Skip to content

Replace Jaeger archive patch with upstream OpenTelemetry SDK upgrade #7337

Description

@apurvvkumaria

Summary

The proposed NemoClaw mitigation in #7280 rewrites the reviewed @openclaw/diagnostics-otel@2026.7.1 archive. The remediation replaces @opentelemetry/propagator-jaeger@2.8.0 with 2.9.0 and nests @opentelemetry/core@2.9.0 because the bundled @opentelemetry/sdk-node@0.219.0 pins the vulnerable propagator version.

That exact, integrity-verified patch removes the vulnerable graph, but it should remain a temporary compatibility measure. NemoClaw should consume an upstream-supported OpenTelemetry dependency graph and then remove the custom Jaeger/core archive surgery.

As of 2026-07-21:

  • @opentelemetry/sdk-node@0.221.0 depends on @opentelemetry/propagator-jaeger@2.10.0.
  • The latest stable @openclaw/diagnostics-otel@2026.7.1 still depends on @opentelemetry/sdk-node@0.219.0, so the clean upgrade is not yet available through the published OpenClaw diagnostics package.
  • fix(deps): clear audit and native locale gate failures openclaw/openclaw#112406 is the current upstream candidate for moving diagnostics to a safe SDK graph, but it is not yet merged or published.

Acceptance criteria

  • Upgrade to a reviewed OpenClaw diagnostics release that bundles a supported OpenTelemetry SDK with @opentelemetry/propagator-jaeger>=2.9.0.
  • Remove the diagnostics-specific Jaeger/core replacement branch and associated exact pins from scripts/lib/openclaw-npm-remediation.mts once the upstream graph is safe.
  • Refresh the reviewed archive metadata, shrinkwrap expectations, exact registry integrity and tarball checks, and dependency-review documentation.
  • Add a runtime regression test proving malformed percent-encoded uber-trace-id and uberctx-* headers do not throw.
  • Keep the fix(security): update OpenClaw to 2026.7.1 #7280 remediation in place until the upstream-supported graph is shipped and validated.
  • Verify the reviewed production graph reports no high or critical findings and run the relevant package, integration, and E2E validation.

Related work

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area: observabilityLogging, metrics, tracing, diagnostics, or debug outputarea: packagingPackages, images, registries, installers, or distributionsecurityv0.0.131Release target

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions