🚨 [security] Update all of sentry 8.4.0 → 10.64.0 (major)#665
Open
depfu[bot] wants to merge 1 commit into
Open
🚨 [security] Update all of sentry 8.4.0 → 10.64.0 (major)#665depfu[bot] wants to merge 1 commit into
depfu[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ @sentry/browser (8.4.0 → 10.64.0) · Repo · Changelog
Security Advisories 🚨
🚨 Sentry SDK Prototype Pollution gadget in JavaScript SDKs
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 66 commits:
release: 10.64.0Merge pull request #22016 from getsentry/prepare-release/10.64.0meta(changelog): Update changelog for 10.64.0fix(core): Print getTraceMetaTags in 1 line to prevent hydration errors (#22004)fix(nextjs): Handle `Middleware.execute` root spans on Node.js runtime (#22013)chore: Make @sentry/conventions sideEffect free during bundling (#22015)test(node): Attempt to unflake docker-based node integration tests (#21905)feat(server-utils): Rewrite `@opentelemetry/instrumentation-hapi` to orchestrion (#21866)chore(cloudflare): Disallow server-utils usage outside of nodejs_compat (#21918)feat(cloudflare): Enable AI v7 support for Cloudflare in the /nodejs_compat entrypoint (#21917)chore(cloudflare): Disallow Node SDK usage outside of nodejs_compat (#21884)feat(cloudflare): Expose prismaIntegration in nodejs_compat export (#21882)feat(cloudflare): Add nodejs_compat entrypoint (#21881)feat(replays): Record segment names that occur during replay (#21851)ref(node): Streamline Prisma v5 instrumentation (#21980)chore: Add experimentalUseDiagnosticsChannelInjection in node size-limit (#21992)feat(deps): Bump OpenTelemetry dependencies to latest (#21988)chore: Remove runtime ESM/CJS switching (#21761)test(e2e): Use `injectDiagnostics` for orchestrion marker (#21987)test(browser): Fix web worker route-registration race in debug ID test (#21920)fix(nextjs): Add immutable browser chunks to upload assets (#21978)fix(react/solid/vue): Instrument TanStack Router navigations via `onBeforeLoad`/`onResolved` (#21975)fix(cloudflare): Catch potential errors during flush and dispose (#21976)test(node): Migrate http client span tests to createCjsTests (#21956)test(node): Migrate logging integration tests to create*Tests helpers (#21955)test(node): Refactor remaining express integrations tests to new runner (#21949)test(node): Migrate fs & contextLines-filename integration tests to helpers (#21958)ref(node): Refactor orchestrion config into separate files (#21957)feat(server-utils): Implement orchestrion-based instrumentation for vercel-ai v6 (#21658)feat(core): Add `sentry.trace_lifecycle` attribute (#21850)feat(server-utils): Migrate `@opentelemetry/instrumentation-ioredis` to orchestrion (#21849)test(e2e): Revert nf3 dependency override in nitro-3 e2e test (#21951)feat(server-utils): Migrate Anthropic integration to orchestrion (#21902)feat(server-utils): Migrate OpenAI integration to orchestrion (#21877)chore: Add external contributor to CHANGELOG.md (#21945)fix(browser): Accept precisely-typed GrowthBook class in growthbookIntegration (#21825)ref(deno): add deno-integration-tests dev-package (#21827)feat(bun): enable new mysql, pg integrations in 'bun build' (#21828)feat(mongoose): Instrument mongoose >= 9.7 via native tracing channels (#21803)feat(bun,deno,node): pg orchestrion instrumentation (#21826)chore(node-core): Move isCjs to its own file to prevent sideEffects (#21856)test(google-genai): Move google-genai integration tests to use a real client (#21909)test(node): Automatically run all node-integration tests with orchestrion (#21911)feat(node): Wire up SentryTracerProvider (#21680)feat(core): Seal SentryTracerProvider spans against mutation after they end (#21842)feat(core): Add deferred segment-span transaction capture (#21839)feat(opentelemetry): Add SentryTracerProvider (#21666)fix(core): Capture Anthropic stream stop_reason from message_delta (#21907)chore(ci): Replace `app-id` with `client-id` in GH workflows (#21914)tests(core): Move anthropic node integration tests to use a real client (#21906)test(node): Collapse mysql span streaming tests into same suite (#21890)ref(core): Add `@sentry/conventions` to `@sentry/core` and align versions (#21855)ci: Increase Node integration test timeout to 20 minutes (#21903)ref(node): Use `@sentry/conventions` and vendor remaining semantic conventions (#21893)deps(server-utils): Bump @apm-js-collab/tracing-hooks to 0.10.1 (#21892)test(e2e): Fix failing nitro-3 e2e test due to broken dependency (#21895)test(node): Ensure logs are auto-printed when a test fails (#21887)test(node): Update pg-native tests to use `additionalDependencies` (#21878)chore: Clarify usage of hoistTransitiveImports option (#21888)Merge pull request #21879 from getsentry/masterMerge branch 'release/10.63.0'test(nextjs): Tolerate aborted navigation in streaming RSC error E2E test (#21847)ref(node-core): Move node fetch instrumentation into node-core (#21873)ref(node): Fold breadcrumb & trace propagation into node fetch instrumentation (#21872)test(node): Improve tests for Prisma v5 (#21876)fix(browser): Flush telemetry when page is hidden (#21862)✳️ @sentry/node (8.4.0 → 10.64.0) · Repo · Changelog
Security Advisories 🚨
🚨 Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true`
🚨 Potential DoS when using ContextLines integration
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 66 commits:
release: 10.64.0Merge pull request #22016 from getsentry/prepare-release/10.64.0meta(changelog): Update changelog for 10.64.0fix(core): Print getTraceMetaTags in 1 line to prevent hydration errors (#22004)fix(nextjs): Handle `Middleware.execute` root spans on Node.js runtime (#22013)chore: Make @sentry/conventions sideEffect free during bundling (#22015)test(node): Attempt to unflake docker-based node integration tests (#21905)feat(server-utils): Rewrite `@opentelemetry/instrumentation-hapi` to orchestrion (#21866)chore(cloudflare): Disallow server-utils usage outside of nodejs_compat (#21918)feat(cloudflare): Enable AI v7 support for Cloudflare in the /nodejs_compat entrypoint (#21917)chore(cloudflare): Disallow Node SDK usage outside of nodejs_compat (#21884)feat(cloudflare): Expose prismaIntegration in nodejs_compat export (#21882)feat(cloudflare): Add nodejs_compat entrypoint (#21881)feat(replays): Record segment names that occur during replay (#21851)ref(node): Streamline Prisma v5 instrumentation (#21980)chore: Add experimentalUseDiagnosticsChannelInjection in node size-limit (#21992)feat(deps): Bump OpenTelemetry dependencies to latest (#21988)chore: Remove runtime ESM/CJS switching (#21761)test(e2e): Use `injectDiagnostics` for orchestrion marker (#21987)test(browser): Fix web worker route-registration race in debug ID test (#21920)fix(nextjs): Add immutable browser chunks to upload assets (#21978)fix(react/solid/vue): Instrument TanStack Router navigations via `onBeforeLoad`/`onResolved` (#21975)fix(cloudflare): Catch potential errors during flush and dispose (#21976)test(node): Migrate http client span tests to createCjsTests (#21956)test(node): Migrate logging integration tests to create*Tests helpers (#21955)test(node): Refactor remaining express integrations tests to new runner (#21949)test(node): Migrate fs & contextLines-filename integration tests to helpers (#21958)ref(node): Refactor orchestrion config into separate files (#21957)feat(server-utils): Implement orchestrion-based instrumentation for vercel-ai v6 (#21658)feat(core): Add `sentry.trace_lifecycle` attribute (#21850)feat(server-utils): Migrate `@opentelemetry/instrumentation-ioredis` to orchestrion (#21849)test(e2e): Revert nf3 dependency override in nitro-3 e2e test (#21951)feat(server-utils): Migrate Anthropic integration to orchestrion (#21902)feat(server-utils): Migrate OpenAI integration to orchestrion (#21877)chore: Add external contributor to CHANGELOG.md (#21945)fix(browser): Accept precisely-typed GrowthBook class in growthbookIntegration (#21825)ref(deno): add deno-integration-tests dev-package (#21827)feat(bun): enable new mysql, pg integrations in 'bun build' (#21828)feat(mongoose): Instrument mongoose >= 9.7 via native tracing channels (#21803)feat(bun,deno,node): pg orchestrion instrumentation (#21826)chore(node-core): Move isCjs to its own file to prevent sideEffects (#21856)test(google-genai): Move google-genai integration tests to use a real client (#21909)test(node): Automatically run all node-integration tests with orchestrion (#21911)feat(node): Wire up SentryTracerProvider (#21680)feat(core): Seal SentryTracerProvider spans against mutation after they end (#21842)feat(core): Add deferred segment-span transaction capture (#21839)feat(opentelemetry): Add SentryTracerProvider (#21666)fix(core): Capture Anthropic stream stop_reason from message_delta (#21907)chore(ci): Replace `app-id` with `client-id` in GH workflows (#21914)tests(core): Move anthropic node integration tests to use a real client (#21906)test(node): Collapse mysql span streaming tests into same suite (#21890)ref(core): Add `@sentry/conventions` to `@sentry/core` and align versions (#21855)ci: Increase Node integration test timeout to 20 minutes (#21903)ref(node): Use `@sentry/conventions` and vendor remaining semantic conventions (#21893)deps(server-utils): Bump @apm-js-collab/tracing-hooks to 0.10.1 (#21892)test(e2e): Fix failing nitro-3 e2e test due to broken dependency (#21895)test(node): Ensure logs are auto-printed when a test fails (#21887)test(node): Update pg-native tests to use `additionalDependencies` (#21878)chore: Clarify usage of hoistTransitiveImports option (#21888)Merge pull request #21879 from getsentry/masterMerge branch 'release/10.63.0'test(nextjs): Tolerate aborted navigation in streaming RSC error E2E test (#21847)ref(node-core): Move node fetch instrumentation into node-core (#21873)ref(node): Fold breadcrumb & trace propagation into node fetch instrumentation (#21872)test(node): Improve tests for Prisma v5 (#21876)fix(browser): Flush telemetry when page is hidden (#21862)Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands