Skip to content

chore(deps): update JavaScript SDK to v11.6.0 - #6773

Draft
github-actions[bot] wants to merge 1 commit into
mainfrom
deps/scripts/update-javascript.sh
Draft

github-actions[bot] wants to merge 1 commit into
mainfrom
deps/scripts/update-javascript.sh

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Bumps scripts/update-javascript.sh from 10.76.0 to 11.6.0.

Auto-generated by a dependency updater.

Changelog

11.6.0

Important Changes

  • feat(nextjs): Add sentry/nextjs/cloudflare (#24998)

    The new sentry/nextjs/cloudflare entry point exports withSentry for the Worker entry of a Next.js app on Cloudflare Workers, for example .open-next/worker.js of OpenNext. It is withSentry of sentry/cloudflare with the Next.js server handling added, so a Next.js app on Workers gets the same spans as on Node.js.

    import * as Sentry from 'sentry/nextjs/cloudflare';
    import handler from './.open-next/worker.js';
    
    export default Sentry.withSentry(
      env => ({
        dsn: env.SENTRY_DSN,
        tracesSampleRate: 1.0,
      }),
      handler,
    );
  • feat(server-utils): Add instrumentation for pi-durable (#24993)

    The new piDurableIntegration traces agents built with pi-durable: each run, with its model requests and tool calls.

  • fix(core): Correct sleep clock drift on telemetry timestamps (#23054)

    When a device sleeps, the performance.now() clock of the browser stops. Before this change, timestamps of spans and other telemetry recorded after the sleep could be too early. The SDK now detects this drift and corrects its time origin, also for spans created from performance entries. Span end times are now computed from the performance.now() duration since the span start, like in OpenTelemetry (#24903).

Other Changes

  • feat(cloudflare): Skip spans for the pi_ tables of PiHarness (#25028)
  • feat(remix): Propagate the server trace to Remix 3 page loads (#25145)
  • feat(server-utils): Map Mastra classifier evaluations to gen_ai.evaluate spans (#25044)
  • feat(server-utils): Record LangChain TypeSafeClassifier runs as gen_ai.evaluate spans (#25120)
  • fix(browser): Check for clock drift on page lifecycle events (#25091)
  • fix(core): Exclude attachments from internal exception events (#25160)
  • fix(effect): Convert Effect span times to the Sentry clock (#24972)
  • fix(effect): Detect HTTP spans named after the request method (#25159)
  • fix(node): Register Vercel keep-alive listeners once (#25146)
  • fix(replay): Place CLS and INP web vitals at the right time (#24990)
  • fix(server-utils): Record LangGraph span I/O for non-MessagesAnnotation state (#23315)
  • fix(sveltekit): Upload source maps with SvelteKit 3 (#25139) Internal Changes
  • chore: Add external contributor to CHANGELOG.md (#25136)
  • chore(deps-dev): Bump next from 15.5.24 to 15.5.27 (#25171)
  • chore(nitro): Remove stale bundler-plugin-core rollup external (#25149)
  • feat(cloudflare): Wrap vinext Worker entries with sentry/nextjs/cloudflare (#25000)
  • feat(deps): Bump next from 16.2.11 to 16.3.8 in /dev-packages/e2e-tests/test-applications/nextjs-sourcemaps (#25170)
  • fix(deps): Bump graphql-tools/utils to 12.0.3 (#25162)
  • ref(eslint-plugin-sdk): Improve no-unsafe-random-apis rule (#25123)
  • test(cloudflare): Port the remaining static suites to span streaming (#25112)
  • test(cloudflare): Widen the wrangler readiness retry window in integration tests (#24925)
  • test(e2e): Add a cloudflare-pi-durable end-to-end application (#25022)
  • test(e2e): Add a node-pi-durable end-to-end application (#24994)
  • test(e2e): Add Mastra Jev classifier test to node-mastra (#25115)
  • test(e2e): Wait for the soft navigation entry before hiding the page (#25127)
  • test(nextjs): Run nextjs-16 on Bun, Deno and Cloudflare (#24999)
  • test(node): Add streamed span collection helpers (#25131)
  • test(node): Cover Jev calls inside createAgent and LangGraph (#25132)
  • test(node): Port AMQP integration tests to span streaming (#25158)
  • test(node): Port Anthropic integration tests to span streaming (#25082)
  • test(node): Port Bedrock tests to span streaming (#25086)
  • test(node): Port Google GenAI tests to span streaming (#25083)
  • test(node): Port Knex integration tests to span streaming (#25154)
  • test(node): Port LangChain tests to span streaming (#25084)
  • test(node): Port LangGraph tests to span streaming (#25085)
  • test(node): Port Mastra tests to span streaming (#25087)
  • test(node): Port MySQL integration tests to span streaming (#25148)
  • test(node): Port OpenAI integration tests to span streaming (#25081)
  • test(node): Port pool and DataLoader integration tests to span streaming (#25156)
  • test(node): Port Tedious integration tests to span streaming (#25155)
  • test(node): Port Vercel AI v5-v7 tests to span streaming (#25090)
    Work in this release was contributed by zkasuran. Thank you for your contribution!

