Skip to content

meta(changelog): Update changelog for 11.2.0 - #24927

Merged
JPeer264 merged 66 commits into
masterfrom
prepare-release/11.2.0
Oct 1, 2026
Merged

JPeer264 merged 66 commits into
masterfrom
prepare-release/11.2.0

Conversation

@JPeer264

@JPeer264 JPeer264 commented Oct 1, 2026

Copy link
Copy Markdown
Member

No description provided.

github-actions Bot and others added 30 commits September 28, 2026 16:38
[Gitflow] Merge master into develop
Similar to #24676 and #24726, split the shared Node integration suites
running on Deno across two CI jobs as coverage grows. The native Deno
suites still run once, on shard 1; only the Vitest suites are sharded.

Co-authored-by: GPT-6 <codex@openai.com>
Similar to #24676 and #24726, split Bun integration tests across two CI
jobs as coverage grows. Bun on develop currently only takes around 2
minutes and with this change 1 minute, so this is not yet really
necessary but also doesn't hurt.

Co-authored-by: GPT-6 <codex@openai.com>
Add the missing `beforeExit` flush for metrics, matching the existing
behavior for logs and client reports. This ensures buffered metrics are
sent when a Node process exits naturally, even if the timer or size
threshold has not triggered a flush yet.
Nuxt fixed it in:
nuxt/nuxt@7758942

Follow-up for this PR (just reverting the commit):
#24788
Adds a dedicated Bun + Express E2E application covering automatic
request tracing and error capture. The app exercises both a
parameterized success route and an exception route, asserting Express
handler spans, route naming, status propagation, the Bun runtime
context, and trace correlation.

The app is built with `sentryBunPlugin` because Express instrumentation
under Bun relies on build-time diagnostics-channel injection. The SDK
and Express remain external so the app validates the normal package
boundary, while CI now installs its pinned Bun version for this matrix
entry.

The targeted `bun-express` E2E run passes both Playwright cases on Bun
1.3.14. `yarn format`, `yarn build:dev`, and `yarn build:tarball` also
complete successfully. The full local lint and unit-suite runs still
surface pre-existing environment/baseline failures outside the files
changed here; CI will provide the authoritative full-suite result.

Fixes #12732

Co-authored-by: OpenAI Codex <codex@openai.com>
fix(core): Stop LRUMap.set from evicting when updating an existing key
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #24306

Co-authored-by: nicohrubec <29484629+nicohrubec@users.noreply.github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from
10.4.0 to 10.7.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/beaugunderson/ip-address/releases">ip-address's
releases</a>.</em></p>
<blockquote>
<h2>v10.7.2</h2>
<h2>What's Changed</h2>
<ul>
<li>Accept an arpa suffix in any case and without the root dot in
fromArpa by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/227">beaugunderson/ip-address#227</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.7.1...v10.7.2">https://github.com/beaugunderson/ip-address/compare/v10.7.1...v10.7.2</a></p>
<h2>v10.7.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump js-yaml and brace-expansion in the lockfile by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/226">beaugunderson/ip-address#226</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.7.0...v10.7.1">https://github.com/beaugunderson/ip-address/compare/v10.7.0...v10.7.1</a></p>
<h2>v10.7.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Add offset() and nextNetwork(), accept prefix-length ip6.arpa names,
correct the IPv6 end-address docs by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/225">beaugunderson/ip-address#225</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.6.0...v10.7.0">https://github.com/beaugunderson/ip-address/compare/v10.6.0...v10.7.0</a></p>
<h2>v10.6.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Add isGlobal() and pin the classifiers to the IANA special-purpose
registries by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/224">beaugunderson/ip-address#224</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.5.1...v10.6.0">https://github.com/beaugunderson/ip-address/compare/v10.5.1...v10.6.0</a></p>
<h2>v10.5.1</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.5.0...v10.5.1">https://github.com/beaugunderson/ip-address/compare/v10.5.0...v10.5.1</a></p>
<h2>v10.5.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Honor the fromURL graceful-failure contract for non-IPv6 hosts by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/218">beaugunderson/ip-address#218</a></li>
<li>Correct the documentation where it disagreed with the library by <a
href="https://github.com/beaugunderson"><code>@​beaugunderson</code></a>
in <a
href="https://redirect.github.com/beaugunderson/ip-address/pull/219">beaugunderson/ip-address#219</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/beaugunderson/ip-address/compare/v10.4.0...v10.5.0">https://github.com/beaugunderson/ip-address/compare/v10.4.0...v10.5.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/974b48d9ade9348accdb377ba0a15feba4a11361"><code>974b48d</code></a>
10.7.2</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/4dfe8e5eb34fdb47698834b213526814234c0cb1"><code>4dfe8e5</code></a>
Accept an arpa suffix in any case and without the root dot in fromArpa
(<a
href="https://redirect.github.com/beaugunderson/ip-address/issues/227">#227</a>)</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/f0c25dfd4fbf7886e45116ba0940207f81401e28"><code>f0c25df</code></a>
10.7.1</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5"><code>8b34a21</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/13b615554f129bdcdbd10f39b5918fef4bcf96c5"><code>13b6155</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134"><code>469ead1</code></a>
Reject an address longer than the family allows before parsing it</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28"><code>1343629</code></a>
Report an address of the other family as not contained</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/4c2184a0cbd8f913e15a64a2063afc9eef410bd2"><code>4c2184a</code></a>
Bump js-yaml and brace-expansion in the lockfile (<a
href="https://redirect.github.com/beaugunderson/ip-address/issues/226">#226</a>)</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/2b7cab51c7aec0cb56f820f192a38901614e5a9f"><code>2b7cab5</code></a>
10.7.0</li>
<li><a
href="https://github.com/beaugunderson/ip-address/commit/87fae235d95ab0ce18665ae5690f98f65e882d6a"><code>87fae23</code></a>
Add offset() and nextNetwork(), accept prefix-length ip6.arpa names,
correct ...</li>
<li>Additional commits viewable in <a
href="https://github.com/beaugunderson/ip-address/compare/v10.4.0...v10.7.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ip-address&package-manager=npm_and_yarn&previous-version=10.4.0&new-version=10.7.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/getsentry/sentry-javascript/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
The `reportPageLoaded` default tests flaked in CI with a pageload span
duration of ~3.16s against a `< 3` upper bound.

_Root cause:_ the pageload span starts at navigation start, but the 2.5s
`setTimeout` before `Sentry.reportPageLoaded()` only begins once the
test bundle has executed, so page load time on a slow runner is added on
top. Bumping the upper bound to 4s gives enough headroom; the
`idle_span_finish_reason: 'reportPageLoaded'` assertion already
guarantees the span wasn't ended by a timeout. Applied to both the
static and streamed variants.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… the sentry CLI (#24514)

This is helpful for the stacked PR where we add a test for workers-ai

Adds `fetchSpanAttributes(traceId, spanId)` to
`@sentry-internal/test-utils/cli`, so send-to-sentry E2E tests can
assert span attributes and not only the span op.

`sentry trace view --json` looks like it returns span attributes, but it
silently drops all of them for most spans: the trace-items endpoint
sends `int` attribute values as strings, the CLI's schema (0.44.1 and
0.45.0) expects numbers, and a failed schema check only logs `Could not
fetch details for span`. The helper calls the same endpoint through
`sentry api`, which does no schema check. The spawn and credential
handling moved into a shared runner so both helpers use the E2E token
the same way.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
…y E2E test (#24515)

closes #24759

Adds a Workers AI call to the real-Worker E2E app and checks that the
`gen_ai.chat` span reaches Sentry with `gen_ai.input.messages` and
`gen_ai.output.messages`. The unit and integration tests only see the
envelope, so this is the first check that the Workers AI span and its
attributes survive ingestion.

The test expects `gen_ai.output.messages` and not
`gen_ai.response.text`, because Sentry stores the SDK's
`gen_ai.response.text` under that name. It uses
`@cf/meta/llama-3.2-1b-instruct` with `max_tokens: 5` to keep the
Workers AI cost of each run small.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Invocations longer than 300 seconds can hit fetch's headers timeout and
leave the Lambda extension registered but no longer polling, hanging
subsequent invocations. Use timeout-free HTTP polling, with three
retries for transient connection errors after 100, 200, and 400
milliseconds. Successful polls reset the retry budget; HTTP errors and
exhausted retries log and exit so the environment cannot remain silently
stuck.

Based on @LuccaRebelloToledo's diagnosis and initial fix in #24219.
Verified with the Node 22 Lambda emulator: after a 310-second
invocation, the baseline's next invocation hangs while the patched
version returns in 0.14 seconds. The built extension also recovers from
injected connection resets and exits after exhausting consecutive
retries.

Fixes #24218

---------

Co-authored-by: LuccaRebelloToledo <luccarebtoledo@gmail.com>
Co-authored-by: OpenAI GPT-6 <codex@openai.com>
Add the missing metrics exit on flush in Deno similar to
#24806.

---------

Co-authored-by: GPT-6 <codex@openai.com>
Credit @LuccaRebelloToledo in the unreleased changelog for the Lambda
polling diagnosis and original fix in #24219, incorporated in #24811.
The external-contributor workflow skips member-authored PRs and does not
inspect commit co-authors.

Co-authored-by: OpenAI GPT-6 <codex@openai.com>
The `replay.mutations` breadcrumb is created asynchronously — only once
rrweb's `MutationObserver` fires — whereas the incremental snapshots and
the `ui.click` breadcrumb are buffered synchronously on the click.
Because the test's `forceFlushReplay()` races the force-flush triggered
by `stop({ reason: 'mutationLimit' })`, those events can be split across
two separate replay envelopes.

The test waited for the *first* request containing snapshots and
asserted that single request held both `replay.mutations` and
`ui.click`. Whenever the mutation breadcrumb landed in the second flush,
that first request only carried `['ui.click']`, producing the CI flake.
The fix aggregates recording snapshots across requests via the existing
`collectReplayRequests` helper, resolving once the mutation breadcrumb
has arrived, so the assertions no longer depend on the flush split.
Since `ui.click` is always buffered before the async mutation
breadcrumb, it's guaranteed present in the aggregated set by then.

_Root cause_: flush-ordering race between the test's manual flush and
replay's stop-triggered force-flush.

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
…#24612)

Under `bun run` the SDK cannot inject diagnostics channels into
libraries (#23882), so a Bun app only gets framework, database and AI
spans when it is built with `@sentry/bun/plugin`. That path had no
integration coverage. The new `node-suites-bun-build` project bundles
each auto-instrumentation scenario with the plugin right before it
starts and runs it with `@sentry/bun`. Express, Fastify, Hapi, Koa,
Apollo, most AI suites and the Docker database suites now run on Bun.

`pg-native` and the CommonJS `postgresjs` tests are skipped on Bun: the
`libpq` addon needs a Node symbol that Bun does not have, and through
the `bun` export condition `require('postgres')` returns the ES module
namespace.

Closes #23889.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…HandleRequest (#24826)

## What

Adds a `getNonce` option to `createSentryHandleRequest` so apps can pass
a per-request CSP nonce to both `<ServerRouter>` and
`renderToPipeableStream`.

## Why

React Router needs the same fresh nonce in both places, and the helper
had no way to set it. Apps with a strict CSP had to copy the whole
handler.

Closes: #23445

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… test runner (#24176)

closes #24146

Adds the shared span assertion helpers `cloudflare-integration-tests` is
missing, so the ~80 suites still pinned to `traceLifecycle: 'static'`
can be ported without each one hand-rolling its own
`getSpanContainer(envelope)`. Three copies of that function exist in the
package today.

The new helpers are inspired by the E2E tests:
- `collectStreamedSpans`
- `collectStreamedSpansUntilSegment`

We don't need `waitForStreamedSpan` as given in the ticket, as we
already have the `.expect`

### Renamed tests

- `public-api/startSpan-streamed` is renamed to `public-api/startSpan`
- `tracing/ignoreSpans-streamed` to `tracing/ignoreSpans`

Both are ported onto the helpers so the shape is proven before the bulk
work starts.

### Per-runner teardown

A runner now tears down its own worker and its own mock server when it
settles, instead of running the shared `cleanupChildProcesses`. A suite
that asserts only on streamed spans never calls `completed()`, so its
runner settles from the abort signal after its own test has ended. The
shared cleanup would then kill the worker the next test had already
started, and leaving the mock server open would keep one server per
scenario listening for the whole run. The ported suites failed
intermittently in large runs until both halves of this were fixed. The
process-exit cleanup still covers every runner.

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This PR ports the `suites/tracing` suites of
`cloudflare-integration-tests` to span streaming. It removes the
`traceLifecycle: 'static'` pin from each suite, and rewrites the
assertions from transaction envelopes to span v2. 23 suites, 38 tests.
The twelve `tracing/propagation` suites are in the PR stacked on this
one.

`tracing/d1` also loses its env-gated `STREAMED` switch and the static
copy of its test, so one test now covers the streamed behaviour.

### What the runs showed

Three behaviours shaped the rewrite, and each one is worth knowing
before the next package is ported.

A `url` source segment span keeps the method only. `GET /error` becomes
`GET`. Those suites now assert `GET` and read the route from the
`url.path` attribute. Suites on a `route` source, such as `/`, keep the
full `GET /` name.

The segment span can arrive in a later envelope than its children,
because it ends last. `opentelemetry-tracer/internal-request-handler`
failed on exactly that, and now uses `collectStreamedSpansUntilSegment`.

Start timestamps tie at millisecond resolution in workerd, so an
order-based assertion over child spans is unreliable.
`opentelemetry-tracer/enabled` matches spans by name instead of sorting
them.

### Two shapes for multi-isolate traces

A worker and a Durable Object each stream their own envelope for the
same trace. A suite therefore has to choose how to read them.

`instrument-fetcher` and the Durable Object storage suites use
`collectStreamedSpans`, which groups by trace and resolves once the
whole trace is in hand. These are the first callers of the helper added
in the base PR. They also exercise the observe-not-consume behaviour,
because `durableobject-sql` and `durableobject-sync-kv` collect spans
while a flush-marker error envelope still matches an ordered
expectation.

The other suites keep one envelope expectation per isolate with
`.unordered()`, which stays closer to the shape they already had and
keeps the diff readable.

Part of #24147

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ng (#24185)

closes #24147

This PR is the same as #24179, just for the `/propagation` entry. The
sole purpose is to reduce the size of the PR

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ng (#24189)

Ports the seventeen `suites/vite-autoinstrument` suites off the
`traceLifecycle: 'static'` pin.

Under streaming a whole request chain is one trace, so each suite reads
the trace with `collectStreamedSpans` instead of one envelope
expectation per hop. Every hop here (a Durable Object, a
`WorkerEntrypoint`, a Workflow step) runs in its own isolate and streams
its own envelope, so a single-envelope read would be a race.

The proof of instrumentation is unchanged, only its shape is: a Durable
Object still shows the `durable_object_storage_get` /
`durable_object_storage_put` pair, now as children of its own segment
span rather than as `spans` of its transaction. The chain is asserted
directly, a hop's segment span carries the previous hop's `span_id` as
its `parent_span_id`, which is stronger than the disjointness the old
unordered expectations relied on.

Every route in these suites is a raw URL, so the streamed segment name
keeps the method only. `GET /greet` becomes `GET`, and the hop is
identified through its `url.path` attribute. That matters for the
entrypoint and combination suites, where the transaction name used to
tell the hops apart.

The per-suite `expectDurableObjectTransaction`,
`expectMainWorkerTransaction` and `expectPlainTransaction` helpers are
gone. The assertions are inlined, and the suites that hit two endpoints
loop over the two paths.

Part of #24148

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ports the binding suites off the `traceLifecycle: 'static'` pin: `d1`,
`r2`, `queue`, `prisma`, `durableobject/error`, `workflows/step-context`
and `vite/diagnostics-channel/vercelai-6`.

`durableobject/error` and `workflows/step-context` only assert on error
events, so the pin is all that goes. `cache-client` and
`durableobject-scope` were already unpinned and keep ignoring spans, so
they are untouched.

Most binding spans keep the shape they had and only the encoding
changes, so the r2 and queue suites keep one envelope expectation per
request. Two things do change.

D1 and Prisma spans carry the `db.query` op, so streaming names them
after `db.query.summary`: `SELECT * FROM users WHERE id = ?` becomes
`SELECT users`. The Prisma suite loses the description-based split
between its two `SELECT` spans, which now share the name `SELECT
main.User`. The D1 one is picked by its op instead, and the traceparent
comment that used to be matched on the description is asserted on
`db.query.text`.

`prisma` and `vercelai-6` switch to `collectStreamedSpansUntilSegment`.
Both assert on the complete child set of one request and the span buffer
flushes on a timer, so reading a single envelope would be a race.
`vercelai-6` also drops the separate span container it used to read next
to the transaction item: a streamed gen_ai span is an ordinary item of
the one span envelope.

`/` keeps its `GET /` name under streaming (the source is `route`, not
`url`), so `vercelai-6` waits on that rather than the bare method the
raw-URL suites see.

Part of #24148

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…eaming (#24195)

Removes the `traceLifecycle: 'static'` pin from the five
`suites/integrations/http-server*` suites.

Nothing else changes. These suites cover request body capture, so they
assert on the event the worker sends and never on a transaction. None of
them sets `tracesSampleRate` either, so the pin only ever selected a
trace lifecycle for a client that emits no spans in the first place.

Part of #24148

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…24196)

Ports the remaining request handler suites off the `traceLifecycle:
'static'` pin: `hono-sdk`, `double-instrumentation` and
`public-api/metrics/server-address`.

`double-instrumentation` and the metrics suite assert on an error event
and on a metric envelope, so only the pin goes. `double-instrumentation`
swaps its `ignore('transaction')` for `ignore('span')`, which is the
envelope the `http.server` span now races the error event with.

The Hono routes are parametrized patterns, so their segment names
survive streaming unchanged. What does change is the status: span v2
carries the coarse `error` on the span and the specific `internal_error`
in the `sentry.status.message` attribute.

## Static trace lifecycle guard

`suites/basic` keeps the static pin as the package's guard. It is the
smallest suite that still covers a plain worker fetch, so it is the
cheapest one to keep on the old lifecycle.

## Suite left behind

`suites/request-handler/subpath` also stays pinned, but not by choice.
With the pin removed, `wrapRequestHandler` from
`@sentry/cloudflare/request` still sends a transaction envelope. That
holds with `traceLifecycle: 'stream'` passed explicitly and with
`cacheClient: false`, and the transaction's own
`sentry.sdk.integrations` lists `SpanStreaming` — so the client the
event is processed by does have streaming on, while `getClient()` inside
`_onSpanEnded` does not see a streaming client and falls through to
`_convertSpanToTransaction`. Every other entry point in the package
streams, and they differ only in which default integration set they
inject, so this looks like a gap in the `/request` entry rather than a
test problem. It is tracked separately and the suite is left as it was.

Fixes #24148

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
#24819)

Adds some tests for low-cardinality span names for cache spans. We
already sent low-cardinality span names but we didn't have explicit
tests so far.
Since these are both pre v1 we need to keep them up-to-date!
Node and Bun have not included `dedupeIntegration` in their default
integrations since v5, while the browser, Deno, Vercel Edge and
Cloudflare SDKs do. Add it to the Node and Bun defaults (we also claim
that in our docs)

`anrIntegration` collects contexts by running a placeholder event
through all event processors on every worker start. On a restart, Dedupe
dropped that event and ANR events lost their contexts. Skip the Dedupe
processor there.

Tests that trigger the same server error in consecutive requests now
remove Dedupe, because only the first of these events would be sent.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Skips injecting meta tags during the app build phase. Detected via a new
Vite plugin that injects an env var during build and removes it again
once the build is done.

Closes #15267

---------

Co-authored-by: Lukas Stracke <lukas.stracke@sentry.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
javascript-sdk-gitflow Bot and others added 13 commits October 1, 2026 08:09
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #24854

Co-authored-by: nicohrubec <29484629+nicohrubec@users.noreply.github.com>
)

Patches `createRouter` through orchestrion to prepend a Sentry
middleware to every router. The middleware opens no span: Remix 3 serves
over `node:http`, so `httpIntegration` has already opened the
`http.server` span. It only enriches that span with `http.route`, the
response status and a low cardinality name.

The SDK supplies the router's matcher, because the router never exposes
one and the request context carries no pattern at middleware entry. The
route is resolved by re-running the match against that matcher.

Remix 3 has no build step, so no bundler plugin can apply the transform.
The `--import @sentry/remix/v3/node` entry registers the module hook and
subscribes before the app's own modules are imported, and replaces
`--import remix/node-tsx` rather than adding a second flag.

Error handling is a separate pull request.


Fixes #24663

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
…24783)

OpenAI's `chat.completions.parse()` / `response.parse()` helpers could
fail because instrumentation triggered an extra response body read. Use
synchronous instrumentation and observe OpenAI's internal parser to
preserve lazy parsing while still recording spans.

Fixes #24773.

---------

Co-authored-by: GPT-6 <codex@openai.com>
Anthropic automatic instrumentation could consume response bodies before
callers read them through `.asResponse()`. Share OpenAI's lazy response
observer to preserve raw bodies while still completing request and
streaming spans.

Stacked on #24783. Addresses the Anthropic portion of
[JS-3856](https://linear.app/getsentry/issue/JS-3856).

---------

Co-authored-by: GPT-6 <codex@openai.com>
…4906)

Groq and Together automatic instrumentation could consume
`.asResponse()` bodies before application code read them. Reuse the
shared API-promise observer to preserve raw chat, streaming, and
embeddings responses while completing their spans.

Stacked on #24902. Part of #24882.

Co-authored-by: GPT-6 <codex@openai.com>
…sponses (#24908)

OpenAI embeddings and conversations still used eager promise
instrumentation, which consumed `.asResponse()` bodies before callers
could read them. Switch these remaining methods to synchronous
instrumentation so the shared API-promise observer preserves lazy
parsing and completes their spans.

Stacked on #24906. Fixes #24882 together with the preceding PRs.

Co-authored-by: GPT-6 <codex@openai.com>
Bumps [axios](https://github.com/axios/axios) from 1.18.0 to 1.20.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/releases">axios's
releases</a>.</em></p>
<blockquote>
<h2>v1.20.0 — August 19, 2026</h2>
<p>This release hardens runtime option handling, adds RFC 9110
status-code aliases, fixes Node.js and XHR reliability issues, and
refreshes project tooling and documentation.</p>
<h2>⚠️ Breaking Changes &amp; Deprecations</h2>
<ul>
<li>HTTP Status Naming: Added ContentTooLarge (413) and
UnprocessableContent (422), while retaining PayloadTooLarge and
UnprocessableEntity as backward-compatible deprecated aliases. (<a
href="https://redirect.github.com/axios/axios/issues/11082">#11082</a>)</li>
</ul>
<h2>🔒 Security Fixes</h2>
<ul>
<li>Runtime Option Handling: Hardened behavioral configuration reads
against shared and foreign prototype pollution and normalized unsafe
interceptor replacement objects. This also clarifies Fetch redirect and
custom implementation behavior, HTTP/2 DNS and proxy handling,
CIDR-based NO_PROXY matching, and malformed data URI rejection; see the
PR for documented compatibility effects. (<a
href="https://redirect.github.com/axios/axios/issues/11141">#11141</a>)</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li>Interceptor Lifecycle: Prevented unbounded handler-array growth by
trimming trailing ejected interceptors without changing iteration
semantics, and kept interceptor operations safe when the public handlers
field is nullish. (<a
href="https://redirect.github.com/axios/axios/issues/11087">#11087</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li>
<li>Request Error Preservation: Prevented custom Error.prepareStackTrace
implementations that return non-string values from replacing the
original request failure with an unrelated TypeError. (<a
href="https://redirect.github.com/axios/axios/issues/11109">#11109</a>)</li>
<li>XHR Reliability: Navigation-canceled requests now reject with
ECONNABORTED instead of resolving with status 0, while successful
downloads flush their final progress callback during the live loadend
dispatch. (<a
href="https://redirect.github.com/axios/axios/issues/11094">#11094</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li>
<li>Node.js Socket Memory: Removed request-context retention from
per-socket error listeners, preventing completed response data from
being pinned for the lifetime of pooled keep-alive sockets. (<a
href="https://redirect.github.com/axios/axios/issues/11091">#11091</a>)</li>
<li>Core Methods and HTTP Errors: Prevented structural method-header
buckets from leaking into outgoing headers, standardized invalid DNS
lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and
corrected the timeoutErrorMessage merge strategy. (<a
href="https://redirect.github.com/axios/axios/issues/11096">#11096</a>)</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>Dependencies: Updated fast-uri, postcss, js-yaml, mocha,
development-tooling groups, and GitHub Actions dependencies. (<a
href="https://redirect.github.com/axios/axios/issues/11092">#11092</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11098">#11098</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11099">#11099</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11106">#11106</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11107">#11107</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11122">#11122</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11123">#11123</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11126">#11126</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11127">#11127</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11133">#11133</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11140">#11140</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11143">#11143</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11144">#11144</a>)</li>
<li>Documentation: Applied the v1.19.0 documentation updates, added the
missing fs import to the README stream example, introduced localized
global search, and repaired the interceptor test link. (<a
href="https://redirect.github.com/axios/axios/issues/11101">#11101</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11113">#11113</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11097">#11097</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11119">#11119</a>)</li>
<li>Sponsorship: Updated sponsorship links and data and added
ScrapingBee as a sponsor. (<a
href="https://redirect.github.com/axios/axios/issues/11124">#11124</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11136">#11136</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11137">#11137</a>)</li>
<li>CI and Release: Switched ESM smoke tests to locked dependencies and
synchronized package and runtime version metadata for v1.20.0. (<a
href="https://redirect.github.com/axios/axios/issues/11128">#11128</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11152">#11152</a>)</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve axios:</p>
<ul>
<li><a href="https://github.com/yens1"><code>@​yens1</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11109">#11109</a>)</li>
<li><a
href="https://github.com/Sasireddy001"><code>@​Sasireddy001</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11113">#11113</a>)</li>
<li><a
href="https://github.com/ari-token-security"><code>@​ari-token-security</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11094">#11094</a>)</li>
<li><a
href="https://github.com/timothyokooboh"><code>@​timothyokooboh</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11097">#11097</a>)</li>
<li><a
href="https://github.com/gi9439041-png"><code>@​gi9439041-png</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11119">#11119</a>)</li>
<li><a
href="https://github.com/Hashim1999164"><code>@​Hashim1999164</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11082">#11082</a>)</li>
<li><a href="https://github.com/v-dev-cl"><code>@​v-dev-cl</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11091">#11091</a>)</li>
<li><a href="https://github.com/r0h1tb"><code>@​r0h1tb</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li>
<li><a href="https://github.com/ostapondo"><code>@​ostapondo</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li>
</ul>
<p>Full Changelog (<a
href="https://github.com/axios/axios/compare/v1.19.0...v1.20.0">https://github.com/axios/axios/compare/v1.19.0...v1.20.0</a>)</p>
<h2>v1.19.0 - July 22, 2026</h2>
<p>This release raises the form-data security floor, adds configuration
and type-system capabilities, and fixes NO_PROXY matching, interceptor
errors, progress reporting, and serialization edge cases.</p>
<h2>🔒 Security Fixes</h2>
<ul>
<li>Multipart Form Data: Raised the form-data dependency floor to
^4.0.6, preventing fresh installations from resolving versions affected
by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a
href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>).
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md">axios's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v1.19.0 — July 22, 2026</h2>
<p>This release raises the form-data security floor, adds configuration
and type-system capabilities, and fixes NO_PROXY matching, interceptor
errors, progress reporting, and serialization edge cases.</p>
<h2>🔒 Security Fixes</h2>
<ul>
<li>Multipart Form Data: Raised the form-data dependency floor to
^4.0.6, preventing fresh installations from resolving versions affected
by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a
href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>).
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
</ul>
<h2>🚀 New Features</h2>
<ul>
<li>Configuration Extensibility: Preserved own-enumerable symbol-keyed
fields through mergeConfig and added a generic params type across public
TypeScript declarations, responses, errors,
adapters, and serializers. (<a
href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11081">#11081</a>)</li>
<li>Header Parameter Parsing: Added the opt-in
AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP
parameter parsing while preserving legacy parsing behavior. (<a
href="https://redirect.github.com/axios/axios/issues/11051">#11051</a>)</li>
<li>HTTP Status Codes: Added the missing Cloudflare 520
WebServerReturnsAnUnknownError status and matching ESM/CJS declarations.
(<a
href="https://redirect.github.com/axios/axios/issues/11067">#11067</a>)</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li>
<p>Form Data Conversion: Limited formDataToJSON path splitting to dot
and bracket notation, preserving literal punctuation in keys, and
removed browser-facing Buffer.from usage from toFormData to avoid
unnecessary polyfills. (<a
href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11018">#11018</a>)</p>
</li>
<li>
<p>Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal
forms during NO_PROXY matching and honored * entries within comma- or
space-separated bypass lists. (<a
href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11053">#11053</a>)</p>
</li>
<li>
<p>Cancellation: Propagated already-aborted input signals immediately
when composing abort signals. (<a
href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</p>
</li>
<li>
<p>Header Handling: Preserved empty first values for duplicate singleton
headers and made AxiosHeaders#getSetCookie() consistently return arrays
for present values. (<a
href="https://redirect.github.com/axios/axios/issues/11036">#11036</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11037">#11037</a>)</p>
</li>
<li>
<p>URL Handling: Included normalized, safely redacted offending URLs in
malformed-protocol errors and removed repeated trailing slashes when
combining base URLs. (<a
href="https://redirect.github.com/axios/axios/issues/11008">#11008</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11038">#11038</a>)</p>
</li>
<li>
<p>Progress Events: Clamped malformed negative progress values to zero
and ensured final Node.js download progress events are delivered before
streamed responses close. (<a
href="https://redirect.github.com/axios/axios/issues/11039">#11039</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11040">#11040</a>)</p>
</li>
<li>
<p>Error and JSON Serialization: Serialized Set values as arrays in
JSON-compatible snapshots and synthesized useful AxiosError messages
from otherwise-empty AggregateError instances. (<a
href="https://redirect.github.com/axios/axios/issues/11044">#11044</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11059">#11059</a>)</p>
</li>
<li>
<p>Content-Length Enforcement: Corrected base64 data: URL size
estimation so maxContentLength is enforced consistently by the HTTP and
Fetch adapters. (<a
href="https://redirect.github.com/axios/axios/issues/11061">#11061</a>)</p>
</li>
<li>
<p>Synchronous Interceptors: Prevented requests from being dispatched
after synchronous request interceptors fail unless their paired
rejection handler resolves successfully. (<a
href="https://redirect.github.com/axios/axios/issues/11071">#11071</a>)</p>
</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>Dependencies: Updated development and test tooling, the docs
fixture's Axios version, and GitHub Actions integrations including
Checkout, Setup Node, Setup Deno, and Zizmor. (<a
href="https://redirect.github.com/axios/axios/issues/11031">#11031</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11055">#11055</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11056">#11056</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11058">#11058</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11079">#11079</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11080">#11080</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11088">#11088</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11089">#11089</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11090">#11090</a>)</li>
<li>Build Outputs: Limited sourcemap generation to published minified
bundles, removing broken map references from non-minified builds. (<a
href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li>
<li>Form Data Internals: Centralized FormData header handling and made
the Node.js adapter tolerate getHeaders() returning undefined under the
content-only policy. (<a
href="https://redirect.github.com/axios/axios/issues/11062">#11062</a>)</li>
<li>Developer Experience: Ignored common local AI-tooling directories
and fixed a constant-reassignment crash when the development sandbox
serves its root path. (<a
href="https://redirect.github.com/axios/axios/issues/11032">#11032</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11073">#11073</a>)</li>
<li>Documentation: Updated sponsor information, clarified that baseURL
is not a path-security boundary, scoped provenance claims to attested
releases, and corrected the configuration-defaults documentation. (<a
href="https://redirect.github.com/axios/axios/issues/11041">#11041</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11068">#11068</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11076">#11076</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11078">#11078</a>)</li>
<li>Publishing: Simplified v1 publishing to use the npm version bundled
with Node.js 26 and updated package metadata for the 1.19.0 release. (<a
href="https://redirect.github.com/axios/axios/issues/11083">#11083</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11095">#11095</a>)</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve Axios:</p>
<ul>
<li><a
href="https://github.com/afonsojramos"><code>@​afonsojramos</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
<li><a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>)</li>
<li><a
href="https://github.com/yassertawfik4"><code>@​yassertawfik4</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11024">#11024</a>)</li>
<li><a
href="https://github.com/AnandSundar"><code>@​AnandSundar</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>)</li>
<li><a
href="https://github.com/lin-hongkuan"><code>@​lin-hongkuan</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</li>
<li><a
href="https://github.com/Wali007-lab"><code>@​Wali007-lab</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li>
<li><a href="https://github.com/magicdawn"><code>@​magicdawn</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/axios/axios/commit/84a9f3b9a4f3244b8c8e818f557d64c7b964fb25"><code>84a9f3b</code></a>
chore(release): prepare release 1.20.0 (<a
href="https://redirect.github.com/axios/axios/issues/11152">#11152</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/e6824eec5fcf9da467a9792724396badc490c469"><code>e6824ee</code></a>
fix: core methodList, HTTP adapter errors, and add tests (<a
href="https://redirect.github.com/axios/axios/issues/11096">#11096</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/d8a919fd81403d59058c0e9dbefc540407dee83f"><code>d8a919f</code></a>
fix(xhr): flush final progress during the live loadend dispatch (<a
href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/2d2a21af8a433089474a2149781799c93acbcf3c"><code>2d2a21a</code></a>
fix(interceptors): tolerate nullish handlers in syncHandlerEntries (<a
href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"><code>d19040b</code></a>
fix: harden runtime option handling (<a
href="https://redirect.github.com/axios/axios/issues/11141">#11141</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/e0a02dd16671deabe2b809334d4c2ebede29a233"><code>e0a02dd</code></a>
chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the
github-...</li>
<li><a
href="https://github.com/axios/axios/commit/d10cb3aa3cda1d78721ddf96be590478df26cd81"><code>d10cb3a</code></a>
chore(deps-dev): bump the development_dependencies group with 4 updates
(<a
href="https://redirect.github.com/axios/axios/issues/11143">#11143</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/2c94646eb7cb7ab9dcb2aefdb04ab1b040c28e16"><code>2c94646</code></a>
chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (<a
href="https://redirect.github.com/axios/axios/issues/11133">#11133</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/76c12bce5a4fe9a45bef9a5bf2baaf599d7d382e"><code>76c12bc</code></a>
chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (<a
href="https://redirect.github.com/axios/axios/issues/11140">#11140</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/ba98559a7f5a18e531b5762387e5957bd281af3d"><code>ba98559</code></a>
docs: add ScrapingBee sponsor (<a
href="https://redirect.github.com/axios/axios/issues/11137">#11137</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/axios/axios/compare/v1.18.0...v1.20.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=axios&package-manager=npm_and_yarn&previous-version=1.18.0&new-version=1.20.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/getsentry/sentry-javascript/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fastify](https://github.com/fastify/fastify) from 5.12.1 to
5.12.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fastify/fastify/releases">fastify's
releases</a>.</em></p>
<blockquote>
<h2>v5.12.5</h2>
<h2>⚠️ Security release</h2>
<ul>
<li>Fix for <a
href="https://github.com/fastify/fastify/security/advisories/GHSA-4mh8-r7rc-xpvc">https://github.com/fastify/fastify/security/advisories/GHSA-4mh8-r7rc-xpvc</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>[Backport 5.x] perf: reduce content-type parser overhead by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/fastify/fastify/pull/7019">fastify/fastify#7019</a></li>
<li>[Backport 5.x] perf: avoid redundant request-part reads during
validation by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/fastify/fastify/pull/7020">fastify/fastify#7020</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fastify/compare/v5.12.4...v5.12.5">https://github.com/fastify/fastify/compare/v5.12.4...v5.12.5</a></p>
<h2>v5.12.4</h2>
<p>Fixed the <code>fastify.js</code> version mismatch.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fastify/compare/v5.12.2...v5.12.4">https://github.com/fastify/fastify/compare/v5.12.2...v5.12.4</a></p>
<h2>v5.12.2</h2>
<h2>⚠️ Security release</h2>
<ul>
<li>Fix for <a
href="https://github.com/fastify/fastify/security/advisories/GHSA-9q9j-q6p8-xq58">https://github.com/fastify/fastify/security/advisories/GHSA-9q9j-q6p8-xq58</a></li>
<li>Fix for <a
href="https://github.com/fastify/fastify/security/advisories/GHSA-hwr6-493r-vm6h">https://github.com/fastify/fastify/security/advisories/GHSA-hwr6-493r-vm6h</a></li>
<li>Fix for <a
href="https://github.com/fastify/fastify/security/advisories/GHSA-p68q-wchp-6fh7">https://github.com/fastify/fastify/security/advisories/GHSA-p68q-wchp-6fh7</a></li>
<li>Fix for <a
href="https://github.com/fastify/fastify/security/advisories/GHSA-667r-xxjv-c9mm">https://github.com/fastify/fastify/security/advisories/GHSA-667r-xxjv-c9mm</a></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>[Backport 5.x] fix: callNotFound should run not-found preHandler
regardless of registration order by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/fastify/fastify/pull/6973">fastify/fastify#6973</a></li>
<li>[Backport 5.x] chore: npm ignore remaining agent files by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/fastify/fastify/pull/7003">fastify/fastify#7003</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fastify/compare/v5.12.1...v5.12.2">https://github.com/fastify/fastify/compare/v5.12.1...v5.12.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/fastify/fastify/commit/ba235fdcd9a83a4c7ccf793f7b2596a8f65389b6"><code>ba235fd</code></a>
Bumped v5.12.5</li>
<li><a
href="https://github.com/fastify/fastify/commit/ad06a4c3fe8a944a904f38068249b18b8f552e90"><code>ad06a4c</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/fastify/fastify/commit/7af0d7719d928cb7f24a074e831e83a819b4f626"><code>7af0d77</code></a>
[Backport 5.x] perf: avoid redundant request-part reads during
validation (<a
href="https://redirect.github.com/fastify/fastify/issues/7">#7</a>...</li>
<li><a
href="https://github.com/fastify/fastify/commit/990ebef15d54b87b531c40aaeb1fe6314797b8bb"><code>990ebef</code></a>
[Backport 5.x] perf: reduce content-type parser overhead (<a
href="https://redirect.github.com/fastify/fastify/issues/7019">#7019</a>)</li>
<li><a
href="https://github.com/fastify/fastify/commit/1690e350121afa6eedce8ada46ac07d1a423ce75"><code>1690e35</code></a>
Bumped v5.12.4</li>
<li><a
href="https://github.com/fastify/fastify/commit/1c991c40f9615e8d33f8004c8f8cbe35d4be7f4f"><code>1c991c4</code></a>
Bumped v5.12.3</li>
<li><a
href="https://github.com/fastify/fastify/commit/942a2be8704244db778f8db9a0bb4951b8825156"><code>942a2be</code></a>
Bumped v5.12.2</li>
<li><a
href="https://github.com/fastify/fastify/commit/853f6e2538e46e5aafe163f7deeb2866f3ef6841"><code>853f6e2</code></a>
test(validation): cover normalization and async branches</li>
<li><a
href="https://github.com/fastify/fastify/commit/f02d8d4ab1ab208f10819c4dc213595b06497833"><code>f02d8d4</code></a>
fix(validation): do not unwrap async validator results</li>
<li><a
href="https://github.com/fastify/fastify/commit/93c239a380f3f2778bb7565fcdf777e91cfe1fbc"><code>93c239a</code></a>
fix: reject malformed URLs before custom 404 handlers</li>
<li>Additional commits viewable in <a
href="https://github.com/fastify/fastify/compare/v5.12.1...v5.12.5">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fastify&package-manager=npm_and_yarn&previous-version=5.12.1&new-version=5.12.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/getsentry/sentry-javascript/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Forgot to push an e2e test in #24777 for Sveltekit 2. Since the added
plugin there has different logic for Kit 2 and 3 I think we should still
add this test for Kit 2. There is an e2e test for Kit 2 in static mode
but once we get rid of transactions, this test might be removed. so
can't hurt to add it here.
Bumps [hono](https://github.com/honojs/hono) from 4.13.5 to 4.13.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/honojs/hono/releases">hono's
releases</a>.</em></p>
<blockquote>
<h2>v4.13.7</h2>
<h2>Security fixes</h2>
<p>This release includes a fix for the following security issue:</p>
<h3><code>hono/jsx</code> renders plain strings unescaped in boundary
components, leading to XSS</h3>
<p>Affects: <code>Suspense</code>, <code>ErrorBoundary</code>, and
<code>Context.Provider</code> in <code>hono/jsx</code>, and
<code>renderToString()</code> / <code>renderToReadableStream()</code> in
<code>hono/jsx/dom/server</code>. Fixes missing HTML escaping for a
plain string placed directly as a child or <code>fallback</code> of
these components, or as the root value of the server rendering
functions, so untrusted strings could be emitted as markup.
GHSA-hxh3-vqpv-xpqv</p>
<hr />
<p>Users who render untrusted strings inside <code>Suspense</code>,
<code>ErrorBoundary</code>, or <code>Context.Provider</code>, or pass
them directly to <code>hono/jsx/dom/server</code>, are strongly
encouraged to upgrade to this version.</p>
<h2>v4.13.6</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(client): keep a param value of &quot;index&quot; in $url() and
$path() in <a
href="https://redirect.github.com/honojs/hono/pull/5297">honojs/hono#5297</a></li>
<li>fix(client): normalize root WebSocket URLs in <a
href="https://redirect.github.com/honojs/hono/pull/5291">honojs/hono#5291</a></li>
<li>fix(types): allow symbol keys in Context<!-- raw HTML omitted -->
get and set fallbacks in <a
href="https://redirect.github.com/honojs/hono/pull/5300">honojs/hono#5300</a></li>
<li>chore: bump <code>editorconfig-checker</code> in <a
href="https://redirect.github.com/honojs/hono/pull/5336">honojs/hono#5336</a></li>
<li>refactor(on-handler): use forEach for consistent handler iteration
in <a
href="https://redirect.github.com/honojs/hono/pull/5326">honojs/hono#5326</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/honojs/hono/compare/v4.13.5...v4.13.6">https://github.com/honojs/hono/compare/v4.13.5...v4.13.6</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/honojs/hono/commit/eebdf7be39abf0a872671835ccce0c4f03ea497a"><code>eebdf7b</code></a>
4.13.7</li>
<li><a
href="https://github.com/honojs/hono/commit/2b8ed402cdab6dfc5e829b480806dcd8db94161e"><code>2b8ed40</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/cac0c4d3fe29aca4e426031067cbbb3b9131e30c"><code>cac0c4d</code></a>
4.13.6</li>
<li><a
href="https://github.com/honojs/hono/commit/dac5d5794c6134711e469c5e69d09cd6274e1fc1"><code>dac5d57</code></a>
refactor(on-handler): use forEach for consistent handler iteration (<a
href="https://redirect.github.com/honojs/hono/issues/5326">#5326</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/ec648d683768ec5093315e5dc694c05594fec185"><code>ec648d6</code></a>
chore: bump <code>editorconfig-checker</code> (<a
href="https://redirect.github.com/honojs/hono/issues/5336">#5336</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/e2740d5a1bd0b4254e517e3af8b60789284bc7bd"><code>e2740d5</code></a>
fix(types): allow symbol keys in Context&lt;any&gt; get and set
fallbacks (<a
href="https://redirect.github.com/honojs/hono/issues/5300">#5300</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/499c35ebda35777fd35a7dd1906dd4f2687da61e"><code>499c35e</code></a>
fix(client): normalize root WebSocket URLs (<a
href="https://redirect.github.com/honojs/hono/issues/5291">#5291</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/50b8788cf54cb60112b7cd93642bc5094901475c"><code>50b8788</code></a>
fix(client): keep a param value of &quot;index&quot; in $url() and
$path() (<a
href="https://redirect.github.com/honojs/hono/issues/5297">#5297</a>)</li>
<li>See full diff in <a
href="https://github.com/honojs/hono/compare/v4.13.5...v4.13.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=hono&package-manager=npm_and_yarn&previous-version=4.13.5&new-version=4.13.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/getsentry/sentry-javascript/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [moment](https://github.com/moment/moment) from 2.30.1 to 2.31.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/moment/moment/releases">moment's
releases</a>.</em></p>
<blockquote>
<h2>2.31.0</h2>
<p><em>Released Sep 14, 2026</em></p>
<h4>Security fixes</h4>
<ul>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-17495">CVE-2026-17495</a>
(<a
href="https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw">GHSA-4p3w-j4w9-5jqw</a>)</li>
</ul>
<h4>Bug fixes</h4>
<ul>
<li><a
href="https://redirect.github.com/moment/moment/pull/6376">#6376</a>
Prevent object prototype properties from being used as format
tokens</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6386">#6386</a>
Normalize lazy-loaded locale names</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6404">#6404</a> Fix
parsing issue with <code>eHHmm</code> format</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6433">#6433</a>
Ignore non-Moment arguments in min and max</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6434">#6434</a> Fix
inherited lowercase long date formats</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6436">#6436</a>
Reset locale parsing caches after updates</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6437">#6437</a> Fix
weekday mismatch when the format only has part of a date</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6442">#6442</a> Fix
<code>locale('__proto__')</code> corrupting the global locale</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6443">#6443</a>
Avoid <code>Object.assign</code> in <code>duration.humanize</code></li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6446">#6446</a>
Validate range when parsing a time zone offset</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6447">#6447</a>
Include metadata in all-locales bundle</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6448">#6448</a>
Apply postformat to locale relative time methods</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6450">#6450</a> Add
stack traces to conditional deprecation warnings</li>
</ul>
<h4>New features</h4>
<ul>
<li><a
href="https://redirect.github.com/moment/moment/pull/6451">#6451</a> Add
internal date-default hook for Moment Timezone</li>
</ul>
<h5>New locales</h5>
<ul>
<li><a
href="https://redirect.github.com/moment/moment/pull/6000">#6000</a>:
Pashto ('ps')</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6278">#6278</a>, <a
href="https://redirect.github.com/moment/moment/pull/6379">#6379</a>:
Amharic (Ethiopia) ('am-et')</li>
</ul>
<h4>Updates to existing locales</h4>
<ul>
<li><a
href="https://redirect.github.com/moment/moment/pull/5404">#5404</a>
Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6197">#6197</a>
Indonesian ('id'): Correct the abbreviation for August</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6217">#6217</a>
Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct <code>L</code>
date formats</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6289">#6289</a>
Swedish ('sv'): Correct the abbreviation for Thursday</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6306">#6306</a>
Catalan ('ca'): Use typographic apostrophes in relative time</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6347">#6347</a>
Swahili ('sw'): Correct the spelling of hour in calendar output</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6360">#6360</a>
Ukrainian ('uk'): Use ISO week numbering</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6370">#6370</a>
Ukrainian ('uk'): Use U+02BC apostrophes in Friday names</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6371">#6371</a>
Hungarian ('hu'): Preserve numeric values in relative seconds</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6391">#6391</a>
Swahili ('sw'): Fix weekday and relative-time grammar</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6396">#6396</a>
German ('de', 'de-at', 'de-ch'): Parse short months without trailing
dots</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6409">#6409</a>
Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6410">#6410</a>
Polish ('pl'): Use genitive month names in dotted day formats</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/moment/moment/blob/develop/CHANGELOG.md">moment's
changelog</a>.</em></p>
<blockquote>
<h3>2.31.0</h3>
<p><em>Released Sep 14, 2026</em></p>
<h4>Security fixes</h4>
<ul>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-17495">CVE-2026-17495</a>
(<a
href="https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw">GHSA-4p3w-j4w9-5jqw</a>)</li>
</ul>
<h4>Bug fixes</h4>
<ul>
<li><a
href="https://redirect.github.com/moment/moment/pull/6376">#6376</a>
Prevent object prototype properties from being used as format
tokens</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6386">#6386</a>
Normalize lazy-loaded locale names</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6404">#6404</a> Fix
parsing issue with <code>eHHmm</code> format</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6433">#6433</a>
Ignore non-Moment arguments in min and max</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6434">#6434</a> Fix
inherited lowercase long date formats</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6436">#6436</a>
Reset locale parsing caches after updates</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6437">#6437</a> Fix
weekday mismatch when the format only has part of a date</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6442">#6442</a> Fix
<code>locale('__proto__')</code> corrupting the global locale</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6443">#6443</a>
Avoid <code>Object.assign</code> in <code>duration.humanize</code></li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6446">#6446</a>
Validate range when parsing a time zone offset</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6447">#6447</a>
Include metadata in all-locales bundle</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6448">#6448</a>
Apply postformat to locale relative time methods</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6450">#6450</a> Add
stack traces to conditional deprecation warnings</li>
</ul>
<h4>New features</h4>
<ul>
<li><a
href="https://redirect.github.com/moment/moment/pull/6451">#6451</a> Add
internal date-default hook for Moment Timezone</li>
</ul>
<h5>New locales</h5>
<ul>
<li><a
href="https://redirect.github.com/moment/moment/pull/6000">#6000</a>:
Pashto ('ps')</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6278">#6278</a>, <a
href="https://redirect.github.com/moment/moment/pull/6379">#6379</a>:
Amharic (Ethiopia) ('am-et')</li>
</ul>
<h4>Updates to existing locales</h4>
<ul>
<li><a
href="https://redirect.github.com/moment/moment/pull/5404">#5404</a>
Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6197">#6197</a>
Indonesian ('id'): Correct the abbreviation for August</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6217">#6217</a>
Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct <code>L</code>
date formats</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6289">#6289</a>
Swedish ('sv'): Correct the abbreviation for Thursday</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6306">#6306</a>
Catalan ('ca'): Use typographic apostrophes in relative time</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6347">#6347</a>
Swahili ('sw'): Correct the spelling of hour in calendar output</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6360">#6360</a>
Ukrainian ('uk'): Use ISO week numbering</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6370">#6370</a>
Ukrainian ('uk'): Use U+02BC apostrophes in Friday names</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6371">#6371</a>
Hungarian ('hu'): Preserve numeric values in relative seconds</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6391">#6391</a>
Swahili ('sw'): Fix weekday and relative-time grammar</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6396">#6396</a>
German ('de', 'de-at', 'de-ch'): Parse short months without trailing
dots</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6409">#6409</a>
Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting</li>
<li><a
href="https://redirect.github.com/moment/moment/pull/6410">#6410</a>
Polish ('pl'): Use genitive month names in dotted day formats</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/moment/moment/commit/15b45d48a176312e8f34143c5a800090abf4787f"><code>15b45d4</code></a>
[pkg] Build 2.31.0 (<a
href="https://redirect.github.com/moment/moment/issues/6452">#6452</a>)</li>
<li><a
href="https://github.com/moment/moment/commit/631cd81454ee001e1f508e21270eae0b6bb62974"><code>631cd81</code></a>
[pkg] Update changelog for upcoming release (<a
href="https://redirect.github.com/moment/moment/issues/6394">#6394</a>)</li>
<li><a
href="https://github.com/moment/moment/commit/6caff9e0d54e85a63a6eb97d7361f1da35bc58f4"><code>6caff9e</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/moment/moment/commit/710703b7eac93535ad125cbf4feb3d42afed6fb3"><code>710703b</code></a>
[feature] Add internal date-default hook for Moment Timezone (<a
href="https://redirect.github.com/moment/moment/issues/6451">#6451</a>)</li>
<li><a
href="https://github.com/moment/moment/commit/863ed940556e6e63c43de23981a4853036a003ac"><code>863ed94</code></a>
[bugfix] Add stack traces to conditional deprecation warnings (<a
href="https://redirect.github.com/moment/moment/issues/6450">#6450</a>)</li>
<li><a
href="https://github.com/moment/moment/commit/2c7abe1c42ee15445d30c2c5d536750a1e43a09a"><code>2c7abe1</code></a>
[bugfix] Apply postformat to locale relative time methods (<a
href="https://redirect.github.com/moment/moment/issues/6448">#6448</a>)</li>
<li><a
href="https://github.com/moment/moment/commit/9c45ac38690c649c95e19923276b63da5fe2be26"><code>9c45ac3</code></a>
[bugfix] Include metadata in all-locales bundle (<a
href="https://redirect.github.com/moment/moment/issues/6447">#6447</a>)</li>
<li><a
href="https://github.com/moment/moment/commit/f6eefc5fc7b44ceccbd007aeffc48ebc5eac30fa"><code>f6eefc5</code></a>
[bugfix] Validate timezone offset range (<a
href="https://redirect.github.com/moment/moment/issues/6446">#6446</a>)</li>
<li><a
href="https://github.com/moment/moment/commit/136b441794a3bb207d593add3b59e9de0e062523"><code>136b441</code></a>
[bugfix] Avoid Object.assign in duration.humanize (<a
href="https://redirect.github.com/moment/moment/issues/6443">#6443</a>)</li>
<li><a
href="https://github.com/moment/moment/commit/0d1050437b40f66ac47e14b285bb3d09676cf2e0"><code>0d10504</code></a>
[bugfix] Fix locale('<strong>proto</strong>') corrupting the global
locale (<a
href="https://redirect.github.com/moment/moment/issues/6442">#6442</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/moment/moment/compare/2.30.1...2.31.0">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for moment since your current version.</p>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary

Batched **runtime** dependency security fixes. One commit per
vulnerability.

### Fixes

- `brace-expansion` 1.1.18 → 1.1.21 — GHSA-q2hr-2g5m-vwhr /
CVE-2026-102277 (medium) —
https://github.com/getsentry/sentry-javascript/security/dependabot/2599

### Notes

`brace-expansion` is not a direct dependency anywhere in the monorepo —
the only vulnerable instance was the `brace-expansion@^1.1.7` lockfile
entry pulled in via `minimatch@3.x`. That range already permits the
patched `1.1.21`, so this is a **lockfile-only re-resolution**: no
`package.json` change and no `resolutions` override.

Re-resolving the lockfile also moved two non-vulnerable entries forward
within their existing semver ranges:

- `brace-expansion@^2.0.1, ^2.0.2`: 2.0.2 → 2.1.7
- `brace-expansion@^5.0.5`: 5.0.6 → 5.0.12

`yarn dedupe-deps:check` passes.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@JPeer264 JPeer264 self-assigned this Oct 1, 2026
@JPeer264
JPeer264 requested review from a team as code owners October 1, 2026 09:38
@JPeer264
JPeer264 requested review from isaacs, logaretm, mydea, nicohrubec and s1gr1d and removed request for a team October 1, 2026 09:38
Comment thread CHANGELOG.md
### Other Changes

- chore(bundler-plugins): Allow magic-string 1.x ([#24768](https://github.com/getsentry/sentry-javascript/pull/24768))
- feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 ([#24823](https://github.com/getsentry/sentry-javascript/pull/24823))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

internal?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really, it is dependencies which were bumped

Comment thread CHANGELOG.md
- fix(solidstart): Support `rolldownOptions` in instrumentation file plugin ([#24863](https://github.com/getsentry/sentry-javascript/pull/24863))
- fix(sveltekit): Skip trace meta tags when prerendering ([#24777](https://github.com/getsentry/sentry-javascript/pull/24777))
- fix(vue): Share one root render span debounce timer across components ([#24868](https://github.com/getsentry/sentry-javascript/pull/24868))
- perf(server-utils): Avoid quadratic SQL sanitizer output handling ([#24834](https://github.com/getsentry/sentry-javascript/pull/24834))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

internal?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

server-utils per se is internal, but the changes hit a public surface. I'm always in between putting server-utils being internal and public. I still like to keep this one here

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

⚠️ Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

Path Size % Change Change
@sentry/browser 29.36 kB +0.43% +125 B 🔺
@sentry/browser - with treeshaking flags 27.65 kB +0.52% +143 B 🔺
@sentry/browser - with treeshaking flags tracing without tracing 27.54 kB +0.52% +141 B 🔺
@sentry/browser (incl. Tracing) 51.3 kB +0.3% +152 B 🔺
@sentry/browser (incl. Tracing + Span Streaming) 51.32 kB +0.29% +144 B 🔺
@sentry/browser (incl. Tracing, Profiling) 54.31 kB +0.25% +132 B 🔺
@sentry/browser (incl. Tracing, Replay) 90.89 kB +0.15% +128 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 79.99 kB +0.17% +134 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas) 95.58 kB +0.13% +121 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback) 108.57 kB +0.15% +154 B 🔺
@sentry/browser (incl. Feedback) 46.88 kB +0.26% +120 B 🔺
@sentry/browser (incl. sendFeedback) 34.43 kB +0.38% +128 B 🔺
@sentry/browser (incl. FeedbackAsync) 39.54 kB +0.33% +128 B 🔺
@sentry/browser (incl. Metrics) 30.38 kB +0.42% +126 B 🔺
@sentry/browser (incl. Logs) 30.66 kB +0.5% +150 B 🔺
@sentry/browser (incl. Metrics & Logs) 31.33 kB +0.49% +150 B 🔺
@sentry/react 31.2 kB +0.37% +115 B 🔺
@sentry/react (incl. Tracing) 53.67 kB +0.25% +133 B 🔺
@sentry/vue 36.9 kB +0.45% +164 B 🔺
@sentry/vue (incl. Tracing) 53.88 kB +0.34% +182 B 🔺
@sentry/svelte 29.39 kB +0.46% +133 B 🔺
CDN Bundle 31.18 kB +0.53% +163 B 🔺
CDN Bundle (incl. Tracing) 51.95 kB +0.34% +172 B 🔺
CDN Bundle (incl. Logs, Metrics) 33.43 kB +0.43% +141 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) 53.89 kB +0.27% +140 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) 74.16 kB +0.21% +153 B 🔺
CDN Bundle (incl. Tracing, Replay) 89.52 kB +0.18% +157 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 91.5 kB +0.18% +163 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) 95.7 kB +0.18% +166 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 97.67 kB +0.19% +177 B 🔺
CDN Bundle - uncompressed 92.05 kB +0.43% +386 B 🔺
CDN Bundle (incl. Tracing) - uncompressed 154.44 kB +0.27% +404 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed 98.62 kB +0.4% +386 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 160.39 kB +0.26% +404 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 228.19 kB +0.17% +386 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed 274.17 kB +0.15% +404 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 280.1 kB +0.15% +404 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 287.87 kB +0.15% +404 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 293.8 kB +0.14% +404 B 🔺
@sentry/nextjs (client) 55.91 kB +0.24% +129 B 🔺
@sentry/sveltekit (client) 51.74 kB +0.28% +141 B 🔺
@sentry/core/server 39.99 kB +0.01% +2 B 🔺
@sentry/core/browser 13.63 kB - -
@sentry/node 144.32 kB +1.73% +2.45 kB 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection) 83.01 kB +0.16% +132 B 🔺
@sentry/node - without tracing 92.96 kB +2.29% +2.07 kB 🔺
@sentry/node - without channel injection 122.66 kB +2.01% +2.41 kB 🔺
@sentry/aws-serverless 101.25 kB +2.14% +2.12 kB 🔺
@sentry/cloudflare (withSentry) - minified 206.69 kB +0.04% +77 B 🔺
@sentry/cloudflare (withSentry) 514.13 kB +0.03% +116 B 🔺

View base workflow run

Comment on lines +49 to +59
function wrapRawResponse(apiPromise: ApiPromise): void {
apiPromise.asResponse = new Proxy(apiPromise.asResponse, {
apply(original, thisArg, args): Promise<Response> {
return (Reflect.apply(original, thisArg, args) as Promise<Response>).then(response => {
if (!parsing) {
onResponse(undefined);
}
return response;
});
},
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Calling .asResponse() on an Anthropic APIPromise results in missing response attributes on the final instrumentation span because the onResponse callback receives an undefined result.
Severity: MEDIUM

Suggested Fix

Modify the logic to ensure that the onResponse callback receives the parsed response data, not undefined, when .asResponse() is used. This might involve adjusting the proxy's .then handler in apiPromise.ts to wait for the response to be parsed before ending the span, ensuring that data.result is correctly populated.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: packages/server-utils/src/ai/core/apiPromise.ts#L49-L59

Potential issue: When a user calls `.asResponse()` on an `APIPromise` for an Anthropic
API call, the `onResponse` callback is invoked with `undefined`. This causes the
`data.result` to be `undefined` when `beforeSpanEnd` is called. As a result, the
`addResponseAttributes` function returns early, and the final instrumentation span is
missing critical response attributes such as `GEN_AI_RESPONSE_ID`,
`GEN_AI_RESPONSE_MODEL`, and token counts. This regression affects a documented and
tested usage pattern, leading to a loss of observability for these API calls.

Did we get this right? 👍 / 👎 to inform future reviews.

@JPeer264
JPeer264 merged commit 95153b1 into master Oct 1, 2026
679 of 681 checks passed
@JPeer264
JPeer264 deleted the prepare-release/11.2.0 branch October 1, 2026 09:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.