias NieÃen)
[#63644](https://redirect.github.com/nodejs/node/pull/63644)
-
\[[`9a29cb0964`](https://redirect.github.com/nodejs/node/commit/9a29cb0964)]
- **crypto**: fix warnings in test\_node\_crypto.cc (Maya Lekova)
[#63490](https://redirect.github.com/nodejs/node/pull/63490)
-
\[[`8bb536066d`](https://redirect.github.com/nodejs/node/commit/8bb536066d)]
- **crypto**: optimize normalizeAlgorithm dispatch hot path (Filip
Skokan)
[#62756](https://redirect.github.com/nodejs/node/pull/62756)
-
\[[`329e5496ff`](https://redirect.github.com/nodejs/node/commit/329e5496ff)]
- **crypto,tls**: do not ignore BN\_get\_word error (Tobias NieÃen)
[#63895](https://redirect.github.com/nodejs/node/pull/63895)
-
\[[`97b7a3f9c7`](https://redirect.github.com/nodejs/node/commit/97b7a3f9c7)]
- **debugger**: add --max-hit option to probe mode (Joyee Cheung)
[#63704](https://redirect.github.com/nodejs/node/pull/63704)
-
\[[`9098585c5e`](https://redirect.github.com/nodejs/node/commit/9098585c5e)]
- **debugger**: add more logs to probe mode (Joyee Cheung)
[#63663](https://redirect.github.com/nodejs/node/pull/63663)
-
\[[`59cca26cd5`](https://redirect.github.com/nodejs/node/commit/59cca26cd5)]
- **debugger**: surface inspector failures in probe mode (Joyee Cheung)
[#63437](https://redirect.github.com/nodejs/node/pull/63437)
-
\[[`2922290eae`](https://redirect.github.com/nodejs/node/commit/2922290eae)]
- **debugger**: disambiguate probe location binding (Joyee Cheung)
[#63286](https://redirect.github.com/nodejs/node/pull/63286)
-
\[[`6fb2c2c7e2`](https://redirect.github.com/nodejs/node/commit/6fb2c2c7e2)]
- **debugger**: lazily wait for initial break output (Trivikram Kamat)
[#63969](https://redirect.github.com/nodejs/node/pull/63969)
-
\[[`688e792551`](https://redirect.github.com/nodejs/node/commit/688e792551)]
- **debugger**: defer probe pause handling until startup (Trivikram
Kamat)
[#63608](https://redirect.github.com/nodejs/node/pull/63608)
-
\[[`1ac93cc05a`](https://redirect.github.com/nodejs/node/commit/1ac93cc05a)]
- **debugger**: await initialization after run and restart (Trivikram
Kamat)
[#63607](https://redirect.github.com/nodejs/node/pull/63607)
-
\[[`92a909cf72`](https://redirect.github.com/nodejs/node/commit/92a909cf72)]
- **debugger,test**: deflake resume failure test and add debug logs
(Joyee Cheung)
[#63524](https://redirect.github.com/nodejs/node/pull/63524)
-
\[[`8b37af8b11`](https://redirect.github.com/nodejs/node/commit/8b37af8b11)]
- **deps**: V8: backport
[`bef0d9c`](https://redirect.github.com/nodejs/node/commit/bef0d9c1bc90)
(Joyee Cheung)
[#62132](https://redirect.github.com/nodejs/node/pull/62132)
-
\[[`8832126422`](https://redirect.github.com/nodejs/node/commit/8832126422)]
- **deps**: V8: cherry-pick
[`64b36b4`](https://redirect.github.com/nodejs/node/commit/64b36b441179)
(Dan Carney)
[#61712](https://redirect.github.com/nodejs/node/pull/61712)
-
\[[`75990c2cd6`](https://redirect.github.com/nodejs/node/commit/75990c2cd6)]
- **deps**: update googletest to
[`8b53336`](https://redirect.github.com/nodejs/node/commit/8b53336594cc52213c6c2c7a0b29194fa896d039)
(Node.js GitHub Bot)
[#64181](https://redirect.github.com/nodejs/node/pull/64181)
-
\[[`8500c7ba86`](https://redirect.github.com/nodejs/node/commit/8500c7ba86)]
- **deps**: update sqlite to 3.53.3 (Node.js GitHub Bot)
[#64180](https://redirect.github.com/nodejs/node/pull/64180)
-
\[[`dc78091b45`](https://redirect.github.com/nodejs/node/commit/dc78091b45)]
- **deps**: c-ares: cherry-pick
[`8ba37af`](https://redirect.github.com/nodejs/node/commit/8ba37af8e3fb)
(RenÊ)
[#64110](https://redirect.github.com/nodejs/node/pull/64110)
-
\[[`873cc72125`](https://redirect.github.com/nodejs/node/commit/873cc72125)]
- **deps**: update googletest to
[`0b1e895`](https://redirect.github.com/nodejs/node/commit/0b1e895ba4226c2fda5ee0178c9b5b1195a741aa)
(Node.js GitHub Bot)
[#64039](https://redirect.github.com/nodejs/node/pull/64039)
-
\[[`1d3d166538`](https://redirect.github.com/nodejs/node/commit/1d3d166538)]
- **deps**: update acorn to 8.17.0 (Node.js GitHub Bot)
[#63901](https://redirect.github.com/nodejs/node/pull/63901)
-
\[[`35222948be`](https://redirect.github.com/nodejs/node/commit/35222948be)]
- **(SEMVER-MINOR)** **deps**: update OpenSSL build config to support
compression (Tim Perry)
[#62217](https://redirect.github.com/nodejs/node/pull/62217)
-
\[[`e40cee5f79`](https://redirect.github.com/nodejs/node/commit/e40cee5f79)]
- **deps**: upgrade npm to 11.17.0 (npm team)
[#63857](https://redirect.github.com/nodejs/node/pull/63857)
-
\[[`85c6d46606`](https://redirect.github.com/nodejs/node/commit/85c6d46606)]
- **deps**: add ngtcp2\_fmt.c to build configuration (ngtcp2.gyp) (æ˛é¸ŋéŖ)
[#63821](https://redirect.github.com/nodejs/node/pull/63821)
-
\[[`d2ea8b7a8c`](https://redirect.github.com/nodejs/node/commit/d2ea8b7a8c)]
- **deps**: update googletest to
[`7140cd4`](https://redirect.github.com/nodejs/node/commit/7140cd416cecd7462a8aae488024abeee55598e4)
(Node.js GitHub Bot)
[#63775](https://redirect.github.com/nodejs/node/pull/63775)
-
\[[`25b4d57bb6`](https://redirect.github.com/nodejs/node/commit/25b4d57bb6)]
- **deps**: update sqlite to 3.53.2 (Node.js GitHub Bot)
[#63774](https://redirect.github.com/nodejs/node/pull/63774)
-
\[[`a96368e4c7`](https://redirect.github.com/nodejs/node/commit/a96368e4c7)]
- **deps**: update zlib to 1.3.2.1-motley-3246f1b (Node.js GitHub Bot)
[#63773](https://redirect.github.com/nodejs/node/pull/63773)
-
\[[`b59f1f5f37`](https://redirect.github.com/nodejs/node/commit/b59f1f5f37)]
- **deps**: update amaro to 1.1.10 (Node.js GitHub Bot)
[#63670](https://redirect.github.com/nodejs/node/pull/63670)
-
\[[`0b3b56ee95`](https://redirect.github.com/nodejs/node/commit/0b3b56ee95)]
- **deps**: update googletest to
[`8736d2c`](https://redirect.github.com/nodejs/node/commit/8736d2cd5c1dcba41170ed2fddca14021d4916c3)
(Node.js GitHub Bot)
[#63669](https://redirect.github.com/nodejs/node/pull/63669)
-
\[[`aa67b5b9c4`](https://redirect.github.com/nodejs/node/commit/aa67b5b9c4)]
- **dgram**: add synchronous Socket connectSync() (Guy Bedford)
[#63932](https://redirect.github.com/nodejs/node/pull/63932)
-
\[[`ef38374875`](https://redirect.github.com/nodejs/node/commit/ef38374875)]
- **dgram**: add synchronous Socket.prototype.bindSync() (Guy Bedford)
[#63838](https://redirect.github.com/nodejs/node/pull/63838)
-
\[[`6edc3a9967`](https://redirect.github.com/nodejs/node/commit/6edc3a9967)]
- **dgram**: skip dns.lookup() for literal IP addresses (Ruben
Bridgewater)
[#64133](https://redirect.github.com/nodejs/node/pull/64133)
-
\[[`d4cfe2d8ac`](https://redirect.github.com/nodejs/node/commit/d4cfe2d8ac)]
- **dns**: coerce -0 to +0 in lookup and resolver inputs (Filip Skokan)
[#63556](https://redirect.github.com/nodejs/node/pull/63556)
-
\[[`91c9ce5a45`](https://redirect.github.com/nodejs/node/commit/91c9ce5a45)]
- **doc**: improve `fs.StatFs` properties descriptions (aymanxdev)
[#62578](https://redirect.github.com/nodejs/node/pull/62578)
-
\[[`54e21675fa`](https://redirect.github.com/nodejs/node/commit/54e21675fa)]
- **doc**: fix inconsistencies in CJS code snippets (Antoine du Hamel)
[#63199](https://redirect.github.com/nodejs/node/pull/63199)
-
\[[`64c23daa76`](https://redirect.github.com/nodejs/node/commit/64c23daa76)]
- **doc**: remove typo comma from man page (Vas Sudanagunta)
[#63080](https://redirect.github.com/nodejs/node/pull/63080)
-
\[[`bc943cd34a`](https://redirect.github.com/nodejs/node/commit/bc943cd34a)]
- **doc**: update Http2SecureServer.on("timeout") default value (YuSheng
Chen)
[#64187](https://redirect.github.com/nodejs/node/pull/64187)
-
\[[`a46bc452a6`](https://redirect.github.com/nodejs/node/commit/a46bc452a6)]
- **doc**: add note on visibility of CI failures to new contributor
guide (Stewart X Addison)
[#64256](https://redirect.github.com/nodejs/node/pull/64256)
-
\[[`c0fb52506c`](https://redirect.github.com/nodejs/node/commit/c0fb52506c)]
- **doc**: clarify HTTP/1.1 response ordering (Matteo Collina)
[#64213](https://redirect.github.com/nodejs/node/pull/64213)
-
\[[`d3073a7ba6`](https://redirect.github.com/nodejs/node/commit/d3073a7ba6)]
- **doc**: recommend node-stress-single-test for flaky tests (Trivikram
Kamat)
[#64223](https://redirect.github.com/nodejs/node/pull/64223)
-
\[[`bb9951ead0`](https://redirect.github.com/nodejs/node/commit/bb9951ead0)]
- **doc**: fix typo in examples (Vas Sudanagunta)
[#64184](https://redirect.github.com/nodejs/node/pull/64184)
-
\[[`fe674e96fc`](https://redirect.github.com/nodejs/node/commit/fe674e96fc)]
- **doc**: clarify defense-in-depth issues (Matteo Collina)
[#64215](https://redirect.github.com/nodejs/node/pull/64215)
-
\[[`faad042184`](https://redirect.github.com/nodejs/node/commit/faad042184)]
- **doc**: add guide and answers to FAQs for first-time contributors
(Joyee Cheung)
[#63685](https://redirect.github.com/nodejs/node/pull/63685)
-
\[[`79d685adf3`](https://redirect.github.com/nodejs/node/commit/79d685adf3)]
- **doc**: update `Http2Server.close` & `Http2SecureServer.close`
(YuSheng Chen)
[#63298](https://redirect.github.com/nodejs/node/pull/63298)
-
\[[`744e40e05e`](https://redirect.github.com/nodejs/node/commit/744e40e05e)]
- **doc**: update list of people in `SECURITY.md` (Richard Lau)
[#64152](https://redirect.github.com/nodejs/node/pull/64152)
-
\[[`185f57c4a4`](https://redirect.github.com/nodejs/node/commit/185f57c4a4)]
- **doc**: add missing option to man page (Richard Lau)
[#64156](https://redirect.github.com/nodejs/node/pull/64156)
-
\[[`8933303568`](https://redirect.github.com/nodejs/node/commit/8933303568)]
- **doc**: fix callback example import in fs docs (Kamal Rawal)
[#63912](https://redirect.github.com/nodejs/node/pull/63912)
-
\[[`3a0549dacb`](https://redirect.github.com/nodejs/node/commit/3a0549dacb)]
- **doc**: fix keepAliveTimeout default in http.createServer options
(Jahanzaib iqbal)
[#63974](https://redirect.github.com/nodejs/node/pull/63974)
-
\[[`5a35e48d08`](https://redirect.github.com/nodejs/node/commit/5a35e48d08)]
- **doc**: add sxa GPG key
([`ed25519`](https://redirect.github.com/nodejs/node/commit/ed25519))
(Stewart X Addison)
[#64193](https://redirect.github.com/nodejs/node/pull/64193)
-
\[[`66e7f815f1`](https://redirect.github.com/nodejs/node/commit/66e7f815f1)]
- **doc**: add aduh95 to last security release steward (Antoine du
Hamel)
[#63981](https://redirect.github.com/nodejs/node/pull/63981)
-
\[[`a7e35040dd`](https://redirect.github.com/nodejs/node/commit/a7e35040dd)]
- **doc**: fix typo in util.md (Daijiro Wachi)
[#63961](https://redirect.github.com/nodejs/node/pull/63961)
-
\[[`d74b3a7e90`](https://redirect.github.com/nodejs/node/commit/d74b3a7e90)]
- **doc**: clarify callback exceptions (Matteo Collina)
[#63939](https://redirect.github.com/nodejs/node/pull/63939)
-
\[[`b7a8f8fabd`](https://redirect.github.com/nodejs/node/commit/b7a8f8fabd)]
- **doc**: fix incorrect test runner mock examples (Kimaswa Emmanuel
Yusufu)
[#63656](https://redirect.github.com/nodejs/node/pull/63656)
-
\[[`f11aa690cd`](https://redirect.github.com/nodejs/node/commit/f11aa690cd)]
- **doc**: fix typo in cli.md (Daijiro Wachi)
[#63883](https://redirect.github.com/nodejs/node/pull/63883)
-
\[[`df85f50269`](https://redirect.github.com/nodejs/node/commit/df85f50269)]
- **doc**: fix typo in vm.md (Daijiro Wachi)
[#63881](https://redirect.github.com/nodejs/node/pull/63881)
-
\[[`a00a567175`](https://redirect.github.com/nodejs/node/commit/a00a567175)]
- **doc**: fix typo in packages.md (Daijiro Wachi)
[#63882](https://redirect.github.com/nodejs/node/pull/63882)
-
\[[`206c1b8437`](https://redirect.github.com/nodejs/node/commit/206c1b8437)]
- **doc**: fix a/an article typos in module, util, and dns (Daijiro
Wachi)
[#63766](https://redirect.github.com/nodejs/node/pull/63766)
-
\[[`e3e5ef1cff`](https://redirect.github.com/nodejs/node/commit/e3e5ef1cff)]
- **doc**: update npm supported versions link (hojeong park)
[#63672](https://redirect.github.com/nodejs/node/pull/63672)
-
\[[`e3c4852413`](https://redirect.github.com/nodejs/node/commit/e3c4852413)]
- **doc**: fix AES-OCB IV length in SubtleCrypto.supports example
(Anshika Jain)
[#63717](https://redirect.github.com/nodejs/node/pull/63717)
-
\[[`0b3fbc82d7`](https://redirect.github.com/nodejs/node/commit/0b3fbc82d7)]
- **doc**: add webstreams to args for `pipeline` from `stream/promises`
(David Sanders)
[#63628](https://redirect.github.com/nodejs/node/pull/63628)
-
\[[`62078a8328`](https://redirect.github.com/nodejs/node/commit/62078a8328)]
- **doc**: fix "used to sent" â "used to send" in http2 (Daijiro Wachi)
[#63700](https://redirect.github.com/nodejs/node/pull/63700)
-
\[[`fd74eefb23`](https://redirect.github.com/nodejs/node/commit/fd74eefb23)]
- **doc**: clarify tty raw mode applies to input processing only
(Muhammad Zeeshan)
[#63438](https://redirect.github.com/nodejs/node/pull/63438)
-
\[[`42cd7e47de`](https://redirect.github.com/nodejs/node/commit/42cd7e47de)]
- **doc**: add worker\_threads history entries (Bob Put)
[#63545](https://redirect.github.com/nodejs/node/pull/63545)
-
\[[`d6ab039f24`](https://redirect.github.com/nodejs/node/commit/d6ab039f24)]
- **(SEMVER-MINOR)** **doc**: update `blockList` stability status to
release candidate (alphaleadership)
[#63050](https://redirect.github.com/nodejs/node/pull/63050)
-
\[[`56bdd87378`](https://redirect.github.com/nodejs/node/commit/56bdd87378)]
- **doc**: move hyperlinks outside of text blocks (Aviv Keller)
[#63493](https://redirect.github.com/nodejs/node/pull/63493)
-
\[[`1da05fb79d`](https://redirect.github.com/nodejs/node/commit/1da05fb79d)]
- **doc**: mark stream.compose stable (Matteo Collina)
[#62562](https://redirect.github.com/nodejs/node/pull/62562)
-
\[[`7bb6dab70c`](https://redirect.github.com/nodejs/node/commit/7bb6dab70c)]
- **doc,crypto**: mark argon2 and encap/decap as stable (Filip Skokan)
[#63924](https://redirect.github.com/nodejs/node/pull/63924)
-
\[[`1a4edb3c22`](https://redirect.github.com/nodejs/node/commit/1a4edb3c22)]
- **doc,lib**: align WebCrypto names with spec (Filip Skokan)
[#63518](https://redirect.github.com/nodejs/node/pull/63518)
-
\[[`3c1636dabf`](https://redirect.github.com/nodejs/node/commit/3c1636dabf)]
- **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag
(Efe)
[#62300](https://redirect.github.com/nodejs/node/pull/62300)
-
\[[`e0f211ca79`](https://redirect.github.com/nodejs/node/commit/e0f211ca79)]
- **events**: improve `addAbortListener` perf by caching options object
(Raz Luvaton)
[#52367](https://redirect.github.com/nodejs/node/pull/52367)
-
\[[`a124429b36`](https://redirect.github.com/nodejs/node/commit/a124429b36)]
- **fs**: do not treat EPERM as ENOTEMPTY on Windows (Kirill Saied)
[#63709](https://redirect.github.com/nodejs/node/pull/63709)
-
\[[`e323e877be`](https://redirect.github.com/nodejs/node/commit/e323e877be)]
- **(SEMVER-MINOR)** **fs**: support caller-supplied readFile() buffers
(Matteo Collina)
[#63634](https://redirect.github.com/nodejs/node/pull/63634)
-
\[[`a41b4824d7`](https://redirect.github.com/nodejs/node/commit/a41b4824d7)]
- **fs**: prevent spurious recursive watch events on prefix siblings
(Marco)
[#63095](https://redirect.github.com/nodejs/node/pull/63095)
-
\[[`c63e00e3a5`](https://redirect.github.com/nodejs/node/commit/c63e00e3a5)]
- **fs**: ignore deleted dirs in recursive watch scan (Trivikram Kamat)
[#63686](https://redirect.github.com/nodejs/node/pull/63686)
-
\[[`d3d7cd05e3`](https://redirect.github.com/nodejs/node/commit/d3d7cd05e3)]
- **fs**: coerce -0 to +0 in mode flags and watch intervals (Filip
Skokan)
[#63556](https://redirect.github.com/nodejs/node/pull/63556)
-
\[[`6f6387ecb3`](https://redirect.github.com/nodejs/node/commit/6f6387ecb3)]
- **gyp**: update deps gypfiles (Nad Alaba)
[#63117](https://redirect.github.com/nodejs/node/pull/63117)
-
\[[`592544af44`](https://redirect.github.com/nodejs/node/commit/592544af44)]
- **http**: document and validate options.path when it's in
absolute-form (Joyee Cheung)
[#64108](https://redirect.github.com/nodejs/node/pull/64108)
-
\[[`c1248c9544`](https://redirect.github.com/nodejs/node/commit/c1248c9544)]
- **(SEMVER-MINOR)** **http**: add httpValidation option to configure
header value validation (RajeshKumar11)
[#61597](https://redirect.github.com/nodejs/node/pull/61597)
-
\[[`85a223bf15`](https://redirect.github.com/nodejs/node/commit/85a223bf15)]
- **http**: fix drain event with cork/uncork (David Evans)
[#64038](https://redirect.github.com/nodejs/node/pull/64038)
-
\[[`8b060a9628`](https://redirect.github.com/nodejs/node/commit/8b060a9628)]
- **inspector**: fix crash when writing to closed inspector socket
(ympark2011)
[#64209](https://redirect.github.com/nodejs/node/pull/64209)
-
\[[`e68a3d33ac`](https://redirect.github.com/nodejs/node/commit/e68a3d33ac)]
- **inspector**: fix inspector.close() documented behavior (Chengzhong
Wu) [#63837](https://redirect.github.com/nodejs/node/pull/63837)
-
\[[`d3682930b7`](https://redirect.github.com/nodejs/node/commit/d3682930b7)]
- **lib**: fix missing lazyDOMException import (Filip Skokan)
[#64033](https://redirect.github.com/nodejs/node/pull/64033)
-
\[[`af9ea9cfcf`](https://redirect.github.com/nodejs/node/commit/af9ea9cfcf)]
- **lib**: reject string "0" in validatePort when allowZero is false
(Daijiro Wachi)
[#64174](https://redirect.github.com/nodejs/node/pull/64174)
-
\[[`cd1ea26110`](https://redirect.github.com/nodejs/node/commit/cd1ea26110)]
- **lib**: use `__proto__: null` when calling `ObjectDefineProperty`
(Antoine du Hamel)
[#64239](https://redirect.github.com/nodejs/node/pull/64239)
-
\[[`5b264398ce`](https://redirect.github.com/nodejs/node/commit/5b264398ce)]
- **lib**: lazily initialize kEvents and kHandlers maps (Guilherme
AraÃējo)
[#63702](https://redirect.github.com/nodejs/node/pull/63702)
-
\[[`823efe8c71`](https://redirect.github.com/nodejs/node/commit/823efe8c71)]
- **lib**: improve control abstraction coverage in frozen intrinsics
(Renegade334)
[#63698](https://redirect.github.com/nodejs/node/pull/63698)
-
\[[`7f4af5568f`](https://redirect.github.com/nodejs/node/commit/7f4af5568f)]
- **lib**: add Iterator global to primordials (Renegade334)
[#63698](https://redirect.github.com/nodejs/node/pull/63698)
-
\[[`c8f3f5e5a5`](https://redirect.github.com/nodejs/node/commit/c8f3f5e5a5)]
- **lib**: make `Navigator#language` getter throw on invalid `this`
(Mohamed Sayed)
[#63601](https://redirect.github.com/nodejs/node/pull/63601)
-
\[[`1ebbbd59cf`](https://redirect.github.com/nodejs/node/commit/1ebbbd59cf)]
- **lib**: optimize webidl conversion options (Filip Skokan)
[#62756](https://redirect.github.com/nodejs/node/pull/62756)
-
\[[`88590d1bb7`](https://redirect.github.com/nodejs/node/commit/88590d1bb7)]
- **meta**: bump actions/checkout from 6.0.2 to 6.0.3 (dependabot\[bot])
[#63726](https://redirect.github.com/nodejs/node/pull/63726)
-
\[[`0ea9cb9630`](https://redirect.github.com/nodejs/node/commit/0ea9cb9630)]
- **meta**: bump actions/upload-artifact from 7.0.0 to 7.0.1
(dependabot\[bot])
[#62850](https://redirect.github.com/nodejs/node/pull/62850)
-
\[[`f7275a0864`](https://redirect.github.com/nodejs/node/commit/f7275a0864)]
- **meta**: fix linter warning in `stale.yml` (Antoine du Hamel)
[#64281](https://redirect.github.com/nodejs/node/pull/64281)
-
\[[`3a77d21d8c`](https://redirect.github.com/nodejs/node/commit/3a77d21d8c)]
- **meta**: bump actions/cache from 5.0.5 to 6.1.0 (dependabot\[bot])
[#64248](https://redirect.github.com/nodejs/node/pull/64248)
-
\[[`84e2836c95`](https://redirect.github.com/nodejs/node/commit/84e2836c95)]
- **meta**: bump github/codeql-action/autobuild from 4.36.1 to 4.36.2
(dependabot\[bot])
[#64247](https://redirect.github.com/nodejs/node/pull/64247)
-
\[[`09f800eec6`](https://redirect.github.com/nodejs/node/commit/09f800eec6)]
- **meta**: bump github/codeql-action/analyze from 4.36.1 to 4.36.2
(dependabot\[bot])
[#64246](https://redirect.github.com/nodejs/node/pull/64246)
-
\[[`6df1f97e64`](https://redirect.github.com/nodejs/node/commit/6df1f97e64)]
- **meta**: bump codecov/codecov-action from 6.0.1 to 7.0.0
(dependabot\[bot])
[#64244](https://redirect.github.com/nodejs/node/pull/64244)
-
\[[`737eb89651`](https://redirect.github.com/nodejs/node/commit/737eb89651)]
- **meta**: bump rtCamp/action-slack-notify from 2.3.3 to 2.4.0
(dependabot\[bot])
[#64243](https://redirect.github.com/nodejs/node/pull/64243)
-
\[[`dac3cd8b8f`](https://redirect.github.com/nodejs/node/commit/dac3cd8b8f)]
- **meta**: bump github/codeql-action/init from 4.36.1 to 4.36.2
(dependabot\[bot])
[#64242](https://redirect.github.com/nodejs/node/pull/64242)
-
\[[`108a6bc481`](https://redirect.github.com/nodejs/node/commit/108a6bc481)]
- **meta**: bump github/codeql-action/upload-sarif from 4.36.1 to 4.36.2
(dependabot\[bot])
[#64240](https://redirect.github.com/nodejs/node/pull/64240)
-
\[[`34d09a725d`](https://redirect.github.com/nodejs/node/commit/34d09a725d)]
- **meta**: clarify V8 flags are outside threat model (Matteo Collina)
[#64224](https://redirect.github.com/nodejs/node/pull/64224)
-
\[[`944d9bc25f`](https://redirect.github.com/nodejs/node/commit/944d9bc25f)]
- **meta**: move one or more collaborators to emeritus (Node.js GitHub
Bot) [#64057](https://redirect.github.com/nodejs/node/pull/64057)
-
\[[`cc22555402`](https://redirect.github.com/nodejs/node/commit/cc22555402)]
- **meta**: update status of past strategic initiatives (Joyee Cheung)
[#63480](https://redirect.github.com/nodejs/node/pull/63480)
-
\[[`da7a21931e`](https://redirect.github.com/nodejs/node/commit/da7a21931e)]
- **meta**: speed up stale bot (Aviv Keller)
[#64075](https://redirect.github.com/nodejs/node/pull/64075)
-
\[[`7bfcf7ca56`](https://redirect.github.com/nodejs/node/commit/7bfcf7ca56)]
- **meta**: bump github/codeql-action from 4.35.3 to 4.36.1
(dependabot\[bot])
[#63724](https://redirect.github.com/nodejs/node/pull/63724)
-
\[[`db6c983cdd`](https://redirect.github.com/nodejs/node/commit/db6c983cdd)]
- **meta**: bump actions/cache from 5.0.4 to 5.0.5 (dependabot\[bot])
[#62847](https://redirect.github.com/nodejs/node/pull/62847)
-
\[[`9e4f1339d1`](https://redirect.github.com/nodejs/node/commit/9e4f1339d1)]
- **meta**: bump codecov/codecov-action from 6.0.0 to 6.0.1
(dependabot\[bot])
[#63725](https://redirect.github.com/nodejs/node/pull/63725)
-
\[[`92c98d3ade`](https://redirect.github.com/nodejs/node/commit/92c98d3ade)]
- **meta**: bump actions/stale from 10.2.0 to 10.3.0 (dependabot\[bot])
[#63728](https://redirect.github.com/nodejs/node/pull/63728)
-
\[[`bbd3ffde89`](https://redirect.github.com/nodejs/node/commit/bbd3ffde89)]
- **meta**: bump step-security/harden-runner from 2.19.0 to 2.19.4
(dependabot\[bot])
[#63727](https://redirect.github.com/nodejs/node/pull/63727)
-
\[[`a6dd675c82`](https://redirect.github.com/nodejs/node/commit/a6dd675c82)]
- **module**: enable import support for addons by default (Chengzhong
Wu) [#64221](https://redirect.github.com/nodejs/node/pull/64221)
-
\[[`fb2ccb15a1`](https://redirect.github.com/nodejs/node/commit/fb2ccb15a1)]
- **module**: use file: URL as sourceURL for type-stripped CommonJS
(Joyee Cheung)
[#63705](https://redirect.github.com/nodejs/node/pull/63705)
-
\[[`b9e17dc424`](https://redirect.github.com/nodejs/node/commit/b9e17dc424)]
- **net**: early TCP binding via synchronous net.BoundSocket (Guy
Bedford)
[#63951](https://redirect.github.com/nodejs/node/pull/63951)
-
\[[`a534b65815`](https://redirect.github.com/nodejs/node/commit/a534b65815)]
- **(SEMVER-MINOR)** **net**: support TCP\_KEEPINTVL and TCP\_KEEPCNT in
setKeepAlive (Guy Bedford)
[#63825](https://redirect.github.com/nodejs/node/pull/63825)
-
\[[`c55dd030e6`](https://redirect.github.com/nodejs/node/commit/c55dd030e6)]
- **net**: coerce -0 to +0 in BlockList prefixes (Filip Skokan)
[#63556](https://redirect.github.com/nodejs/node/pull/63556)
-
\[[`a23cdec683`](https://redirect.github.com/nodejs/node/commit/a23cdec683)]
- **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop
iteration (Pablo Erhard)
[#62935](https://redirect.github.com/nodejs/node/pull/62935)
-
\[[`f08b83bc1d`](https://redirect.github.com/nodejs/node/commit/f08b83bc1d)]
- **perf\_hooks**: add NODE\_PERFORMANCE\_GC\_MINOR\_MARK\_SWEEP
constant (Attila Szegedi)
[#63877](https://redirect.github.com/nodejs/node/pull/63877)
-
\[[`8d58e1b415`](https://redirect.github.com/nodejs/node/commit/8d58e1b415)]
- **process**: fix finalization cleanup ref tracking (Trivikram Kamat)
[#64087](https://redirect.github.com/nodejs/node/pull/64087)
-
\[[`c757e3ef59`](https://redirect.github.com/nodejs/node/commit/c757e3ef59)]
- **sqlite**: do not leave database open after failed open (Yagiz
Nizipli)
[#63854](https://redirect.github.com/nodejs/node/pull/63854)
-
\[[`87064a096b`](https://redirect.github.com/nodejs/node/commit/87064a096b)]
- **sqlite**: fix stack-use-after-scope with function callback
(ndossche)
[#63640](https://redirect.github.com/nodejs/node/pull/63640)
-
\[[`7428b57a37`](https://redirect.github.com/nodejs/node/commit/7428b57a37)]
- **(SEMVER-MINOR)** **src**: allow empty --experimental-config-file
(Marco Ippolito)
[#61610](https://redirect.github.com/nodejs/node/pull/61610)
-
\[[`d7946c9c07`](https://redirect.github.com/nodejs/node/commit/d7946c9c07)]
- **src**: add test flag to config file (Marco Ippolito)
[#60798](https://redirect.github.com/nodejs/node/pull/60798)
-
\[[`a642657d71`](https://redirect.github.com/nodejs/node/commit/a642657d71)]
- **src**: rename config file testRunner to test (Marco Ippolito)
[#60798](https://redirect.github.com/nodejs/node/pull/60798)
-
\[[`818b43d09e`](https://redirect.github.com/nodejs/node/commit/818b43d09e)]
- **src**: do not enable wasm trap handler if there's not enough vmem
(Joyee Cheung)
[#62132](https://redirect.github.com/nodejs/node/pull/62132)
-
\[[`af5e1a9729`](https://redirect.github.com/nodejs/node/commit/af5e1a9729)]
- **src**: fix escaping of single quotes in task runner (Antoine du
Hamel)
[#64089](https://redirect.github.com/nodejs/node/pull/64089)
-
\[[`8a5d3bc168`](https://redirect.github.com/nodejs/node/commit/8a5d3bc168)]
- **src**: abstract tracing agent for both legacy and perfetto
(Chengzhong Wu)
[#64053](https://redirect.github.com/nodejs/node/pull/64053)
-
\[[`ce6f29e45b`](https://redirect.github.com/nodejs/node/commit/ce6f29e45b)]
- **src**: avoid redundant call to `std::get_if<>()` (Tobias NieÃen)
[#64094](https://redirect.github.com/nodejs/node/pull/64094)
-
\[[`96478050f2`](https://redirect.github.com/nodejs/node/commit/96478050f2)]
- **src**: omit unconvertible names in cjs\_lexer::Parse (Yagiz Nizipli)
[#63943](https://redirect.github.com/nodejs/node/pull/63943)
-
\[[`0147ed746e`](https://redirect.github.com/nodejs/node/commit/0147ed746e)]
- **src**: guard OpenSSL compression header include (Filip Skokan)
[#64009](https://redirect.github.com/nodejs/node/pull/64009)
-
\[[`8d2858a9c4`](https://redirect.github.com/nodejs/node/commit/8d2858a9c4)]
- **src**: handle empty MaybeLocal in cjs\_lexer::Parse (Yagiz Nizipli)
[#63885](https://redirect.github.com/nodejs/node/pull/63885)
-
\[[`e5289d180f`](https://redirect.github.com/nodejs/node/commit/e5289d180f)]
- **src**: do not track weak `BaseObject`s as childrens of `Realm`s
(Anna Henningsen)
[#63842](https://redirect.github.com/nodejs/node/pull/63842)
-
\[[`e8352ff754`](https://redirect.github.com/nodejs/node/commit/e8352ff754)]
- **src**: allow tracking children in `MemoryTracker` with weak edges
(Anna Henningsen)
[#63842](https://redirect.github.com/nodejs/node/pull/63842)
-
\[[`a408f279c5`](https://redirect.github.com/nodejs/node/commit/a408f279c5)]
- **src**: use C++14 deprecated attribute for `NODE_DEPRECATED` (Anna
Henningsen)
[#63755](https://redirect.github.com/nodejs/node/pull/63755)
-
\[[`4b5eb7b72d`](https://redirect.github.com/nodejs/node/commit/4b5eb7b72d)]
- **src**: add cleanup hooks to `node::ObjectWrap` (Anna Henningsen)
[#63642](https://redirect.github.com/nodejs/node/pull/63642)
-
\[[`44976c6071`](https://redirect.github.com/nodejs/node/commit/44976c6071)]
- **src**: fix edge case when deflateInit2() fails with
Z\_VERSION\_ERROR (Nora Dossche)
[#63476](https://redirect.github.com/nodejs/node/pull/63476)
-
\[[`5b3bb284f3`](https://redirect.github.com/nodejs/node/commit/5b3bb284f3)]
- **src**: add Latin1 fast path in StringBytes::Encode utf8 (Mert Can
Altin)
[#63385](https://redirect.github.com/nodejs/node/pull/63385)
-
\[[`7cdad636c4`](https://redirect.github.com/nodejs/node/commit/7cdad636c4)]
- **src**: fix crash when reading length on Storage.prototype (Mohamed
Sayed)
[#63529](https://redirect.github.com/nodejs/node/pull/63529)
-
\[[`c438250c68`](https://redirect.github.com/nodejs/node/commit/c438250c68)]
- **stream**: cut per-chunk overhead in WHATWG streams (Matteo Collina)
[#64252](https://redirect.github.com/nodejs/node/pull/64252)
-
\[[`291c127947`](https://redirect.github.com/nodejs/node/commit/291c127947)]
- **stream**: reduce allocations on WHATWG streams hot paths (Matteo
Collina)
[#63876](https://redirect.github.com/nodejs/node/pull/63876)
-
\[[`3d91aeb434`](https://redirect.github.com/nodejs/node/commit/3d91aeb434)]
- **stream**: optimize pipeTo promise handling (Matteo Collina)
[#63572](https://redirect.github.com/nodejs/node/pull/63572)
-
\[[`fcbff00a44`](https://redirect.github.com/nodejs/node/commit/fcbff00a44)]
- **stream**: preserve half-open duplexes in async iteration (Efe)
[#64275](https://redirect.github.com/nodejs/node/pull/64275)
-
\[[`e57597173c`](https://redirect.github.com/nodejs/node/commit/e57597173c)]
- **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo
Collina)
[#64195](https://redirect.github.com/nodejs/node/pull/64195)
-
\[[`a48edf40e8`](https://redirect.github.com/nodejs/node/commit/a48edf40e8)]
- **stream**: proxy first own method in Readable.wrap() (Daijiro Wachi)
[#64048](https://redirect.github.com/nodejs/node/pull/64048)
-
\[[`f58c5bafcf`](https://redirect.github.com/nodejs/node/commit/f58c5bafcf)]
- **stream**: fix Writable.toWeb() desiredSize for non-object-mode
(Matteo Collina)
[#62986](https://redirect.github.com/nodejs/node/pull/62986)
-
\[[`7261276f45`](https://redirect.github.com/nodejs/node/commit/7261276f45)]
- **stream**: fix Utf8Stream stall after full write of multi-byte data
(Daijiro Wachi)
[#63964](https://redirect.github.com/nodejs/node/pull/63964)
-
\[[`1558986b78`](https://redirect.github.com/nodejs/node/commit/1558986b78)]
- **stream**: only pass the expected number of parameters to callbacks
(Antoine du Hamel)
[#63909](https://redirect.github.com/nodejs/node/pull/63909)
-
\[[`edef89ba6a`](https://redirect.github.com/nodejs/node/commit/edef89ba6a)]
- **stream**: fix dropped first chunk in Utf8Stream buffer mode (Daijiro
Wachi)
[#63833](https://redirect.github.com/nodejs/node/pull/63833)
-
\[[`915e3e2f42`](https://redirect.github.com/nodejs/node/commit/915e3e2f42)]
- **stream**: check done before backpressure in stream reader (Daijiro
Wachi)
[#63699](https://redirect.github.com/nodejs/node/pull/63699)
-
\[[`2d29628b5b`](https://redirect.github.com/nodejs/node/commit/2d29628b5b)]
- **test**: update WPT for WebCryptoAPI to
[`03a1476`](https://redirect.github.com/nodejs/node/commit/03a1476844)
(Node.js GitHub Bot)
[#63900](https://redirect.github.com/nodejs/node/pull/63900)
-
\[[`89e23b70c4`](https://redirect.github.com/nodejs/node/commit/89e23b70c4)]
- **test**: deflake test-debugger-probe-timeout (Joyee Cheung)
[#63547](https://redirect.github.com/nodejs/node/pull/63547)
-
\[[`54ca514414`](https://redirect.github.com/nodejs/node/commit/54ca514414)]
- **test**: make blob desiredSize assertion robust (Trivikram Kamat)
[#64106](https://redirect.github.com/nodejs/node/pull/64106)
-
\[[`01cbe530eb`](https://redirect.github.com/nodejs/node/commit/01cbe530eb)]
- **test**: update WPT for urlpattern to
[`11a459a`](https://redirect.github.com/nodejs/node/commit/11a459a2b1)
(Node.js GitHub Bot)
[#64037](https://redirect.github.com/nodejs/node/pull/64037)
-
\[[`6fcd3cf516`](https://redirect.github.com/nodejs/node/commit/6fcd3cf516)]
- **test**: improve lcov reporter snapshot diagnostics (Trivikram Kamat)
[#64049](https://redirect.github.com/nodejs/node/pull/64049)
-
\[[`f50a55d7e5`](https://redirect.github.com/nodejs/node/commit/f50a55d7e5)]
- **test**: keep finalization close fixture ref alive (Trivikram Kamat)
[#64085](https://redirect.github.com/nodejs/node/pull/64085)
-
\[[`3085714530`](https://redirect.github.com/nodejs/node/commit/3085714530)]
- **test**: fix typo from overriden to overridden (parkhojeong)
[#63403](https://redirect.github.com/nodejs/node/pull/63403)
-
\[[`9f5347e8df`](https://redirect.github.com/nodejs/node/commit/9f5347e8df)]
- **test**: mark hr-time WPT flaky on macos15-x64 (Trivikram Kamat)
[#64054](https://redirect.github.com/nodejs/node/pull/64054)
-
\[[`44b4fe4246`](https://redirect.github.com/nodejs/node/commit/44b4fe4246)]
- **test**: use one-off agent in http consumed timeout test (Trivikram
Kamat)
[#64052](https://redirect.github.com/nodejs/node/pull/64052)
-
\[[`2f567edaca`](https://redirect.github.com/nodejs/node/commit/2f567edaca)]
- **test**: fix flaky test-runner coverage threshold test (Trivikram
Kamat)
[#64051](https://redirect.github.com/nodejs/node/pull/64051)
-
\[[`a56fbb2d36`](https://redirect.github.com/nodejs/node/commit/a56fbb2d36)]
- **test**: tolerate duplicate watch change events (Trivikram Kamat)
[#63937](https://redirect.github.com/nodejs/node/pull/63937)
-
\[[`b636f4769c`](https://redirect.github.com/nodejs/node/commit/b636f4769c)]
- **test**: mark test-debugger-run-after-quit-restart as flaky on macOS
(Matteo Collina)
[#64006](https://redirect.github.com/nodejs/node/pull/64006)
-
\[[`ba23eb9717`](https://redirect.github.com/nodejs/node/commit/ba23eb9717)]
- **test**: update WPT for url to
[`d4598eb`](https://redirect.github.com/nodejs/node/commit/d4598eba09)
(Node.js GitHub Bot)
[#63899](https://redirect.github.com/nodejs/node/pull/63899)
-
\[[`bc420f20d8`](https://redirect.github.com/nodejs/node/commit/bc420f20d8)]
- **test**: update WPT for urlpattern to
[`23aac92`](https://redirect.github.com/nodejs/node/commit/23aac92784)
(Node.js GitHub Bot)
[#63898](https://redirect.github.com/nodejs/node/pull/63898)
-
\[[`d2c9c07af8`](https://redirect.github.com/nodejs/node/commit/d2c9c07af8)]
- **test**: add tests for 3 methods in utils (Daijiro Wachi)
[#63765](https://redirect.github.com/nodejs/node/pull/63765)
-
\[[`4e00c8ec2e`](https://redirect.github.com/nodejs/node/commit/4e00c8ec2e)]
- **test**: mark SEA tests flaky on linux arm debug (Trivikram Kamat)
[#63743](https://redirect.github.com/nodejs/node/pull/63743)
-
\[[`a17cf06d12`](https://redirect.github.com/nodejs/node/commit/a17cf06d12)]
- **test**: validate ERR\_INVALID\_THIS for scheduler methods (Daijiro
Wachi)
[#63764](https://redirect.github.com/nodejs/node/pull/63764)
-
\[[`d59d7fdd16`](https://redirect.github.com/nodejs/node/commit/d59d7fdd16)]
- **test**: add coverage outside SEA (Daijiro Wachi)
[#63744](https://redirect.github.com/nodejs/node/pull/63744)
-
\[[`71a32d31bf`](https://redirect.github.com/nodejs/node/commit/71a32d31bf)]
- **test**: update WPT for urlpattern to
[`2f28df5`](https://redirect.github.com/nodejs/node/commit/2f28df545c)
(Node.js GitHub Bot)
[#63771](https://redirect.github.com/nodejs/node/pull/63771)
-
\[[`28c77ab174`](https://redirect.github.com/nodejs/node/commit/28c77ab174)]
- **test**: make Brotli 16GB test wait for backpressure (Trivikram
Kamat)
[#63389](https://redirect.github.com/nodejs/node/pull/63389)
-
\[[`9a81921d4a`](https://redirect.github.com/nodejs/node/commit/9a81921d4a)]
- **test**: add regression test for using `ObjectWrap` in worker
(Mohamed Akram)
[#63642](https://redirect.github.com/nodejs/node/pull/63642)
