From 8cc3e7f1e281c254aa00f121fc579bd88c019974 Mon Sep 17 00:00:00 2001 From: Hector Hernandez <39923391+hectorhdzg@users.noreply.github.com> Date: Tue, 6 Oct 2026 11:22:52 -0700 Subject: [PATCH 1/3] chore(release): 1.5.0 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- CHANGELOG.md | 2 ++ package-lock.json | 4 ++-- package.json | 2 +- samples/agent365-s2s/package-lock.json | 2 +- samples/package-lock.json | 2 +- src/types.ts | 2 +- 6 files changed, 8 insertions(+), 6 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9265d1d..0281d6f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## [Unreleased] +## [1.5.0] - 2026-10-06 + ### Bugs Fixed - Update `@grpc/grpc-js` from 1.14.4 to 1.14.5 in the root and AKS LangChain sample lockfiles to address [CVE-2026-101915](https://github.com/advisories/GHSA-f596-whhp-79r4) and [CVE-2026-101916](https://github.com/advisories/GHSA-m9gg-hp2v-232j). - A365: centralize shared request attributes in the base scope, including session and conversation IDs, channel details, and `operationSource` as `service.name`, while retaining last-write-wins `recordAttributes()` behavior. [#243](https://github.com/microsoft/opentelemetry-distro-javascript/pull/243) diff --git a/package-lock.json b/package-lock.json index ac908d9..e6885bb 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@microsoft/opentelemetry", - "version": "1.4.0", + "version": "1.5.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@microsoft/opentelemetry", - "version": "1.4.0", + "version": "1.5.0", "license": "MIT", "dependencies": { "@azure-rest/core-client": "^2.8.0", diff --git a/package.json b/package.json index f6edea0..256d8e4 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "@microsoft/opentelemetry", "author": "Microsoft Corporation", - "version": "1.4.0", + "version": "1.5.0", "description": "Microsoft OpenTelemetry distribution for JavaScript/TypeScript", "main": "./dist/commonjs/index.js", "module": "./dist/esm/index.js", diff --git a/samples/agent365-s2s/package-lock.json b/samples/agent365-s2s/package-lock.json index 91336d1..524b695 100644 --- a/samples/agent365-s2s/package-lock.json +++ b/samples/agent365-s2s/package-lock.json @@ -23,7 +23,7 @@ }, "../..": { "name": "@microsoft/opentelemetry", - "version": "1.4.0", + "version": "1.5.0", "license": "MIT", "dependencies": { "@azure-rest/core-client": "^2.8.0", diff --git a/samples/package-lock.json b/samples/package-lock.json index dc69b9d..8ceb8df 100644 --- a/samples/package-lock.json +++ b/samples/package-lock.json @@ -31,7 +31,7 @@ }, "..": { "name": "@microsoft/opentelemetry", - "version": "1.4.0", + "version": "1.5.0", "license": "MIT", "dependencies": { "@azure-rest/core-client": "^2.8.0", diff --git a/src/types.ts b/src/types.ts index 38bbee7..b1bfcb4 100644 --- a/src/types.ts +++ b/src/types.ts @@ -11,7 +11,7 @@ import type { A365Options } from "./a365/index.js"; /** * Microsoft OpenTelemetry distribution version. */ -export const MICROSOFT_OPENTELEMETRY_VERSION = "1.4.0"; +export const MICROSOFT_OPENTELEMETRY_VERSION = "1.5.0"; /** * Microsoft OpenTelemetry Options From 4d78c69f2dec6817541c991fcf11923bf6b4961a Mon Sep 17 00:00:00 2001 From: Hector Hernandez <39923391+hectorhdzg@users.noreply.github.com> Date: Tue, 6 Oct 2026 11:25:37 -0700 Subject: [PATCH 2/3] docs: complete 1.5.0 release notes Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- CHANGELOG.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 0281d6f..77e76df 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,11 +5,12 @@ ## [1.5.0] - 2026-10-06 ### Bugs Fixed -- Update `@grpc/grpc-js` from 1.14.4 to 1.14.5 in the root and AKS LangChain sample lockfiles to address [CVE-2026-101915](https://github.com/advisories/GHSA-f596-whhp-79r4) and [CVE-2026-101916](https://github.com/advisories/GHSA-m9gg-hp2v-232j). +- Update `@grpc/grpc-js` from 1.14.4 to 1.14.5 in the root and AKS LangChain sample lockfiles to address [CVE-2026-101915](https://github.com/advisories/GHSA-f596-whhp-79r4) and [CVE-2026-101916](https://github.com/advisories/GHSA-m9gg-hp2v-232j). [#250](https://github.com/microsoft/opentelemetry-distro-javascript/pull/250) - A365: centralize shared request attributes in the base scope, including session and conversation IDs, channel details, and `operationSource` as `service.name`, while retaining last-write-wins `recordAttributes()` behavior. [#243](https://github.com/microsoft/opentelemetry-distro-javascript/pull/243) - Default `InvokeAgentScope` spans to `SpanKind.INTERNAL` while preserving explicit span-kind overrides. [#241](https://github.com/microsoft/opentelemetry-distro-javascript/pull/241) ### Features Added +- Add a standalone Agent365 service-to-service observability sample with two-stage MSAL authentication, expiry-aware token caching, safe diagnostics, deterministic manual telemetry, and all five manual scope types. [#244](https://github.com/microsoft/opentelemetry-distro-javascript/pull/244) - Add typed ExecuteTool argument and result schemas with default schema_version: "1.0", collision-safe `extension_data` emitted under `metadata`, and non-throwing validation aligned with the .NET and Python distros. [#240](https://github.com/microsoft/opentelemetry-distro-javascript/pull/240) - Add manual `sessionId` propagation to `ExecuteToolScope` and `InferenceScope`, plus opt-in custom baggage enrichment for recognized GenAI spans through `BaggageBuilder.customAttribute()` and `customAttributes()`. [#242](https://github.com/microsoft/opentelemetry-distro-javascript/pull/242) - Add GenAI v1.42 InvokeAgent request, response, cache-token, and provider attribute capture for manual A365 scopes. [#239](https://github.com/microsoft/opentelemetry-distro-javascript/pull/239) @@ -17,8 +18,8 @@ ### Other Changes - Consolidate Dependabot updates for root markdown-it 14.3.2 and Hono 4.13.12, samples brace-expansion 5.0.12 and fast-uri 3.1.8, and root and samples ip-address 10.7.2. [#255](https://github.com/microsoft/opentelemetry-distro-javascript/pull/255) - Add upstream compatibility contracts for OpenTelemetry resource detectors, service instance identity precedence, telemetry SDK pipelines, and W3C trace propagation. [#249](https://github.com/microsoft/opentelemetry-distro-javascript/pull/249) -- Add offline SDK throughput and signed memory benchmarks with raw artifacts and explicitly configured named OTLP log result export. -- Consolidate Dependabot updates for Vitest 4.1.11, Hono 4.13.7, qs 6.16.0, fast-uri 3.1.7, actions/deploy-pages 5.0.1, and actions/checkout 7.0.1. +- Add offline SDK throughput and signed memory benchmarks with raw artifacts and explicitly configured named OTLP log result export. [#246](https://github.com/microsoft/opentelemetry-distro-javascript/pull/246) +- Consolidate Dependabot updates for Vitest 4.1.11, Hono 4.13.7, qs 6.16.0, fast-uri 3.1.7, actions/deploy-pages 5.0.1, and actions/checkout 7.0.1. [#238](https://github.com/microsoft/opentelemetry-distro-javascript/pull/238) - Document local npm lockfile regeneration for contributors who cannot access the Microsoft package proxy, while retaining the proxy-generated lockfile. [#245](https://github.com/microsoft/opentelemetry-distro-javascript/pull/245) ## [1.4.0] - 2026-09-08 From 681a2b44b63119e839aa07b93799018c8b5f7147 Mon Sep 17 00:00:00 2001 From: Hector Hernandez <39923391+hectorhdzg@users.noreply.github.com> Date: Tue, 6 Oct 2026 11:45:22 -0700 Subject: [PATCH 3/3] chore(deps): update Azure Monitor exporter to beta.46 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- CHANGELOG.md | 1 + package-lock.json | 8 ++++---- package.json | 2 +- samples/agent365-s2s/package-lock.json | 2 +- samples/package-lock.json | 2 +- 5 files changed, 8 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 77e76df..87a9ecf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -16,6 +16,7 @@ - Add GenAI v1.42 