Sitelet https://github.com/open-telemetry/weaver/releases
Skip to content

Releases: open-telemetry/weaver

0.27.0 - 2026-10-02

Choose a tag to compare

@github-actions github-actions released this 04 Oct 00:24
0f7c529

Release Notes

  • Support virtual-directory format for --advice-policies and --advice-data in live-check. (#1760 by @lmolkova)
  • 💥 BREAKING CHANGE 💥 registry live-check --output http: POST /stop no longer returns the report. It stops the run and returns once the report is ready. Read the report with the new GET /report, then end the process with the new POST /shutdown. Reading the report is no longer tied to the process exiting, so large reports are never truncated. In this mode --inactivity-timeout is ignored: the client owns the run. Fixes #1657. (#1770 by @jerbly)
  • Live-check reports now retain OTLP context on their samples, including span and log trace IDs, timestamps, span-event and link context, and metric data-point timing. OTLP finding logs are correlated with their source spans. (#1749 by @clarsen)
  • Live-check matchers (#1721 by @jerbly)
    • Added [[live-check.matchers]]. A matcher uses a CEL expression to select samples, and names the v2 signal and attribute groups they are checked against. v2 registries only.
    • A matcher's attribute_groups lists the attribute groups allowed on a sample. Their definitions are used for the attribute checks, but an attribute missing from the sample is not reported. To enforce a group's requirement levels, name it in the new strict_attribute_groups. A signal's own attributes are always enforced.
    • A span_event matcher cannot name a signal. A semantic convention event is a log-based event, and a span event has a different data model, so the two are not comparable. A span event's attributes are checked with attribute_groups or strict_attribute_groups, or with a Rego policy, and span events do not count toward event coverage. (#1793 by @jerbly)
    • New findings: kind_mismatch and unexpected_attribute. A v2 metric or log raises unexpected_attribute against the signal its name resolves to, or against the matcher's signal when a matcher sets signal.
    • By default, a v2 registry compares an attribute with the signal and attribute groups of its match. With search_all_attributes, it also searches the whole registry and its dependencies. v1 is unchanged.
    • Every sample's result holds a match_info with the signal, the attribute groups, and what each applied matcher contributed.
    • Statistics count the samples each matcher matched and errored on. A matcher that matched nothing is reported as a warning.
    • Added -D/--param and --params to pass parameters to the output template. The ansi format reads show_finding_id, which labels a finding with its id instead of its level.
    • Added Matchers, a guide with a worked example for each sample type. Corrected the config section in the live-check and config READMEs from [live_check] to [live-check]. The underscore form was silently ignored.
  • 💥 BREAKING CHANGE 💥 Fix live-check treating any key that starts with a template's name as an instance of it: http.request.headers.host no longer matches the template http.request.header, and now raises missing_attribute. A dot must follow the template name. The namespace separator is a fixed . throughout, so registry mcp --namespace-separator and its [mcp] namespace_separator config key are removed. Fixes #1743 - (#1775 by @jerbly)
  • Config sections are checked when they are read. A command section in .weaver.toml that does not deserialize, or an unknown key under [live-check], now stops the run instead of being ignored. (#1721 by @jerbly)
  • 💥 BREAKING CHANGE 💥 Fixes #1741 registry infer renames --grpc-address and --grpc-port to --otlp-grpc-address and --otlp-grpc-port to match registry live-check. Its listener settings move from [infer] to [infer.otlp] (grpc_address, grpc_port, admin_port, inactivity_timeout), the same shape as [live-check.otlp], and an unknown key under [infer] now stops the run. (#1780 by @jerbly)
  • Fix findings on resource samples being emitted without the resource's attributes. (#1612 by @fabiovincenzi)
  • Fix: a ref to an attribute of a published (packaged) dependency resolving as required when it sets no requirement_level. It now takes the default, recommended, as it already did when the dependency is resolved from source. A new signal, an attribute group, or a refinement adding an attribute its parent does not carry were all affected. (#1789 by @jerbly)
  • Fix signals imported from a published (packaged) dependency adding their attributes to the importing registry's registry.attributes, as if it defined them. A dependent registry could then ref those attributes through it, reaching past the dependencies it declares. An imported span, metric, event, entity or attribute group now records each attribute as a reference to the registry that defines it, as it already did when the dependency is resolved from source. (#1790 by @jerbly)
  • Fix an attribute group imported from a published (packaged) dependency being left out of the resolved v2 registry. A published registry holds only public groups, so an imported group is now public and kept, with its requirement levels, as it already was when the dependency is resolved from source. (#1791 by @jerbly)

Install weaver 0.27.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.27.0/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.27.0/weaver-installer.ps1 | iex"

Download weaver 0.27.0

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
weaver-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.26.1 - 2026-09-02

Choose a tag to compare

@github-actions github-actions released this 03 Sep 01:25
38befce

Release Notes

  • Fix weaver-installer.sh failing to detect Unix platforms due to missing bash shell in release workflow. (#1744)

Install weaver 0.26.1

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.26.1/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.26.1/weaver-installer.ps1 | iex"

Download weaver 0.26.1

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
weaver-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.26.0 - 2026-09-02

Choose a tag to compare

@github-actions github-actions released this 02 Sep 19:06
cc7e73c

Release Notes

  • 💥 BREAKING CHANGE 💥 registry live-check and registry infer now bind their OTLP and HTTP admin listeners to 127.0.0.1 instead of 0.0.0.0, so they no longer listen on every local address by default. Pass --otlp-grpc-address (live-check) or --grpc-address (infer) to bind a specific interface, or 0.0.0.0 for all of them. The admin listener now binds to the same address as the OTLP listener rather than always to 0.0.0.0. (#1740 by @lmolkova)
  • Add selectable Rustls crypto providers (crypto-ring, crypto-aws-lc, crypto-openssl, crypto-openssl-vendored, crypto-symcrypt), with crypto-ring as the default. (#1712 by @lquerel)
  • Add resolve configuration to allow overriding schema URLs for dependencies in weaver.yaml and .weaver.toml. (#1693 by @jsuereth)
  • Add entity_refs and lookup_entity to the semconv Rego library, so an after_resolution policy can read the entity definition that an entity_associations leaf names, including one a dependency defines. entity_refs walks the one_of and all_of levels of an association. (#1719 by @jerbly)
  • Add a lookup_entity Jinja function, which turns an entity_associations leaf into the entity definition it names, for weaver registry generate on a v2 registry. (#1718 by @jerbly)
  • Live-check now follows a v2 entity_associations reference into a dependency, or to an entity refinement, neither of which the checker could see before: those entities went unchecked, so a resource missing their required attributes passed clean. A Rego advice policy can read the same v2 definitions, as data.entities. (#1716 by @jerbly)
  • 💥 BREAKING CHANGE 💥 An entity_associations leaf in the materialized schema now says which registry defines the entity, as the published schema already did. A leaf that was the bare name host is now { type: host, provenance: { source: <schema url> } }, and a leaf with no provenance means this registry defines it. A template, jq filter or Rego policy that read the leaf as a string reads .type instead, and the serve UI and its API are updated too. (#1710 by @jerbly)
  • dependencies in the materialized (forge) schema is now a map keyed by schema url holding each registry once, and the dependency_graph gives the direct dependencies of each. (#1730 by @jerbly)
  • Fix a legacy type: resource group converting to a v2 entity whose type carried the group-id prefix. The entity type now comes from the group's name, as it always did for imports, and falls back to the id when the group has none. Every resource group of semconv v1.33.0 has this shape, so resource.host became the entity resource.host rather than host, and an entity_associations entry naming host matched nothing. (#1704 by @jerbly)
  • 💥 BREAKING CHANGE 💥 (v2 only) The resolution no longer strips a leading entity. or span. prefix from the type. I.e. an entity authored as type: entity.test now keeps the type entity.test instead of test. (#1704 by @jerbly)
  • Report two groups whose ids differ but that take one id in the v2 output, as a warning. A v2 signal id drops the group-type prefix, so the groups entity.host and host both become the entity host and the second silently replaced the first. (#1704 by @jerbly)
  • 💥 BREAKING CHANGE 💥 Resolve every entity_associations entry, and record which registry defines the entity it names. A name that nothing in scope defines now fails resolution, as does one that two dependencies each declare an unrelated entity under. A private entity (dependency_resolution.exclude) satisfies an association only for a signal that is private too. In the v2 resolved schema an association leaf is now an object ({ type, provenance }) instead of a bare entity type; provenance.source indexes dependencies and is absent for an entity of this registry. (#1704 by @jerbly)
  • Disallow stability and deprecated on v2 attribute references. (#1720 by @lmolkova)
  • Report an imports pattern that matched nothing in any dependency, as a warning. A typo or a stale name was previously dropped in silence. (#1701 by @jerbly)
  • Fix a span imported from a v2 dependency losing the sampling_relevant setting on its attributes. This is per-span state, held on the span's attribute reference rather than on the catalog attribute, so the import path never read it. Refining such a span was unaffected. (#1694 by @jerbly)
  • Fix imports never matching a legacy type: resource entity in a dependency. Such a group sets no name and holds its entity type in the group id, so the matcher now matches the group id as well as the name. (#1694 by @jerbly)
  • Fix a definition reached by two paths through the dependency graph being imported twice, which produced duplicate groups and misleading duplicate-declaration warnings. Imported groups are now deduplicated as the per-dependency results are joined. (#1694 by @jerbly)
  • Restore support for dependencies declared by name + registry_path in legacy (v1) manifests. (#1696 by @lmolkova)
  • Fix the v2 conversion dropping an attribute that has no stability from the signal that declares it. The catalog lookup required the field to be present, so an entity could be published with an empty identity. A missing stability now converts to development, the documented default, instead of alpha. (#1695 by @jerbly)
  • Fix elements inherited from a transitive dependency being reported as locally defined. A resolved schema's dependencies set is the table that DependencyRef provenance indexes into, but it listed only direct dependencies, so anything reaching the registry through a dependency-of-a-dependency had no entry to point at. It now records the full closure. (#1655 by @jerbly)
  • Fix provenance and resolution of attributes inherited from dependencies. (#1669 by @lmolkova)
  • Drop signal refinements from the forge v1 schema representation. (#1676 by @lmolkova)
  • Refactor semantic convention v1 and v2 models and schemas into dedicated modules. (#1732 by @jsuereth)
  • Live-check: preserve instrumentation scope through OTLP ingestion, expose it to Rego policies, and render it in standard output. (#1605 by @McGluut)
  • Live-check: add support for OTel Profiles (#1698 by @flehner)