-
\[[`88ab61f2f8`](https://redirect.github.com/nodejs/node/commit/88ab61f2f8)]
- **test**: accept SIGILL aborts in async-hooks tests (Trivikram Kamat)
[#63687](https://redirect.github.com/nodejs/node/pull/63687)
-
\[[`b4f5c86463`](https://redirect.github.com/nodejs/node/commit/b4f5c86463)]
- **test**: add more test cases for pathToFileURL (Rafael Gonzaga)
[#63293](https://redirect.github.com/nodejs/node/pull/63293)
-
\[[`812a66f0ac`](https://redirect.github.com/nodejs/node/commit/812a66f0ac)]
- **test**: update test426-fixtures to
[`2965987`](https://redirect.github.com/nodejs/node/commit/2965987bf4c96afa400c9356c8e620cb340aaee)
(Node.js GitHub Bot)
[#63668](https://redirect.github.com/nodejs/node/pull/63668)
-
\[[`2bf0de838d`](https://redirect.github.com/nodejs/node/commit/2bf0de838d)]
- **test**: cover webcrypto prototype pollution systematically (Filip
Skokan)
[#63520](https://redirect.github.com/nodejs/node/pull/63520)
-
\[[`bec6856ae8`](https://redirect.github.com/nodejs/node/commit/bec6856ae8)]
- **test,debugger**: add test for type stripping in debugger probe mode
(Joyee Cheung)
[#63748](https://redirect.github.com/nodejs/node/pull/63748)
-
\[[`a2b9095e03`](https://redirect.github.com/nodejs/node/commit/a2b9095e03)]
- **test\_runner**: avoid recompiling coverage globs for every file
(sangwook)
[#63675](https://redirect.github.com/nodejs/node/pull/63675)
-
\[[`02fbff446f`](https://redirect.github.com/nodejs/node/commit/02fbff446f)]
- **test\_runner**: cache `shouldSkipFileCoverage` result per URL
(sangwook)
[#63675](https://redirect.github.com/nodejs/node/pull/63675)
-
\[[`094869354a`](https://redirect.github.com/nodejs/node/commit/094869354a)]
- **test\_runner**: ignore erased TS lines in coverage (Matteo Collina)
[#63510](https://redirect.github.com/nodejs/node/pull/63510)
-
\[[`68edc2b009`](https://redirect.github.com/nodejs/node/commit/68edc2b009)]
- **test\_runner**: fix suite diagnostic chanel end (Moshe Atlow)
[#63533](https://redirect.github.com/nodejs/node/pull/63533)
-
\[[`659d5bf068`](https://redirect.github.com/nodejs/node/commit/659d5bf068)]
- **test\_runner**: add parentId to test events with testId (Moshe
Atlow)
[#63435](https://redirect.github.com/nodejs/node/pull/63435)
-
\[[`eaebeb8b88`](https://redirect.github.com/nodejs/node/commit/eaebeb8b88)]
- **test\_runner**: fix hooks test context (Moshe Atlow)
[#63285](https://redirect.github.com/nodejs/node/pull/63285)
-
\[[`d03d96889b`](https://redirect.github.com/nodejs/node/commit/d03d96889b)]
- **test\_runner**: add tags option and tag-name filter (Chemi Atlow)
[#63221](https://redirect.github.com/nodejs/node/pull/63221)
-
\[[`e8c3db1364`](https://redirect.github.com/nodejs/node/commit/e8c3db1364)]
- **test\_runner**: add `getTestContext()` (Moshe Atlow)
[#62501](https://redirect.github.com/nodejs/node/pull/62501)
-
\[[`345c591d10`](https://redirect.github.com/nodejs/node/commit/345c591d10)]
- **test\_runner**: filter execArgv fallback for child tests (Trivikram
Kamat)
[#64056](https://redirect.github.com/nodejs/node/pull/64056)
-
\[[`2f47fb23bf`](https://redirect.github.com/nodejs/node/commit/2f47fb23bf)]
- **test\_runner**: improve coverage failure diagnostics (Trivikram
Kamat)
[#64050](https://redirect.github.com/nodejs/node/pull/64050)
-
\[[`260cf1ac89`](https://redirect.github.com/nodejs/node/commit/260cf1ac89)]
- **test\_runner**: add timestamp to JUnit reporter testsuites
(sangwook)
[#64029](https://redirect.github.com/nodejs/node/pull/64029)
-
\[[`24140eafdf`](https://redirect.github.com/nodejs/node/commit/24140eafdf)]
- **test\_runner**: remove unused shuffleArrayWithSeed (Daijiro Wachi)
[#63847](https://redirect.github.com/nodejs/node/pull/63847)
-
\[[`b7fdb4891a`](https://redirect.github.com/nodejs/node/commit/b7fdb4891a)]
- **test\_runner**: fix watch cwd with isolation none (Trivikram Kamat)
[#63690](https://redirect.github.com/nodejs/node/pull/63690)
-
\[[`e48b307e09`](https://redirect.github.com/nodejs/node/commit/e48b307e09)]
- **timers**: reuse Timeout objects in setStreamTimeout (Matteo Collina)
[#64254](https://redirect.github.com/nodejs/node/pull/64254)
-
\[[`5396235993`](https://redirect.github.com/nodejs/node/commit/5396235993)]
- **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip
Skokan)
[#64119](https://redirect.github.com/nodejs/node/pull/64119)
-
\[[`a653e9bb57`](https://redirect.github.com/nodejs/node/commit/a653e9bb57)]
- **tls**: handle large RSA exponents in X.509 cert (Tobias NieÃen)
[#64093](https://redirect.github.com/nodejs/node/pull/64093)
-
\[[`5e901b5cd9`](https://redirect.github.com/nodejs/node/commit/5e901b5cd9)]
- **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim
Perry)
[#62217](https://redirect.github.com/nodejs/node/pull/62217)
-
\[[`3abcfa723c`](https://redirect.github.com/nodejs/node/commit/3abcfa723c)]
- **tls**: route event listener exceptions through error handlers
(Antoine du Hamel)
[#63822](https://redirect.github.com/nodejs/node/pull/63822)
-
\[[`eaba4cd59d`](https://redirect.github.com/nodejs/node/commit/eaba4cd59d)]
- **tools**: bump the eslint group in /tools/eslint with 8 updates
(dependabot\[bot])
[#64249](https://redirect.github.com/nodejs/node/pull/64249)
-
\[[`7d7ea1dbca`](https://redirect.github.com/nodejs/node/commit/7d7ea1dbca)]
- **tools**: update c-ares updater script (Antoine du Hamel)
[#64194](https://redirect.github.com/nodejs/node/pull/64194)
-
\[[`976827cd71`](https://redirect.github.com/nodejs/node/commit/976827cd71)]
- **tools**: validate version number in release proposal commit message
lint (Antoine du Hamel)
[#64070](https://redirect.github.com/nodejs/node/pull/64070)
-
\[[`cc0c586b52`](https://redirect.github.com/nodejs/node/commit/cc0c586b52)]
- **tools**: update sccache to v0.16.0 (MichaÃĢl Zasso)
[#63078](https://redirect.github.com/nodejs/node/pull/63078)
-
\[[`f0a35fa56a`](https://redirect.github.com/nodejs/node/commit/f0a35fa56a)]
- **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/lint-md
(dependabot\[bot])
[#63948](https://redirect.github.com/nodejs/node/pull/63948)
-
\[[`dafbd23240`](https://redirect.github.com/nodejs/node/commit/dafbd23240)]
- **tools**: bump js-yaml from 4.1.1 to 4.2.0 in /tools/eslint
(dependabot\[bot])
[#63947](https://redirect.github.com/nodejs/node/pull/63947)
-
\[[`0ae1552650`](https://redirect.github.com/nodejs/node/commit/0ae1552650)]
- **tools**: update the llhttp updater script (Antoine du Hamel)
[#63819](https://redirect.github.com/nodejs/node/pull/63819)
-
\[[`3623586d1f`](https://redirect.github.com/nodejs/node/commit/3623586d1f)]
- **tools**: align Bash snippets in GHA with `lint-sh` conventions
(Antoine du Hamel)
[#63829](https://redirect.github.com/nodejs/node/pull/63829)
-
\[[`64b130ce1d`](https://redirect.github.com/nodejs/node/commit/64b130ce1d)]
- **tools**: bump the eslint group in /tools/eslint with 7 updates
(dependabot\[bot])
[#63730](https://redirect.github.com/nodejs/node/pull/63730)
-
\[[`4900cac251`](https://redirect.github.com/nodejs/node/commit/4900cac251)]
- **tools**: fix zlib updater script (Antoine du Hamel)
[#63707](https://redirect.github.com/nodejs/node/pull/63707)
-
\[[`8edf3abafc`](https://redirect.github.com/nodejs/node/commit/8edf3abafc)]
- **typings**: add typing for crypto (Filip Skokan)
[#64122](https://redirect.github.com/nodejs/node/pull/64122)
-
\[[`d5be94e820`](https://redirect.github.com/nodejs/node/commit/d5be94e820)]
- **url**: fix URLSearchParams(null) to prudce null= per spec (Marco)
[#63782](https://redirect.github.com/nodejs/node/pull/63782)
-
\[[`ee66a3851c`](https://redirect.github.com/nodejs/node/commit/ee66a3851c)]
- **util**: fix OOM in inspect color stack formatting (Ijtihed Kilani)
[#64022](https://redirect.github.com/nodejs/node/pull/64022)
-
\[[`e26f183699`](https://redirect.github.com/nodejs/node/commit/e26f183699)]
- **util**: fix scientific notation formatting (Daijiro Wachi)
[#63823](https://redirect.github.com/nodejs/node/pull/63823)
-
\[[`7993e3e476`](https://redirect.github.com/nodejs/node/commit/7993e3e476)]
- **util**: fix -0 formatting when numericSeparator is enabled (Daijiro
Wachi)
[#63815](https://redirect.github.com/nodejs/node/pull/63815)
-
\[[`38758a7789`](https://redirect.github.com/nodejs/node/commit/38758a7789)]
- **util**: remove style caches from styleText slow path (Guilherme
AraÃējo)
[#63706](https://redirect.github.com/nodejs/node/pull/63706)
-
\[[`46a0ca256a`](https://redirect.github.com/nodejs/node/commit/46a0ca256a)]
- **watch**: print name of changed file that triggers restart (Marco)
[#63781](https://redirect.github.com/nodejs/node/pull/63781)
-
\[[`e1582818ad`](https://redirect.github.com/nodejs/node/commit/e1582818ad)]
- **watch**: cancel pending restart on shutdown (Trivikram Kamat)
[#63383](https://redirect.github.com/nodejs/node/pull/63383)
-
\[[`9a208668b0`](https://redirect.github.com/nodejs/node/commit/9a208668b0)]
- **zlib**: validate flush king for all streams (Ic3b3rg)
[#63746](https://redirect.github.com/nodejs/node/pull/63746)
-
\[[`928981d803`](https://redirect.github.com/nodejs/node/commit/928981d803)]
- **zlib**: validate flush kind for brotli streams (Ic3b3rg)
[#63746](https://redirect.github.com/nodejs/node/pull/63746)
-
\[[`fd0fb00164`](https://redirect.github.com/nodejs/node/commit/fd0fb00164)]
- **zlib**: expose rejectGarbageAfterEnd option (Filip Skokan)
[#64023](https://redirect.github.com/nodejs/node/pull/64023)
-
\[[`e334d30b4c`](https://redirect.github.com/nodejs/node/commit/e334d30b4c)]
- **zlib**: reject trailing gzip members in web streams (Filip Skokan)
[#64023](https://redirect.github.com/nodejs/node/pull/64023)
-
\[[`7433c3df2e`](https://redirect.github.com/nodejs/node/commit/7433c3df2e)]
- **zlib**: coerce -0 to +0 for crc32 seeds (Filip Skokan)
[#63556](https://redirect.github.com/nodejs/node/pull/63556)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
mise.lock | 29 ++++++++++++++++-------------
mise.toml | 2 +-
2 files changed, 17 insertions(+), 14 deletions(-)
diff --git a/mise.lock b/mise.lock
index c1a4b9364..8dfeeceec 100644
--- a/mise.lock
+++ b/mise.lock
@@ -486,34 +486,37 @@ url = "https://github.com/lycheeverse/lychee/releases/download/lychee-v0.24.2/ly
url_api = "https://api.github.com/repos/lycheeverse/lychee/releases/assets/409959491"
[[tools.node]]
-version = "24.18.1"
+version = "24.19.0"
backend = "core:node"
[tools.node."platforms.linux-arm64"]
-checksum = "sha256:df224555a083b918e46260cc969838501b9f9a87140c1195e5b9597b56d5dae2"
-url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-linux-arm64.tar.gz"
+checksum = "sha256:d28c8a5bf0a808f0ed434a1dce8c54ae98f0371c0bd86ac58abc613f73e6643f"
+url = "https://nodejs.org/dist/v24.19.0/node-v24.19.0-linux-arm64.tar.gz"
[tools.node."platforms.linux-arm64-musl"]
-url = "https://unofficial-builds.nodejs.org/download/release/v24.18.1/node-v24.18.1-linux-arm64-musl.tar.gz"
+checksum = "sha256:16fe258006a6e86844fbe05b3b5e1e5623ca8d3da54e32d98d9e83234bf25b01"
+url = "https://nodejs.org/dist/v24.19.0/node-v24.19.0.tar.gz"
+install = "source"
[tools.node."platforms.linux-x64"]
-checksum = "sha256:9f5eb6ac21845a66c493c91a253b1da32fd684e89e9b7202d4936982336be4ca"
-url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-linux-x64.tar.gz"
+checksum = "sha256:f625d97cd707df4ff96254916fbc5ff014f09c09effe5a1e0ca8f6d41a8789d4"
+url = "https://nodejs.org/dist/v24.19.0/node-v24.19.0-linux-x64.tar.gz"
[tools.node."platforms.linux-x64-musl"]
-url = "https://unofficial-builds.nodejs.org/download/release/v24.18.1/node-v24.18.1-linux-x64-musl.tar.gz"
+checksum = "sha256:c60223786df14a5d23e220ebb8e60318f5322640a62f90e6d9e54d3a18da532e"
+url = "https://unofficial-builds.nodejs.org/download/release/v24.19.0/node-v24.19.0-linux-x64-musl.tar.gz"
[tools.node."platforms.macos-arm64"]
-checksum = "sha256:eb02f7fab96d3d67de40c5ec8566096fcb4c2026728787683ae5a97eb612b941"
-url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-darwin-arm64.tar.gz"
+checksum = "sha256:8294b7aa9b03997481c06babf1e8b270c859358f27da57a11509afe537ac381d"
+url = "https://nodejs.org/dist/v24.19.0/node-v24.19.0-darwin-arm64.tar.gz"
[tools.node."platforms.macos-x64"]
-checksum = "sha256:6fb20fceacbb157c2f95825b80df4a454a0f6d81cdcd7bb81eeae9147e0e76ec"
-url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-darwin-x64.tar.gz"
+checksum = "sha256:d1b5e999db158c62fe8f7267a4476b035d8bd93b1a605bac24a3f0dd166e3316"
+url = "https://nodejs.org/dist/v24.19.0/node-v24.19.0-darwin-x64.tar.gz"
[tools.node."platforms.windows-x64"]
-checksum = "sha256:ec56b84a7551893ab2324ebdfdc4ab974a63b4781162600b68a1293cc3e53765"
-url = "https://nodejs.org/dist/v24.18.1/node-v24.18.1-win-x64.zip"
+checksum = "sha256:57f71ab3652e797d84acddc79c81cc9ff1c6ddb2a1974cdb83f00fee9bff4c73"
+url = "https://nodejs.org/dist/v24.19.0/node-v24.19.0-win-x64.zip"
[[tools."npm:renovate"]]
version = "43.279.1"
diff --git a/mise.toml b/mise.toml
index d4a1ec530..5993e544b 100644
--- a/mise.toml
+++ b/mise.toml
@@ -3,7 +3,7 @@
"aqua:grafana/oats" = "0.10.0"
hugo = "0.164.0"
java = "temurin-25.0.3+9.0.LTS"
-node = "24.18.1"
+node = "24.19.0"
protoc = "35.1"
# Linters
From 1fbc0a2b758235d278dcfb62ea3872be16ef11e6 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Tue, 4 Aug 2026 20:57:27 -0400
Subject: [PATCH 18/54] chore(deps): update
otel/opentelemetry-collector-contrib docker tag to v0.158.0 (#2370)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
|
[otel/opentelemetry-collector-contrib](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases)
| minor | `0.157.0` â `0.158.0` |
---
### Release Notes
open-telemetry/opentelemetry-collector-releases
(otel/opentelemetry-collector-contrib)
###
[`v0.158.0`](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/blob/HEAD/CHANGELOG.md#v01580)
[Compare
Source](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/compare/v0.157.0...v0.158.0)
##### đ Breaking changes đ
- `all`: Update Cosign usage to work with v3
([#1570](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1570))
The Cosign v3 upgrade introduced a change in signing workflow. Previous
two files
were required to map the outputs (certificate and signature), now only
one file is required.
The new file is a bundle that contains both outputs in JSON format.
This change has been done following the guidance from
.
With this change, anyone who wants to verify the signature of the
artifacts produced by the
release will need to use Cosign V3 and point to the new bundle file or
download the bundle and
unpack it to get the certificate and signature files.
- `all`: Use split checksum for all binaries and distros
([#1582](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1582))
The previous attempt at splitting the checksum file for AIX releases was
not successful.
The problem lies on the fac that `.runtime.GOOS` will always be the
runtime of the compiled
goreleaser binary ("linux" in this case). The only way to split the
checksum file per target
is what's implement here, but it ends up giving one checksum file per
produced artifact.
##### đ New components đ
- `icmpcheckreceiver`: Add icmpcheckreceiver to the contrib distribution
([#1577](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1577))
##### đĄ Enhancements đĄ
- `all`: Add new binaries for aix/ppc64
([#1424](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1424))
##### đ§° Bug fixes đ§°
- `all`: Skip Docker build and publish in AIX release job.
([#1580](https://redirect.github.com/open-telemetry/opentelemetry-collector-releases/issues/1580))
The release for Contrib on AIX runs in its own job, where it doesn't
build
Docker images. The `continue --merge` phase of goreleaser runs all
publishers
by default, including the Docker manifests one. This will fail for AIX
as
the images aren't built.
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
examples/example-exemplars-tail-sampling/docker-compose.yaml | 2 +-
examples/example-exporter-opentelemetry/docker-compose.yaml | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/examples/example-exemplars-tail-sampling/docker-compose.yaml b/examples/example-exemplars-tail-sampling/docker-compose.yaml
index 780431624..1169fbf24 100644
--- a/examples/example-exemplars-tail-sampling/docker-compose.yaml
+++ b/examples/example-exemplars-tail-sampling/docker-compose.yaml
@@ -36,7 +36,7 @@ services:
- -jar
- /example-greeting-service.jar
collector:
- image: otel/opentelemetry-collector-contrib:0.157.0@sha256:f2f01157055a9b2aab9df7118e1f1c9abf345e99b23bc7a2bc791db374a7d0f6
+ image: otel/opentelemetry-collector-contrib:0.158.0@sha256:c5918f78992ee73b0d6f0e599423ac5ec52dd5d9726733114d6eca53d5a32ed5
network_mode: host
volumes:
- ./config/otelcol-config.yaml:/config.yaml
diff --git a/examples/example-exporter-opentelemetry/docker-compose.yaml b/examples/example-exporter-opentelemetry/docker-compose.yaml
index 7ab385bb3..fea21cbba 100644
--- a/examples/example-exporter-opentelemetry/docker-compose.yaml
+++ b/examples/example-exporter-opentelemetry/docker-compose.yaml
@@ -13,7 +13,7 @@ services:
#- -agentlib:jdwp=transport=dt_socket,server=y,suspend=y,address=*:5005
- /example-exporter-opentelemetry.jar
collector:
- image: otel/opentelemetry-collector-contrib:0.157.0@sha256:f2f01157055a9b2aab9df7118e1f1c9abf345e99b23bc7a2bc791db374a7d0f6
+ image: otel/opentelemetry-collector-contrib:0.158.0@sha256:c5918f78992ee73b0d6f0e599423ac5ec52dd5d9726733114d6eca53d5a32ed5
network_mode: host
volumes:
- ./config/otelcol-config.yaml:/config.yaml
From 08967e0aca1442935f2052f59f10df66c807ca0b Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Tue, 4 Aug 2026 20:57:43 -0400
Subject: [PATCH 19/54] fix(deps): update jetty monorepo to v12.1.12 (#2371)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [org.eclipse.jetty.ee10:jetty-ee10-servlet](https://jetty.org)
([source](https://redirect.github.com/jetty/jetty.project)) | `12.1.11`
â `12.1.12` |

|

|
| [org.eclipse.jetty:jetty-server](https://jetty.org)
([source](https://redirect.github.com/jetty/jetty.project)) | `12.1.11`
â `12.1.12` |

|

|
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about these
updates again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.../it-exporter/it-exporter-servlet-jetty-sample/pom.xml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/integration-tests/it-exporter/it-exporter-servlet-jetty-sample/pom.xml b/integration-tests/it-exporter/it-exporter-servlet-jetty-sample/pom.xml
index e17e391a0..a8a93ab20 100644
--- a/integration-tests/it-exporter/it-exporter-servlet-jetty-sample/pom.xml
+++ b/integration-tests/it-exporter/it-exporter-servlet-jetty-sample/pom.xml
@@ -15,7 +15,7 @@
Jetty Sample for the Exporter Integration Test
- 12.1.11
+ 12.1.12
25
From 565a58396c92ddfbe1b64de37c40a0a8c165a612 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Wed, 5 Aug 2026 01:07:54 +0000
Subject: [PATCH 20/54] chore(deps): update grafana/grafana docker tag to
v13.1.2 (#2369)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [grafana/grafana](https://redirect.github.com/grafana/grafana) | patch
| `13.1.1` â `13.1.2` |
---
### Release Notes
grafana/grafana (grafana/grafana)
###
[`v13.1.2`](https://redirect.github.com/grafana/grafana/blob/HEAD/CHANGELOG.md#1310-2026-06-23)
##### Features and enhancements
- **A11y:** Remove interactivity from UserIcon if onClick is not
provided
[#120284](https://redirect.github.com/grafana/grafana/pull/120284),
[@idastambuk](https://redirect.github.com/idastambuk)
- **Accessibility:** Add `aria-pressed` state to `FilterPill`
[#123069](https://redirect.github.com/grafana/grafana/pull/123069),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **Accessibility:** Colorblind-safe line style fill patterns
[#121386](https://redirect.github.com/grafana/grafana/pull/121386),
[@vijaygovindaraja](https://redirect.github.com/vijaygovindaraja)
- **Alerting:** Add Mimir Alertmanager auto-sync configuration to
settings page
[#124855](https://redirect.github.com/grafana/grafana/pull/124855),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Add alerting.rulesAPIV2 feature flag
[#122606](https://redirect.github.com/grafana/grafana/pull/122606),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Add common section to filter dropdown in Alerts Activity
[#124547](https://redirect.github.com/grafana/grafana/pull/124547),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Add feature flag for notifications api migration
[#124625](https://redirect.github.com/grafana/grafana/pull/124625),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Add label section to enrichment view/edit drawers
(Enterprise)
- **Alerting:** Add reusable hook to add enrichment query param to url
on drawer open
[#123584](https://redirect.github.com/grafana/grafana/pull/123584),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Add support for label selectors in AlertRule and
RecordingRule legacy storage
[#122293](https://redirect.github.com/grafana/grafana/pull/122293),
[@moustafab](https://redirect.github.com/moustafab)
- **Alerting:** Alert activity UI improvements part 3
[#121790](https://redirect.github.com/grafana/grafana/pull/121790),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Alert activity groupBy not filtering by environment
[#121952](https://redirect.github.com/grafana/grafana/pull/121952),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Alerts Activity Instance drawer drilldown, Silence flow
[#122317](https://redirect.github.com/grafana/grafana/pull/122317),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Allow restricting contact point integration types
[#118858](https://redirect.github.com/grafana/grafana/pull/118858),
[@chriscerie](https://redirect.github.com/chriscerie)
- **Alerting:** Block Viewers from Alert Group edit route
[#125669](https://redirect.github.com/grafana/grafana/pull/125669),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Block editing plugin-provided and provisioned rule
groups
[#123214](https://redirect.github.com/grafana/grafana/pull/123214),
[@konrad147](https://redirect.github.com/konrad147)
- **Alerting:** Deduplicate and validate `groupBy` labels in alerts
[#122983](https://redirect.github.com/grafana/grafana/pull/122983),
[@yuri-tceretian](https://redirect.github.com/yuri-tceretian)
- **Alerting:** Export external Alertmanager sender metrics with data
source UIDs
[#121996](https://redirect.github.com/grafana/grafana/pull/121996),
[@santihernandezc](https://redirect.github.com/santihernandezc)
- **Alerting:** Include error in Loki state history when
exec\_err\_state is Alerting
[#125775](https://redirect.github.com/grafana/grafana/pull/125775),
[@imankurpatel000](https://redirect.github.com/imankurpatel000)
- **Alerting:** Mark notification provisioning endpoints deprecated
[#121995](https://redirect.github.com/grafana/grafana/pull/121995),
[@titolins](https://redirect.github.com/titolins)
- **Alerting:** Move filters to sidebar alerts activity
[#121577](https://redirect.github.com/grafana/grafana/pull/121577),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Open new alert rule drawer from panel menu
[#125712](https://redirect.github.com/grafana/grafana/pull/125712),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Preview notification routing in the alert instances
table
[#121699](https://redirect.github.com/grafana/grafana/pull/121699),
[@ppcano](https://redirect.github.com/ppcano)
- **Alerting:** Propagate plugin rule origin as X-Rule-Origin header
[#125206](https://redirect.github.com/grafana/grafana/pull/125206),
[@yuri-tceretian](https://redirect.github.com/yuri-tceretian)
- **Alerting:** Remove alertRuleUseFiredAtForStartsAt feature toggle
[#124677](https://redirect.github.com/grafana/grafana/pull/124677),
[@fayzal-g](https://redirect.github.com/fayzal-g)
- **Alerting:** Restrict email contact point recipients to org members
[#123173](https://redirect.github.com/grafana/grafana/pull/123173),
[@yuri-tceretian](https://redirect.github.com/yuri-tceretian)
- **Alerting:** Set enrichment uid in url for enrichment view/edit
drawer (Enterprise)
- **Alerting:** Small improvements to instance drawer drilldown silence
flow
[#123429](https://redirect.github.com/grafana/grafana/pull/123429),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Support creating Grafana-managed rules without a group
[#120228](https://redirect.github.com/grafana/grafana/pull/120228),
[@moustafab](https://redirect.github.com/moustafab)
- **Alerting:** Surface contact point save errors in the UI
[#123211](https://redirect.github.com/grafana/grafana/pull/123211),
[@konrad147](https://redirect.github.com/konrad147)
- **Alerting:** Surface errors on contact point creation
[#124339](https://redirect.github.com/grafana/grafana/pull/124339),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Surface save and bulk-delete errors to the user
[#123690](https://redirect.github.com/grafana/grafana/pull/123690),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Use Rules API v2 in panel alert rule drawer
[#125787](https://redirect.github.com/grafana/grafana/pull/125787),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Annotations:** Clustering GA
[#124173](https://redirect.github.com/grafana/grafana/pull/124173),
[@gtk-grafana](https://redirect.github.com/gtk-grafana)
- **Auth:** Support inline public keys for JWT authentication
[#126184](https://redirect.github.com/grafana/grafana/pull/126184),
[@cinaglia](https://redirect.github.com/cinaglia)
- **Auth:** Use GrafanaComProxyAPIToken for managed plugin API requests
(Enterprise)
- **Auth:** Use dedicated token for requests to Grafana.com
[#122269](https://redirect.github.com/grafana/grafana/pull/122269),
[@s4kh](https://redirect.github.com/s4kh)
- **Azure Monitor:** Pool gzip writers in Log Analytics deep-link
encoder
[#123555](https://redirect.github.com/grafana/grafana/pull/123555),
[@adamyeats](https://redirect.github.com/adamyeats)
- **Azure Monitor:** Refactor `fetchInitialRows` to improve async
utilisation
[#123278](https://redirect.github.com/grafana/grafana/pull/123278),
[@adamyeats](https://redirect.github.com/adamyeats)
- **Azure Monitor:** Stream-decode responses and typed structs for
portal deep link
[#123565](https://redirect.github.com/grafana/grafana/pull/123565),
[@adamyeats](https://redirect.github.com/adamyeats)
- **Browse Dashboards:** Change messaging of delete/move modal and add
counts to tabs in folder detail
[#124299](https://redirect.github.com/grafana/grafana/pull/124299),
[@aocenas](https://redirect.github.com/aocenas)
- **Browse Dashboards:** Refresh old parent folder on save dashboard
[#125323](https://redirect.github.com/grafana/grafana/pull/125323),
[@aocenas](https://redirect.github.com/aocenas)
- **CloudWatch Logs:** Remove data links from results
[#120348](https://redirect.github.com/grafana/grafana/pull/120348),
[@iwysiu](https://redirect.github.com/iwysiu)
- **Cloudwatch:** Add id to metric expression datalinks
[#120526](https://redirect.github.com/grafana/grafana/pull/120526),
[@iwysiu](https://redirect.github.com/iwysiu)
- **Combobox:** Add isOpen and onIsOpenChangeHandler
[#122992](https://redirect.github.com/grafana/grafana/pull/122992),
[@L2D2Grafana](https://redirect.github.com/L2D2Grafana)
- **ConvertFieldType:** Preserve null and empty string in
string-to-number conversion
[#120893](https://redirect.github.com/grafana/grafana/pull/120893),
[@moktamd](https://redirect.github.com/moktamd)
- **CsvExport:** Remove legacy CsvExportPage (Enterprise)
- **Dashboard variables:** Improve accessibility
[#120758](https://redirect.github.com/grafana/grafana/pull/120758),
[@idastambuk](https://redirect.github.com/idastambuk)
- **Dashboard/DTO:** Remove isStarred property
[#122118](https://redirect.github.com/grafana/grafana/pull/122118),
[@ryantxu](https://redirect.github.com/ryantxu)
- **Dashboard:** Add annotation CRUD to mutation API
[#123939](https://redirect.github.com/grafana/grafana/pull/123939),
[@ivanortegaalba](https://redirect.github.com/ivanortegaalba)
- **Dashboard:** Display variable label in outline to better match what
the users sees in the dashboard
[#123321](https://redirect.github.com/grafana/grafana/pull/123321),
[@oscarkilhed](https://redirect.github.com/oscarkilhed)
- **Dashboard:** Edit pane go back action
[#122918](https://redirect.github.com/grafana/grafana/pull/122918),
[@torkelo](https://redirect.github.com/torkelo)
- **Dashboard:** Preserve timezone user-preference when converting V1 â
V2
[#122267](https://redirect.github.com/grafana/grafana/pull/122267),
[@ivanortegaalba](https://redirect.github.com/ivanortegaalba)
- **Dashboard:** Switch tab selects tab only when pane is open (docked
or not)
[#121755](https://redirect.github.com/grafana/grafana/pull/121755),
[@torkelo](https://redirect.github.com/torkelo)
- **Dashboards:** Add panel screenshot API
[#124045](https://redirect.github.com/grafana/grafana/pull/124045),
[@dprokop](https://redirect.github.com/dprokop)
- **Dashboards:** Preserve query variable sort modes in v1->v2
conversion
[#124247](https://redirect.github.com/grafana/grafana/pull/124247),
[@oscarkilhed](https://redirect.github.com/oscarkilhed)
- **Dashboards:** Remove dashboardScene and publicDashboardsScene
feature toggles
[#121781](https://redirect.github.com/grafana/grafana/pull/121781),
[@Sergej-Vlasov](https://redirect.github.com/Sergej-Vlasov)
- **Dashboards:** Show k8s format in provisioned save
[#123033](https://redirect.github.com/grafana/grafana/pull/123033),
[@stephaniehingtgen](https://redirect.github.com/stephaniehingtgen)
- **Dashboards:** Strip BOM characters in admission mutation hook
[#122677](https://redirect.github.com/grafana/grafana/pull/122677),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Data Source:** Add forward\_user\_agent option to preserve client
User-Agent
[#124244](https://redirect.github.com/grafana/grafana/pull/124244),
[@marcsanmi](https://redirect.github.com/marcsanmi)
- **DataSources:** Introduce async APIs and hooks as replacement for
datasourceSrv
[#123037](https://redirect.github.com/grafana/grafana/pull/123037),
[@mckn](https://redirect.github.com/mckn)
- **Datasources:** Add dynamodb to supported plugins list in dsauth
(Enterprise)
- **Datasources:** Allow editing data source title
[#122053](https://redirect.github.com/grafana/grafana/pull/122053),
[@MattIPv4](https://redirect.github.com/MattIPv4)
- **Datasources:** Finish decoupling mssql & postgresql - backend
[#119110](https://redirect.github.com/grafana/grafana/pull/119110),
[@njvrzm](https://redirect.github.com/njvrzm)
- **Datasources:** Finish decoupling mssql, tempo, and graphite -
frontend changes
[#119106](https://redirect.github.com/grafana/grafana/pull/119106),
[@njvrzm](https://redirect.github.com/njvrzm)
- **Docker:** Bump Alpine-based images to 3.23.4
[#122930](https://redirect.github.com/grafana/grafana/pull/122930),
[@Proximyst](https://redirect.github.com/Proximyst)
- **Docker:** Bump Alpine-based images to 3.24.1
[#126529](https://redirect.github.com/grafana/grafana/pull/126529),
[@macabu](https://redirect.github.com/macabu)
- **Dynamic dashboards:** preserve tab/row URL slugs and keep legacy tab
URLs working
[#123159](https://redirect.github.com/grafana/grafana/pull/123159),
[@idastambuk](https://redirect.github.com/idastambuk)
- **Expressions:** Add memory limit for math expression binary
operations
[#121945](https://redirect.github.com/grafana/grafana/pull/121945),
[@rwwiv](https://redirect.github.com/rwwiv)
- **Go:** Update to 1.25.9
[#122094](https://redirect.github.com/grafana/grafana/pull/122094),
[@macabu](https://redirect.github.com/macabu)
- **Google Cloud Monitoring:** Add Forward OAuth Identity authentication
(frontend)
[#124618](https://redirect.github.com/grafana/grafana/pull/124618),
[@ktw4071](https://redirect.github.com/ktw4071)
- **GrafanaUI:** Remove feature toggle for new panel padding
[#124870](https://redirect.github.com/grafana/grafana/pull/124870),
[@torkelo](https://redirect.github.com/torkelo)
- **Graphite:** Strip tagged path from `tags.name` when `aliasSub`
wrapping is detected
[#122277](https://redirect.github.com/grafana/grafana/pull/122277),
[@adamyeats](https://redirect.github.com/adamyeats)
- **Histogram:** filter NaN and Infinity from bucket size calculation
[#117698](https://redirect.github.com/grafana/grafana/pull/117698),
[@ethervoid](https://redirect.github.com/ethervoid)
- **Homepage:** Support v2 dashboards if defined by a file
[#122994](https://redirect.github.com/grafana/grafana/pull/122994),
[@stephaniehingtgen](https://redirect.github.com/stephaniehingtgen)
- **I18n:** Prevents `en-US` localization resources from loading
[#125327](https://redirect.github.com/grafana/grafana/pull/125327),
[@hugohaggmark](https://redirect.github.com/hugohaggmark)
- **Import:** Library panel missing DS when imported in v1 and classic
[#119980](https://redirect.github.com/grafana/grafana/pull/119980),
[@ivanortegaalba](https://redirect.github.com/ivanortegaalba)
- **InfluxDB:** Decouple backend
[#119167](https://redirect.github.com/grafana/grafana/pull/119167),
[@njvrzm](https://redirect.github.com/njvrzm)
- **InfluxDB:** Decouple frontend
[#119169](https://redirect.github.com/grafana/grafana/pull/119169),
[@njvrzm](https://redirect.github.com/njvrzm)
- **InteractiveTable:** Support specific column widths
[#121384](https://redirect.github.com/grafana/grafana/pull/121384),
[@vijaygovindaraja](https://redirect.github.com/vijaygovindaraja)
- **LibraryPanels:** Return 403 instead of 500 for insufficient
permissions
[#123407](https://redirect.github.com/grafana/grafana/pull/123407),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Log Details:** Add support for filtering from add-hoc stats and to
include/exclude the log line
[#126782](https://redirect.github.com/grafana/grafana/pull/126782),
[@matyax](https://redirect.github.com/matyax)
- **Log Details:** Add support to expand or shrink inline Log Details
[#123156](https://redirect.github.com/grafana/grafana/pull/123156),