InvokeAgent request, response, cache-token, and provider attribute capture for manual A365 scopes. [#239](https://github.com/microsoft/opentelemetry-distro-javascript/pull/239) ### Other Changes +- Raise the `@azure/monitor-opentelemetry-exporter` floor to `1.0.0-beta.46`, the latest exporter beta. - Consolidate Dependabot updates for root markdown-it 14.3.2 and Hono 4.13.12, samples brace-expansion 5.0.12 and fast-uri 3.1.8, and root and samples ip-address 10.7.2. [#255](https://github.com/microsoft/opentelemetry-distro-javascript/pull/255) - Add upstream compatibility contracts for OpenTelemetry resource detectors, service instance identity precedence, telemetry SDK pipelines, and W3C trace propagation. [#249](https://github.com/microsoft/opentelemetry-distro-javascript/pull/249) - Add offline SDK throughput and signed memory benchmarks with raw artifacts and explicitly configured named OTLP log result export. [#246](https://github.com/microsoft/opentelemetry-distro-javascript/pull/246) diff --git a/package-lock.json b/package-lock.json index e6885bb..fc2a673 100644 --- a/package-lock.json +++ b/package-lock.json @@ -13,7 +13,7 @@ "@azure/core-auth": "^1.11.0", "@azure/core-rest-pipeline": "^1.25.0", "@azure/logger": "^1.4.0", - "@azure/monitor-opentelemetry-exporter": ">=1.0.0-beta.45 <1.0.0-c", + "@azure/monitor-opentelemetry-exporter": ">=1.0.0-beta.46 <1.0.0-c", "@azure/opentelemetry-instrumentation-azure-sdk": "^1.1.0-beta.1", "@microsoft/applicationinsights-web-snippet": "^1.2.3", "@opentelemetry/api": "^1.9.1", @@ -219,9 +219,9 @@ } }, "node_modules/@azure/monitor-opentelemetry-exporter": { - "version": "1.0.0-beta.45", - "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@azure/monitor-opentelemetry-exporter/-/monitor-opentelemetry-exporter-1.0.0-beta.45.tgz", - "integrity": "sha1-G9v/g//cBjwX3AxPLXK+Gdd0IDI=", + "version": "1.0.0-beta.46", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@azure/monitor-opentelemetry-exporter/-/monitor-opentelemetry-exporter-1.0.0-beta.46.tgz", + "integrity": "sha512-DXrkmKi2+zZCZEWPZN2cwEv3++NSeoo93F6FlHivoT+t7Q/7IRxLrCVttn22jGvFs8636cRKcWA8tqS8jPFOsQ==", "license": "MIT", "dependencies": { "@azure-rest/core-client": "^2.5.2", diff --git a/package.json b/package.json index 256d8e4..f61e96d 100644 --- a/package.json +++ b/package.json @@ -84,7 +84,7 @@ "@azure/core-auth": "^1.11.0", "@azure/core-rest-pipeline": "^1.25.0", "@azure/logger": "^1.4.0", - "@azure/monitor-opentelemetry-exporter": ">=1.0.0-beta.45 <1.0.0-c", + "@azure/monitor-opentelemetry-exporter": ">=1.0.0-beta.46 <1.0.0-c", "@azure/opentelemetry-instrumentation-azure-sdk": "^1.1.0-beta.1", "@microsoft/applicationinsights-web-snippet": "^1.2.3", "@opentelemetry/api": "^1.9.1", diff --git a/samples/agent365-s2s/package-lock.json b/samples/agent365-s2s/package-lock.json index 524b695..df9ce6f 100644 --- a/samples/agent365-s2s/package-lock.json +++ b/samples/agent365-s2s/package-lock.json @@ -30,7 +30,7 @@ "@azure/core-auth": "^1.11.0", "@azure/core-rest-pipeline": "^1.25.0", "@azure/logger": "^1.4.0", - "@azure/monitor-opentelemetry-exporter": ">=1.0.0-beta.45 <1.0.0-c", + "@azure/monitor-opentelemetry-exporter": ">=1.0.0-beta.46 <1.0.0-c", "@azure/opentelemetry-instrumentation-azure-sdk": "^1.1.0-beta.1", "@microsoft/applicationinsights-web-snippet": "^1.2.3", "@opentelemetry/api": "^1.9.1", diff --git a/samples/package-lock.json b/samples/package-lock.json index 8ceb8df..65b2399 100644 --- a/samples/package-lock.json +++ b/samples/package-lock.json @@ -38,7 +38,7 @@ "@azure/core-auth": "^1.11.0", "@azure/core-rest-pipeline": "^1.25.0", "@azure/logger": "^1.4.0", - "@azure/monitor-opentelemetry-exporter": ">=1.0.0-beta.45 <1.0.0-c", + "@azure/monitor-opentelemetry-exporter": ">=1.0.0-beta.46 <1.0.0-c", "@azure/opentelemetry-instrumentation-azure-sdk": "^1.1.0-beta.1", "@microsoft/applicationinsights-web-snippet": "^1.2.3", "@opentelemetry/api": "^1.9.1",