Releases: open-telemetry/weaver
Release list
0.27.0 - 2026-10-02
Release Notes
- Support virtual-directory format for
--advice-policiesand--advice-datain live-check. (#1760 by @lmolkova) - 💥 BREAKING CHANGE 💥
registry live-check --output http:POST /stopno longer returns the report. It stops the run and returns once the report is ready. Read the report with the newGET /report, then end the process with the newPOST /shutdown. Reading the report is no longer tied to the process exiting, so large reports are never truncated. In this mode--inactivity-timeoutis ignored: the client owns the run. Fixes #1657. (#1770 by @jerbly) - Live-check reports now retain OTLP context on their samples, including span and log trace IDs, timestamps, span-event and link context, and metric data-point timing. OTLP finding logs are correlated with their source spans. (#1749 by @clarsen)
- Live-check matchers (#1721 by @jerbly)
- Added
[[live-check.matchers]]. A matcher uses a CEL expression to select samples, and names the v2 signal and attribute groups they are checked against. v2 registries only. - A matcher's
attribute_groupslists the attribute groups allowed on a sample. Their definitions are used for the attribute checks, but an attribute missing from the sample is not reported. To enforce a group's requirement levels, name it in the newstrict_attribute_groups. A signal's own attributes are always enforced. - A
span_eventmatcher cannot name asignal. A semantic convention event is a log-based event, and a span event has a different data model, so the two are not comparable. A span event's attributes are checked withattribute_groupsorstrict_attribute_groups, or with a Rego policy, and span events do not count toward event coverage. (#1793 by @jerbly) - New findings:
kind_mismatchandunexpected_attribute. A v2 metric or log raisesunexpected_attributeagainst the signal its name resolves to, or against the matcher's signal when a matcher setssignal. - By default, a v2 registry compares an attribute with the signal and attribute groups of its match. With
search_all_attributes, it also searches the whole registry and its dependencies. v1 is unchanged. - Every sample's result holds a
match_infowith the signal, the attribute groups, and what each applied matcher contributed. - Statistics count the samples each matcher matched and errored on. A matcher that matched nothing is reported as a warning.
- Added
-D/--paramand--paramsto pass parameters to the output template. The ansi format readsshow_finding_id, which labels a finding with its id instead of its level. - Added Matchers, a guide with a worked example for each sample type. Corrected the config section in the live-check and config READMEs from
[live_check]to[live-check]. The underscore form was silently ignored.
- Added
- 💥 BREAKING CHANGE 💥 Fix live-check treating any key that starts with a template's name as an instance of it:
http.request.headers.hostno longer matches the templatehttp.request.header, and now raisesmissing_attribute. A dot must follow the template name. The namespace separator is a fixed.throughout, soregistry mcp --namespace-separatorand its[mcp] namespace_separatorconfig key are removed. Fixes #1743 - (#1775 by @jerbly) - Config sections are checked when they are read. A command section in
.weaver.tomlthat does not deserialize, or an unknown key under[live-check], now stops the run instead of being ignored. (#1721 by @jerbly) - 💥 BREAKING CHANGE 💥 Fixes #1741
registry inferrenames--grpc-addressand--grpc-portto--otlp-grpc-addressand--otlp-grpc-portto matchregistry live-check. Its listener settings move from[infer]to[infer.otlp](grpc_address,grpc_port,admin_port,inactivity_timeout), the same shape as[live-check.otlp], and an unknown key under[infer]now stops the run. (#1780 by @jerbly) - Fix findings on resource samples being emitted without the resource's attributes. (#1612 by @fabiovincenzi)
- Fix: a
refto an attribute of a published (packaged) dependency resolving asrequiredwhen it sets norequirement_level. It now takes the default,recommended, as it already did when the dependency is resolved from source. A new signal, an attribute group, or a refinement adding an attribute its parent does not carry were all affected. (#1789 by @jerbly) - Fix signals imported from a published (packaged) dependency adding their attributes to the importing registry's
registry.attributes, as if it defined them. A dependent registry could thenrefthose attributes through it, reaching past the dependencies it declares. An imported span, metric, event, entity or attribute group now records each attribute as a reference to the registry that defines it, as it already did when the dependency is resolved from source. (#1790 by @jerbly) - Fix an attribute group imported from a published (packaged) dependency being left out of the resolved v2 registry. A published registry holds only public groups, so an imported group is now public and kept, with its requirement levels, as it already was when the dependency is resolved from source. (#1791 by @jerbly)
Install weaver 0.27.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.27.0/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.27.0/weaver-installer.ps1 | iex"Download weaver 0.27.0
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| weaver-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.26.1 - 2026-09-02
Release Notes
- Fix
weaver-installer.shfailing to detect Unix platforms due to missing bash shell in release workflow. (#1744)
Install weaver 0.26.1
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.26.1/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.26.1/weaver-installer.ps1 | iex"Download weaver 0.26.1
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| weaver-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.26.0 - 2026-09-02
Release Notes
- 💥 BREAKING CHANGE 💥
registry live-checkandregistry infernow bind their OTLP and HTTP admin listeners to127.0.0.1instead of0.0.0.0, so they no longer listen on every local address by default. Pass--otlp-grpc-address(live-check) or--grpc-address(infer) to bind a specific interface, or0.0.0.0for all of them. The admin listener now binds to the same address as the OTLP listener rather than always to0.0.0.0. (#1740 by @lmolkova) - Add selectable Rustls crypto providers (
crypto-ring,crypto-aws-lc,crypto-openssl,crypto-openssl-vendored,crypto-symcrypt), withcrypto-ringas the default. (#1712 by @lquerel) - Add resolve configuration to allow overriding schema URLs for dependencies in
weaver.yamland.weaver.toml. (#1693 by @jsuereth) - Add
entity_refsandlookup_entityto thesemconvRego library, so anafter_resolutionpolicy can read the entity definition that anentity_associationsleaf names, including one a dependency defines.entity_refswalks theone_ofandall_oflevels of an association. (#1719 by @jerbly) - Add a
lookup_entityJinja function, which turns anentity_associationsleaf into the entity definition it names, forweaver registry generateon a v2 registry. (#1718 by @jerbly) - Live-check now follows a v2
entity_associationsreference into a dependency, or to an entity refinement, neither of which the checker could see before: those entities went unchecked, so a resource missing their required attributes passed clean. A Rego advice policy can read the same v2 definitions, asdata.entities. (#1716 by @jerbly) - 💥 BREAKING CHANGE 💥 An
entity_associationsleaf in the materialized schema now says which registry defines the entity, as the published schema already did. A leaf that was the bare namehostis now{ type: host, provenance: { source: <schema url> } }, and a leaf with no provenance means this registry defines it. A template, jq filter or Rego policy that read the leaf as a string reads.typeinstead, and theserveUI and its API are updated too. (#1710 by @jerbly) dependenciesin the materialized (forge) schema is now a map keyed by schema url holding each registry once, and thedependency_graphgives the direct dependencies of each. (#1730 by @jerbly)- Fix a legacy
type: resourcegroup converting to a v2 entity whose type carried the group-id prefix. The entity type now comes from the group'sname, as it always did for imports, and falls back to the id when the group has none. Everyresourcegroup of semconv v1.33.0 has this shape, soresource.hostbecame the entityresource.hostrather thanhost, and anentity_associationsentry naminghostmatched nothing. (#1704 by @jerbly) - 💥 BREAKING CHANGE 💥 (v2 only) The resolution no longer strips a leading
entity.orspan.prefix from the type. I.e. an entity authored astype: entity.testnow keeps the typeentity.testinstead oftest. (#1704 by @jerbly) - Report two groups whose ids differ but that take one id in the v2 output, as a warning. A v2 signal id drops the group-type prefix, so the groups
entity.hostandhostboth become the entityhostand the second silently replaced the first. (#1704 by @jerbly) - 💥 BREAKING CHANGE 💥 Resolve every
entity_associationsentry, and record which registry defines the entity it names. A name that nothing in scope defines now fails resolution, as does one that two dependencies each declare an unrelated entity under. A private entity (dependency_resolution.exclude) satisfies an association only for a signal that is private too. In the v2 resolved schema an association leaf is now an object ({ type, provenance }) instead of a bare entity type;provenance.sourceindexesdependenciesand is absent for an entity of this registry. (#1704 by @jerbly) - Disallow
stabilityanddeprecatedon v2 attribute references. (#1720 by @lmolkova) - Report an
importspattern that matched nothing in any dependency, as a warning. A typo or a stale name was previously dropped in silence. (#1701 by @jerbly) - Fix a span imported from a v2 dependency losing the
sampling_relevantsetting on its attributes. This is per-span state, held on the span's attribute reference rather than on the catalog attribute, so the import path never read it. Refining such a span was unaffected. (#1694 by @jerbly) - Fix
importsnever matching a legacytype: resourceentity in a dependency. Such a group sets nonameand holds its entity type in the group id, so the matcher now matches the group id as well as the name. (#1694 by @jerbly) - Fix a definition reached by two paths through the dependency graph being imported twice, which produced duplicate groups and misleading duplicate-declaration warnings. Imported groups are now deduplicated as the per-dependency results are joined. (#1694 by @jerbly)
- Restore support for dependencies declared by
name+registry_pathin legacy (v1) manifests. (#1696 by @lmolkova) - Fix the v2 conversion dropping an attribute that has no
stabilityfrom the signal that declares it. The catalog lookup required the field to be present, so an entity could be published with an emptyidentity. A missing stability now converts todevelopment, the documented default, instead ofalpha. (#1695 by @jerbly) - Fix elements inherited from a transitive dependency being reported as locally defined. A resolved schema's
dependenciesset is the table thatDependencyRefprovenance indexes into, but it listed only direct dependencies, so anything reaching the registry through a dependency-of-a-dependency had no entry to point at. It now records the full closure. (#1655 by @jerbly) - Fix provenance and resolution of attributes inherited from dependencies. (#1669 by @lmolkova)
- Drop signal refinements from the forge v1 schema representation. (#1676 by @lmolkova)
- Refactor semantic convention v1 and v2 models and schemas into dedicated modules. (#1732 by @jsuereth)
- Live-check: preserve instrumentation scope through OTLP ingestion, expose it to Rego policies, and render it in standard output. (#1605 by @McGluut)
- Live-check: add support for OTel Profiles (#1698 by @flehner)
Install weaver 0.26.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.26.0/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.26.0/weaver-installer.ps1 | iex"Download weaver 0.26.0
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | [checksum](https:... |
0.25.1 - 2026-07-28
Release Notes
- Fix v2 attribute resolution so a
refinside an included group (ref_group) merges field-by-field instead of replacing the whole attribute. (#1634 by @lmolkova) - Make schema_url mandatory for manifest dependencies (#1651 by @jerbly)
- Fix imported groups keeping the losing version's definition and provenance (#1650 by @jerbly)
- Fix imported attributes losing their origin registry provenance (#1649 by @jerbly)
- Fix live-check admin server (and /stop) shutting down 60s after startup (#1645 by @NimrodAvni78)
- Fix signals imported from a dependency losing their per-signal attribute data. When several signals reference the same attribute with different
requirement_levelorrole, each imported signal was re-pointed at whichever variant of the attribute was registered first. E.g. silently rewriting requirement levels or droppingrole: identifyingfrom imported entities. Each signal now references the attribute variant it actually declares. Per-name conflict resolution still applies to root-attribute provenance. (#1635 by @jerbly)
Install weaver 0.25.1
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.25.1/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.25.1/weaver-installer.ps1 | iex"Download weaver 0.25.1
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| weaver-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.25.0 - 2026-07-24
Release Notes
- Use semantic conventions v2 for
weaver registry infer. (#1334 by @ArthurSens) - 💥 BREAKING CHANGE 💥Expand dependency conflict resolution to allow different versions of a dependency when their major versions are compatible. Llatest version in the major series wins. (#1573 by @jsuereth)
- This expands flexibility of schema resolution to allow dependency version conflicts to be resolved using major version number.
- This release breaks dependencies that were not following the SchemaURL specification, requiring a semantic version as
the last section of the URL.
- Add
--fail-on <violation|improvement|information|none>toweaver registry live-checkto choose the severity threshold that produces a non-zero exit code. (#1517 by @cijothomas) - Fix (#733) - default an enum member's
valueto itsidwhen no explicitvalueis provided. (#1444 by @nanookclaw) - Regenerate the
weaver-config.jsonJSON schema so it matches the current configuration. (#1606 by @jerbly) - Live-check: (Fixes: #1626) fix a shutdown race where
live-check --output httpcould exit before the/stopresponse was fully delivered, resetting the connection on large reports. The live-check command now waits for the admin HTTP server's graceful shutdown to finish before exiting. (#1632 by @jerbly) - Live-check: (Fixes: #1614) add
[[live-check.finding_level_overrides]]to rewrite a finding's level instead of dropping it (e.g. treatundefined_enum_variantas a violation), scoped by the samesignal_type/sample_namesrules asfinding_filters. (#1625 by @jerbly) - Change v2 refinement attribute precedence so
ref_groupdetails win over inherited attributes. (#1604 by @lmolkova) - Make
deprecated.noteoptional for{reason: renamed}- inferred fromrenamed_to. (#1622 by @lmolkova) - Add v2 entity refinements to the resolved and materialized schema, allow to refine attributes without changing entity identity. (#1588 by @lmolkova)
- Live-check: (Fixes: #1613) add
sample_namesto[[live-check.finding_filters]]to scope a filter to matching sample names, with glob wildcard support (also added toexclude_samples). (#1619 by @jerbly) - Add a tree view to the
serveUI's search page, grouping results by namespace with expand/collapse controls, and a "Hide deprecated" toggle (on by default) for both the list and tree views. (#1595 by @jerbly) - Support signal refinements over a published dependency. (#1587 by @lmolkova)
- 💥 BREAKING CHANGE 💥 Preserve per-attribute
requirement_levelon attribute refs of public attribute groups in the v2 resolved and materialized schemas. Each entry in an attribute group'sattributesis now an object ({ base, requirement_level }) instead of a bareattribute_catalogindex. (#1584 by @lmolkova) - Use the OS-native certificate store (via ureq's
platform-verifierfeature) to validate TLS connections for remote registry downloads, instead of a fixed bundled root CA list. (#1583 by @jerbly) - Fix panic when a registry, policy, or template path uses a commit SHA. (#1414)
- Add a stats dashboard with charts to the
serveUI. (#1570 by @jerbly) - Add
semconv_grouped_entitiesJQ helper. (#1560 by @lmolkova) - Add optional
whenclause to template entries inweaver.yaml— a JQ expression that gates whether a template is applied. (#1561 by @lmolkova) - Add
[template]section to.weaver.tomlwithacronymsandtext_maps, applied on top of every template'sweaver.yaml. (#1561 by @lmolkova) - Add optional
namefield toSpanRefinementin v2 syntax, and fix span name propagation so refinements (and imported spans) inherit the base span'snamewhen they don't override it. (#1403 by @lmolkova) - Fix
registry update-markdownso it does not requireregistrysubdirectory matchingregistry generatebehavior. (#1544 by @lmolkova) - Live-check: support loading additional Rego data from glob patterns via
--advice-data. (#1539 by @lmolkova). - Refactor resolution engine so we can support multiple schema urls registered
and cached (#1504 by @jsuereth). - Change
--include-unreferencedso that this is the same as creating a
a set ofimport:statements in the registry manifest. (#1442 by @jsuereth)
Install weaver 0.25.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.25.0/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.25.0/weaver-installer.ps1 | iex"Download weaver 0.25.0
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| weaver-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.24.2 - 2026-06-23
Release Notes
- Fix boolean flags (
--v2,--skip-policies, etc.) consuming the following positional argument; bare flags work again and--flag=falseoverrides.weaver.toml. (#1532 by @jerbly)
Install weaver 0.24.2
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.24.2/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.24.2/weaver-installer.ps1 | iex"Download weaver 0.24.2
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| weaver-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.24.1 - 2026-06-21
Release Notes
Install weaver 0.24.1
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.24.1/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.24.1/weaver-installer.ps1 | iex"Download weaver 0.24.1
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| weaver-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.24.0 - 2026-06-19
Release Notes
-
Add
requirement_level(recommended/opt_in) for all v2 signals (metrics, spans, events, entities). (#1515 by @lmolkova) -
Add
dependency_resolution.excludeannotation to hide attributes, groups, and signals from registries that depend on this one. (#1458 by @lmolkova) -
Add
one_ofandall_ofcombinators toentity_associations, letting a signal (span, metric, or event) require any-of or all-of a set of entities, nested arbitrarily. A bare list of entity references remains supported and is treated as an implicitone_of. Seesemconv-syntax.v2.md. (#1493 by @jerbly) -
Add
weaver-live-check-startandweaver-live-check-stopcomposite GitHub Actions for CI integration. (#1448) -
Rename
resolved_schema_uritoresolved_registry_uriin publication manifest and inpackagecommand. (#1425) -
Fix V2 resolver overwriting
SpanName.notewith the span type id during resolution. (#1401) -
Add
semconv_grouped_eventsJQ helper with v1/v2 options parity and coverage. (#1439) -
New feature (#1344) - Support authenticated HTTP downloads of remote registries, including GitHub private release assets. Auth is configured per-URL via
[[auth]]entries in.weaver.toml(longesturl_prefixwins), with tokens sourced from a literaltoken, atoken_envvariable, or atoken_commandhelper (e.g.["gh", "auth", "token"]). (#1356 by @jerbly) -
New feature -
.weaver.tomlproject configuration now covers all subcommands allowing for simplified configuration management. See the README.md (#1410 by @jerbly) -
Fix (#1297) - Live-check: entity validation now supported. (#1426 by @jerbly)
-
Live-check OTLP log findings are now dog-fooded: the event schema, attributes, and enumerations are defined in a semconv model and code-generated using Weaver's own templates. See
finding.mdfor the generated reference documentation anddog-fooding.mdfor the full dog-fooding guide.💥 BREAKING CHANGES 💥 to the log schema:
attribute_name→attribute_key(inweaver.finding.context)weaver.finding.sample_type→weaver.finding.sample.typeweaver.finding.signal_type→weaver.finding.signal.typeweaver.finding.signal_name→weaver.finding.signal.nameweaver.finding.resource_attribute.<key>→weaver.finding.resource.attribute.<key>
Install weaver 0.24.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.24.0/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.24.0/weaver-installer.ps1 | iex"Download weaver 0.24.0
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| weaver-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.23.0 - 2026-04-22
Release Notes
- New feature (#1247, #1248) -
.weaver.tomlproject configuration file forlive-check. Covers alllive-checkCLI flags plus[[live_check.finding_filters]]for dropping findings by ID, minimum level, sample name, and signal type. CLI flags take precedence over config values. Use--configor auto-discovery from CWD. (#1256 by @jerbly) - Fix attribute catalog sorting for attributes with the same key when converting from v1 to v2 catalog. (#1359 by @michaelvanstraten)
- Fix (#1323) - Live-check: treat observed
intas compatible with expecteddoubleattribute type, avoiding false violations from OTLP serializers (e.g. JS) that emitint_valuefor integral numbers. (#1331 by @jerbly) - Fix CLI so it doesn't error out early when loading a resolved schema. (#1304 by @jsuereth)
- 💥 BREAKING CHANGE 💥 Use
schema_urlto track registries consistently in lineage / provenance (#1298 by @jsuereth) - Publish and document missing JSON schemas. Add
head_schema_url/baseline_schema_urlto diff v2. (#1106 by @lmolkova) - Add
--allow-git-credentialsglobal flag to enable system credential helpers (e.g.osxkeychain,git-credential-manager) when cloning private registries. By default, git operations remain isolated for security. (#1306 by @jerbly) - MCP: Add
browse_namespacetool andfindings_onlyoutput mode forlive_check. Add configurable namespace separator via--namespace-separator. (#1324 by @jerbly) - chore(deps): update all patch versions. (#1379 by @renovate[bot])
- Remove vendored openssl dependency. (#1380 by @sapatrjv)
Install weaver 0.23.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.23.0/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.23.0/weaver-installer.ps1 | iex"Download weaver 0.23.0
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| weaver-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| weaver-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>0.22.1 - 2026-03-13
Release Notes
Note: 0.22.0 release was skipped due to release CI/CD issues.
- Fix: Update release workflow for pnpm migration (use pnpm lockfile instead of npm lockfile). (#1289 by @jerbly)
- Add support for git references in the registry url (#182 by @sebasnabas)
- New feature (#1153) - Live-check now has a
/healthendpoint that can be used in long-running scenarios to confirm readiness and liveness of the live-check server. (#1193 by @jerbly) - New feature (#1100) - Set
--output=httpto have live-check send its report as the response to/stop. (#1193 by @jerbly) - Unified output handling across all registry subcommands. Builtin output formats (json, yaml, jsonl) are now available in
registry stats,registry diff, andregistry resolve.registry statsalso supports--templatesfor custom text output templates. (#1200 by @jerbly) - New feature (#1152) - Live-check with
--emit-otlp-logswill now include the attributes from the resource in the emitted log record, this helps to identify the source of the finding in a multi-source environment. (#1206 by @jerbly) - New Experimental feature:
weaver registry infercommand that listens for OTLP telemetry and infers a semantic convention registry file from the received data. Supports spans, metrics, events, and resource attributes. Includes configurable gRPC address/port, admin server for graceful shutdown, and inactivity timeout. (#1138 by @ArthurSens) - Fix: Include unit in inferred schema even if empty to prevent live-check failures. (#1284 by @ArthurSens)
- Use
schema_urlin registry manifest, dependencies, and resolved schema instead ofregistry_url. Parse registry name and version
from it. (#1202 by @lmolkova) - Default to
manifest.yamlfor registry manifest file, deprecateregistry_manifest.yamland add warning when it's used. (#1202 by @lmolkova) - 💥 BREAKING CHANGE 💥 (Fixes #760) - Auto-escaping is now off by default (
none) for all templates, regardless of file extension. To opt in, setauto_escape: htmlorauto_escape: jsonper template inweaver.yaml. Within a template,{% autoescape false %}blocks can selectively disable escaping for sections. Use|tojsonfor explicit JSON/YAML value escaping where needed. (#1239 by @jerbly) - 💥 BREAKING CHANGE 💥 Replace
version: "2"withfile_format: definition/2for v2 definition schema (#1154 by @lmolkova) - Add JSON schema for resolved registry v2 (#1261 by @lmolkova)
- Add
weaver registry packagecommand to generate manifest and write resolved schema. (#1254 by @lmolkova) - Fix:
weaver registry packagecommand not producing output due to warnings. (#1271 by @lmolkova) - Update JSON Schema v2 to include
file_format(#1262 by @lmolkova) - Add JSON schema for
PolicyFinding, makecontextfield optional. (#1270 by @lmolkova) - Deprecate
weaver registry resolvecommand, please useweaver registry generateorpackageinstead (#1255 by @lmolkova) - Support
importsfor all signal types and public attribute groups in v2 registry. (#1267 by @jsuereth) - Support refinements in v2 syntax: metric names, notes, etc. are now copied from the refined group. (#1250 by @jsuereth)
- Fix stability/ordering issues in v2 publishing; attributes are now sorted and deduplicated consistently. (#1282 by @jsuereth)
- Fix resolution for dependencies: both v1 and v2 resolution now returns the correct attribute from the right registry when using dependencies. (#1280 by @lmolkova)
- JQ helper v2 for spans: fixes and improvements. (#1251 by @lmolkova)
- Fix 404 on template-type attributes in the
weaver serveAPI. (#1240 by @jerbly) - New Experimental feature:
weaver serveUI migrated to React. (#1147 by @nicolastakashi)
Install weaver 0.22.1
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/open-telemetry/weaver/releases/download/v0.22.1/weaver-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/open-telemetry/weaver/releases/download/v0.22.1/weaver-installer.ps1 | iex"Download weaver 0.22.1
| File | Platform | Checksum |
|---|---|---|
| weaver-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| weaver-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| weaver-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| weaver-x86_64-pc-windows-msvc.msi | x64 Windows | checksum |
| weaver-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo open-telemetry/weaverYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>