feat(core): Add and use dataCollection.graphQL - #22221
Conversation
| graphQL?: { | ||
| document?: boolean; | ||
| variables?: boolean; | ||
| }; |
There was a problem hiding this comment.
Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH
Suggested Fix
Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.
Did we get this right? 👍 / 👎 to inform future reviews.
size-limit report 📦
|
| graphQL?: { | ||
| document?: boolean; | ||
| variables?: boolean; | ||
| }; |
There was a problem hiding this comment.
Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.
It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.
An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.
There was a problem hiding this comment.
The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.
Maybe we should make this more clear in the JSDoc?
There was a problem hiding this comment.
I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.
Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.
| // The GraphQL document has literal values redacted at collection time, so it was historically | ||
| // always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior. | ||
| graphQL: { document: true, variables: true }, |
There was a problem hiding this comment.
Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH
Suggested Fix
Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies). This updates what `package.json` declares. The range may already have permitted the newer version, in which case only the declaration was stale. Lockfile resolved by `npm`, with no install and no lifecycle scripts. Produced by a script, not a model — a lockfile is not something to write by hand. <details><summary>Release notes</summary> ### 10.70.0 - feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986)) - feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992)) - feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163)) - fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189)) - fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192)) - fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190)) - fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985)) - fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193)) - fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript …truncated; see the release link above. ### 10.69.0 ### Important Changes - **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786 The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)). ### Other Changes - feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796)) - feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803)) - feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770)) - feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith …truncated; see the release link above. ### 10.68.0 - feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967)) - feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224)) - feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389)) - feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094)) - feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141)) - feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379)) - feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564)) - feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533)) - feat(v10/cloudflare) …truncated; see the release link above. ### 10.67.0 ### Important Changes - **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264 The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically. ### Other Changes - feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143)) - feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126)) - feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035)) - feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119)) - feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217)) - feat(mongodb): impl …truncated; see the release link above. ### 10.66.0 - chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285)) - chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284)) - deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172)) - feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036)) - feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124)) - feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180)) - feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219)) - feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221)) - feat(core): Add stringify helper and make AI-traci …truncated; see the release link above. ### 10.65.0 - feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985)) - feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011)) - feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079)) - feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952)) - feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999)) - feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052)) - feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095)) - feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824)) - feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https …truncated; see the release link above. ### 10.64.0 ### Important Changes - **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881 The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)). This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11. - **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842 The Node SDK now registers Sentry's own …truncated; see the release link above. ### 10.63.0 - feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846)) - feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759)) - feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785)) - feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833)) - feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786)) - feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706)) - fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844)) - fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815)) - fix(core): Serialize streamed span status message to `sentry.status.message` attri …truncated; see the release link above. _71 earlier release(s) in this range are not shown._ Releases: https://github.com/getsentry/sentry-javascript/releases </details>
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies). This updates what `package.json` declares. The range may already have permitted the newer version, in which case only the declaration was stale. Lockfile resolved by `npm`, with no install and no lifecycle scripts. Produced by a script, not a model — a lockfile is not something to write by hand. <details><summary>Release notes</summary> ### 10.70.0 - feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986)) - feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992)) - feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163)) - fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189)) - fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192)) - fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190)) - fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985)) - fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193)) - fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript …truncated; see the release link above. ### 10.69.0 ### Important Changes - **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786 The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)). ### Other Changes - feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796)) - feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803)) - feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770)) - feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith …truncated; see the release link above. ### 10.68.0 - feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967)) - feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224)) - feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389)) - feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094)) - feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141)) - feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379)) - feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564)) - feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533)) - feat(v10/cloudflare) …truncated; see the release link above. ### 10.67.0 ### Important Changes - **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264 The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically. ### Other Changes - feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143)) - feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126)) - feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035)) - feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119)) - feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217)) - feat(mongodb): impl …truncated; see the release link above. ### 10.66.0 - chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285)) - chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284)) - deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172)) - feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036)) - feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124)) - feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180)) - feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219)) - feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221)) - feat(core): Add stringify helper and make AI-traci …truncated; see the release link above. ### 10.65.0 - feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985)) - feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011)) - feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079)) - feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952)) - feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999)) - feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052)) - feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095)) - feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824)) - feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https …truncated; see the release link above. ### 10.64.0 ### Important Changes - **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881 The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)). This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11. - **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842 The Node SDK now registers Sentry's own …truncated; see the release link above. ### 10.63.0 - feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846)) - feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759)) - feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785)) - feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833)) - feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786)) - feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706)) - fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844)) - fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815)) - fix(core): Serialize streamed span status message to `sentry.status.message` attri …truncated; see the release link above. _71 earlier release(s) in this range are not shown._ Releases: https://github.com/getsentry/sentry-javascript/releases </details>
* Bump @sentry/vue from 10.0.0 to 10.70.0 `@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies). This updates what `package.json` declares. The range may already have permitted the newer version, in which case only the declaration was stale. Lockfile resolved by `npm`, with no install and no lifecycle scripts. Produced by a script, not a model — a lockfile is not something to write by hand. <details><summary>Release notes</summary> ### 10.70.0 - feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986)) - feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992)) - feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163)) - fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189)) - fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192)) - fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190)) - fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985)) - fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193)) - fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript …truncated; see the release link above. ### 10.69.0 ### Important Changes - **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786 The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)). ### Other Changes - feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796)) - feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803)) - feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770)) - feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith …truncated; see the release link above. ### 10.68.0 - feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967)) - feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224)) - feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389)) - feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094)) - feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141)) - feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379)) - feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564)) - feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533)) - feat(v10/cloudflare) …truncated; see the release link above. ### 10.67.0 ### Important Changes - **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264 The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically. ### Other Changes - feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143)) - feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126)) - feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035)) - feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119)) - feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217)) - feat(mongodb): impl …truncated; see the release link above. ### 10.66.0 - chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285)) - chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284)) - deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172)) - feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036)) - feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124)) - feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180)) - feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219)) - feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221)) - feat(core): Add stringify helper and make AI-traci …truncated; see the release link above. ### 10.65.0 - feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985)) - feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011)) - feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079)) - feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952)) - feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999)) - feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052)) - feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095)) - feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824)) - feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https …truncated; see the release link above. ### 10.64.0 ### Important Changes - **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881 The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)). This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11. - **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842 The Node SDK now registers Sentry's own …truncated; see the release link above. ### 10.63.0 - feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846)) - feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759)) - feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785)) - feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833)) - feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786)) - feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706)) - fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844)) - fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815)) - fix(core): Serialize streamed span status message to `sentry.status.message` attri …truncated; see the release link above. _71 earlier release(s) in this range are not shown._ Releases: https://github.com/getsentry/sentry-javascript/releases </details> * Bump @sentry/vue from 10.0.0 to 10.70.0 `@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies). This updates what `package.json` declares. The range may already have permitted the newer version, in which case only the declaration was stale. Lockfile resolved by `npm`, with no install and no lifecycle scripts. Produced by a script, not a model — a lockfile is not something to write by hand. <details><summary>Release notes</summary> ### 10.70.0 - feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986)) - feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992)) - feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163)) - fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189)) - fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192)) - fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190)) - fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985)) - fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193)) - fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript …truncated; see the release link above. ### 10.69.0 ### Important Changes - **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786 The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)). ### Other Changes - feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796)) - feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803)) - feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770)) - feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith …truncated; see the release link above. ### 10.68.0 - feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967)) - feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224)) - feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389)) - feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094)) - feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141)) - feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379)) - feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564)) - feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533)) - feat(v10/cloudflare) …truncated; see the release link above. ### 10.67.0 ### Important Changes - **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264 The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically. ### Other Changes - feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143)) - feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126)) - feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035)) - feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119)) - feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217)) - feat(mongodb): impl …truncated; see the release link above. ### 10.66.0 - chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285)) - chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284)) - deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172)) - feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036)) - feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124)) - feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180)) - feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219)) - feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221)) - feat(core): Add stringify helper and make AI-traci …truncated; see the release link above. ### 10.65.0 - feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985)) - feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011)) - feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079)) - feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952)) - feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999)) - feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052)) - feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095)) - feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824)) - feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https …truncated; see the release link above. ### 10.64.0 ### Important Changes - **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881 The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)). This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11. - **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842 The Node SDK now registers Sentry's own …truncated; see the release link above. ### 10.63.0 - feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846)) - feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759)) - feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785)) - feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833)) - feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786)) - feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706)) - fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844)) - fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815)) - fix(core): Serialize streamed span status message to `sentry.status.message` attri …truncated; see the release link above. _71 earlier release(s) in this range are not shown._ Releases: https://github.com/getsentry/sentry-javascript/releases </details>
Sets the default collection behavior to
trueas it has been collected already.