Install weaver 0.26.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.26.0/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.26.0/weaver-installer.ps1 | iex"

Download weaver 0.26.0

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux [checksum](https:...
Read more

0.25.1 - 2026-07-28

Choose a tag to compare

@github-actions github-actions released this 29 Jul 01:39
26c685f

Release Notes

  • Fix v2 attribute resolution so a ref inside an included group (ref_group) merges field-by-field instead of replacing the whole attribute. (#1634 by @lmolkova)
  • Make schema_url mandatory for manifest dependencies (#1651 by @jerbly)
  • Fix imported groups keeping the losing version's definition and provenance (#1650 by @jerbly)
  • Fix imported attributes losing their origin registry provenance (#1649 by @jerbly)
  • Fix live-check admin server (and /stop) shutting down 60s after startup (#1645 by @NimrodAvni78)
  • Fix signals imported from a dependency losing their per-signal attribute data. When several signals reference the same attribute with different requirement_level or role, each imported signal was re-pointed at whichever variant of the attribute was registered first. E.g. silently rewriting requirement levels or dropping role: identifying from imported entities. Each signal now references the attribute variant it actually declares. Per-name conflict resolution still applies to root-attribute provenance. (#1635 by @jerbly)

Install weaver 0.25.1

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.25.1/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.25.1/weaver-installer.ps1 | iex"

Download weaver 0.25.1

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
weaver-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.25.0 - 2026-07-24