[@matyax](https://redirect.github.com/matyax)
- **Logs Panel:** Add support to copy a log entry with fields/labels as
JSON
[#124816](https://redirect.github.com/grafana/grafana/pull/124816),
[@matyax](https://redirect.github.com/matyax)
- **Logs:** Add emergency to supported LogLevel mapping
[#119957](https://redirect.github.com/grafana/grafana/pull/119957),
[@Kuehn-Andreas](https://redirect.github.com/Kuehn-Andreas)
- **Logs:** Add keyboard navigation support for Log Details
[#123406](https://redirect.github.com/grafana/grafana/pull/123406),
[@matyax](https://redirect.github.com/matyax)
- **Logs:** Add optional download support for dashboards
[#123256](https://redirect.github.com/grafana/grafana/pull/123256),
[@matyax](https://redirect.github.com/matyax)
- **Logs:** Highlight multi-unit durations in log syntax highlighting
[#124433](https://redirect.github.com/grafana/grafana/pull/124433),
[@o6ivp](https://redirect.github.com/o6ivp)
- **Logs:** Log line menu is now sticky
[#126572](https://redirect.github.com/grafana/grafana/pull/126572),
[@matyax](https://redirect.github.com/matyax)
- **Logs:** Removed logsPanelControls feature flag and related
components
[#122114](https://redirect.github.com/grafana/grafana/pull/122114),
[@matyax](https://redirect.github.com/matyax)
- **Logs:** introduce "unspecified" log level for missing log level and
separate from "unknown"
[#125716](https://redirect.github.com/grafana/grafana/pull/125716),
[@matyax](https://redirect.github.com/matyax)
- **Migration:** Widen team.updated to DATETIME(3) on MySQL
[#124314](https://redirect.github.com/grafana/grafana/pull/124314),
[@mgyongyosi](https://redirect.github.com/mgyongyosi)
- **PieChartPanel:** Add gradient color scheme with WCAG-aware slice
labels
[#121303](https://redirect.github.com/grafana/grafana/pull/121303),
[@fedir](https://redirect.github.com/fedir)
- **Plugins:** Add plugins.marketplaceLicensing feature toggle
[#124246](https://redirect.github.com/grafana/grafana/pull/124246),
[@xnyo](https://redirect.github.com/xnyo)
- **Plugins:** Sanitise header values to printable ASCII for gRPC
compatibility
[#122237](https://redirect.github.com/grafana/grafana/pull/122237),
[@adamyeats](https://redirect.github.com/adamyeats)
- **Prometheus:** Fetch metric metadata on code editor mount
[#121339](https://redirect.github.com/grafana/grafana/pull/121339)
- **Prometheus:** Prevent prometheus package to be released
automatically
[#122824](https://redirect.github.com/grafana/grafana/pull/122824),
[@itsmylife](https://redirect.github.com/itsmylife)
- **Prometheus:** Use
[@grafana/prometheus](https://redirect.github.com/grafana/prometheus)
v13.1.2
[#123024](https://redirect.github.com/grafana/grafana/pull/123024),
[@itsmylife](https://redirect.github.com/itsmylife)
- **Provisioning:** Add commit signing configuration UI (GPG, SSH,
S/MIME)
[#126023](https://redirect.github.com/grafana/grafana/pull/126023),
[@amalavet](https://redirect.github.com/amalavet)
- **Provisioning:** Don't mark folders pending due to \_folder.json
metadata
[#124118](https://redirect.github.com/grafana/grafana/pull/124118),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** Enforce folder version in finalizer handler
[#123179](https://redirect.github.com/grafana/grafana/pull/123179),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Honor ruleset bypass for write workflow validation
[#123893](https://redirect.github.com/grafana/grafana/pull/123893),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** Include dashboard validation errors in pull request
comments
[#122233](https://redirect.github.com/grafana/grafana/pull/122233),
[@gttrigger](https://redirect.github.com/gttrigger)
- **Provisioning:** Invalid resources should cause a warning job
[#123047](https://redirect.github.com/grafana/grafana/pull/123047),
[@gttrigger](https://redirect.github.com/gttrigger)
- **Provisioning:** List resources should return correct api version
[#122653](https://redirect.github.com/grafana/grafana/pull/122653),
[@gttrigger](https://redirect.github.com/gttrigger)
- **Provisioning:** Negotiate receive-pack capabilities for git pushes
[#124122](https://redirect.github.com/grafana/grafana/pull/124122),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** Per-verb fallback for the files subresource
[#123867](https://redirect.github.com/grafana/grafana/pull/123867),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** Remove GET method from webhook connector
[#125539](https://redirect.github.com/grafana/grafana/pull/125539),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** Require new token when provisioning URL changes
[#125525](https://redirect.github.com/grafana/grafana/pull/125525),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Retry SQLITE\_BUSY on repository status patch
[#123873](https://redirect.github.com/grafana/grafana/pull/123873),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** Return Bad request for repo mismatch in webhook
[#124453](https://redirect.github.com/grafana/grafana/pull/124453),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Return early for errors on resource creation in
Parser
[#125122](https://redirect.github.com/grafana/grafana/pull/125122),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Rotate webhook secret periodically
[#122797](https://redirect.github.com/grafana/grafana/pull/122797),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Scope repository uniqueness by (URL, branch, path)
[#123498](https://redirect.github.com/grafana/grafana/pull/123498),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Surface folder uid-too-long and other validation 4xx
as sync warnings
[#123797](https://redirect.github.com/grafana/grafana/pull/123797),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** Use full sync instead of incremental if diff size
exceeds a certain amount
[#123127](https://redirect.github.com/grafana/grafana/pull/123127),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Write `_folder.json` when creating dashboards in new
folders
[#126042](https://redirect.github.com/grafana/grafana/pull/126042),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Write `_folder.json` when moving dashboards into new
folders
[#126552](https://redirect.github.com/grafana/grafana/pull/126552),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** add PR comment if resources metadata is removed
[#122664](https://redirect.github.com/grafana/grafana/pull/122664),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** add new check for webhook creation in repository
controller
[#122725](https://redirect.github.com/grafana/grafana/pull/122725),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** add public\_root\_url instance setting for external
URLs
[#123613](https://redirect.github.com/grafana/grafana/pull/123613),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** replay protection for GitHub webhooks
[#125550](https://redirect.github.com/grafana/grafana/pull/125550),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** validate ref query parameter on files and history
endpoints
[#125551](https://redirect.github.com/grafana/grafana/pull/125551),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Pyroscope:** Add support for heatmap query API
[#120995](https://redirect.github.com/grafana/grafana/pull/120995),
[@simonswine](https://redirect.github.com/simonswine)
- **Pyroscope:** Include profile ID and absolute times in assistant
context
[#122665](https://redirect.github.com/grafana/grafana/pull/122665),
[@marcsanmi](https://redirect.github.com/marcsanmi)
- **Removal:** GroupAttributeSync routes
[#126247](https://redirect.github.com/grafana/grafana/pull/126247),
[@Jguer](https://redirect.github.com/Jguer)
- **Reporting:** Add backend support for URL-based report rendering
(Enterprise)
- **Reporting:** Limit report emails to org members only (behind new
config property) (Enterprise)
- **Revert "Alerting:** Migrate notifications.alerting.grafana.app from
v0alpha1 to v1beta1"
[#121955](https://redirect.github.com/grafana/grafana/pull/121955),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Scenes:** Upgrade to v8
[#123698](https://redirect.github.com/grafana/grafana/pull/123698),
[@torkelo](https://redirect.github.com/torkelo)
- **Search API:** Filter out k6 technical folder in unified search
[#122674](https://redirect.github.com/grafana/grafana/pull/122674),
[@aocenas](https://redirect.github.com/aocenas)
- **Secrets Keeper:** AWS create form with instruction wizard
(Enterprise)
- **Secrets Keeper:** Activate and deactivate keeper from the UI
(Enterprise)
- **Secrets Keeper:** Add delete keeper functionality (Enterprise)
- **Secrets Keeper:** Add keeper edit page with form prepopulation
(Enterprise)
- **Sidebar:** Open pane actions, dock, and go back redesign
[#123683](https://redirect.github.com/grafana/grafana/pull/123683),
[@torkelo](https://redirect.github.com/torkelo)
- **SqlExpressions:** Interpolate variables in schema queries
[#123779](https://redirect.github.com/grafana/grafana/pull/123779),
[@NWRichmond](https://redirect.github.com/NWRichmond)
- **SqlExpressions:** Migrate AI features to Grafana Assistant
[#122085](https://redirect.github.com/grafana/grafana/pull/122085),
[@NWRichmond](https://redirect.github.com/NWRichmond)
- **Stats:** Remove dashboard version metric
[#121900](https://redirect.github.com/grafana/grafana/pull/121900),
[@stephaniehingtgen](https://redirect.github.com/stephaniehingtgen)
- **Table:** GroupToNestedTable v2 UI
[#121646](https://redirect.github.com/grafana/grafana/pull/121646),
[@fastfrwrd](https://redirect.github.com/fastfrwrd)
- **Team folders:** Refresh browse dashboard cache after changes to team
folders
[#123794](https://redirect.github.com/grafana/grafana/pull/123794),
[@aocenas](https://redirect.github.com/aocenas)
- **Tempo:** Unify dynamic int/double span attributes as float64
[#121645](https://redirect.github.com/grafana/grafana/pull/121645),
[@zoltanbedi](https://redirect.github.com/zoltanbedi)
- **Tempo:** Unify nested span subframe schema across span sets
[#124885](https://redirect.github.com/grafana/grafana/pull/124885),
[@zoltanbedi](https://redirect.github.com/zoltanbedi)
- **TimeRangePicker:** Adjust accent color to be accessible
[#122040](https://redirect.github.com/grafana/grafana/pull/122040),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **Transformations:** Removes unused predicate matchers
[#124790](https://redirect.github.com/grafana/grafana/pull/124790),
[@hugohaggmark](https://redirect.github.com/hugohaggmark)
- **Unified Storage:** Pass commit message when routing managed-resource
writes
[#125556](https://redirect.github.com/grafana/grafana/pull/125556),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Users:** Use SHA-256 for Gravatar email identifier
[#122319](https://redirect.github.com/grafana/grafana/pull/122319),
[@Jguer](https://redirect.github.com/Jguer)
- **Zipkin:** Remove core datasource (Enterprise)
- **patch(security):** apply May 2026 patches
[#124824](https://redirect.github.com/grafana/grafana/pull/124824),
[@github-actions\[bot\]](https://redirect.github.com/github-actions\[bot])
##### Bug fixes
- **Alerting:** Fix named policy route showing as Default when routing
toggle is off
[#125817](https://redirect.github.com/grafana/grafana/pull/125817),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Add warning when editing grouped alert rule to ungrouped
[#126292](https://redirect.github.com/grafana/grafana/pull/126292),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Fix AlertManagerPicker visibility to check Alertmanager
datasources
[#123137](https://redirect.github.com/grafana/grafana/pull/123137),
[@konrad147](https://redirect.github.com/konrad147)
- **Alerting:** Fix Test button not shown for provisioned contact points
[#126371](https://redirect.github.com/grafana/grafana/pull/126371),
[@gillesdemey](https://redirect.github.com/gillesdemey)
- **Alerting:** Fix crash when MultiCombobox value contains duplicates
[#122180](https://redirect.github.com/grafana/grafana/pull/122180),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Fix crash when ruler returns namespace with empty groups
array
[#122704](https://redirect.github.com/grafana/grafana/pull/122704),
[@konrad147](https://redirect.github.com/konrad147)
- **Alerting:** Fix error toaster when removing last rule from group
[#126296](https://redirect.github.com/grafana/grafana/pull/126296),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Fix inhibition status flickering during load of alert
rule detail
[#126288](https://redirect.github.com/grafana/grafana/pull/126288),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Fix missing permission check for routing preview
[#122344](https://redirect.github.com/grafana/grafana/pull/122344),
[@rodrigopk](https://redirect.github.com/rodrigopk)
- **Alerting:** Fix notification policies tab hidden for Viewer/Editor
after managed routes migration
[#122123](https://redirect.github.com/grafana/grafana/pull/122123),
[@gillesdemey](https://redirect.github.com/gillesdemey)
- **Alerting:** Fix page title for /alerting/groups when V2 nav is
enabled without triage
[#123286](https://redirect.github.com/grafana/grafana/pull/123286),
[@firasmosbehi](https://redirect.github.com/firasmosbehi)
- **Alerting:** Fix rule matching when expressions contain inline
comments
[#126152](https://redirect.github.com/grafana/grafana/pull/126152),
[@gillesdemey](https://redirect.github.com/gillesdemey)
- **Alerting:** Fix slug in alerting nested folder URL
[#123670](https://redirect.github.com/grafana/grafana/pull/123670),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Fix threshold value reset when changing condition type
[#122455](https://redirect.github.com/grafana/grafana/pull/122455),
[@gillesdemey](https://redirect.github.com/gillesdemey)
- **Alerting:** Fix toast spam when typing silence matcher regex
[#125643](https://redirect.github.com/grafana/grafana/pull/125643),
[@laurenashleigh](https://redirect.github.com/laurenashleigh)
- **Alerting:** Make contact point settings redaction logic case
insensitive
[#124955](https://redirect.github.com/grafana/grafana/pull/124955),
[@khalilhaji](https://redirect.github.com/khalilhaji)
- **Alerting:** Set 'ResolvedAt' when transitioning from Error to Normal
[#122329](https://redirect.github.com/grafana/grafana/pull/122329),
[@santihernandezc](https://redirect.github.com/santihernandezc)
- **Auth:** URL-encode redirectTo cookie value in OAuth login flow
[#121953](https://redirect.github.com/grafana/grafana/pull/121953),
[@jsclayton](https://redirect.github.com/jsclayton)
- **AzureMonitor:** Fix focus trapping on `ResourceField` modal
[#123072](https://redirect.github.com/grafana/grafana/pull/123072),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **Browse dashboards:** Fix delete modal affected counts
[#122747](https://redirect.github.com/grafana/grafana/pull/122747),
[@aocenas](https://redirect.github.com/aocenas)
- **Dashboads:** Fixes flickering issues
[#118567](https://redirect.github.com/grafana/grafana/pull/118567),
[@torkelo](https://redirect.github.com/torkelo)
- **Dashboard:** DashboardCodePane width refactoring and fixes
[#122700](https://redirect.github.com/grafana/grafana/pull/122700),
[@torkelo](https://redirect.github.com/torkelo)
- **Dashboard:** Fixes issue with interval variable with Auto value
[#123889](https://redirect.github.com/grafana/grafana/pull/123889),
[@torkelo](https://redirect.github.com/torkelo)
- **DashboardDS:** Fix Mixed panels not updating on time-range change
with stale upstreams
[#124665](https://redirect.github.com/grafana/grafana/pull/124665),
[@ivanortegaalba](https://redirect.github.com/ivanortegaalba)
- **DashboardDS:** Fix Mixed panels with a time override stuck in
permanent loading
[#125954](https://redirect.github.com/grafana/grafana/pull/125954),
[@oscarkilhed](https://redirect.github.com/oscarkilhed)
- **Dashboards:** Fix broken add panel button after removing last panel
[#124551](https://redirect.github.com/grafana/grafana/pull/124551),
[@ifrost](https://redirect.github.com/ifrost)
- **Datasources:** return 400 when payload UID does not match URL UID in
PUT /api/datasources/uid/:uid
[#125398](https://redirect.github.com/grafana/grafana/pull/125398),
[@papagian](https://redirect.github.com/papagian)
- **Fix:** Don't mutate shared SecureJSONData map in dsauth (Enterprise)
- **Fix:** Short-cut auth service Apply for non-handled plugin IDs
(Enterprise)
- **GrafanaUI:** Correctly close `Select`/`Combobox` menus with the
keyboard
[#122133](https://redirect.github.com/grafana/grafana/pull/122133),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **HomePage:** Fix redirect when served under a subpath
[#124557](https://redirect.github.com/grafana/grafana/pull/124557),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **Jaeger:** Fix log event timestamp unit conversion in trace view
[#123302](https://redirect.github.com/grafana/grafana/pull/123302),
[@ktw4071](https://redirect.github.com/ktw4071)
- **K8s Dashboards:** Fix folder permission check to use
dashboards:create
[#124612](https://redirect.github.com/grafana/grafana/pull/124612),
[@mihai-turdean](https://redirect.github.com/mihai-turdean)
- **Loki:** Show Step option for all query types and fix volume reload
on step change
[#122184](https://redirect.github.com/grafana/grafana/pull/122184),
[@paulojmdias](https://redirect.github.com/paulojmdias)
- **Menu:** Correctly show active state in forced colors mode
[#123633](https://redirect.github.com/grafana/grafana/pull/123633),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **Portal:** Fix nested portals to overlay correctly
[#122450](https://redirect.github.com/grafana/grafana/pull/122450),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **PostgreSQL:** Allow sql\_engine to return results for EXPLAIN
queries
[#122739](https://redirect.github.com/grafana/grafana/pull/122739),
[@sdague](https://redirect.github.com/sdague)
- **Provisioning:** Bump nanogit to v0.17.0 to fix pushes with
repositories using git modules
[#124114](https://redirect.github.com/grafana/grafana/pull/124114),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Provisioning:** Fix PR comments on multi-org Grafana instances
[#126700](https://redirect.github.com/grafana/grafana/pull/126700),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Fix PR links when folder is renamed via UI
[#126695](https://redirect.github.com/grafana/grafana/pull/126695),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Fix duplicate folder cleanup during full sync
[#124256](https://redirect.github.com/grafana/grafana/pull/124256),
[@ferruvich](https://redirect.github.com/ferruvich)
- **Provisioning:** Fix race in PullStatus condition with controller
patches
[#123358](https://redirect.github.com/grafana/grafana/pull/123358),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **Public Dashboards:** Fix issues navigating to public dashboards from
a logged-in session
[#121017](https://redirect.github.com/grafana/grafana/pull/121017),
[@mmandrus](https://redirect.github.com/mmandrus)
- **QueryEditor:** Fix loss of query edits when switching queries
[#123001](https://redirect.github.com/grafana/grafana/pull/123001),
[@NWRichmond](https://redirect.github.com/NWRichmond)
- **Tempo Datasource:** Fix gRPC basic auth over non-TLS connections
[#123026](https://redirect.github.com/grafana/grafana/pull/123026),
[@RobertClarke64](https://redirect.github.com/RobertClarke64)
- **Tempo:** Fix Ctrl+/ comment toggle in TraceQL editor
[#121460](https://redirect.github.com/grafana/grafana/pull/121460),
[@Krishnachaitanyakc](https://redirect.github.com/Krishnachaitanyakc)
- **Tempo:** Fix trace rendering failure when span attributes contain
NaN or Infinity
[#122504](https://redirect.github.com/grafana/grafana/pull/122504),
[@Tarasusrus](https://redirect.github.com/Tarasusrus)
- **TimePicker:** Show label for fiscal-quarter relative ranges
[#122384](https://redirect.github.com/grafana/grafana/pull/122384),
[@jeanibarz](https://redirect.github.com/jeanibarz)
- **Unified storage:** Skip migrations if dualwrite state shows they
were already migrated
[#122866](https://redirect.github.com/grafana/grafana/pull/122866),
[@stephaniehingtgen](https://redirect.github.com/stephaniehingtgen)
- **alerting:** fix ORM table mapping bug causing SELECT alert\_rule
columns FROM user on PostgreSQL
[#124935](https://redirect.github.com/grafana/grafana/pull/124935),
[@dhananjay6561](https://redirect.github.com/dhananjay6561)
- **fix(provisioning):** ignore terminating repositories when validating
connection delete
[#126822](https://redirect.github.com/grafana/grafana/pull/126822),
[@MissingRoberto](https://redirect.github.com/MissingRoberto)
- **fix:** bad MySQL query in datasource\_type column migration
[#126821](https://redirect.github.com/grafana/grafana/pull/126821),
[@gassiss](https://redirect.github.com/gassiss)
##### Breaking changes
- **Prometheus:** Remove azure and sigv4 auth from core prometheus
[#123089](https://redirect.github.com/grafana/grafana/pull/123089),
[@itsmylife](https://redirect.github.com/itsmylife)
- **Prometheus:** Remove grafana-prometheus
[package#122953](https://redirect.github.com/package/grafana/issues/122953)
[#123035](https://redirect.github.com/grafana/grafana/pull/123035),
[@itsmylife](https://redirect.github.com/itsmylife)
- **Zipkin:** Remove from core plugins
[#124148](https://redirect.github.com/grafana/grafana/pull/124148),
[@itsmylife](https://redirect.github.com/itsmylife)
##### Plugin development fixes & changes
- **Card:** Improve responsiveness
[#123876](https://redirect.github.com/grafana/grafana/pull/123876),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **Combobox:** Fix caret jumping to the end of the input
[#123950](https://redirect.github.com/grafana/grafana/pull/123950),
[@joshhunt](https://redirect.github.com/joshhunt)
- **DataLinkInput:** Expose prop to properly link labels to input
[#123795](https://redirect.github.com/grafana/grafana/pull/123795),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **RadioButton:** Fix selected visibility in forced colors mode
[#123952](https://redirect.github.com/grafana/grafana/pull/123952),
[@ashharrison90](https://redirect.github.com/ashharrison90)
- **RadioButtonGroup:** Prevent RadioButtonGroup overflow with ellipsis
and hover title
[#119124](https://redirect.github.com/grafana/grafana/pull/119124),
[@Apahadi73](https://redirect.github.com/Apahadi73)
- **TimeOfDayPicker:** use Combobox
[#123777](https://redirect.github.com/grafana/grafana/pull/123777),
[@leeoniya](https://redirect.github.com/leeoniya)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
examples/example-custom-buckets/docker-compose.yaml | 2 +-
examples/example-exemplars-tail-sampling/docker-compose.yaml | 2 +-
examples/example-native-histogram/docker-compose.yaml | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/examples/example-custom-buckets/docker-compose.yaml b/examples/example-custom-buckets/docker-compose.yaml
index 77166969c..242161802 100644
--- a/examples/example-custom-buckets/docker-compose.yaml
+++ b/examples/example-custom-buckets/docker-compose.yaml
@@ -18,7 +18,7 @@ services:
- --enable-feature=native-histograms
- --config.file=/prometheus.yml
grafana:
- image: grafana/grafana:13.1.1@sha256:7cb8c64c4d57a57e734073f3cc94620adb24a0acb929bd80ba9f14017e3a975b
+ image: grafana/grafana:13.1.2@sha256:d177053ab62253815f130d81504f77063baf5fd4ca93299d6048453bd31e047a
network_mode: host
volumes:
- ./docker-compose/grafana-datasources.yaml:/etc/grafana/provisioning/datasources/grafana-datasources.yaml
diff --git a/examples/example-exemplars-tail-sampling/docker-compose.yaml b/examples/example-exemplars-tail-sampling/docker-compose.yaml
index 1169fbf24..87ddbff96 100644
--- a/examples/example-exemplars-tail-sampling/docker-compose.yaml
+++ b/examples/example-exemplars-tail-sampling/docker-compose.yaml
@@ -59,7 +59,7 @@ services:
command:
- --config.file=/config.yaml
grafana:
- image: grafana/grafana:13.1.1@sha256:7cb8c64c4d57a57e734073f3cc94620adb24a0acb929bd80ba9f14017e3a975b
+ image: grafana/grafana:13.1.2@sha256:d177053ab62253815f130d81504f77063baf5fd4ca93299d6048453bd31e047a
network_mode: host
ports:
- "3000:3000"
diff --git a/examples/example-native-histogram/docker-compose.yaml b/examples/example-native-histogram/docker-compose.yaml
index 50062aed5..dac46e4b8 100644
--- a/examples/example-native-histogram/docker-compose.yaml
+++ b/examples/example-native-histogram/docker-compose.yaml
@@ -18,7 +18,7 @@ services:
- --enable-feature=native-histograms
- --config.file=/prometheus.yml
grafana:
- image: grafana/grafana:13.1.1@sha256:7cb8c64c4d57a57e734073f3cc94620adb24a0acb929bd80ba9f14017e3a975b
+ image: grafana/grafana:13.1.2@sha256:d177053ab62253815f130d81504f77063baf5fd4ca93299d6048453bd31e047a
network_mode: host
volumes:
- ./docker-compose/grafana-datasources.yaml:/etc/grafana/provisioning/datasources/grafana-datasources.yaml
From 76e3395295817904bb64aeb38abdf403f49d685b Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 14:10:01 -0400
Subject: [PATCH 21/54] chore(deps): update github/codeql-action action to
v4.37.6 (#2368)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[github/codeql-action](https://redirect.github.com/github/codeql-action)
| action | patch | `v4.37.5` â `v4.37.6` |
---
### Release Notes
github/codeql-action (github/codeql-action)
###
[`v4.37.6`](https://redirect.github.com/github/codeql-action/releases/tag/v4.37.6)
[Compare
Source](https://redirect.github.com/github/codeql-action/compare/v4.37.5...v4.37.6)
- Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
`.github/codeql-config.yml` to align it with the suggested path that is
used elsewhere.
[#4070](https://redirect.github.com/github/codeql-action/pull/4070)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/workflows/codeql.yml | 4 ++--
.github/workflows/scorecard.yml | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index 1ca3c4ac0..0c75b31fd 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -37,7 +37,7 @@ jobs:
path: ~/.m2/repository
key: ${{ runner.os }}-maven-codeql-${{ hashFiles('**/pom.xml') }}
- name: Initialize CodeQL
- uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
+ uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
with:
languages: java
tools: linked
@@ -56,6 +56,6 @@ jobs:
-Djavadoc.skip=true
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
+ uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
with:
category: /language:java
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 604296434..95e2597d2 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -41,6 +41,6 @@ jobs:
retention-days: 5
- name: Upload to code scanning
- uses: github/codeql-action/upload-sarif@d1ba80a13dd99fba24a470575428917156a28b43 # v4.37.5
+ uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
with:
sarif_file: results.sarif
From 82aad34da8886646cf9d791d0a0fe744774d1670 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 14:10:14 -0400
Subject: [PATCH 22/54] chore(deps): update grafana/grafana docker tag to
v13.1.3 (#2372)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [grafana/grafana](https://redirect.github.com/grafana/grafana) | patch
| `13.1.2` â `13.1.3` |
---
### Release Notes
grafana/grafana (grafana/grafana)
###
[`v13.1.3`](https://redirect.github.com/grafana/grafana/releases/tag/v13.1.3):
13.1.3
[Download page](https://grafana.com/grafana/download/13.1.3)
[What's new
highlights](https://grafana.com/docs/grafana/latest/whatsnew/)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
examples/example-custom-buckets/docker-compose.yaml | 2 +-
examples/example-exemplars-tail-sampling/docker-compose.yaml | 2 +-
examples/example-native-histogram/docker-compose.yaml | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/examples/example-custom-buckets/docker-compose.yaml b/examples/example-custom-buckets/docker-compose.yaml
index 242161802..379100650 100644
--- a/examples/example-custom-buckets/docker-compose.yaml
+++ b/examples/example-custom-buckets/docker-compose.yaml
@@ -18,7 +18,7 @@ services:
- --enable-feature=native-histograms
- --config.file=/prometheus.yml
grafana:
- image: grafana/grafana:13.1.2@sha256:d177053ab62253815f130d81504f77063baf5fd4ca93299d6048453bd31e047a
+ image: grafana/grafana:13.1.3@sha256:ab5cb380e3ff3172d6c8bd2e7cfd31cce977d2881b260e1f5bc089bf0b759b43
network_mode: host
volumes:
- ./docker-compose/grafana-datasources.yaml:/etc/grafana/provisioning/datasources/grafana-datasources.yaml
diff --git a/examples/example-exemplars-tail-sampling/docker-compose.yaml b/examples/example-exemplars-tail-sampling/docker-compose.yaml
index 87ddbff96..f2ab03ee7 100644
--- a/examples/example-exemplars-tail-sampling/docker-compose.yaml
+++ b/examples/example-exemplars-tail-sampling/docker-compose.yaml
@@ -59,7 +59,7 @@ services:
command:
- --config.file=/config.yaml
grafana:
- image: grafana/grafana:13.1.2@sha256:d177053ab62253815f130d81504f77063baf5fd4ca93299d6048453bd31e047a
+ image: grafana/grafana:13.1.3@sha256:ab5cb380e3ff3172d6c8bd2e7cfd31cce977d2881b260e1f5bc089bf0b759b43
network_mode: host
ports:
- "3000:3000"
diff --git a/examples/example-native-histogram/docker-compose.yaml b/examples/example-native-histogram/docker-compose.yaml
index dac46e4b8..34eb30258 100644
--- a/examples/example-native-histogram/docker-compose.yaml
+++ b/examples/example-native-histogram/docker-compose.yaml
@@ -18,7 +18,7 @@ services:
- --enable-feature=native-histograms
- --config.file=/prometheus.yml
grafana:
- image: grafana/grafana:13.1.2@sha256:d177053ab62253815f130d81504f77063baf5fd4ca93299d6048453bd31e047a
+ image: grafana/grafana:13.1.3@sha256:ab5cb380e3ff3172d6c8bd2e7cfd31cce977d2881b260e1f5bc089bf0b759b43
network_mode: host
volumes:
- ./docker-compose/grafana-datasources.yaml:/etc/grafana/provisioning/datasources/grafana-datasources.yaml
From ee5f8e9e355c2ae01d857b28623ac45af6338cd1 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 14:10:32 -0400
Subject: [PATCH 23/54] chore(deps): update dependency grafana/docker-otel-lgtm
to v0.30.1 (#2373)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
|
[grafana/docker-otel-lgtm](https://redirect.github.com/grafana/docker-otel-lgtm)
| patch | `0.30.0` â `0.30.1` |
---
### Release Notes
grafana/docker-otel-lgtm (grafana/docker-otel-lgtm)
###
[`v0.30.1`](https://redirect.github.com/grafana/docker-otel-lgtm/releases/tag/v0.30.1)
[Compare
Source](https://redirect.github.com/grafana/docker-otel-lgtm/compare/v0.30.0...v0.30.1)
#### What's Changed
##### OpenTelemetry & LGTM
- chore(deps): update dependency prometheus to v3.13.2 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1678](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1678)
##### Other Changes
- Update renovate config by
[@martincostello](https://redirect.github.com/martincostello) in
[#1668](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1668)
- Add renovate schedule by
[@martincostello](https://redirect.github.com/martincostello) in
[#1683](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1683)
**Full Changelog**:
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
mise.toml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mise.toml b/mise.toml
index 5993e544b..7d4966db1 100644
--- a/mise.toml
+++ b/mise.toml
@@ -27,7 +27,7 @@ zizmor = "1.28.0"
[env]
FLINT_CONFIG_DIR = ".github/config"
# renovate: datasource=github-releases depName=grafana/docker-otel-lgtm
-LGTM_VERSION = "0.30.0"
+LGTM_VERSION = "0.30.1"
# Latest JMX Exporter release; used as the default ref for the compatibility job.
# renovate: datasource=github-tags depName=prometheus/jmx_exporter versioning=semver-coerced
DEFAULT_JMX_EXPORTER_VERSION = "v1.6.0"
From d1ade5280bdc613d3c7fc5f231ead1e2dca9882e Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 14:10:46 -0400
Subject: [PATCH 24/54] fix(deps): update junit-framework monorepo to v6.1.3
(#2374)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [org.junit:junit-bom](https://junit.org/)
([source](https://redirect.github.com/junit-team/junit-framework)) |
`6.1.2` â `6.1.3` |

|

|
| [org.junit.jupiter:junit-jupiter-params](https://junit.org/)
([source](https://redirect.github.com/junit-team/junit-framework)) |
`6.1.2` â `6.1.3` |

|

|
| [org.junit.jupiter:junit-jupiter](https://junit.org/)
([source](https://redirect.github.com/junit-team/junit-framework)) |
`6.1.2` â `6.1.3` |

|

|
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about these
updates again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
integration-tests/it-spring-boot-smoke-test/pom.xml | 2 +-
pom.xml | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/integration-tests/it-spring-boot-smoke-test/pom.xml b/integration-tests/it-spring-boot-smoke-test/pom.xml
index 7261a024f..e27ae713e 100644
--- a/integration-tests/it-spring-boot-smoke-test/pom.xml
+++ b/integration-tests/it-spring-boot-smoke-test/pom.xml
@@ -20,7 +20,7 @@
25
- 6.1.2
+ 6.1.3
diff --git a/pom.xml b/pom.xml
index 32e30634c..2ba361bb1 100644
--- a/pom.xml
+++ b/pom.xml
@@ -25,7 +25,7 @@
2.3.0
4.3.0
3.13.2
- 6.1.2
+ 6.1.3
2.30.0-alpha
8
25
From 90f99d635109472d8ccca304f044f93a1b0f1436 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 10 Aug 2026 14:11:11 -0400
Subject: [PATCH 25/54] chore(deps): update grafana/k6 docker digest to 5221b62
(#2377)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| grafana/k6 | digest | `e7eeddf` â `5221b62` |
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
examples/example-exemplars-tail-sampling/docker-compose.yaml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/examples/example-exemplars-tail-sampling/docker-compose.yaml b/examples/example-exemplars-tail-sampling/docker-compose.yaml
index f2ab03ee7..fd2b26a55 100644
--- a/examples/example-exemplars-tail-sampling/docker-compose.yaml
+++ b/examples/example-exemplars-tail-sampling/docker-compose.yaml
@@ -68,7 +68,7 @@ services:
- ./config/grafana-dashboards.yaml:/etc/grafana/provisioning/dashboards/grafana-dashboards.yaml
- ./config/grafana-example-dashboard.json:/etc/grafana/example-dashboard.json
k6:
- image: grafana/k6@sha256:e7eeddf1ce2361df6920d925297f487c0ba549c44be242c6a9c22f28d9b08efa
+ image: grafana/k6@sha256:5221b620a4f874faff6e32ba597aa667c058391fe4898b1c6f6377f062c6cdec
network_mode: host
volumes:
- ./config/k6-script.js:/k6-script.js
From 2ea6cd1bd796a87603cc3abcfff57b4dd51450ae Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 17 Aug 2026 10:55:18 +0200
Subject: [PATCH 26/54] chore(deps): update github/codeql-action action to
v4.37.7 (#2381)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[github/codeql-action](https://redirect.github.com/github/codeql-action)
| action | patch | `v4.37.6` â `v4.37.7` |
---
### Release Notes
github/codeql-action (github/codeql-action)
###
[`v4.37.7`](https://redirect.github.com/github/codeql-action/releases/tag/v4.37.7)
[Compare
Source](https://redirect.github.com/github/codeql-action/compare/v4.37.6...v4.37.7)
- Update default CodeQL bundle version to
[2.26.3](https://redirect.github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3).
[#4085](https://redirect.github.com/github/codeql-action/pull/4085)
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/workflows/codeql.yml | 4 ++--
.github/workflows/scorecard.yml | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index 0c75b31fd..b9ae9d3ce 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -37,7 +37,7 @@ jobs:
path: ~/.m2/repository
key: ${{ runner.os }}-maven-codeql-${{ hashFiles('**/pom.xml') }}
- name: Initialize CodeQL
- uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
+ uses: github/codeql-action/init@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
with:
languages: java
tools: linked
@@ -56,6 +56,6 @@ jobs:
-Djavadoc.skip=true
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
+ uses: github/codeql-action/analyze@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
with:
category: /language:java
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 95e2597d2..290d3c9da 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -41,6 +41,6 @@ jobs:
retention-days: 5
- name: Upload to code scanning
- uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
+ uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
with:
sarif_file: results.sarif
From 16a5599c3c75662cddc7e20276ef83a4601c9388 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 17 Aug 2026 10:55:35 +0200
Subject: [PATCH 27/54] chore(deps): update zeitlinger/micrometer digest to
00c7e14 (#2351)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| zeitlinger/micrometer | digest | `8f90b70` â `f240f09` |
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/workflows/micrometer-compatibility.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/micrometer-compatibility.yml b/.github/workflows/micrometer-compatibility.yml
index 5937d6344..e4212cb72 100644
--- a/.github/workflows/micrometer-compatibility.yml
+++ b/.github/workflows/micrometer-compatibility.yml
@@ -25,7 +25,7 @@ jobs:
# Follow-up: https://github.com/prometheus/client_java/issues/2182
repository: zeitlinger/micrometer
# renovate: datasource=git-refs depName=zeitlinger/micrometer packageName=https://github.com/zeitlinger/micrometer currentValue=feat/prom-client-java-typed-family-descriptor
- ref: 8f90b70807f5a063c592e3b17ef3b908be894086
+ ref: f240f0978366378dae66ac005ea1d2ef65708ff3
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
From 915815fd786fc082ae1104309287262513736be8 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 17 Aug 2026 10:55:54 +0200
Subject: [PATCH 28/54] chore(deps): lock file maintenance (#2376)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Update | Change |
|---|---|
| lockFileMaintenance | All locks refreshed |
đ§ This Pull Request updates lock files to use the latest dependency
versions.
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đģ **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
mise.lock | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/mise.lock b/mise.lock
index 8dfeeceec..04bc99807 100644
--- a/mise.lock
+++ b/mise.lock
@@ -494,9 +494,8 @@ checksum = "sha256:d28c8a5bf0a808f0ed434a1dce8c54ae98f0371c0bd86ac58abc613f73e66
url = "https://nodejs.org/dist/v24.19.0/node-v24.19.0-linux-arm64.tar.gz"
[tools.node."platforms.linux-arm64-musl"]
-checksum = "sha256:16fe258006a6e86844fbe05b3b5e1e5623ca8d3da54e32d98d9e83234bf25b01"
-url = "https://nodejs.org/dist/v24.19.0/node-v24.19.0.tar.gz"
-install = "source"
+checksum = "sha256:20824e4d35948fae5b337dccef47813b04d8995312f59df7386f2256d9f9ab7e"
+url = "https://unofficial-builds.nodejs.org/download/release/v24.19.0/node-v24.19.0-linux-arm64-musl.tar.gz"
[tools.node."platforms.linux-x64"]
checksum = "sha256:f625d97cd707df4ff96254916fbc5ff014f09c09effe5a1e0ca8f6d41a8789d4"
From c5dd9e3d12b587194a84b8115b007514a8e2c116 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 17 Aug 2026 10:56:12 +0200
Subject: [PATCH 29/54] chore(deps): update dependency grafana/docker-otel-lgtm
to v0.30.2 (#2383)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
|
[grafana/docker-otel-lgtm](https://redirect.github.com/grafana/docker-otel-lgtm)
| patch | `0.30.1` â `0.30.2` |
---
### Release Notes
grafana/docker-otel-lgtm (grafana/docker-otel-lgtm)
###
[`v0.30.2`](https://redirect.github.com/grafana/docker-otel-lgtm/releases/tag/v0.30.2)
[Compare
Source](https://redirect.github.com/grafana/docker-otel-lgtm/compare/v0.30.1...v0.30.2)
#### What's Changed
##### OpenTelemetry & LGTM
- chore(deps): update dependency grafana to v13.1.2 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1706](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1706)
- chore(deps): update dependency grafana to v13.1.3 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1717](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1717)
- chore(deps): update dependency pyroscope to v2.2.1 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1719](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1719)
- chore(deps): update dependency loki to v3.7.6 by
[@renovate-sh-app](https://redirect.github.com/renovate-sh-app)\[bot]
in
[#1718](https://redirect.github.com/grafana/docker-otel-lgtm/pull/1718)
**Full Changelog**:
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
mise.toml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/mise.toml b/mise.toml
index 7d4966db1..bbe142c3e 100644
--- a/mise.toml
+++ b/mise.toml
@@ -27,7 +27,7 @@ zizmor = "1.28.0"
[env]
FLINT_CONFIG_DIR = ".github/config"
# renovate: datasource=github-releases depName=grafana/docker-otel-lgtm
-LGTM_VERSION = "0.30.1"
+LGTM_VERSION = "0.30.2"
# Latest JMX Exporter release; used as the default ref for the compatibility job.
# renovate: datasource=github-tags depName=prometheus/jmx_exporter versioning=semver-coerced
DEFAULT_JMX_EXPORTER_VERSION = "v1.6.0"
From c1fb8c739f4a1aefff6ea0a23da6b89486e58293 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 17 Aug 2026 10:56:20 +0200
Subject: [PATCH 30/54] chore(deps): update eclipse-temurin:25.0.3_9-jre docker
digest to a214efa (#2379)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin)
([source](https://redirect.github.com/adoptium/containers)) | final |
digest | `f19dbf0` â `a214efa` |
| [eclipse-temurin](https://hub.docker.com/_/eclipse-temurin)
([source](https://redirect.github.com/adoptium/containers)) | | digest |
`f19dbf0` â `a214efa` |
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about these
updates again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
examples/example-custom-buckets/docker-compose.yaml | 2 +-
.../example-exporter-opentelemetry/oats-tests/agent/Dockerfile | 2 +-
.../example-exporter-opentelemetry/oats-tests/http/Dockerfile | 2 +-
examples/example-native-histogram/docker-compose.yaml | 2 +-
4 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/examples/example-custom-buckets/docker-compose.yaml b/examples/example-custom-buckets/docker-compose.yaml
index 379100650..0d105b2a1 100644
--- a/examples/example-custom-buckets/docker-compose.yaml
+++ b/examples/example-custom-buckets/docker-compose.yaml
@@ -1,7 +1,7 @@
version: "3"
services:
example-application:
- image: eclipse-temurin:25.0.3_9-jre@sha256:f19dbf0a22d0b3658fda48ce7d7181df05ad14bda151dd5ad12cc09d1451c70e
+ image: eclipse-temurin:25.0.3_9-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
network_mode: host
volumes:
- ./target/example-custom-buckets.jar:/example-custom-buckets.jar
diff --git a/examples/example-exporter-opentelemetry/oats-tests/agent/Dockerfile b/examples/example-exporter-opentelemetry/oats-tests/agent/Dockerfile
index 4fdc0e09c..352c5914b 100644
--- a/examples/example-exporter-opentelemetry/oats-tests/agent/Dockerfile
+++ b/examples/example-exporter-opentelemetry/oats-tests/agent/Dockerfile
@@ -1,4 +1,4 @@
-FROM eclipse-temurin:25.0.3_9-jre@sha256:f19dbf0a22d0b3658fda48ce7d7181df05ad14bda151dd5ad12cc09d1451c70e
+FROM eclipse-temurin:25.0.3_9-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
COPY target/example-exporter-opentelemetry.jar ./app.jar
# check that the resource attributes from the agent are used, epsecially the service.instance.id should be the same
diff --git a/examples/example-exporter-opentelemetry/oats-tests/http/Dockerfile b/examples/example-exporter-opentelemetry/oats-tests/http/Dockerfile
index 26ab27cf8..9a9419fa0 100644
--- a/examples/example-exporter-opentelemetry/oats-tests/http/Dockerfile
+++ b/examples/example-exporter-opentelemetry/oats-tests/http/Dockerfile
@@ -1,4 +1,4 @@
-FROM eclipse-temurin:25.0.3_9-jre@sha256:f19dbf0a22d0b3658fda48ce7d7181df05ad14bda151dd5ad12cc09d1451c70e
+FROM eclipse-temurin:25.0.3_9-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
COPY target/example-exporter-opentelemetry.jar ./app.jar
diff --git a/examples/example-native-histogram/docker-compose.yaml b/examples/example-native-histogram/docker-compose.yaml
index 34eb30258..1847fe75f 100644
--- a/examples/example-native-histogram/docker-compose.yaml
+++ b/examples/example-native-histogram/docker-compose.yaml
@@ -1,7 +1,7 @@
version: "3"
services:
example-application:
- image: eclipse-temurin:25.0.3_9-jre@sha256:f19dbf0a22d0b3658fda48ce7d7181df05ad14bda151dd5ad12cc09d1451c70e
+ image: eclipse-temurin:25.0.3_9-jre@sha256:a214efa3200af4b657e41935799aa12d7aee3336fdb42eb505a0948f6ecdd983
network_mode: host
volumes:
- ./target/example-native-histogram.jar:/example-native-histogram.jar
From 715c293a91a4bdce8fe03c78ae5e8773779aef1f Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 17 Aug 2026 10:56:32 +0200
Subject: [PATCH 31/54] chore(deps): update jdx/mise-action action to v4.2.5
(#2380)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [jdx/mise-action](https://redirect.github.com/jdx/mise-action) |
action | patch | `v4.2.4` â `v4.2.5` |
---
### Release Notes
jdx/mise-action (jdx/mise-action)
###
[`v4.2.5`](https://redirect.github.com/jdx/mise-action/releases/tag/v4.2.5):
: Resilient mise downloads with automatic retries
[Compare
Source](https://redirect.github.com/jdx/mise-action/compare/v4.2.4...v4.2.5)
A small patch release that makes setup more resilient to transient
network failures when downloading mise.
##### Fixed
##### Retry mise downloads after transient failures
([#597](https://redirect.github.com/jdx/mise-action/pull/597) by
[@jdx](https://redirect.github.com/jdx))
The download helpers previously made a single `curl` or `wget` attempt,
so a transient GitHub release-asset HTTP or TLS failure would abort
setup before mise or any user command could run (see
[#596](https://redirect.github.com/jdx/mise-action/issues/596)).
Downloads now run through a retry wrapper that makes up to five attempts
with a 2s pause between failures, logging a warning on each retry. This
applies consistently to binary, checksum, signature, and version
fetches. Checksum and minisign verification still run only after a
successful download â never inside the retry loop â so integrity
guarantees are unchanged.
**Full Changelog**:
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
.github/workflows/acceptance-tests.yml | 2 +-
.github/workflows/api-diff.yml | 2 +-
.github/workflows/build.yml | 2 +-
.github/workflows/bump-api-diff-baseline.yml | 2 +-
.github/workflows/generate-protobuf.yml | 2 +-
.github/workflows/github-pages.yaml | 2 +-
.github/workflows/java-version-matrix-tests.yml | 2 +-
.github/workflows/jmx-exporter-compatibility.yml | 2 +-
.github/workflows/lint.yml | 2 +-
.github/workflows/micrometer-compatibility.yml | 2 +-
.github/workflows/native-tests.yml | 2 +-
.github/workflows/nightly-benchmarks.yml | 2 +-
.github/workflows/pr-benchmarks.yml | 2 +-
.github/workflows/regenerate-api-diff-otel.yml | 2 +-
.github/workflows/release.yml | 2 +-
.github/workflows/test-release-build.yml | 2 +-
16 files changed, 16 insertions(+), 16 deletions(-)
diff --git a/.github/workflows/acceptance-tests.yml b/.github/workflows/acceptance-tests.yml
index 420d8fba9..a953bc4e1 100644
--- a/.github/workflows/acceptance-tests.yml
+++ b/.github/workflows/acceptance-tests.yml
@@ -13,7 +13,7 @@ jobs:
with:
persist-credentials: false
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/api-diff.yml b/.github/workflows/api-diff.yml
index 97171dd80..f500b10de 100644
--- a/.github/workflows/api-diff.yml
+++ b/.github/workflows/api-diff.yml
@@ -32,7 +32,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index 7877d56d3..8d1095b92 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -12,7 +12,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/bump-api-diff-baseline.yml b/.github/workflows/bump-api-diff-baseline.yml
index 20623b920..e2ef4a5ce 100644
--- a/.github/workflows/bump-api-diff-baseline.yml
+++ b/.github/workflows/bump-api-diff-baseline.yml
@@ -33,7 +33,7 @@ jobs:
with:
ref: ${{ env.SNAPSHOT_BRANCH }}
persist-credentials: true
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/generate-protobuf.yml b/.github/workflows/generate-protobuf.yml
index dc9d2f133..454c8fb8b 100644
--- a/.github/workflows/generate-protobuf.yml
+++ b/.github/workflows/generate-protobuf.yml
@@ -18,7 +18,7 @@ jobs:
with:
ref: ${{ github.ref }}
persist-credentials: false
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/github-pages.yaml b/.github/workflows/github-pages.yaml
index a03b03133..7ec9d887c 100644
--- a/.github/workflows/github-pages.yaml
+++ b/.github/workflows/github-pages.yaml
@@ -37,7 +37,7 @@ jobs:
persist-credentials: false
fetch-tags: "true"
fetch-depth: 0
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/java-version-matrix-tests.yml b/.github/workflows/java-version-matrix-tests.yml
index f3ea4a47d..03a9c8a25 100644
--- a/.github/workflows/java-version-matrix-tests.yml
+++ b/.github/workflows/java-version-matrix-tests.yml
@@ -31,7 +31,7 @@ jobs:
persist-credentials: false
- name: Set up mise
- uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/jmx-exporter-compatibility.yml b/.github/workflows/jmx-exporter-compatibility.yml
index 3f165a0a6..68b429e5b 100644
--- a/.github/workflows/jmx-exporter-compatibility.yml
+++ b/.github/workflows/jmx-exporter-compatibility.yml
@@ -22,7 +22,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml
index 1d5a8e1d8..ae22d56b5 100644
--- a/.github/workflows/lint.yml
+++ b/.github/workflows/lint.yml
@@ -21,7 +21,7 @@ jobs:
fetch-depth: 0 # needed for git diff --merge-base in lint:links
- name: Setup mise
- uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/micrometer-compatibility.yml b/.github/workflows/micrometer-compatibility.yml
index e4212cb72..53a3ec1af 100644
--- a/.github/workflows/micrometer-compatibility.yml
+++ b/.github/workflows/micrometer-compatibility.yml
@@ -30,7 +30,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/native-tests.yml b/.github/workflows/native-tests.yml
index 47b646358..689d1affb 100644
--- a/.github/workflows/native-tests.yml
+++ b/.github/workflows/native-tests.yml
@@ -13,7 +13,7 @@ jobs:
with:
persist-credentials: false
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/nightly-benchmarks.yml b/.github/workflows/nightly-benchmarks.yml
index f5b9493d8..87ddcddef 100644
--- a/.github/workflows/nightly-benchmarks.yml
+++ b/.github/workflows/nightly-benchmarks.yml
@@ -34,7 +34,7 @@ jobs:
fetch-depth: 0
- name: Setup mise
- uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/pr-benchmarks.yml b/.github/workflows/pr-benchmarks.yml
index ad89cc358..baabd784d 100644
--- a/.github/workflows/pr-benchmarks.yml
+++ b/.github/workflows/pr-benchmarks.yml
@@ -45,7 +45,7 @@ jobs:
fetch-depth: 0
- name: Setup mise
- uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/regenerate-api-diff-otel.yml b/.github/workflows/regenerate-api-diff-otel.yml
index 0d5abef26..8fe5408c7 100644
--- a/.github/workflows/regenerate-api-diff-otel.yml
+++ b/.github/workflows/regenerate-api-diff-otel.yml
@@ -18,7 +18,7 @@ jobs:
with:
ref: ${{ github.ref }}
persist-credentials: false
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 9dbf33cd1..87f620f54 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -72,7 +72,7 @@ jobs:
ref: ${{ inputs.tag }}
persist-credentials: false
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
diff --git a/.github/workflows/test-release-build.yml b/.github/workflows/test-release-build.yml
index 09bae5b4d..2181fbb81 100644
--- a/.github/workflows/test-release-build.yml
+++ b/.github/workflows/test-release-build.yml
@@ -18,7 +18,7 @@ jobs:
persist-credentials: false
fetch-tags: "true"
fetch-depth: 0
- - uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
+ - uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
version: v2026.7.5
sha256: 5f7ab76afdf0780d12edeaa67e908094e9ccf7924cfe203e415c1cfb87bbf778
From cc04b6e64b136e6ff39d906f99beed10ba961194 Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 17 Aug 2026 10:56:50 +0200
Subject: [PATCH 32/54] chore(deps): update grafana/tempo docker tag to v3.0.3
(#2382)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| grafana/tempo | patch | `3.0.2` â `3.0.3` |
---
### Configuration
đ
**Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
đĻ **Automerge**: Enabled.
âģ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
đ **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/prometheus/client_java).
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
---
examples/example-exemplars-tail-sampling/docker-compose.yaml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/examples/example-exemplars-tail-sampling/docker-compose.yaml b/examples/example-exemplars-tail-sampling/docker-compose.yaml
index fd2b26a55..eadc30f65 100644
--- a/examples/example-exemplars-tail-sampling/docker-compose.yaml
+++ b/examples/example-exemplars-tail-sampling/docker-compose.yaml
@@ -52,7 +52,7 @@ services:
- --enable-feature=native-histograms
- --config.file=/prometheus.yaml
tempo:
- image: grafana/tempo:3.0.2@sha256:cda87c212d8c584dc0b89e337e7ed648a5100feb657e5d528480ee4fa03dbbe3
+ image: grafana/tempo:3.0.3@sha256:0296560ac66f8a3600d7fb3014a52c189d4d9c3549ad6ff441bf2409855d68d5
network_mode: host
volumes:
- ./config/tempo-config.yaml:/config.yaml
From 57eaf5a2d577453e511df576d365928463c127de Mon Sep 17 00:00:00 2001
From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com>
Date: Mon, 17 Aug 2026 10:56:57 +0200
Subject: [PATCH 33/54] chore(deps): update linters (#2375)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
> âšī¸ **Note**
>
> This PR body was truncated due to platform limits.
This PR contains the following updates:
| Package | Type | Update | Change | Pending |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|---|---|---|
|
[aqua:jonwiggins/xmloxide](https://redirect.github.com/jonwiggins/xmloxide)
| tools | minor | `0.4.4` â `0.5.0` | |

|

|
| [biome](https://redirect.github.com/biomejs/biome) | tools | patch |
`2.5.5` â `2.5.8` | |

|

|
|
[editorconfig-checker](https://redirect.github.com/editorconfig-checker/editorconfig-checker)
| tools | minor | `3.8.0` â `3.11.1` | |

|

|
|
[google-java-format](https://redirect.github.com/google/google-java-format)
| tools | minor | `1.35.0` â `1.36.1` | |

|

|
| [npm:renovate](https://renovatebot.com)
([source](https://redirect.github.com/renovatebot/renovate)) | tools |
major | [`43.279.1` â
`44.29.4`](https://octochangelog.com/compare?repo=renovatebot%2Frenovate&from=43.279.1&to=44.29.4)
| `44.31.0` (+6) |

|

|
| [ruff](https://redirect.github.com/astral-sh/ruff) | tools | patch |
`0.16.0` â `0.16.3` | |

|

|
| [rumdl](https://redirect.github.com/rvben/rumdl) | tools | patch |
`v0.2.43` â `v0.2.55` | |

|

|
| [typos](https://redirect.github.com/crate-ci/typos) | tools | minor |
`1.48.0` â `1.49.0` | |

|

|
| [zizmor](https://redirect.github.com/zizmorcore/zizmor) | tools |
minor | `1.28.0` â `1.29.0` | |

|

|
---
### Release Notes
jonwiggins/xmloxide (aqua:jonwiggins/xmloxide)
###
[`v0.5.0`](https://redirect.github.com/jonwiggins/xmloxide/blob/HEAD/CHANGELOG.md#050---2026-08-08)
[Compare
Source](https://redirect.github.com/jonwiggins/xmloxide/compare/v0.4.4...v0.5.0)
##### Changed
- **XPath attribute results are first-class attribute nodes**
([#47](https://redirect.github.com/jonwiggins/xmloxide/issues/47)).
Node-sets (`XPathValue::NodeSet`) now hold `XPathNode` entries â either
a
tree node or an attribute identified by owner element and index â
instead
of bare `NodeId`s. This fixes a family of wrong-answer bugs rooted in
the
old one-value-per-element override map: `//a/@x != //a/@y` comparisons
no
longer clobber each other's values, `@*` yields one node per attribute
(previously only the first per element), `count((//a)[1]/@href)` returns
a
number instead of a type error,
`name()`/`local-name()`/`namespace-uri()`
work on attribute nodes, `@attr/..` navigates to the owner element,
predicates evaluate with the attribute as context node, and namespace
declarations (`xmlns`, `xmlns:*`) are no longer visible as attributes
per
the XPath 1.0 data model. Mixed node-sets (`//a | //a/@x`) sort in
document order with attributes directly after their owner element.
**Breaking:** code matching `XPathValue::NodeSet` must handle
`XPathNode`; use `.anchor()` for the owning tree node or
`.as_tree_node()` to filter attributes out. The single-match collapse
(attribute paths returning `XPathValue::String`) is gone â convert with
`string()` where a string is wanted. `xmllint --xpath` prints attribute
results as `name="value"` lines, matching libxml2. The C API keeps
`xmloxide_xpath_nodeset_item()` (returns the owner element id for
attributes) and adds `xmloxide_xpath_nodeset_item_is_attribute()`,
`..._attr_name()`, and `..._attr_value()`.
- **XPath step predicates apply per context node** per XPath 1.0 §2.4:
`//a/b[1]` now selects the first `b` of *every* `a` (previously the
first
of the merged set), and `position()`/`last()` in step predicates are
relative to each context node's own node-set, matching libxml2. The
parenthesized form `(//a/b)[1]` keeps global-position semantics.
- **Schematron rules with attribute contexts** (`context="//@id"`) now
fire
with the attribute itself as the context node â `.` is the attribute
value and ` ` reads it, per ISO Schematron.
Previously such rules either never fired (single match) or misfired
against the owner element.
##### Security
- **Fix exponential-time entity recursion check**
([#42](https://redirect.github.com/jonwiggins/xmloxide/issues/42),
thanks [@hey-jj](https://redirect.github.com/hey-jj)). The
WFC: No Recursion walks in the DTD validator re-visited entities once
per
path, so a 474-byte document with chained entity declarations took 8+
seconds to parse and a 694-byte one about 22 hours. The walks (including
parameter entities and ATTLIST-default validation) now memoize entities
proven acyclic, making the check linear in the size of the DTD. Cycle
detection is unaffected.
- **Bound element nesting across entity expansions.** Entity replacement
text
is parsed by nested sub-parsers, which now inherit the outer parser's
nesting depth so total element depth stays bounded by
`ParseOptions::max_depth` instead of `max_depth` per expansion level.
##### Fixed
- **General entity replacement text is parsed as content** per XML 1.0
§4.4
([#43](https://redirect.github.com/jonwiggins/xmloxide/issues/43),
thanks [@hey-jj](https://redirect.github.com/hey-jj)).
`EntityRef` nodes now carry their parsed expansion
as children: character references in declarations are expanded when
replacement text is built (§4.5), nested entity references are included,
and markup-bearing entities produce real element children instead of
escaped text â while serialization still emits `&name;`, keeping
round-trips lossless. Replacement text must match the content production
(§4.3.2); unbalanced or split tags are rejected. Entity expansion is
subject to the expansion counter, a nesting-depth cap, and the 5x
amplification guard, matching libxml2. DTD content-model validation sees
through entity references (§4.4.3), so entity-supplied elements are
validated too.
- **XPath `!=` uses its own existential semantics for node-sets** per
XPath
1.0 §3.4
([#44](https://redirect.github.com/jonwiggins/xmloxide/issues/44),
thanks [@hey-jj](https://redirect.github.com/hey-jj)). `!=` was
evaluated as `not(=)`, inverting
empty-node-set comparisons and breaking multi-node sets (both `=` and
`!=`
can hold at once). Node-set vs boolean keeps boolean-conversion
semantics;
scalar comparisons are unchanged. An absent attribute step now also
yields
an empty node-set (false under both `=` and `!=`) instead of an
empty-string sentinel.
- **XPath filter-path continuations navigate instead of filtering**
([#20](https://redirect.github.com/jonwiggins/xmloxide/issues/20),
thanks [@ancientcatz](https://redirect.github.com/ancientcatz)).
`(//a)[1]/@href` parsed to the same AST as
`(//a)[@href]`, so the trailing path acted as a predicate and
`string((//a)[1]/@href)` returned the anchor text. A new
`Expr::FilterPath` AST variant evaluates the continuation steps against
the filter's node-set. **Breaking:** downstream exhaustive matches on
`xpath::ast::Expr` must handle the new variant.
biomejs/biome (biome)
###
[`v2.5.8`](https://redirect.github.com/biomejs/biome/releases/tag/%40biomejs/biome%402.5.8):
Biome CLI v2.5.8
[Compare
Source](https://redirect.github.com/biomejs/biome/compare/@biomejs/biome@2.5.7...@biomejs/biome@2.5.8)
#### 2.5.8
##### Patch Changes
- [#10710](https://redirect.github.com/biomejs/biome/pull/10710)
[`0a0fbc1`](https://redirect.github.com/biomejs/biome/commit/0a0fbc15d67c410c80dfae398903f845544fcd65)
Thanks [@dyc3](https://redirect.github.com/dyc3)! - Added a new
nursery rule
[`useReactCompiler`](https://biomejs.dev/linter/rules/use-react-compiler/),
which reports diagnostics from React Compiler lint mode.
- [#11251](https://redirect.github.com/biomejs/biome/pull/11251)
[`ea9dd8a`](https://redirect.github.com/biomejs/biome/commit/ea9dd8a93e65f849840415e8e26cd668aa1af913)
Thanks [@dyc3](https://redirect.github.com/dyc3)! - Improved
performance of
[`noImportCycles`](https://biomejs.dev/linter/rules/no-import-cycles/).
- [#11247](https://redirect.github.com/biomejs/biome/pull/11247)
[`52b44d6`](https://redirect.github.com/biomejs/biome/commit/52b44d6795741d051bf703bd69c6cb447af8fd1d)
Thanks [@dyc3](https://redirect.github.com/dyc3)! - Added the
nursery rule
[`noSvelteLegacyConst`](https://biomejs.dev/linter/rules/no-svelte-legacy-const/),
which disallows legacy Svelte `{@const}` tags and recommends declaration
tags with `$derived()`.
Invalid:
```svelte
{#each boxes as box}
{@const area = box.width * box.height}
{area}
{/each}
```
Valid:
```svelte
{#each boxes as box}
{const area = $derived(box.width * box.height)}
{area}
{/each}
```
- [#11252](https://redirect.github.com/biomejs/biome/pull/11252)
[`d5f5704`](https://redirect.github.com/biomejs/biome/commit/d5f570414fdcdddf62372e35c05f6dababad9287)
Thanks [@Turtle-Hwan](https://redirect.github.com/Turtle-Hwan)! -
Fixed
[#11250](https://redirect.github.com/biomejs/biome/issues/11250):
[`useAwait`](https://biomejs.dev/linter/rules/use-await/) no longer
reports async functions that contain an `await using` declaration.
- [#11143](https://redirect.github.com/biomejs/biome/pull/11143)
[`6be7be1`](https://redirect.github.com/biomejs/biome/commit/6be7be1b147d7b4352ff5625a78bd54a48958950)
Thanks [@vznh](https://redirect.github.com/vznh)! - Fixed
[#11017](https://redirect.github.com/biomejs/biome/issues/11017):
[`noUselessUndefined`](https://biomejs.dev/linter/rules/no-useless-undefined/)
no longer reports `return undefined` when the enclosing function has a
return type annotation other than `undefined` or `void`.
- [#11234](https://redirect.github.com/biomejs/biome/pull/11234)
[`caefe39`](https://redirect.github.com/biomejs/biome/commit/caefe393c66340914c481f7ccfc82979cf76b61b)
Thanks [@subotac](https://redirect.github.com/subotac)! - Fixed
[#11228](https://redirect.github.com/biomejs/biome/issues/11228):
CSS block comments between a declaration colon and value now preserve
their source indentation.
```diff
:root {
--font-stack:
-/* comment */
+ /* comment */
system-ui;
}
```
- [#11285](https://redirect.github.com/biomejs/biome/pull/11285)
[`bca1f73`](https://redirect.github.com/biomejs/biome/commit/bca1f73d939423056337bfd0a42cbdcb66bb1e3f)
Thanks [@denbezrukov](https://redirect.github.com/denbezrukov)! -
Fixed
[#11280](https://redirect.github.com/biomejs/biome/issues/11280):
CSS formatting keeps comments inside functional pseudo-classes and
pseudo-elements instead of moving them before the function name.
```diff
-:/* comment */ where(div) {}
+:where(/* comment */ div) {}
```
- [#11080](https://redirect.github.com/biomejs/biome/pull/11080)
[`af16a0b`](https://redirect.github.com/biomejs/biome/commit/af16a0bf884c48bad2caab70e7930096e81e1c99)
Thanks [@dyc3](https://redirect.github.com/dyc3)! - HTML `style`
attribute values are now parsed as CSS. All Biome CSS lint rules are
applied to the `style` attributes.
- [#11195](https://redirect.github.com/biomejs/biome/pull/11195)
[`6a85588`](https://redirect.github.com/biomejs/biome/commit/6a85588578725195625281984a47c9a8563bf103)
Thanks [@dyc3](https://redirect.github.com/dyc3)! - Fixed Svelte
files failing to parse when an expression begins with an object literal.
Now the following snippet is correctly parsed:
```svelte
{{ a: true }}
```
- [#11173](https://redirect.github.com/biomejs/biome/pull/11173)
[`481d008`](https://redirect.github.com/biomejs/biome/commit/481d008f6e8872a78749496fbbf1f9c761d9a770)
Thanks [@Austin1serb](https://redirect.github.com/Austin1serb)! -
Fixed
[#10242](https://redirect.github.com/biomejs/biome/issues/10242):
JavaScript GritQL patterns with multiple metavariables now match
snippets consistently in WebAssembly.
- [#11187](https://redirect.github.com/biomejs/biome/pull/11187)
[`23c0369`](https://redirect.github.com/biomejs/biome/commit/23c0369c43b59284ca68c65883d6ede4228b6fb8)
Thanks [@ematipico](https://redirect.github.com/ematipico)! -
Added the nursery rule
[`noInvalidPropertyInitValue`](https://biomejs.dev/linter/rules/no-invalid-property-init-value/),
which reports an `@property` whose `initial-value` does not match its
`syntax` descriptor. For example, the following declaration triggers the
rule because `red` is not a ``:
```css
@property --size {
syntax: "";
inherits: false;
initial-value: red;
}
```
- [#11272](https://redirect.github.com/biomejs/biome/pull/11272)
[`73896e6`](https://redirect.github.com/biomejs/biome/commit/73896e6712ba4c398ba21141829f8361ace45eb2)
Thanks [@ematipico](https://redirect.github.com/ematipico)! -
Improved the diagnostic emitted by
[`noRootType`](https://biomejs.dev/linter/rules/no-root-type).
- [#11240](https://redirect.github.com/biomejs/biome/pull/11240)
[`bd0b68d`](https://redirect.github.com/biomejs/biome/commit/bd0b68d418890059930074b46273aa616fbb735a)
Thanks [@ematipico](https://redirect.github.com/ematipico)! -
Fixed
[#11223](https://redirect.github.com/biomejs/biome/issues/11223):
Improved the
performance of
[`noMisusedPromises`](https://biomejs.dev/linter/rules/no-misused-promises/)
when analyzing async class methods that call other methods through
`this`.
- [#11172](https://redirect.github.com/biomejs/biome/pull/11172)
[`4a0bc5c`](https://redirect.github.com/biomejs/biome/commit/4a0bc5c46e6dbbefd17fa133ea426aa41f0a23f8)
Thanks
[@saberoueslati](https://redirect.github.com/saberoueslati)! -
Fixed
[#10806](https://redirect.github.com/biomejs/biome/issues/10806):
[`noUselessFragments`](https://biomejs.dev/linter/rules/no-useless-fragments/)
no longer causes Biome to panic when its unsafe fix removes a fragment
used as a JSX attribute value.
- [#11227](https://redirect.github.com/biomejs/biome/pull/11227)
[`4d603b0`](https://redirect.github.com/biomejs/biome/commit/4d603b072fae45a69bd291ab92f3379232cd34df)
Thanks
[@saberoueslati](https://redirect.github.com/saberoueslati)! -
Fixed
[#11178](https://redirect.github.com/biomejs/biome/issues/11178):
[`noUndeclaredVariables`](https://biomejs.dev/linter/rules/no-undeclared-variables/)
no longer reports Vue's built-in instance properties, such as `$slots`
and `$attrs`, in template expressions or `$event` in inline
event-handler expressions. The instance properties are still reported
inside `