chore(deps): update JavaScript SDK to v11.4.0 - #6773
github-actions[bot] wants to merge 1 commit into
Conversation
Semver Impact of This PR⚪ None (no version bump detected) 📋 Changelog PreviewThis is how your changes will appear in the changelog.
🤖 This preview updates automatically when you update the PR. |
antonis
left a comment
There was a problem hiding this comment.
Marking as blocked since we will bump with our next major
|
Tested out the changes with #6730 |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 3 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit adfb87a. Configure here.
| "@sentry/core": "11.0.0", | ||
| "@sentry/expo-upload-sourcemaps": "workspace:*", | ||
| "@sentry/react": "10.75.2" | ||
| "@sentry/react": "11.0.0" |
There was a problem hiding this comment.
PII collected by default after v11
High Severity
Flagged because the review rules require PII to stay gated behind sendDefaultPii and require changelog review on JS dependency bumps. v11 replaces sendDefaultPii with dataCollection and collects user info, cookies, HTTP bodies, and similar data by default. This SDK still documents and implements sendDefaultPii (default off) and omits dataCollection from ReactNativeOptions, so JS-core collection turns on while apps cannot disable it through the public options type.
Triggered by project rule: PR Review Guidelines for Cursor Bot
Reviewed by Cursor Bugbot for commit adfb87a. Configure here.
| "@sentry/core": "11.0.0", | ||
| "@sentry/expo-upload-sourcemaps": "workspace:*", | ||
| "@sentry/react": "10.75.2" | ||
| "@sentry/react": "11.0.0" |
There was a problem hiding this comment.
Unmigrated v11 breaking JS APIs
High Severity
Flagged because the review rules require JS dependency bumps to be checked for breaking API and default-integration changes. This PR only retargets @sentry/core, @sentry/browser, and @sentry/react to 11.0.0. Default integrations still call removed inboundFiltersIntegration, the public entry still re-exports removed instrumentLangGraph and AI helpers that moved off @sentry/core, and tracing still imports startIdleSpan from the default @sentry/core entry. No code, types, or changelog migration accompanies the major bump.
Triggered by project rule: PR Review Guidelines for Cursor Bot
Reviewed by Cursor Bugbot for commit adfb87a. Configure here.
| "@sentry/core": "11.0.0", | ||
| "@sentry/expo-upload-sourcemaps": "workspace:*", | ||
| "@sentry/react": "10.75.2" | ||
| "@sentry/react": "11.0.0" |
There was a problem hiding this comment.
Span streaming default breaks tracing
High Severity
Flagged because the review rules call out silent default and telemetry-shape changes on dependency updates. v11 enables span streaming by default and deprecates transaction-mode hooks such as beforeSendTransaction and forceTransaction. This SDK's navigation, app-start, and idle-span pipeline still assumes root spans are buffered as transactions and discarded via transaction event processors. Streaming would emit child spans before those filters run and change the telemetry apps currently receive.
Triggered by project rule: PR Review Guidelines for Cursor Bot
Reviewed by Cursor Bugbot for commit adfb87a. Configure here.
5b99eba to
a7da763
Compare
a5d19b4 to
5949ab3
Compare
9caf113 to
c8c3cc3
Compare
c2a203e to
c6bdd9e
Compare
27cdb2b to
21d6b41
Compare
af263e2 to
88eb841
Compare
6d18dd9 to
edc58d1
Compare
edc58d1 to
4143ce0
Compare


Bumps scripts/update-javascript.sh from 10.76.0 to 11.4.0.
Auto-generated by a dependency updater.
Changelog
11.4.0
11.3.0
Important Changes
Remix 3 support (alpha, may break in minor releases)
feat(nextjs): Add
cache_originspan links touse cachehit spans (#24821)A
cache.getspan for a"use cache"hit now carries a span link (sentry.link.type: 'cache_origin') to thecache.putspan of the request that filled the cache entry, connecting the trace that reads a cached value to the trace that produced it.fix(cloudflare): Don't treat DO constructor work as incoming RPC calls (#24829)
Durable Object constructors now run in their own isolation scope. When work that the constructor starts, for example a
blockConcurrencyWhilecallback, calls a method of the instance, that call is no longer treated as an incoming RPC call, so an error the instance catches itself is no longer reported as unhandled. As a result,Sentry.setTag(),setUser()andsetContext()in a constructor now apply only to that constructor work. They no longer reach laterfetch, RPC oralarminvocations, because the scope they used to write to is shared by every Durable Object and handler in the isolate. UseinitialScopefor static data, and set per-instance data in each handler.fix(effect)!: Change peerDependency to v4 and fix currentSpan (#24940)
sentry/effectnow requires a stable Effect v4 release. Effect v4 beta and release candidate versions are no longer supported.sentry/effectis in alpha, so this ships in a minor release.Other Changes
feat(astro): Register astro route provider (#23792)
feat(cloudflare): Trace TypeSafe Jev calls in Workers AI as evaluate spans (#24833)
feat(core): Add route provider API for parameterized route resolution (#23551)
feat(deps): bump devalue from 5.9.2 to 5.9.4 (#24964)
feat(effect): Add opt-in for external span parents and isolate root spans (#23900)
feat(nextjs): Register nextjs route provider (#23552)
feat(nuxt): Register nuxt route provider (#23794)
feat(remix): Register remix route provider (#23791)
feat(vue): Register Vue route provider (#23793)
fix(bundler-plugins): Keep debug IDs on Vite source maps after the preload rewrite (#24920)
fix(bundler-plugins): Stabilize debug IDs for Rolldown and Vite 8 builds (#24919)
fix(cloudflare): Skip binding instrumentation work when spans are not sent (#24655)
fix(core, node, bun, deno): Align server span client address with event IP (#24767)
fix(hono): Return the existing client on repeated init in Bun and Deno (#24520)
fix(nitro): Capture errors only through the Nitro error hook (#24952)
fix(profiling-node): Send profile chunks with
client.sendEnvelope(#24896)fix(react-router): Avoid duplicating Vite config arrays (#24930)
fix(react-router): Resolve the Cloudflare entry in Workers and skip trace meta tags in prerendered pages (#24866)
fix(server-utils): Match the Anthropic stream helper header regardless of case (#24855)
fix(server-utils): Skip Fastify 4xx errors raised before the reply status is set (#24924)
fix(tanstackstart-react): Avoid duplicating Vite config arrays (#24929)
chore(deps-dev): bump vercel/nft from 1.5.0 to 1.11.0 (#24954)
chore(deps): Bump sentry/conventions to 0.25.0 (#24958)
chore(deps): dev dependency security fixes (#24275)
chore(size-limit): weekly auto-bump (#24969)
ci(deps): bump anthropics/claude-code-action from 1.0.210 to 1.0.236 (#24950)
ci(deps): bump getsentry/craft from 2.30.1 to 2.31.2 (#24951)
ci(deps): bump getsentry/github-workflows/validate-pr from 4013fc6e1aeb1be1f9d3b4d232624f0ec1afa613 to 36c729264d2edc29ebae61950c50e1e9f043ad7e (#24949)
ci(deps): bump pnpm/action-setup from 6.0.10 to 6.1.0 (#24948)
license: Add cli FSL notice (#24956)
ref(core): Use cache attribute constants from conventions (#24973)
ref(core): Use conversation ID constant from conventions (#24966)
ref(core): Use exclusive time constant from conventions (#24971)
ref(core): Use HTTP method constant from conventions (#24977)
ref(core): Use idle span finish reason constant from conventions (#24970)
ref(core): Use profile ID constant from conventions (#24976)
ref(core): Use SDK metadata constants from conventions (#24978)
ref(core): Use status message constant from conventions (#24967)
ref(core): Use user attribute constants from conventions (#24974)
ref(server-utils): Clarify API promise helper naming and references (#24928)
test(cloudflare): Add Flue E2E test that deploys a real Worker and sends to Sentry (#24816)
test(cloudflare): Match the expected error in the WebSocket e2e tests (#24923)
test(deno): Port integration tests to span streaming (#24870)
test(e2e): Add node-anthropic-send-to-sentry test app (#24856)
test(e2e): Avoid rate limits when polling Sentry in send-to-sentry tests (#24957)
Work in this release was contributed by Shubham-Padkonde and tobias-schnabel. Thank you for your contributions!
11.2.0
Important Changes
feat(hono): add orchestrion-based auto-instrumentation (#24497)
Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.
feat(node/bun): Enable dedupeIntegration by default (#24794)
sentry/nodeandsentry/bunnow includededupeIntegrationin their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration:integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)
On Remix 3, the SDK now adds the matched route as
http.route, the response status and a low-cardinality name to thehttp.serverspan of eachfetch-routerrequest. Start the app with--import sentry/remix/v3/nodein place of--import remix/node-tsx.Other Changes
bunRuntimeMetricsIntegration(#24892)fmt/parameterizemessages (#24770)nextis called (#24854)rolldownOptionsin instrumentation file plugin (#24863)Internal Changes
externallabel on PRs of external contributors (#24825)dedupeIntegration(#24893)test-utils/cloudflare(#24815)Work in this release was contributed by nabi-noor, LuccaRebelloToledo, andasan, breken-ai, EmileBrunelle, and diobriggs. Thank you for your contributions!
11.1.0
Important Changes
feat(server-utils): Auto-instrument MCP servers via orchestrion (#24529)
A new default
mcpServerIntegrationwraps everyMcpServerinstance (frommodelcontextprotocol/serverandmodelcontextprotocol/sdk) when it is created. You no longer need to callwrapMcpServerWithSentrymanually. You can still callwrapMcpServerWithSentryto override options, for examplerecordInputs: false.feat(node): Support Prisma 8 in
prismaIntegration(#24682)prismaIntegrationnow creates aprisma:client:operationspan for each Prisma 8 ORM call, with the database query spans nested below it. No code changes are necessary.feat(server-utils): Add TypeSafe integration (#24703)
A new default
typesafeIntegrationcreates agen_ai.evaluatespan for each TypeSafe Jev call throughtypesafe-ai/sdk(TypeSafeClient.systemOne). For runtimes without auto-instrumentation, useinstrumentTypeSafeClient().feat(server-utils): Instrument Vercel AI
experimental_evaluate(#24694)Vercel AI
experimental_evaluatecalls now create agen_ai.evaluatespan, with the state and questions as input messages and the answers as output messages.Other Changes
onErrorcallback toshowReportDialog(#24780)registerHookspath) (#24705)opentelemetry/apivia the SDK on SvelteKit 3 (#24736)Internal Changes
sentry/conventionsto 0.24.0 (#24645)cloudflare/think(#24660)Work in this release was contributed by camc314, ihsraham, zkasuran, Shubham-Padkonde, and itz-puneet. Thank you for your contributions!
11.0.0
Version
11.0.0marks a major release of the Sentry JavaScript SDKs containing breaking changes.The goal of this release is to be better compatible with OpenTelemetry, make our integrations work across Node.js, Cloudflare, Bun and Deno through run-time and build-time instrumentation, and make span streaming and more permissive data collection the default.
How To Upgrade
Please carefully read through the migration guide in the Sentry docs on how to upgrade from version 10 to version 11. Make sure to select your specific platform/framework in the top left corner: https://docs.sentry.io/platforms/javascript/migration/v10-to-v11/
A comprehensive migration guide outlining all changes can be found within the Sentry JavaScript SDK Repository: https://github.com/getsentry/sentry-javascript/blob/develop/MIGRATION.md
Breaking Changes
All SDKs
--require(#22513)http.*span attributes (#23574)net.span attributes (#23301)skipOpenTelemetrySetupwithenableOpenTelemetrySetup(#23199)http.targetspan attribute (#23575)>=20.19.0as minimum supported version (#22558)handlerspan op for terminal request handlers (#22871)middlewarespan op for web-server middleware (#22852)functionop for framework functions (#23047)honoIntegration(#22480)AI integrations
sentry/server-utils(#22954)sentry/server-utils(#22959)sentry/server-utils(#22962)sentry/server-utils(#22953)sentry/server-utils(#22964)sentry/server-utils(#22960)sentry/angular
routerspan op for frontend routers (#23086)ui.mountandfunctionspan ops for tracing decorators (#22667)sentry/astro
sourceMapsUploadOptionsbuild option (#23630)sentry/aws-serverless
nodejs18.xfrom the Lambda layer runtimes (#23155)disableAwsContextPropagationoption (#23170)faas.invocation_idandcloud.resource_id(#24384)startTraceoption andtryPatchHandler(#23219)function.awsspan op for Lambda invocations (#22677)queueSpan OP for AWS SQS & SNS messaging (#23757)sentry/browser
profilesSampleRate(#23220)performance.{mark,measure}spans into newuserTimingSpansIntegration(#22554)interactionsIntegration(#23295)bfcacheIntegrationtobfcacheMetricsIntegration(#23776)browser.navigation.typeexactly as web-vitals does (#24479)unhandledinstead ofcrashedfor unhandled errors (#22475)page(#21245)browser.paintspan op for paint entries (#22673)trackFetchStreamPerformanceflag (#23172)navigationStartfallback andpagehidelisteners (#21293)beforeSpanEndcallback in favor ofbeforeIdleSpanEndhook (#22818)sentry/bundler-plugins
webpack5entry point (#24455)sentry/cloudflare
functionspan op for cron, email and workflow steps (#22703)instrumentD1WithSentryexport (#23153)SentryTracerProviderfor OpenTelemetry interop (#23300)sentry/core
spanfromScopeData(#23225)attachStacktraceto true (#22572)genAIdefaults to collect it by default (#22706)dataCollection.httpBodies(#22834)beforeSendSpancompatible with streamed spans by default (#22643)tracePropagationTargetsmatching case-insensitive (#23534)enableMetricsoption (#23321)enableTruncationflag and all AI integrations truncation logic (#23045)endTimestampfromSentrySpanArguments(#23269)kindfor spans, move tosentry.kindattribute (#22528)queryParamsin favor ofurlQueryParams(#22711)scope.clear()method (#23230)sendDefaultPiiin favor ofdataCollection(#22918)sentry.sdk_meta.gen_ai.input.messages.original_lengthattribute (#22516)streamGenAiSpansflag (#22495)_experiments.enableLogsoption (#22808)inboundFiltersIntegration(#23008)instrumentLangGraph(#22485)StreamedSpanJSONfromspanToJSON(#23238)url.full,url.fragmentandurl.query(#22547)rpcspan op for tRPC spans (#22914)routerspan op for backend router layers (#23088)enableLogsoption (#23319)attributesin sampling context required (#24153)attributesrequired onScopeData(#23277)getComponentNameto browser-utils (#23716)getLocationHrefexport from core (#23717)startIdleSpanfrom server exports (#23420)supportsDOMError,supportsHistory,supportsReportingObserverexports (#23718)supportsNativeFetchexport (#23719)addAutoIpAddressToUserexport (#23174)htmlTreeAsStringfrom core (#23715)patchExpressModule(options)signature (#23175)spanOriginargument frominstrumentFetchRequest(#23177)enableMetrics/beforeSendMetricflags (#23276)gen_ai.request.available_toolstogen_ai.tool.definitions(#22820)gen_ai.systemtogen_ai.provider.name(#22814)gen_ai.tool.inputtogen_ai.tool.call.arguments(#22821)gen_ai.tool.outputtogen_ai.tool.call.result(#22822)code.*andfs_errorspan attributes (#23401)gen_ai.tool.typespan attribute (#22824)tracePropagationvspropagateTraceoption names (#23649)sentry/deno
sentry/ember
routerspan op for frontend routers (#23086)functionandui.taskspan ops for route hooks and runloop (#22669)'ui.ember.component.render'toui.render(#23587)sentry/feedback
sentry/google-cloud-serverless
function.gcpop for GCP functions (#23050)grpcspan op for GCP gRPC calls (#22666)http.clientspan op for GCP HTTP requests (#22660)sentry/nestjs
functionspan op for setup & lifecycle handlers (#22897)sentry/nextjs
vercel-prefix from default environment and deploys (#24197)middlewarespan op for Next.js middleware (#22674)withSentryConfigtosentry/nextjs/config(#23628)sentry/nitro
sentry/node
profilesSampleRateandprofilesSampler) (#23216)shouldHandleErrorfromsetupExpressErrorHandler(#23732)<3.21.0(#22752)init,preloadentry points andpreloadOpenTelemetry(#23074)