Choose a tag to compare

@github-actions github-actions released this 24 Jul 19:58
v0.25.0
a177fb6

Release Notes

  • Use semantic conventions v2 for weaver registry infer. (#1334 by @ArthurSens)
  • 💥 BREAKING CHANGE 💥Expand dependency conflict resolution to allow different versions of a dependency when their major versions are compatible. Llatest version in the major series wins. (#1573 by @jsuereth)
    • This expands flexibility of schema resolution to allow dependency version conflicts to be resolved using major version number.
    • This release breaks dependencies that were not following the SchemaURL specification, requiring a semantic version as
      the last section of the URL.
  • Add --fail-on <violation|improvement|information|none> to weaver registry live-check to choose the severity threshold that produces a non-zero exit code. (#1517 by @cijothomas)
  • Fix (#733) - default an enum member's value to its id when no explicit value is provided. (#1444 by @nanookclaw)
  • Regenerate the weaver-config.json JSON schema so it matches the current configuration. (#1606 by @jerbly)
  • Live-check: (Fixes: #1626) fix a shutdown race where live-check --output http could exit before the /stop response was fully delivered, resetting the connection on large reports. The live-check command now waits for the admin HTTP server's graceful shutdown to finish before exiting. (#1632 by @jerbly)
  • Live-check: (Fixes: #1614) add [[live-check.finding_level_overrides]] to rewrite a finding's level instead of dropping it (e.g. treat undefined_enum_variant as a violation), scoped by the same signal_type/sample_names rules as finding_filters. (#1625 by @jerbly)
  • Change v2 refinement attribute precedence so ref_group details win over inherited attributes. (#1604 by @lmolkova)
  • Make deprecated.note optional for {reason: renamed} - inferred from renamed_to. (#1622 by @lmolkova)
  • Add v2 entity refinements to the resolved and materialized schema, allow to refine attributes without changing entity identity. (#1588 by @lmolkova)
  • Live-check: (Fixes: #1613) add sample_names to [[live-check.finding_filters]] to scope a filter to matching sample names, with glob wildcard support (also added to exclude_samples). (#1619 by @jerbly)
  • Add a tree view to the serve UI's search page, grouping results by namespace with expand/collapse controls, and a "Hide deprecated" toggle (on by default) for both the list and tree views. (#1595 by @jerbly)
  • Support signal refinements over a published dependency. (#1587 by @lmolkova)
  • 💥 BREAKING CHANGE 💥 Preserve per-attribute requirement_level on attribute refs of public attribute groups in the v2 resolved and materialized schemas. Each entry in an attribute group's attributes is now an object ({ base, requirement_level }) instead of a bare attribute_catalog index. (#1584 by @lmolkova)
  • Use the OS-native certificate store (via ureq's platform-verifier feature) to validate TLS connections for remote registry downloads, instead of a fixed bundled root CA list. (#1583 by @jerbly)
  • Fix panic when a registry, policy, or template path uses a commit SHA. (#1414)
  • Add a stats dashboard with charts to the serve UI. (#1570 by @jerbly)
  • Add semconv_grouped_entities JQ helper. (#1560 by @lmolkova)
  • Add optional when clause to template entries in weaver.yaml — a JQ expression that gates whether a template is applied. (#1561 by @lmolkova)
  • Add [template] section to .weaver.toml with acronyms and text_maps, applied on top of every template's weaver.yaml. (#1561 by @lmolkova)
  • Add optional name field to SpanRefinement in v2 syntax, and fix span name propagation so refinements (and imported spans) inherit the base span's name when they don't override it. (#1403 by @lmolkova)
  • Fix registry update-markdown so it does not require registry subdirectory matching registry generate behavior. (#1544 by @lmolkova)
  • Live-check: support loading additional Rego data from glob patterns via --advice-data. (#1539 by @lmolkova).
  • Refactor resolution engine so we can support multiple schema urls registered
    and cached (#1504 by @jsuereth).
  • Change --include-unreferenced so that this is the same as creating a
    a set of import: statements in the registry manifest. (#1442 by @jsuereth)

Install weaver 0.25.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.25.0/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.25.0/weaver-installer.ps1 | iex"

Download weaver 0.25.0

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
weaver-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.24.2 - 2026-06-23

Choose a tag to compare

@github-actions github-actions released this 23 Jun 17:34
adcf6fd

Release Notes

  • Fix boolean flags (--v2, --skip-policies, etc.) consuming the following positional argument; bare flags work again and --flag=false overrides .weaver.toml. (#1532 by @jerbly)

Install weaver 0.24.2

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.24.2/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.24.2/weaver-installer.ps1 | iex"

Download weaver 0.24.2

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
weaver-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.24.1 - 2026-06-21

Choose a tag to compare

@github-actions github-actions released this 21 Jun 21:03
3791ab6

Release Notes

  • Fix stack overflow when generating OpenAPI spec (#1521 by @jerbly)

Install weaver 0.24.1

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.24.1/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.24.1/weaver-installer.ps1 | iex"