11.5.0

Important Changes

  • feat(core): Warn on repeated Sentry.init() and unbind the client on close() (#24962)

    Sentry.init() now warns when it runs while a client is still active. For now, the new client still replaces the active client, but the active client is not closed, so state from both can mix. Call Sentry.init() once, or call await Sentry.close() before you call it again. Sentry.close() now unbinds the client it closes, so after close(), getClient() returns undefined, isInitialized() returns false, and a later init() sets up a new client. In sentry/cloudflare, later requests no longer reuse the isolate's cached client once it is closed or closing. On the server, sentry/nextjs and sentry/remix now return the active client from a repeated init() call, not undefined.

Other Changes

  • chore(deps): Bump rrweb to 2.44.1 (#25100)

  • chore(deps): Bump web-vitals to 6.2.3 (#25062)

  • feat(bun): keep server spans open until streaming responses finish (#25025)

  • feat(langchain): Derive gen_ai.conversation.id from the invoke config (#24831)

  • feat(nextjs): Add code.file.path to use cache fill spans (#24988)

  • feat(react-router): Export createSentryServerInstrumentation from the Cloudflare entry (#25042)

  • feat(remix): Parameterize Remix 3 navigation spans (#25045)

  • feat(remix): Parameterize Remix 3 page load spans (#25053)

  • feat(remix): Report the matched route on Remix 3 HTML responses (#25052)

  • fix(ai): Normalize token usage and preserve cache breakdowns (#25074)

  • fix(browser-utils): Handle NS_ERROR_NOT_INITIALIZED from setTimeout in Firefox (#25024)

  • fix(bun): Add conversationIdIntegration to the default integrations (#25003)

  • fix(cloudflare): Detect TypeSafe Jev calls in Workers AI by model ID (#25033)

  • fix(cloudflare): Keep an installed OpenTelemetry async context strategy (#24995)

  • fix(feedback): Correct overlapping screenshot annotations and drag dimming (#25040)

  • fix(nextjs): Don't capture forbidden() and unauthorized() as errors (#25088)

  • fix(nextjs): Include basePath in request url of Pages Router errors (#24985)

  • fix(nextjs): Skip init inside a request of sentry/cloudflare (#24996)

  • fix(node): Flush telemetry before Vercel functions are suspended (#24910)

  • fix(nuxt): Do not inject debug IDs into the SSR build (#25080)

  • fix(react-router): Pass the project when creating a release (#25089)

  • fix(remix): Pass the project when creating a release (#25079)

  • fix(server-utils): Derive the Vercel AI conversation id from the OpenAI conversation option (#24979)

  • fix(server-utils): Instrument the Vercel AI experimental_decide channel event (#25068)

  • fix(server-utils): Map Flue messages and token usage to the gen_ai conventions (#24992)

  • fix(server-utils): Record Vercel AI experimental_telemetry.metadata on gen_ai spans (#24721)

  • fix(sveltekit): Export consoleLoggingIntegration from worker entry (#25061)

  • fix(tanstackstart-react): Fix server route parametrization gaps (#25071)

  • ref(core): Deprecate SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN (#25039)

  • ref(core): Remove beforeSendSpan null return warning (#24129)

    Internal Changes
  • chore: Add external contributor to CHANGELOG.md (#25111)

  • chore(bugbot): Flag hard-coded attribute names that have a conventions constant (#25070)

  • chore(deps-dev): bump nx from 22.7.7 to 22.7.10 (#25075)

  • chore(deps): Bump sentry/conventions to 0.26.0 (#25073)

  • chore(github): Remove triage-issue workflow (#25098)

  • chore(skills): Drop bundler-plugins cross-repo search from triage-issue skill (#25099)

  • feat(deps): bump compression from 1.8.1 to 1.8.2 (#25109)

  • feat(deps): Bump js-yaml from 3.15.1 to 3.15.2 (#24236)

  • feat(deps): bump proxy-addr from 2.0.7 to 2.0.8 (#25077)

  • feat(deps): bump shell-quote from 1.10.0 to 1.12.0 (#25108)

  • feat(deps): bump source-map-js from 1.2.1 to 1.2.2 (#25076)

  • feat(deps): Bump svgo from 4.0.2 to 4.1.0 (#24220)

  • fix(deps): Bump seroval to 1.6.8 to fix two Dependabot alerts (#25104)

  • ref: Reuse isObjectLike for object guards (#25058)

  • ref(browser): Use SENTRY_ORIGIN convention constant (#25037)

  • ref(core): Use SENTRY_OP convention constant (#24982)

  • ref(core): Use SENTRY_ORIGIN convention constant in shared tracing (#24983)

  • ref(meta-frameworks): Use SENTRY_ORIGIN convention constant (#25038)

  • ref(nextjs): Move the server span hooks into serverSpanHooks.ts (#24997)

  • ref(server): Use SENTRY_ORIGIN convention constant (#25036)

  • test(aws-serverless): Port GraphQL test to span streaming (#25056)

  • test(browser): port general browser integration suites to default streaming (#24876)

  • test(bun): Port request-body tests to span streaming (#25021)

  • test(cloudflare): Add Workers AI tracing tests for Clef (#25027)

  • test(e2e): Add Bun, Deno and Cloudflare variants to react-router-8-framework (#24598)

  • test(e2e): Add eve test for Jev evaluate calls (#25034)

  • test(e2e): Bump bundler plugins to 5.4.1 in e2e test apps (#25107)

  • test(e2e): Cover isolation, trace propagation and logs on all react-router-8-framework runtimes (#25041)

  • test(e2e): Move react-router-8-cloudflare MySQL tests into react-router-8-framework (#24599)

  • test(e2e): Port Astro 5 Cloudflare to span streaming (#25016)

  • test(e2e): Raise mock Sentry server chunk size to fit whole bundles (#25097)

  • test(ember): Pin embroider packages away from broken releases (#25066)

  • test(nextjs): Expect use cache route handler file path on Turbopack (#25117)

  • test(nextjs): Pin nextjs-16-cf-workers latest variant to Next.js 16.3 (#25118)

  • test(node): Port Apollo GraphQL integration tests to span streaming (#25030)

  • test(node): port AWS integration tests to span streaming (#25018)

  • test(node): port filesystem integration tests to span streaming (#25019)

  • test(node): Port GraphQL tracing-channel tests to span streaming (#25055)

  • test(node): port rejection, feature flag, and client-report tests to span streaming (#25020)

  • test(node/bun): drop static pins from non-tracing integration suites (#25017)

  • test(nuxt): Upgrade to Nuxt 4.6 ; Test imports from nuxt/server (#25093)

Work in this release was contributed by minwookshin. Thank you for your contribution!

11.4.0

  • feat(sveltekit): Support stable SvelteKit 3 (#25009)
  • fix(remix): Match the Remix 3.0.0 package versions (#25008)

11.3.0

Important Changes

  • Remix 3 support (alpha, may break in minor releases)

    • feat(remix): Add Remix 3 browser SDK with a bundled client entry (#24802)
    • feat(remix): Add source map upload for Remix 3 (#24943)
    • feat(remix): Capture Remix 3 component render errors (#24873)
    • feat(remix): Complete Remix 3 server error handling (#24878)
    • feat(remix): Inject debug IDs through the Remix 3 asset server (#24761)
    • feat(remix): Run the orchestrion transform on Remix 3 browser modules (#24894)
  • feat(nextjs): Add cache_origin span links to use cache hit spans (#24821)

    A cache.get span for a "use cache" hit now carries a span link (sentry.link.type: 'cache_origin') to the cache.put span of the request that filled the cache entry, connecting the trace that reads a cached value to the trace that produced it.

  • fix(cloudflare): Don't treat DO constructor work as incoming RPC calls (#24829)

    Durable Object constructors now run in their own isolation scope. When work that the constructor starts, for example a blockConcurrencyWhile callback, calls a method of the instance, that call is no longer treated as an incoming RPC call, so an error the instance catches itself is no longer reported as unhandled. As a result, Sentry.setTag(), setUser() and setContext() in a constructor now apply only to that constructor work. They no longer reach later fetch, RPC or alarm invocations, because the scope they used to write to is shared by every Durable Object and handler in the isolate. Use initialScope for static data, and set per-instance data in each handler.

  • fix(effect)!: Change peerDependency to v4 and fix currentSpan (#24940)

    sentry/effect now requires a stable Effect v4 release. Effect v4 beta and release candidate versions are no longer supported. sentry/effect is in alpha, so this ships in a minor release.

