Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
74 commits
Select commit Hold shift + click to select a range
ec4931e
Merge pull request #25012 from getsentry/master
github-actions[bot] Oct 2, 2026
e10598c
test(e2e): Add Bun, Deno and Cloudflare variants to react-router-8-fr…
JPeer264 Oct 5, 2026
b126416
test(node/bun): drop static pins from non-tracing integration suites …
nicohrubec Oct 5, 2026
5b3e480
test(bun): Port request-body tests to span streaming (#25021)
nicohrubec Oct 5, 2026
880a6ac
test(node): port rejection, feature flag, and client-report tests to …
nicohrubec Oct 5, 2026
566d7d8
test(node): port AWS integration tests to span streaming (#25018)
nicohrubec Oct 5, 2026
5f2f5f5
test(e2e): Move react-router-8-cloudflare MySQL tests into react-rout…
JPeer264 Oct 5, 2026
85e5455
ref(core): Use SENTRY_OP convention constant (#24982)
nicohrubec Oct 5, 2026
6181072
fix(cloudflare): Detect TypeSafe Jev calls in Workers AI by model ID …
andreiborza Oct 5, 2026
2237750
test(e2e): Port Astro 5 Cloudflare to span streaming (#25016)
nicohrubec Oct 5, 2026
b139c53
test(node): port filesystem integration tests to span streaming (#25019)
nicohrubec Oct 5, 2026
e74d7cf
ref(browser): Use SENTRY_ORIGIN convention constant (#25037)
nicohrubec Oct 5, 2026
f5d1ee7
ref(core): Use SENTRY_ORIGIN convention constant in shared tracing (#…
nicohrubec Oct 5, 2026
2998151
test(e2e): Add eve test for Jev evaluate calls (#25034)
andreiborza Oct 5, 2026
f94c52e
ref(meta-frameworks): Use SENTRY_ORIGIN convention constant (#25038)
nicohrubec Oct 5, 2026
78d070e
ref(server): Use SENTRY_ORIGIN convention constant (#25036)
nicohrubec Oct 5, 2026
9a47ffe
fix(feedback): Correct overlapping screenshot annotations and drag di…
msonnb Oct 5, 2026
79d84ff
ref(core): Deprecate SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN (#25039)
nicohrubec Oct 5, 2026
3a7ad4b
feat(nextjs): Add `code.file.path` to `use cache` fill spans (#24988)
s1gr1d Oct 5, 2026
40e26c6
fix(browser-utils): Handle NS_ERROR_NOT_INITIALIZED from setTimeout i…
sentry[bot] Oct 5, 2026
ad1d641
fix(nextjs): Include basePath in request url of Pages Router errors (…
chargome Oct 5, 2026
60cd46b
ref(core): Remove `beforeSendSpan` null return warning (#24129)
msonnb Oct 5, 2026
7241723
test(aws-serverless): Port GraphQL test to span streaming (#25056)
nicohrubec Oct 5, 2026
d94b677
fix(cloudflare): Keep an installed OpenTelemetry async context strate…
JPeer264 Oct 5, 2026
a40375d
ref: Reuse `isObjectLike` for object guards (#25058)
msonnb Oct 5, 2026
e741ce8
fix(sveltekit): Export consoleLoggingIntegration from worker entry (#…
JPeer264 Oct 5, 2026
637aa3d
test(ember): Pin embroider packages away from broken releases (#25066)
logaretm Oct 5, 2026
21ba35d
chore(deps): Bump web-vitals to 6.2.3 (#25062)
logaretm Oct 5, 2026
f469f76
fix(server-utils): Record Vercel AI `experimental_telemetry.metadata`…
isaacs Oct 5, 2026
161bd94
fix(node): Flush telemetry before Vercel functions are suspended (#24…
sergical Oct 5, 2026
d93e210
fix(server-utils): Instrument the Vercel AI experimental_decide chann…
RulaKhaled Oct 5, 2026
6805115
feat(core): Warn on repeated `Sentry.init()` and unbind the client on…
isaacs Oct 5, 2026
b31048b
test(browser): port general browser integration suites to default str…
msonnb Oct 6, 2026
212fd13
chore(bugbot): Flag hard-coded attribute names that have a convention…
andreiborza Oct 6, 2026
3dae6a5
fix(server-utils): Map Flue messages and token usage to the gen_ai co…
JPeer264 Oct 6, 2026
cfa5c75
fix(bun): Add conversationIdIntegration to the default integrations (…
JPeer264 Oct 6, 2026
24b945d
test(node): Port GraphQL tracing-channel tests to span streaming (#25…
nicohrubec Oct 6, 2026
95c1146
chore(deps): Bump `@sentry/conventions` to 0.26.0 (#25073)
sentry-junior[bot] Oct 6, 2026
f2fc75c
feat(remix): Report the matched route on Remix 3 HTML responses (#25052)
chargome Oct 6, 2026
32310b5
feat(remix): Parameterize Remix 3 page load spans (#25053)
chargome Oct 6, 2026
1e3cccd
feat(remix): Parameterize Remix 3 navigation spans (#25045)
chargome Oct 6, 2026
7fa60a4
feat(deps): bump source-map-js from 1.2.1 to 1.2.2 (#25076)
dependabot[bot] Oct 6, 2026
c8805d8
feat(deps): bump proxy-addr from 2.0.7 to 2.0.8 (#25077)
dependabot[bot] Oct 6, 2026
d79f44c
fix(nuxt): Do not inject debug IDs into the SSR build (#25080)
s1gr1d Oct 6, 2026
6ba1c68
test(e2e): Raise mock Sentry server chunk size to fit whole bundles (…
andreiborza Oct 6, 2026
d308ed7
chore(github): Remove triage-issue workflow (#25098)
sentry-junior[bot] Oct 6, 2026
02b2df3
chore(skills): Drop bundler-plugins cross-repo search from triage-iss…
sentry-junior[bot] Oct 6, 2026
c25a4dd
chore(deps): Bump rrweb to 2.44.1 (#25100)
sentry-junior[bot] Oct 6, 2026
9ae9a30
test(nuxt): Upgrade to Nuxt 4.6 ; Test imports from `nuxt/server` (#2…
s1gr1d Oct 6, 2026
345064d
fix(nextjs): Skip `init` inside a request of `@sentry/cloudflare` (#2…
JPeer264 Oct 6, 2026
92d9b8a
ref(nextjs): Move the server span hooks into `serverSpanHooks.ts` (#2…
JPeer264 Oct 6, 2026
fcf0619
test(e2e): Bump bundler plugins to 5.4.1 in e2e test apps (#25107)
sentry-junior[bot] Oct 6, 2026
ea31682
feat(deps): Bump js-yaml from 3.15.1 to 3.15.2 (#24236)
dependabot[bot] Oct 6, 2026
b49fbcc
test(e2e): Cover isolation, trace propagation and logs on all react-r…
JPeer264 Oct 6, 2026
2ea0300
feat(react-router): Export createSentryServerInstrumentation from the…
JPeer264 Oct 6, 2026
18e4b7e
feat(deps): bump compression from 1.8.1 to 1.8.2 (#25109)
dependabot[bot] Oct 6, 2026
3cafe93
feat(deps): bump shell-quote from 1.10.0 to 1.12.0 (#25108)
dependabot[bot] Oct 6, 2026
095f485
chore(deps-dev): bump nx from 22.7.7 to 22.7.10 (#25075)
dependabot[bot] Oct 6, 2026
a819a8b
fix(deps): Bump seroval to 1.6.8 to fix two Dependabot alerts (#25104)
chargome Oct 6, 2026
d398658
fix(tanstackstart-react): Fix server route parametrization gaps (#25071)
chargome Oct 6, 2026
99d3ed6
test(node): Port Apollo GraphQL integration tests to span streaming (…
nicohrubec Oct 6, 2026
019c889
feat(bun): keep server spans open until streaming responses finish (#…
minwookshin Oct 6, 2026
4565408
feat(deps): Bump svgo from 4.0.2 to 4.1.0 (#24220)
dependabot[bot] Oct 6, 2026
0369ca9
chore: Add external contributor to CHANGELOG.md (#25111)
javascript-sdk-gitflow[bot] Oct 6, 2026
2cc2b29
fix(server-utils): Derive the Vercel AI conversation id from the Open…
RulaKhaled Oct 6, 2026
40ad4ca
feat(langchain): Derive gen_ai.conversation.id from the invoke config…
RulaKhaled Oct 6, 2026
5fc18dc
fix(remix): Pass the project when creating a release (#25079)
chargome Oct 7, 2026
2a085be
fix(react-router): Pass the project when creating a release (#25089)
chargome Oct 7, 2026
c7ed7ca
test(cloudflare): Add Workers AI tracing tests for Clef (#25027)
JPeer264 Oct 7, 2026
75ae164
fix(nextjs): Don't capture forbidden() and unauthorized() as errors (…
chargome Oct 7, 2026
d441a34
test(nextjs): Expect use cache route handler file path on Turbopack (…
chargome Oct 7, 2026
dd398d0
test(nextjs): Pin nextjs-16-cf-workers latest variant to Next.js 16.3…
chargome Oct 7, 2026
603eb60
fix(ai): Normalize token usage and preserve cache breakdowns (#25074)
msonnb Oct 7, 2026
b47fd85
meta(changelog): Update changelog for 11.5.0
chargome Oct 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 1 addition & 2 deletions .agents/skills/triage-issue/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,11 +73,10 @@ If any of these alternative interpretations apply, capture them in the triage re

### Step 3: Codebase Research

Search for relevant code using Grep/Glob. Find error messages, function names, and stack trace paths in the local repo.
Search for relevant code using Grep/Glob. Find error messages, function names, and stack trace paths in the local repo. Bundler plugin code lives in `packages/bundler-plugins`.

Cross-repo searches (only when clearly relevant):

- Bundler issues: `gh api search/code -X GET -f "q=<term>+repo:getsentry/sentry-javascript-bundler-plugins"`
- Docs issues: `gh api search/code -X GET -f "q=<term>+repo:getsentry/sentry-docs"`

**Shell safety:** Strip shell metacharacters from issue-derived search terms before use in commands.
Expand Down
1 change: 0 additions & 1 deletion .agents/skills/triage-issue/assets/triage-report.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,6 @@

### Cross-Repo Findings

- **bundler-plugins:** <findings or "no matches">
- **sentry-docs:** <findings or "no matches">

### Recommended Next Steps
Expand Down
28 changes: 22 additions & 6 deletions .agents/skills/write-tests/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -307,16 +307,31 @@ it.each([
### Test isolation

Tests must never depend on execution order or share mutable state. For this codebase, many tests
need to reset global Sentry state:
need to reset global Sentry state. Use whatever reset the existing tests in your package use (many
packages have a `resetSdk()` or `cleanupOtel()` helper). Otherwise, pick one:

```typescript
beforeEach(() => {
clearGlobalScope();
getCurrentScope().clear();
getIsolationScope().clear();
});
// Unbind the client. Cheap, and enough for most tests that call `init()`.
getCurrentScope().setClient(undefined);

// Reset the global, isolation, and current scopes, and the client bound to them.
// `setupOnce` still does not run again, because installed integrations are tracked
// outside the carrier.
getMainCarrier().__SENTRY__ = undefined;

// Close and unbind the client. Also flushes, so it is slower.
await Sentry.close();
```

**Reset the client in every test that calls `init()`.** A second `init()` while a client is bound
prints a "`Sentry.init()` was called more than once" warning. After the next major version, it will
return the bound client instead of a new one, so a test without a reset gets the previous test's
client and options. See `docs/repeated-init.md`.

To assert on that warning (or any `consoleSandbox` output), stub `originalConsoleMethods.warn` from
`@sentry/core`. `consoleSandbox` calls the stored original method, so a spy on `console.warn` misses
it once the console integration is set up.

### Grouping

1-2 levels of `describe` is usually enough. Deeper nesting makes tests harder to find and read.
Expand Down Expand Up @@ -526,6 +541,7 @@ Before you're done, verify each test against these criteria:
- [ ] Description reads as a behavior specification (no "should", no "works correctly")
- [ ] No dependency on other tests' execution or state
- [ ] Mocks and spies are restored (via `beforeEach`)
- [ ] Tests that call `init()` reset the bound client between tests
- [ ] Edge cases covered: empty inputs, boundaries, error paths, null/undefined
- [ ] Realistic test data (not `"foo"`, `"test"`, `123`)
- [ ] No try/catch for error testing — `toThrow` / `rejects.toThrow` only
Expand Down
2 changes: 2 additions & 0 deletions .cursor/BUGBOT.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,7 @@ Keep reviews high-signal. Prefer actionable, high-confidence findings over specu
- Flag usage of the following APIs: `getCurrentScope()`, `getIsolationScope()`, `getClient()` if they are avoidable. Flag it with severity Low and acknowledge from the start that this is more a "is this necessary" check, rather than a rule violation.
- Reason for flagging: Usage of these APIs is problematic for multi-client setups where either there is no "current" client/scope, or the wrong client might be used. Calling these APIs would create a current scope, thereby misleading any future calls to these APIs.
- What to do instead: Use an existing reference to the scope or client. For example, this is possible in most `Integration` hooks.
- Flag hard-coded attribute names and span ops (e.g. `'sentry.origin'`, `'sentry.op'`, `'http.request.method'`, `'db.system.name'`) when `@sentry/conventions` exports a constant for them. Use the constant from `@sentry/conventions/attributes` (e.g. `SENTRY_ORIGIN`, `SENTRY_OP`) or `@sentry/conventions/op` instead. Do not flag values that have no constant in `@sentry/conventions`.
- Flag unnecessary `span.setAttribute(s)` calls: If data is already available at span start, it must be set via the `attributes` option of `startSpan`, `startSpanManual`, `startInactiveSpan` or `startIdleSpan` calls. This ensures that as much context as possible is available when `tracesSampler` or `ignoreSpans` SDK options are applied. If a `span.setAttribute(s)` call happens at a later time than right after span start and the attribute value can only be computed at that time, do not flag it.

### Code quality
Expand All @@ -92,6 +93,7 @@ Keep reviews high-signal. Prefer actionable, high-confidence findings over specu
- Flag usage of `expect.objectContaining` and other relaxed assertions, when a test expects something NOT to be included in a payload but there's no respective assertion.
- Flag usage of conditionals in one test and recommend splitting up the test for the different paths.
- Flag usage of loops testing multiple scenarios in one test and recommend using `(it)|(test).each` instead.
- Apply the `@sentry/conventions` constants rule from above to test files too. Test assertions on span attributes and ops must use the constants, not string literals.
- Flag tests that are likely to introduce flakes. In our case this usually means we wait for some telemetry requests sent from an SDK. Patterns to look out for:
- Only waiting for a request, after an action is performed. Instead, start waiting, perform action, await request promise.
- Race conditions when waiting on multiple requests. Ensure that waiting checks are unique enough and don't depend on a hard order when there's a chance that telemetry can be sent in arbitrary order.
Expand Down
14 changes: 14 additions & 0 deletions .github/dependency-review-config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,3 +30,17 @@ allow-ghsas:
# 0.35.0, which is outside that range. Already present on develop via sharp 0.32.6
# and 0.34.5, both of which are affected by the same advisory.
- GHSA-f88m-g3jw-g9cj
# axios, pinned exactly to 1.18.1 by nx (dev-only build tooling, not shipped).
# Can be removed once nx pins axios >= 1.20.0.
- GHSA-542g-h47m-68v8
- GHSA-3pq3-5fj3-cg6v
- GHSA-x97p-jq2g-jp4f
- GHSA-mghh-pgcx-3jjj
- GHSA-c29m-xwm3-cm6r
- GHSA-r4gj-5m52-g5wh
- GHSA-m8m8-qj5v-23w3
# brace-expansion, pinned exactly to 5.0.8 by nx (dev-only build tooling, not shipped).
# Can be removed once nx pins brace-expansion >= 5.0.11.
- GHSA-rgw5-rvv9-x895
- GHSA-6j4f-fj2g-mc7p
- GHSA-qhr7-859c-m2p7
17 changes: 14 additions & 3 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1038,6 +1038,8 @@ jobs:
REACT_APP_E2E_TEST_DSN: 'https://username@domain/123'
E2E_TEST_SENTRY_ORG_SLUG: 'sentry-javascript-sdks'
E2E_TEST_SENTRY_PROJECT: 'sentry-javascript-e2e-tests'
# The `runtime` of a runtime variant, see dev-packages/e2e-tests/README.md
RUNTIME: ${{ matrix.runtime }}
strategy:
fail-fast: false
matrix: ${{ fromJson(needs.job_build.outputs.e2e-matrix) }}
Expand All @@ -1056,7 +1058,7 @@ jobs:
- name: Set up Bun
if:
matrix.test-application == 'node-exports-test-app' || contains(matrix.test-application, 'bun') ||
contains(matrix.label, 'bun')
matrix.runtime == 'bun'
uses: oven-sh/setup-bun@v2
with:
bun-version: '1.3.14'
Expand All @@ -1067,7 +1069,7 @@ jobs:
use-installer: true
token: ${{ secrets.GITHUB_TOKEN }}
- name: Set up Deno
if: contains(matrix.test-application, 'deno') || contains(matrix.label, 'deno')
if: contains(matrix.test-application, 'deno') || matrix.runtime == 'deno'
uses: denoland/setup-deno@v2.0.5
with:
deno-version: ${{ matrix.deno-version || 'v2.8.3' }}
Expand Down Expand Up @@ -1177,6 +1179,8 @@ jobs:
# Used by test apps that deploy a real Cloudflare Worker, e.g. cloudflare-workers-send-to-sentry
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
# The `runtime` of a runtime variant, see dev-packages/e2e-tests/README.md
RUNTIME: ${{ matrix.runtime }}
strategy:
fail-fast: false
matrix: ${{ fromJson(needs.job_build.outputs.e2e-matrix-optional) }}
Expand All @@ -1193,8 +1197,15 @@ jobs:
uses: actions/setup-node@v7
with:
node-version-file: 'dev-packages/e2e-tests/test-applications/${{ matrix.test-application }}/package.json'
- name: Set up Bun
if:
matrix.test-application == 'node-exports-test-app' || contains(matrix.test-application, 'bun') ||
matrix.runtime == 'bun'
uses: oven-sh/setup-bun@v2
with:
bun-version: '1.3.14'
- name: Set up Deno
if: matrix.test-application == 'deno'
if: contains(matrix.test-application, 'deno') || matrix.runtime == 'deno'
uses: denoland/setup-deno@v2.0.5
with:
deno-version: ${{ matrix.deno-version || 'v2.8.3' }}
Expand Down
98 changes: 0 additions & 98 deletions .github/workflows/triage-issue.yml

This file was deleted.

3 changes: 3 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,9 @@ Uses **Git Flow** (see `docs/gitflow.md`).
Runtime packages (`node`, `cloudflare`, ...) re-export from
`@sentry/server-utils` rather than defining their own.

- `Sentry.init()` follows one rule for repeated calls: the first call wins. See
`docs/repeated-init.md` before you add or change an `init()`.

## Linting & Formatting

- This project uses **Oxlint** and **Oxfmt** — NOT ESLint or Prettier
Expand Down
Loading
Loading