Download weaver 0.24.1

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
weaver-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.24.0 - 2026-06-19

Choose a tag to compare

@github-actions github-actions released this 19 Jun 23:40
9b84f5c

Release Notes

  • Add requirement_level (recommended/opt_in) for all v2 signals (metrics, spans, events, entities). (#1515 by @lmolkova)

  • Add dependency_resolution.exclude annotation to hide attributes, groups, and signals from registries that depend on this one. (#1458 by @lmolkova)

  • Add one_of and all_of combinators to entity_associations, letting a signal (span, metric, or event) require any-of or all-of a set of entities, nested arbitrarily. A bare list of entity references remains supported and is treated as an implicit one_of. See semconv-syntax.v2.md. (#1493 by @jerbly)

  • Add weaver-live-check-start and weaver-live-check-stop composite GitHub Actions for CI integration. (#1448)

  • Rename resolved_schema_uri to resolved_registry_uri in publication manifest and in package command. (#1425)

  • Fix V2 resolver overwriting SpanName.note with the span type id during resolution. (#1401)

  • Add semconv_grouped_events JQ helper with v1/v2 options parity and coverage. (#1439)

  • New feature (#1344) - Support authenticated HTTP downloads of remote registries, including GitHub private release assets. Auth is configured per-URL via [[auth]] entries in .weaver.toml (longest url_prefix wins), with tokens sourced from a literal token, a token_env variable, or a token_command helper (e.g. ["gh", "auth", "token"]). (#1356 by @jerbly)

  • New feature - .weaver.toml project configuration now covers all subcommands allowing for simplified configuration management. See the README.md (#1410 by @jerbly)

  • Fix (#1297) - Live-check: entity validation now supported. (#1426 by @jerbly)

  • Live-check OTLP log findings are now dog-fooded: the event schema, attributes, and enumerations are defined in a semconv model and code-generated using Weaver's own templates. See finding.md for the generated reference documentation and dog-fooding.md for the full dog-fooding guide.

    💥 BREAKING CHANGES 💥 to the log schema:

    • attribute_name → attribute_key (in weaver.finding.context)
    • weaver.finding.sample_type → weaver.finding.sample.type
    • weaver.finding.signal_type → weaver.finding.signal.type
    • weaver.finding.signal_name → weaver.finding.signal.name
    • weaver.finding.resource_attribute.<key> → weaver.finding.resource.attribute.<key>

    (#1232 by @jerbly)

Install weaver 0.24.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.24.0/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.24.0/weaver-installer.ps1 | iex"

Download weaver 0.24.0

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
weaver-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.23.0 - 2026-04-22

Choose a tag to compare

@github-actions github-actions released this 22 Apr 23:15
3a3b7cc

Release Notes

  • New feature (#1247, #1248) - .weaver.toml project configuration file for live-check. Covers all live-check CLI flags plus [[live_check.finding_filters]] for dropping findings by ID, minimum level, sample name, and signal type. CLI flags take precedence over config values. Use --config or auto-discovery from CWD. (#1256 by @jerbly)
  • Fix attribute catalog sorting for attributes with the same key when converting from v1 to v2 catalog. (#1359 by @michaelvanstraten)
  • Fix (#1323) - Live-check: treat observed int as compatible with expected double attribute type, avoiding false violations from OTLP serializers (e.g. JS) that emit int_value for integral numbers. (#1331 by @jerbly)
  • Fix CLI so it doesn't error out early when loading a resolved schema. (#1304 by @jsuereth)
  • 💥 BREAKING CHANGE 💥 Use schema_url to track registries consistently in lineage / provenance (#1298 by @jsuereth)
  • Publish and document missing JSON schemas. Add head_schema_url/baseline_schema_url to diff v2. (#1106 by @lmolkova)
  • Add --allow-git-credentials global flag to enable system credential helpers (e.g. osxkeychain, git-credential-manager) when cloning private registries. By default, git operations remain isolated for security. (#1306 by @jerbly)
  • MCP: Add browse_namespace tool and findings_only output mode for live_check. Add configurable namespace separator via --namespace-separator. (#1324 by @jerbly)
  • chore(deps): update all patch versions. (#1379 by @renovate[bot])
  • Remove vendored openssl dependency. (#1380 by @sapatrjv)

Install weaver 0.23.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.23.0/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.23.0/weaver-installer.ps1 | iex"

Download weaver 0.23.0

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
weaver-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
weaver-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

0.22.1 - 2026-03-13

Choose a tag to compare

@github-actions github-actions released this 13 Mar 23:40
7400873

Release Notes

Note: 0.22.0 release was skipped due to release CI/CD issues.

  • Fix: Update release workflow for pnpm migration (use pnpm lockfile instead of npm lockfile). (#1289 by @jerbly)
  • Add support for git references in the registry url (#182 by @sebasnabas)
  • New feature (#1153) - Live-check now has a /health endpoint that can be used in long-running scenarios to confirm readiness and liveness of the live-check server. (#1193 by @jerbly)
  • New feature (#1100) - Set --output=http to have live-check send its report as the response to /stop. (#1193 by @jerbly)
  • Unified output handling across all registry subcommands. Builtin output formats (json, yaml, jsonl) are now available in registry stats, registry diff, and registry resolve. registry stats also supports --templates for custom text output templates. (#1200 by @jerbly)
  • New feature (#1152) - Live-check with --emit-otlp-logs will now include the attributes from the resource in the emitted log record, this helps to identify the source of the finding in a multi-source environment. (#1206 by @jerbly)
  • New Experimental feature: weaver registry infer command that listens for OTLP telemetry and infers a semantic convention registry file from the received data. Supports spans, metrics, events, and resource attributes. Includes configurable gRPC address/port, admin server for graceful shutdown, and inactivity timeout. (#1138 by @ArthurSens)
  • Fix: Include unit in inferred schema even if empty to prevent live-check failures. (#1284 by @ArthurSens)
  • Use schema_url in registry manifest, dependencies, and resolved schema instead of registry_url. Parse registry name and version
    from it. (#1202 by @lmolkova)
  • Default to manifest.yaml for registry manifest file, deprecate registry_manifest.yaml and add warning when it's used. (#1202 by @lmolkova)
  • 💥 BREAKING CHANGE 💥 (Fixes #760) - Auto-escaping is now off by default (none) for all templates, regardless of file extension. To opt in, set auto_escape: html or auto_escape: json per template in weaver.yaml. Within a template, {% autoescape false %} blocks can selectively disable escaping for sections. Use |tojson for explicit JSON/YAML value escaping where needed. (#1239 by @jerbly)
  • 💥 BREAKING CHANGE 💥 Replace version: "2" with file_format: definition/2 for v2 definition schema (#1154 by @lmolkova)
  • Add JSON schema for resolved registry v2 (#1261 by @lmolkova)
  • Add weaver registry package command to generate manifest and write resolved schema. (#1254 by @lmolkova)
  • Fix: weaver registry package command not producing output due to warnings. (#1271 by @lmolkova)
  • Update JSON Schema v2 to include file_format (#1262 by @lmolkova)
  • Add JSON schema for PolicyFinding, make context field optional. (#1270 by @lmolkova)
  • Deprecate weaver registry resolve command, please use weaver registry generate or package instead (#1255 by @lmolkova)
  • Support imports for all signal types and public attribute groups in v2 registry. (#1267 by @jsuereth)
  • Support refinements in v2 syntax: metric names, notes, etc. are now copied from the refined group. (#1250 by @jsuereth)
  • Fix stability/ordering issues in v2 publishing; attributes are now sorted and deduplicated consistently. (#1282 by @jsuereth)
  • Fix resolution for dependencies: both v1 and v2 resolution now returns the correct attribute from the right registry when using dependencies. (#1280 by @lmolkova)
  • JQ helper v2 for spans: fixes and improvements. (#1251 by @lmolkova)
  • Fix 404 on template-type attributes in the weaver serve API. (#1240 by @jerbly)
  • New Experimental feature: weaver serve UI migrated to React. (#1147 by @nicolastakashi)

Install weaver 0.22.1

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.22.1/weaver-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.22.1/weaver-installer.ps1 | iex"

Download weaver 0.22.1

File Platform Checksum
weaver-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
weaver-x86_64-apple-darwin.tar.xz Intel macOS checksum
weaver-x86_64-pc-windows-msvc.zip x64 Windows checksum
weaver-x86_64-pc-windows-msvc.msi x64 Windows checksum
weaver-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaver

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>