Other Changes

  • feat(astro): Register astro route provider (#23792)
  • feat(cloudflare): Trace TypeSafe Jev calls in Workers AI as evaluate spans (#24833)
  • feat(core): Add route provider API for parameterized route resolution (#23551)
  • feat(deps): bump devalue from 5.9.2 to 5.9.4 (#24964)
  • feat(effect): Add opt-in for external span parents and isolate root spans (#23900)
  • feat(nextjs): Register nextjs route provider (#23552)
  • feat(nuxt): Register nuxt route provider (#23794)
  • feat(remix): Register remix route provider (#23791)
  • feat(vue): Register Vue route provider (#23793)
  • fix(bundler-plugins): Keep debug IDs on Vite source maps after the preload rewrite (#24920)
  • fix(bundler-plugins): Stabilize debug IDs for Rolldown and Vite 8 builds (#24919)
  • fix(cloudflare): Skip binding instrumentation work when spans are not sent (#24655)
  • fix(core, node, bun, deno): Align server span client address with event IP (#24767)
  • fix(hono): Return the existing client on repeated init in Bun and Deno (#24520)
  • fix(nitro): Capture errors only through the Nitro error hook (#24952)
  • fix(profiling-node): Send profile chunks with client.sendEnvelope (#24896)
  • fix(react-router): Avoid duplicating Vite config arrays (#24930)
  • fix(react-router): Resolve the Cloudflare entry in Workers and skip trace meta tags in prerendered pages (#24866)
  • fix(server-utils): Match the Anthropic stream helper header regardless of case (#24855)
  • fix(server-utils): Skip Fastify 4xx errors raised before the reply status is set (#24924)
  • fix(tanstackstart-react): Avoid duplicating Vite config arrays (#24929)
Internal Changes
  • chore(deps-dev): bump vercel/nft from 1.5.0 to 1.11.0 (#24954)
  • chore(deps): Bump sentry/conventions to 0.25.0 (#24958)
  • chore(deps): dev dependency security fixes (#24275)
  • chore(size-limit): weekly auto-bump (#24969)
  • ci(deps): bump anthropics/claude-code-action from 1.0.210 to 1.0.236 (#24950)
  • ci(deps): bump getsentry/craft from 2.30.1 to 2.31.2 (#24951)
  • ci(deps): bump getsentry/github-workflows/validate-pr from 4013fc6e1aeb1be1f9d3b4d232624f0ec1afa613 to 36c729264d2edc29ebae61950c50e1e9f043ad7e (#24949)
  • ci(deps): bump pnpm/action-setup from 6.0.10 to 6.1.0 (#24948)
  • license: Add cli FSL notice (#24956)
  • ref(core): Use cache attribute constants from conventions (#24973)
  • ref(core): Use conversation ID constant from conventions (#24966)
  • ref(core): Use exclusive time constant from conventions (#24971)
  • ref(core): Use HTTP method constant from conventions (#24977)
  • ref(core): Use idle span finish reason constant from conventions (#24970)
  • ref(core): Use profile ID constant from conventions (#24976)
  • ref(core): Use SDK metadata constants from conventions (#24978)
  • ref(core): Use status message constant from conventions (#24967)
  • ref(core): Use user attribute constants from conventions (#24974)
  • ref(server-utils): Clarify API promise helper naming and references (#24928)
  • test(cloudflare): Add Flue E2E test that deploys a real Worker and sends to Sentry (#24816)
  • test(cloudflare): Match the expected error in the WebSocket e2e tests (#24923)
  • test(deno): Port integration tests to span streaming (#24870)
  • test(e2e): Add node-anthropic-send-to-sentry test app (#24856)
  • test(e2e): Avoid rate limits when polling Sentry in send-to-sentry tests (#24957)

Work in this release was contributed by Shubham-Padkonde and tobias-schnabel. Thank you for your contributions!

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    sentry/node and sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
Internal Changes - chore: Add external contributor to CHANGELOG.md ([#24822](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24822)) - chore: Add external contributor to CHANGELOG.md ([#24827](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24827)) - chore: Add external contributor to CHANGELOG.md ([#24835](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24835)) - chore: Add external contributor to CHANGELOG.md ([#24850](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24850)) - chore: Add external contributor to CHANGELOG.md ([#24851](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24851)) - chore: Add external contributor to CHANGELOG.md ([#24914](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24914)) - chore(deps): Update to Vitest 4 and Vite 8 ([#24746](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24746)) - chore(github): Add `external` label on PRs of external contributors ([#24825](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24825)) - chore(solidstart): Remove unused Vitest setup from e2e apps ([#24789](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24789)) - ci: shard Bun integration tests ([#24771](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24771)) - ci: shard Deno shared integration tests ([#24772](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24772)) - docs(core): Clarify error object dedupe and `dedupeIntegration` ([#24893](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24893)) - feat(deps): bump axios from 1.18.0 to 1.20.0 ([#24918](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24918)) - feat(deps): bump fast-uri from 3.1.7 to 3.1.8 ([#24889](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24889)) - feat(deps): bump fastify from 5.12.1 to 5.12.5 ([#24917](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24917)) - feat(deps): bump hono from 4.13.5 to 4.13.7 ([#24916](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24916)) - feat(deps): bump ip-address from 10.4.0 to 10.7.2 ([#24810](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24810)) - feat(deps): bump moment from 2.30.1 to 2.31.0 ([#24890](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24890)) - fix(deps): runtime dependency security fixes ([#24911](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24911)) - ref(hono): move shared Hono instrumentation into sentry/server-utils ([#24496](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24496)) - test(browser): Fix flaky reportPageLoaded duration assertion ([#24814](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24814)) - test(bun): Run the auto-instrumentation suites with bundled scenarios ([#24612](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24612)) - test(cloudflare): Add shared streamed-span helpers to the integration test runner ([#24176](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24176)) - test(cloudflare): Assert Workers AI gen_ai spans in the send-to-sentry E2E test ([#24515](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24515)) - test(cloudflare): Port the binding suites to span streaming ([#24190](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24190)) - test(cloudflare): Port the http-server integration suites to span streaming ([#24195](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24195)) - test(cloudflare): Port the request handler suites to span streaming ([#24196](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24196)) - test(cloudflare): Port the tracing propagation suites to span streaming ([#24185](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24185)) - test(cloudflare): Port the tracing suites to span streaming ([#24179](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24179)) - test(cloudflare): Port the vite-autoinstrument suites to span streaming ([#24189](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24189)) - test(e2e): Add Bun Express test app ([#24306](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24306)) - test(e2e): Add trace test for background use cache revalidation ([#24740](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24740)) - test(e2e): Mark supabase-nextjs as optional ([#24898](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24898)) - test(e2e): Retry a hung SAM start in aws-serverless tests ([#24879](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24879)) - test(nextjs): Add tests for low-cardinality span names for cache spans ([#24819](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24819)) - test(nextjs): Add UI components for cached/dynamic content ([#24874](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24874)) - test(nuxt): Remove version pin for nuxt/cli in Nuxt 5 E2E ([#24798](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24798)) - test(replay): De-flake mutationLimit large-mutations test ([#24784](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24784)) - test(sveltekit): Add missing prerender e2e test ([#24921](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24921)) - test(test-utils): Add fetchSpanAttributes to read span attributes via the sentry CLI ([#24514](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24514)) - test(test-utils): Extract Cloudflare Worker deploys into `test-utils/cloudflare` ([#24815](https://github-redirect.dependabot.com/getsentry/sentry-javascript/pull/24815)) Work in this release was contributed by nabi-noor, LuccaRebelloToledo, andasan, breken-ai, EmileBrunelle, and diobriggs. Thank you for your contributions!

11.1.0

Important Changes

  • feat(server-utils): Auto-instrument MCP servers via orchestrion (#24529)

    A new default mcpServerIntegration wraps every McpServer instance (from modelcontextprotocol/server and modelcontextprotocol/sdk) when it is created. You no longer need to call wrapMcpServerWithSentry manually. You can still call wrapMcpServerWithSentry to override options, for example recordInputs: false.

  • feat(node): Support Prisma 8 in prismaIntegration (#24682)

    prismaIntegration now creates a prisma:client:operation span for each Prisma 8 ORM call, with the database query spans nested below it. No code changes are necessary.

  • feat(server-utils): Add TypeSafe integration (#24703)

    A new default typesafeIntegration creates a gen_ai.evaluate span for each TypeSafe Jev call through typesafe-ai/sdk (TypeSafeClient.systemOne). For runtimes without auto-instrumentation, use instrumentTypeSafeClient().

  • feat(server-utils): Instrument Vercel AI experimental_evaluate (#24694)

    Vercel AI experimental_evaluate calls now create a gen_ai.evaluate span, with the state and questions as input messages and the answers as output messages.

Other Changes

  • feat(browser): Add onError callback to showReportDialog (#24780)
  • feat(bun): Add client address, port and protocol to Bun.serve spans (#24523)
  • feat(cloudflare): Re-export httpServerIntegration from /request (#24614)
  • feat(remix): Add Remix 3 export subpaths and optional peer deps (#24697)
  • feat(server-utils): Support amqplib v2 (#24652)
  • feat(server-utils): Support tedious v20 (#24644)
  • fix: Injection silently no-ops on Windows (registerHooks path) (#24705)
  • fix(bun): Keep diagnostics channel subscriptions alive (#24632)
  • fix(cloudflare): Call connect() on the binding for service bindings and DO stubs (#24593)
  • fix(cloudflare): Keep the user's class name when auto-wrapping an export (#24700)
  • fix(core): Support joined set-cookie headers (split them) (#24659)
  • fix(nextjs): Don't prepend basePath to absolute router navigation URLs (#24680)
  • fix(nextjs): Limit Turbopack orchestrion loader to instrumented packages (#24792)
  • fix(nextjs): Stop Turbopack loaders from loading the Sentry CLI (#24651)
  • fix(server-runtime-injection): Keep ES modules working on Deno (#24669)
  • fix(server-utils): Deduplicate Google GenAI streaming tool calls (#23432)
  • fix(sveltekit,remix): Export Mistral manual wrapper (#24566)
  • fix(sveltekit): Resolve opentelemetry/api via the SDK on SvelteKit 3 (#24736)
  • fix(wasm): map wasm:// stack frames to registered debug images (#23999)
  • perf(bundler-plugins): Use fast component annotation for HTML injection mode (#24440)
  • perf(bundler-plugins): Use fast component annotation for Webpack and Turbopack (#24448)
  • ref(bundler-plugins): Remove Babel fallback from component annotation (#24449)
Internal Changes
  • chore: Add external contributor to CHANGELOG.md (#24674)
  • chore: Add external contributor to CHANGELOG.md (#24675)
  • chore: Add external contributor to CHANGELOG.md (#24745)
  • chore: Add external contributor to CHANGELOG.md (#24766)
  • chore: Add external contributor to CHANGELOG.md (#24782)
  • chore: Update base node version to 24.21.0 (#24343)
  • chore: upgrade oxfmt to 0.70.0 (#24637)
  • chore(ci): Assign server package reviews back to server team (#24743)
  • chore(deps-dev): bump elysia from 1.4.27 to 1.4.29 (#24673)
  • chore(deps): Bump sentry/conventions to 0.24.0 (#24645)
  • chore(size-limit): weekly auto-bump (#24729)
  • ci: Replace per-run flaky issues with a weekly report (#24707)
  • ci: shard Cloudflare integration tests (#24726)
  • ci: shard Node integration tests and increase browser Playwright workers (#24676)
  • docs: Point browser SDK READMEs to documentation (#24634)
  • docs: Point Effect, Elysia, and Wasm READMEs to documentation (#24636)
  • docs: Point framework SDK READMEs to documentation (#24631)
  • docs: Point profiling and native READMEs to documentation (#24640)
  • docs: Point Replay and Feedback READMEs to documentation (#24639)
  • docs: Point server SDK READMEs to documentation (#24635)
  • docs: Point tooling READMEs to documentation (#24641)
  • docs: Standardize internal package READMEs (#24638)
  • docs(angular): Point README to SDK documentation (#24623)
  • docs(astro): Point README to SDK documentation (#24626)
  • docs(aws-serverless): Point README to SDK documentation (#24627)
  • docs(cloudflare): Point README to SDK documentation (#24624)
  • docs(ember): Point README to SDK documentation (#24628)
  • docs(hono): Point README to SDK documentation (#24621)
  • docs(nestjs): Point README to SDK documentation (#24618)
  • docs(nitro): Point README to SDK documentation (#24629)
  • docs(opentelemetry): Point README to documentation (#24642)
  • docs(react-router): Point README to SDK documentation (#24625)
  • docs(remix): Point README to SDK documentation (#24630)
  • docs(solidstart): Point README to SDK documentation (#24622)
  • fix(ci): Handle missing workers in E2E cleanup (#24779)
  • fix(server-utils): Use Bun-safe diagnostics channel wrappers in MCP integration (#24797)
  • test(bun, deno): Run shared Node integration suites on Bun and Deno (#24609)
  • test(bun): Exclude Typesafe tests in bun (#24785)
  • test(bun): Run all Node integration suites on Bun (#24610)
  • test(bun): Run the Bun-only suites with the shared Node runner (#24668)
  • test(cloudflare): Add e2e test app for cloudflare/think (#24660)
  • test(cloudflare): Resend requests until the deployed Cloudflare Worker answers (#24560)
  • test(deno): Run all Node integration suites on Deno (#24611)
  • test(e2e): Add cache origin link tests for cached components in pages (#24739)
  • test(e2e): Add cache origin link tests for use cache route handlers (#24734)
  • test(e2e): Add Next.js cache component nesting scenarios (#24704)
  • test(e2e): Add node-prisma-8 test app (#24683)
  • test(e2e): Add pageload connection test for cache component apps (#24741)
  • test(e2e): fix flaky hydrogen send-to-sentry tests (#24708)
  • test(effect): Make effect/http stable (#24781)
  • test(node): Add Prisma 8 integration test suite (#24681)
  • test(node): Assert absence of PII attributes in OpenAI integration tests (#24031)
  • test(node): Port envelope-header tests to span streaming (#24528)
  • test(node): Use a separate instrument file for the Vercel AI evaluate privacy test (#24742)
  • test(nuxt): Fix Nuxt 5 E2E by pinning nuxt/cli (#24788)
  • test(remix): Add Remix 3 e2e test application (#24698)
  • test(vue): verify vue-router 5 support (#24595)

Work in this release was contributed by camc314, ihsraham, zkasuran, Shubham-Padkonde, and itz-puneet. Thank you for your contributions!

11.0.0

Version 11.0.0 marks a major release of the Sentry JavaScript SDKs containing breaking changes.
The goal of this release is to be better compatible with OpenTelemetry, make our integrations work across Node.js, Cloudflare, Bun and Deno through run-time and build-time instrumentation, and make span streaming and more permissive data collection the default.

How To Upgrade

Please carefully read through the migration guide in the Sentry docs on how to upgrade from version 10 to version 11. Make sure to select your specific platform/framework in the top left corner: https://docs.sentry.io/platforms/javascript/migration/v10-to-v11/

A comprehensive migration guide outlining all changes can be found within the Sentry JavaScript SDK Repository: https://github.com/getsentry/sentry-javascript/blob/develop/MIGRATION.md

Breaking Changes

All SDKs
  • feat: Remove support for initialising via --require (#22513)
  • feat!: Rename deprecated http.* span attributes (#23574)
  • feat!: Rename deprecated net. span attributes (#23301)
  • feat!: Replace skipOpenTelemetrySetup with enableOpenTelemetrySetup (#23199)
  • feat!: Replace the deprecated http.target span attribute (#23575)
  • feat!: Require Node >=20.19.0 as minimum supported version (#22558)
  • feat!: Use handler span op for terminal request handlers (#22871)
  • feat!: Use middleware span op for web-server middleware (#22852)
  • feat(frameworks)!: Use function op for framework functions (#23047)
  • feat(node/cloudflare)!: Remove deprecated honoIntegration (#22480)
  • feat(v11): Drop TypeScript 3.8 support (#18604)
AI integrations
  • feat(langchain): Emit gen_ai.pipeline.name instead of langchain.chain.name (#23740)
  • ref(anthropic)!: Move Anthropic AI integration to sentry/server-utils (#22954)
  • ref(google-genai)!: Move Google GenAI integration to sentry/server-utils (#22959)
  • ref(langchain)!: Move LangChain and LangGraph integrations to sentry/server-utils (#22962)
  • ref(langgraph)!: Drop gen_ai.create_agent spans (#22840)
  • ref(openai)!: Move OpenAI AI integration to sentry/server-utils (#22953)
  • ref(vercel-ai)!: Move Vercel AI integration to sentry/server-utils (#22964)
  • ref(workers-ai)!: Move Workers AI integration to sentry/server-utils (#22960)
sentry/angular
  • feat(angular,ember,sveltekit)!: Use router span op for frontend routers (#23086)
  • feat(angular)!: Use ui.mount and function span ops for tracing decorators (#22667)
sentry/astro
  • feat(astro)!: Drop support for Astro 3 (#22683)
  • feat(astro)!: Enable orchestrion instrumentation on Cloudflare Workers (#23003)
  • feat(astro)!: Remove deprecated sourceMapsUploadOptions build option (#23630)
  • feat(astro)!: Remove unstable_sentryVitePluginOptions (#23370)
  • ref(astro)!: Migrate import hook to makeOrchestrionLoader (#22861)
  • ref(astro)!: Remove deprecated release/debug conflict workaround from BuildTimeOptionsBase (#23270)
sentry/aws-serverless
  • chore(aws-serverless)!: Drop nodejs18.x from the Lambda layer runtimes (#23155)

⚠️ Changelog content truncated by 355063 characters because it was over the limit (60000) and wouldn't fit into PR description.

@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Sep 23, 2026
@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

Semver Impact of This PR

⚪ None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): update JavaScript SDK to v11.6.0 by github-actions[bot] in #6773
  • chore(deps): bump handlebars from 4.7.9 to 4.7.10 by dependabot in #6862
  • chore(deps): update Wizard to v8.0.1 by github-actions in #6852

🤖 This preview updates automatically when you update the PR.

@antonis antonis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Marking as blocked since we will bump with our next major

@antonis
antonis marked this pull request as draft September 23, 2026 14:00
@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author
Fails
🚫 Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against f30a73e

@antonis

antonis commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

Tested out the changes with #6730

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 3 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit adfb87a. Configure here.

Comment thread packages/core/package.json Outdated
"@sentry/core": "11.0.0",
"@sentry/expo-upload-sourcemaps": "workspace:*",
"@sentry/react": "10.75.2"
"@sentry/react": "11.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PII collected by default after v11

High Severity

Flagged because the review rules require PII to stay gated behind sendDefaultPii and require changelog review on JS dependency bumps. v11 replaces sendDefaultPii with dataCollection and collects user info, cookies, HTTP bodies, and similar data by default. This SDK still documents and implements sendDefaultPii (default off) and omits dataCollection from ReactNativeOptions, so JS-core collection turns on while apps cannot disable it through the public options type.

Fix in Cursor Fix in Web

Triggered by project rule: PR Review Guidelines for Cursor Bot

Reviewed by Cursor Bugbot for commit adfb87a. Configure here.

Comment thread packages/core/package.json Outdated
"@sentry/core": "11.0.0",
"@sentry/expo-upload-sourcemaps": "workspace:*",
"@sentry/react": "10.75.2"
"@sentry/react": "11.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unmigrated v11 breaking JS APIs

High Severity

Flagged because the review rules require JS dependency bumps to be checked for breaking API and default-integration changes. This PR only retargets @sentry/core, @sentry/browser, and @sentry/react to 11.0.0. Default integrations still call removed inboundFiltersIntegration, the public entry still re-exports removed instrumentLangGraph and AI helpers that moved off @sentry/core, and tracing still imports startIdleSpan from the default @sentry/core entry. No code, types, or changelog migration accompanies the major bump.

Fix in Cursor Fix in Web

Triggered by project rule: PR Review Guidelines for Cursor Bot

Reviewed by Cursor Bugbot for commit adfb87a. Configure here.

Comment thread packages/core/package.json Outdated
"@sentry/core": "11.0.0",
"@sentry/expo-upload-sourcemaps": "workspace:*",
"@sentry/react": "10.75.2"
"@sentry/react": "11.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Span streaming default breaks tracing

High Severity

Flagged because the review rules call out silent default and telemetry-shape changes on dependency updates. v11 enables span streaming by default and deprecates transaction-mode hooks such as beforeSendTransaction and forceTransaction. This SDK's navigation, app-start, and idle-span pipeline still assumes root spans are buffered as transactions and discarded via transaction event processors. Streaming would emit child spans before those filters run and change the telemetry apps currently receive.

Fix in Cursor Fix in Web

Triggered by project rule: PR Review Guidelines for Cursor Bot

Reviewed by Cursor Bugbot for commit adfb87a. Configure here.

@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch 5 times, most recently from 5b99eba to a7da763 Compare September 24, 2026 10:57
Comment thread samples/expo/package.json Outdated
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch 5 times, most recently from a5d19b4 to 5949ab3 Compare September 28, 2026 08:08
@github-actions github-actions Bot changed the title chore(deps): update JavaScript SDK to v11.0.0 chore(deps): update JavaScript SDK to v11.1.0 Sep 29, 2026
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch 3 times, most recently from 9caf113 to c8c3cc3 Compare September 29, 2026 06:54
Comment thread samples/react-native-macos/package.json Outdated
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch 3 times, most recently from c2a203e to c6bdd9e Compare September 30, 2026 07:33
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch 2 times, most recently from af263e2 to 88eb841 Compare October 2, 2026 11:40
@github-actions github-actions Bot changed the title chore(deps): update JavaScript SDK to v11.2.0 chore(deps): update JavaScript SDK to v11.4.0 Oct 3, 2026
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch 14 times, most recently from 8949646 to b314359 Compare October 8, 2026 03:12
@github-actions github-actions Bot changed the title chore(deps): update JavaScript SDK to v11.4.0 chore(deps): update JavaScript SDK to v11.5.0 Oct 8, 2026
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch 3 times, most recently from e91ca5a to 4de25fc Compare October 8, 2026 09:29
Comment thread packages/core/package.json Outdated
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch 4 times, most recently from 849c853 to 255295a Compare October 9, 2026 03:13
@github-actions github-actions Bot changed the title chore(deps): update JavaScript SDK to v11.5.0 chore(deps): update JavaScript SDK to v11.6.0 Oct 9, 2026
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch from 255295a to 6152e61 Compare October 9, 2026 09:23
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-javascript.sh branch from 6152e61 to f30a73e Compare October 9, 2026 09:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Blocked dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants