meta(changelog): Update changelog for 11.2.0 - #24927
Conversation
[Gitflow] Merge master into develop
Add the missing `beforeExit` flush for metrics, matching the existing behavior for logs and client reports. This ensures buffered metrics are sent when a Node process exits naturally, even if the timer or size threshold has not triggered a flush yet.
Nuxt fixed it in: nuxt/nuxt@7758942 Follow-up for this PR (just reverting the commit): #24788
Adds a dedicated Bun + Express E2E application covering automatic request tracing and error capture. The app exercises both a parameterized success route and an exception route, asserting Express handler spans, route naming, status propagation, the Bun runtime context, and trace correlation. The app is built with `sentryBunPlugin` because Express instrumentation under Bun relies on build-time diagnostics-channel injection. The SDK and Express remain external so the app validates the normal package boundary, while CI now installs its pinned Bun version for this matrix entry. The targeted `bun-express` E2E run passes both Playwright cases on Bun 1.3.14. `yarn format`, `yarn build:dev`, and `yarn build:tarball` also complete successfully. The full local lint and unit-suite runs still surface pre-existing environment/baseline failures outside the files changed here; CI will provide the authoritative full-suite result. Fixes #12732 Co-authored-by: OpenAI Codex <codex@openai.com>
fix(core): Stop LRUMap.set from evicting when updating an existing key
This PR adds the external contributor to the CHANGELOG.md file, so that they are credited for their contribution. See #24306 Co-authored-by: nicohrubec <29484629+nicohrubec@users.noreply.github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.4.0 to 10.7.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/beaugunderson/ip-address/releases">ip-address's releases</a>.</em></p> <blockquote> <h2>v10.7.2</h2> <h2>What's Changed</h2> <ul> <li>Accept an arpa suffix in any case and without the root dot in fromArpa by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/227">beaugunderson/ip-address#227</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.7.1...v10.7.2">https://github.com/beaugunderson/ip-address/compare/v10.7.1...v10.7.2</a></p> <h2>v10.7.1</h2> <h2>What's Changed</h2> <ul> <li>Bump js-yaml and brace-expansion in the lockfile by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/226">beaugunderson/ip-address#226</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.7.0...v10.7.1">https://github.com/beaugunderson/ip-address/compare/v10.7.0...v10.7.1</a></p> <h2>v10.7.0</h2> <h2>What's Changed</h2> <ul> <li>Add offset() and nextNetwork(), accept prefix-length ip6.arpa names, correct the IPv6 end-address docs by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/225">beaugunderson/ip-address#225</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.6.0...v10.7.0">https://github.com/beaugunderson/ip-address/compare/v10.6.0...v10.7.0</a></p> <h2>v10.6.0</h2> <h2>What's Changed</h2> <ul> <li>Add isGlobal() and pin the classifiers to the IANA special-purpose registries by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/224">beaugunderson/ip-address#224</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.5.1...v10.6.0">https://github.com/beaugunderson/ip-address/compare/v10.5.1...v10.6.0</a></p> <h2>v10.5.1</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.5.0...v10.5.1">https://github.com/beaugunderson/ip-address/compare/v10.5.0...v10.5.1</a></p> <h2>v10.5.0</h2> <h2>What's Changed</h2> <ul> <li>Honor the fromURL graceful-failure contract for non-IPv6 hosts by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/218">beaugunderson/ip-address#218</a></li> <li>Correct the documentation where it disagreed with the library by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/219">beaugunderson/ip-address#219</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.4.0...v10.5.0">https://github.com/beaugunderson/ip-address/compare/v10.4.0...v10.5.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/beaugunderson/ip-address/commit/974b48d9ade9348accdb377ba0a15feba4a11361"><code>974b48d</code></a> 10.7.2</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/4dfe8e5eb34fdb47698834b213526814234c0cb1"><code>4dfe8e5</code></a> Accept an arpa suffix in any case and without the root dot in fromArpa (<a href="https://redirect.github.com/beaugunderson/ip-address/issues/227">#227</a>)</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/f0c25dfd4fbf7886e45116ba0940207f81401e28"><code>f0c25df</code></a> 10.7.1</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5"><code>8b34a21</code></a> Merge commit from fork</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/13b615554f129bdcdbd10f39b5918fef4bcf96c5"><code>13b6155</code></a> Merge commit from fork</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134"><code>469ead1</code></a> Reject an address longer than the family allows before parsing it</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28"><code>1343629</code></a> Report an address of the other family as not contained</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/4c2184a0cbd8f913e15a64a2063afc9eef410bd2"><code>4c2184a</code></a> Bump js-yaml and brace-expansion in the lockfile (<a href="https://redirect.github.com/beaugunderson/ip-address/issues/226">#226</a>)</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/2b7cab51c7aec0cb56f820f192a38901614e5a9f"><code>2b7cab5</code></a> 10.7.0</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/87fae235d95ab0ce18665ae5690f98f65e882d6a"><code>87fae23</code></a> Add offset() and nextNetwork(), accept prefix-length ip6.arpa names, correct ...</li> <li>Additional commits viewable in <a href="https://github.com/beaugunderson/ip-address/compare/v10.4.0...v10.7.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/getsentry/sentry-javascript/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
The `reportPageLoaded` default tests flaked in CI with a pageload span duration of ~3.16s against a `< 3` upper bound. _Root cause:_ the pageload span starts at navigation start, but the 2.5s `setTimeout` before `Sentry.reportPageLoaded()` only begins once the test bundle has executed, so page load time on a slow runner is added on top. Bumping the upper bound to 4s gives enough headroom; the `idle_span_finish_reason: 'reportPageLoaded'` assertion already guarantees the span wasn't ended by a timeout. Applied to both the static and streamed variants. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… the sentry CLI (#24514) This is helpful for the stacked PR where we add a test for workers-ai Adds `fetchSpanAttributes(traceId, spanId)` to `@sentry-internal/test-utils/cli`, so send-to-sentry E2E tests can assert span attributes and not only the span op. `sentry trace view --json` looks like it returns span attributes, but it silently drops all of them for most spans: the trace-items endpoint sends `int` attribute values as strings, the CLI's schema (0.44.1 and 0.45.0) expects numbers, and a failed schema check only logs `Could not fetch details for span`. The helper calls the same endpoint through `sentry api`, which does no schema check. The spawn and credential handling moved into a shared runner so both helpers use the E2E token the same way. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
…y E2E test (#24515) closes #24759 Adds a Workers AI call to the real-Worker E2E app and checks that the `gen_ai.chat` span reaches Sentry with `gen_ai.input.messages` and `gen_ai.output.messages`. The unit and integration tests only see the envelope, so this is the first check that the Workers AI span and its attributes survive ingestion. The test expects `gen_ai.output.messages` and not `gen_ai.response.text`, because Sentry stores the SDK's `gen_ai.response.text` under that name. It uses `@cf/meta/llama-3.2-1b-instruct` with `max_tokens: 5` to keep the Workers AI cost of each run small. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Invocations longer than 300 seconds can hit fetch's headers timeout and leave the Lambda extension registered but no longer polling, hanging subsequent invocations. Use timeout-free HTTP polling, with three retries for transient connection errors after 100, 200, and 400 milliseconds. Successful polls reset the retry budget; HTTP errors and exhausted retries log and exit so the environment cannot remain silently stuck. Based on @LuccaRebelloToledo's diagnosis and initial fix in #24219. Verified with the Node 22 Lambda emulator: after a 310-second invocation, the baseline's next invocation hangs while the patched version returns in 0.14 seconds. The built extension also recovers from injected connection resets and exits after exhausting consecutive retries. Fixes #24218 --------- Co-authored-by: LuccaRebelloToledo <luccarebtoledo@gmail.com> Co-authored-by: OpenAI GPT-6 <codex@openai.com>
Add the missing metrics exit on flush in Deno similar to #24806. --------- Co-authored-by: GPT-6 <codex@openai.com>
Credit @LuccaRebelloToledo in the unreleased changelog for the Lambda polling diagnosis and original fix in #24219, incorporated in #24811. The external-contributor workflow skips member-authored PRs and does not inspect commit co-authors. Co-authored-by: OpenAI GPT-6 <codex@openai.com>
The `replay.mutations` breadcrumb is created asynchronously — only once
rrweb's `MutationObserver` fires — whereas the incremental snapshots and
the `ui.click` breadcrumb are buffered synchronously on the click.
Because the test's `forceFlushReplay()` races the force-flush triggered
by `stop({ reason: 'mutationLimit' })`, those events can be split across
two separate replay envelopes.
The test waited for the *first* request containing snapshots and
asserted that single request held both `replay.mutations` and
`ui.click`. Whenever the mutation breadcrumb landed in the second flush,
that first request only carried `['ui.click']`, producing the CI flake.
The fix aggregates recording snapshots across requests via the existing
`collectReplayRequests` helper, resolving once the mutation breadcrumb
has arrived, so the assertions no longer depend on the flush split.
Since `ui.click` is always buffered before the async mutation
breadcrumb, it's guaranteed present in the aggregated set by then.
_Root cause_: flush-ordering race between the test's manual flush and
replay's stop-triggered force-flush.
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
…#24612) Under `bun run` the SDK cannot inject diagnostics channels into libraries (#23882), so a Bun app only gets framework, database and AI spans when it is built with `@sentry/bun/plugin`. That path had no integration coverage. The new `node-suites-bun-build` project bundles each auto-instrumentation scenario with the plugin right before it starts and runs it with `@sentry/bun`. Express, Fastify, Hapi, Koa, Apollo, most AI suites and the Docker database suites now run on Bun. `pg-native` and the CommonJS `postgresjs` tests are skipped on Bun: the `libpq` addon needs a Node symbol that Bun does not have, and through the `bun` export condition `require('postgres')` returns the ES module namespace. Closes #23889. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…HandleRequest (#24826) ## What Adds a `getNonce` option to `createSentryHandleRequest` so apps can pass a per-request CSP nonce to both `<ServerRouter>` and `renderToPipeableStream`. ## Why React Router needs the same fresh nonce in both places, and the helper had no way to set it. Apps with a strict CSP had to copy the whole handler. Closes: #23445 --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… test runner (#24176) closes #24146 Adds the shared span assertion helpers `cloudflare-integration-tests` is missing, so the ~80 suites still pinned to `traceLifecycle: 'static'` can be ported without each one hand-rolling its own `getSpanContainer(envelope)`. Three copies of that function exist in the package today. The new helpers are inspired by the E2E tests: - `collectStreamedSpans` - `collectStreamedSpansUntilSegment` We don't need `waitForStreamedSpan` as given in the ticket, as we already have the `.expect` ### Renamed tests - `public-api/startSpan-streamed` is renamed to `public-api/startSpan` - `tracing/ignoreSpans-streamed` to `tracing/ignoreSpans` Both are ported onto the helpers so the shape is proven before the bulk work starts. ### Per-runner teardown A runner now tears down its own worker and its own mock server when it settles, instead of running the shared `cleanupChildProcesses`. A suite that asserts only on streamed spans never calls `completed()`, so its runner settles from the abort signal after its own test has ended. The shared cleanup would then kill the worker the next test had already started, and leaving the mock server open would keep one server per scenario listening for the whole run. The ported suites failed intermittently in large runs until both halves of this were fixed. The process-exit cleanup still covers every runner. --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This PR ports the `suites/tracing` suites of `cloudflare-integration-tests` to span streaming. It removes the `traceLifecycle: 'static'` pin from each suite, and rewrites the assertions from transaction envelopes to span v2. 23 suites, 38 tests. The twelve `tracing/propagation` suites are in the PR stacked on this one. `tracing/d1` also loses its env-gated `STREAMED` switch and the static copy of its test, so one test now covers the streamed behaviour. ### What the runs showed Three behaviours shaped the rewrite, and each one is worth knowing before the next package is ported. A `url` source segment span keeps the method only. `GET /error` becomes `GET`. Those suites now assert `GET` and read the route from the `url.path` attribute. Suites on a `route` source, such as `/`, keep the full `GET /` name. The segment span can arrive in a later envelope than its children, because it ends last. `opentelemetry-tracer/internal-request-handler` failed on exactly that, and now uses `collectStreamedSpansUntilSegment`. Start timestamps tie at millisecond resolution in workerd, so an order-based assertion over child spans is unreliable. `opentelemetry-tracer/enabled` matches spans by name instead of sorting them. ### Two shapes for multi-isolate traces A worker and a Durable Object each stream their own envelope for the same trace. A suite therefore has to choose how to read them. `instrument-fetcher` and the Durable Object storage suites use `collectStreamedSpans`, which groups by trace and resolves once the whole trace is in hand. These are the first callers of the helper added in the base PR. They also exercise the observe-not-consume behaviour, because `durableobject-sql` and `durableobject-sync-kv` collect spans while a flush-marker error envelope still matches an ordered expectation. The other suites keep one envelope expectation per isolate with `.unordered()`, which stays closer to the shape they already had and keeps the diff readable. Part of #24147 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ng (#24189) Ports the seventeen `suites/vite-autoinstrument` suites off the `traceLifecycle: 'static'` pin. Under streaming a whole request chain is one trace, so each suite reads the trace with `collectStreamedSpans` instead of one envelope expectation per hop. Every hop here (a Durable Object, a `WorkerEntrypoint`, a Workflow step) runs in its own isolate and streams its own envelope, so a single-envelope read would be a race. The proof of instrumentation is unchanged, only its shape is: a Durable Object still shows the `durable_object_storage_get` / `durable_object_storage_put` pair, now as children of its own segment span rather than as `spans` of its transaction. The chain is asserted directly, a hop's segment span carries the previous hop's `span_id` as its `parent_span_id`, which is stronger than the disjointness the old unordered expectations relied on. Every route in these suites is a raw URL, so the streamed segment name keeps the method only. `GET /greet` becomes `GET`, and the hop is identified through its `url.path` attribute. That matters for the entrypoint and combination suites, where the transaction name used to tell the hops apart. The per-suite `expectDurableObjectTransaction`, `expectMainWorkerTransaction` and `expectPlainTransaction` helpers are gone. The assertions are inlined, and the suites that hit two endpoints loop over the two paths. Part of #24148 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ports the binding suites off the `traceLifecycle: 'static'` pin: `d1`, `r2`, `queue`, `prisma`, `durableobject/error`, `workflows/step-context` and `vite/diagnostics-channel/vercelai-6`. `durableobject/error` and `workflows/step-context` only assert on error events, so the pin is all that goes. `cache-client` and `durableobject-scope` were already unpinned and keep ignoring spans, so they are untouched. Most binding spans keep the shape they had and only the encoding changes, so the r2 and queue suites keep one envelope expectation per request. Two things do change. D1 and Prisma spans carry the `db.query` op, so streaming names them after `db.query.summary`: `SELECT * FROM users WHERE id = ?` becomes `SELECT users`. The Prisma suite loses the description-based split between its two `SELECT` spans, which now share the name `SELECT main.User`. The D1 one is picked by its op instead, and the traceparent comment that used to be matched on the description is asserted on `db.query.text`. `prisma` and `vercelai-6` switch to `collectStreamedSpansUntilSegment`. Both assert on the complete child set of one request and the span buffer flushes on a timer, so reading a single envelope would be a race. `vercelai-6` also drops the separate span container it used to read next to the transaction item: a streamed gen_ai span is an ordinary item of the one span envelope. `/` keeps its `GET /` name under streaming (the source is `route`, not `url`), so `vercelai-6` waits on that rather than the bare method the raw-URL suites see. Part of #24148 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…eaming (#24195) Removes the `traceLifecycle: 'static'` pin from the five `suites/integrations/http-server*` suites. Nothing else changes. These suites cover request body capture, so they assert on the event the worker sends and never on a transaction. None of them sets `tracesSampleRate` either, so the pin only ever selected a trace lifecycle for a client that emits no spans in the first place. Part of #24148 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…24196) Ports the remaining request handler suites off the `traceLifecycle: 'static'` pin: `hono-sdk`, `double-instrumentation` and `public-api/metrics/server-address`. `double-instrumentation` and the metrics suite assert on an error event and on a metric envelope, so only the pin goes. `double-instrumentation` swaps its `ignore('transaction')` for `ignore('span')`, which is the envelope the `http.server` span now races the error event with. The Hono routes are parametrized patterns, so their segment names survive streaming unchanged. What does change is the status: span v2 carries the coarse `error` on the span and the specific `internal_error` in the `sentry.status.message` attribute. ## Static trace lifecycle guard `suites/basic` keeps the static pin as the package's guard. It is the smallest suite that still covers a plain worker fetch, so it is the cheapest one to keep on the old lifecycle. ## Suite left behind `suites/request-handler/subpath` also stays pinned, but not by choice. With the pin removed, `wrapRequestHandler` from `@sentry/cloudflare/request` still sends a transaction envelope. That holds with `traceLifecycle: 'stream'` passed explicitly and with `cacheClient: false`, and the transaction's own `sentry.sdk.integrations` lists `SpanStreaming` — so the client the event is processed by does have streaming on, while `getClient()` inside `_onSpanEnded` does not see a streaming client and falls through to `_convertSpanToTransaction`. Every other entry point in the package streams, and they differ only in which default integration set they inject, so this looks like a gap in the `/request` entry rather than a test problem. It is tracked separately and the suite is left as it was. Fixes #24148 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
#24819) Adds some tests for low-cardinality span names for cache spans. We already sent low-cardinality span names but we didn't have explicit tests so far.
Since these are both pre v1 we need to keep them up-to-date!
Node and Bun have not included `dedupeIntegration` in their default integrations since v5, while the browser, Deno, Vercel Edge and Cloudflare SDKs do. Add it to the Node and Bun defaults (we also claim that in our docs) `anrIntegration` collects contexts by running a placeholder event through all event processors on every worker start. On a restart, Dedupe dropped that event and ANR events lost their contexts. Skip the Dedupe processor there. Tests that trigger the same server error in consecutive requests now remove Dedupe, because only the first of these events would be sent. --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Skips injecting meta tags during the app build phase. Detected via a new Vite plugin that injects an env var during build and removes it again once the build is done. Closes #15267 --------- Co-authored-by: Lukas Stracke <lukas.stracke@sentry.io> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This PR adds the external contributor to the CHANGELOG.md file, so that they are credited for their contribution. See #24854 Co-authored-by: nicohrubec <29484629+nicohrubec@users.noreply.github.com>
) Patches `createRouter` through orchestrion to prepend a Sentry middleware to every router. The middleware opens no span: Remix 3 serves over `node:http`, so `httpIntegration` has already opened the `http.server` span. It only enriches that span with `http.route`, the response status and a low cardinality name. The SDK supplies the router's matcher, because the router never exposes one and the request context carries no pattern at middleware entry. The route is resolved by re-running the match against that matcher. Remix 3 has no build step, so no bundler plugin can apply the transform. The `--import @sentry/remix/v3/node` entry registers the module hook and subscribes before the app's own modules are imported, and replaces `--import remix/node-tsx` rather than adding a second flag. Error handling is a separate pull request. Fixes #24663 Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
…24783) OpenAI's `chat.completions.parse()` / `response.parse()` helpers could fail because instrumentation triggered an extra response body read. Use synchronous instrumentation and observe OpenAI's internal parser to preserve lazy parsing while still recording spans. Fixes #24773. --------- Co-authored-by: GPT-6 <codex@openai.com>
Anthropic automatic instrumentation could consume response bodies before callers read them through `.asResponse()`. Share OpenAI's lazy response observer to preserve raw bodies while still completing request and streaming spans. Stacked on #24783. Addresses the Anthropic portion of [JS-3856](https://linear.app/getsentry/issue/JS-3856). --------- Co-authored-by: GPT-6 <codex@openai.com>
…4906) Groq and Together automatic instrumentation could consume `.asResponse()` bodies before application code read them. Reuse the shared API-promise observer to preserve raw chat, streaming, and embeddings responses while completing their spans. Stacked on #24902. Part of #24882. Co-authored-by: GPT-6 <codex@openai.com>
…sponses (#24908) OpenAI embeddings and conversations still used eager promise instrumentation, which consumed `.asResponse()` bodies before callers could read them. Switch these remaining methods to synchronous instrumentation so the shared API-promise observer preserves lazy parsing and completes their spans. Stacked on #24906. Fixes #24882 together with the preceding PRs. Co-authored-by: GPT-6 <codex@openai.com>
Bumps [axios](https://github.com/axios/axios) from 1.18.0 to 1.20.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/axios/axios/releases">axios's releases</a>.</em></p> <blockquote> <h2>v1.20.0 — August 19, 2026</h2> <p>This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.</p> <h2>⚠️ Breaking Changes & Deprecations</h2> <ul> <li>HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (<a href="https://redirect.github.com/axios/axios/issues/11082">#11082</a>)</li> </ul> <h2>🔒 Security Fixes</h2> <ul> <li>Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (<a href="https://redirect.github.com/axios/axios/issues/11141">#11141</a>)</li> </ul> <h2>🐛 Bug Fixes</h2> <ul> <li>Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (<a href="https://redirect.github.com/axios/axios/issues/11087">#11087</a>, <a href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li> <li>Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (<a href="https://redirect.github.com/axios/axios/issues/11109">#11109</a>)</li> <li>XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (<a href="https://redirect.github.com/axios/axios/issues/11094">#11094</a>, <a href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li> <li>Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (<a href="https://redirect.github.com/axios/axios/issues/11091">#11091</a>)</li> <li>Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (<a href="https://redirect.github.com/axios/axios/issues/11096">#11096</a>)</li> </ul> <h2>🔧 Maintenance & Chores</h2> <ul> <li>Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (<a href="https://redirect.github.com/axios/axios/issues/11092">#11092</a>, <a href="https://redirect.github.com/axios/axios/issues/11098">#11098</a>, <a href="https://redirect.github.com/axios/axios/issues/11099">#11099</a>, <a href="https://redirect.github.com/axios/axios/issues/11106">#11106</a>, <a href="https://redirect.github.com/axios/axios/issues/11107">#11107</a>, <a href="https://redirect.github.com/axios/axios/issues/11122">#11122</a>, <a href="https://redirect.github.com/axios/axios/issues/11123">#11123</a>, <a href="https://redirect.github.com/axios/axios/issues/11126">#11126</a>, <a href="https://redirect.github.com/axios/axios/issues/11127">#11127</a>, <a href="https://redirect.github.com/axios/axios/issues/11133">#11133</a>, <a href="https://redirect.github.com/axios/axios/issues/11140">#11140</a>, <a href="https://redirect.github.com/axios/axios/issues/11143">#11143</a>, <a href="https://redirect.github.com/axios/axios/issues/11144">#11144</a>)</li> <li>Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (<a href="https://redirect.github.com/axios/axios/issues/11101">#11101</a>, <a href="https://redirect.github.com/axios/axios/issues/11113">#11113</a>, <a href="https://redirect.github.com/axios/axios/issues/11097">#11097</a>, <a href="https://redirect.github.com/axios/axios/issues/11119">#11119</a>)</li> <li>Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (<a href="https://redirect.github.com/axios/axios/issues/11124">#11124</a>, <a href="https://redirect.github.com/axios/axios/issues/11136">#11136</a>, <a href="https://redirect.github.com/axios/axios/issues/11137">#11137</a>)</li> <li>CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (<a href="https://redirect.github.com/axios/axios/issues/11128">#11128</a>, <a href="https://redirect.github.com/axios/axios/issues/11152">#11152</a>)</li> </ul> <h2>🌟 New Contributors</h2> <p>We are thrilled to welcome our new contributors. Thank you for helping improve axios:</p> <ul> <li><a href="https://github.com/yens1"><code>@yens1</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11109">#11109</a>)</li> <li><a href="https://github.com/Sasireddy001"><code>@Sasireddy001</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11113">#11113</a>)</li> <li><a href="https://github.com/ari-token-security"><code>@ari-token-security</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11094">#11094</a>)</li> <li><a href="https://github.com/timothyokooboh"><code>@timothyokooboh</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11097">#11097</a>)</li> <li><a href="https://github.com/gi9439041-png"><code>@gi9439041-png</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11119">#11119</a>)</li> <li><a href="https://github.com/Hashim1999164"><code>@Hashim1999164</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11082">#11082</a>)</li> <li><a href="https://github.com/v-dev-cl"><code>@v-dev-cl</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11091">#11091</a>)</li> <li><a href="https://github.com/r0h1tb"><code>@r0h1tb</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li> <li><a href="https://github.com/ostapondo"><code>@ostapondo</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li> </ul> <p>Full Changelog (<a href="https://github.com/axios/axios/compare/v1.19.0...v1.20.0">https://github.com/axios/axios/compare/v1.19.0...v1.20.0</a>)</p> <h2>v1.19.0 - July 22, 2026</h2> <p>This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.</p> <h2>🔒 Security Fixes</h2> <ul> <li>Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>). (<a href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md">axios's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <h2>v1.19.0 — July 22, 2026</h2> <p>This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.</p> <h2>🔒 Security Fixes</h2> <ul> <li>Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>). (<a href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li> </ul> <h2>🚀 New Features</h2> <ul> <li>Configuration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors, adapters, and serializers. (<a href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>, <a href="https://redirect.github.com/axios/axios/issues/11081">#11081</a>)</li> <li>Header Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (<a href="https://redirect.github.com/axios/axios/issues/11051">#11051</a>)</li> <li>HTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (<a href="https://redirect.github.com/axios/axios/issues/11067">#11067</a>)</li> </ul> <h2>🐛 Bug Fixes</h2> <ul> <li> <p>Form Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (<a href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>, <a href="https://redirect.github.com/axios/axios/issues/11018">#11018</a>)</p> </li> <li> <p>Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (<a href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>, <a href="https://redirect.github.com/axios/axios/issues/11053">#11053</a>)</p> </li> <li> <p>Cancellation: Propagated already-aborted input signals immediately when composing abort signals. (<a href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</p> </li> <li> <p>Header Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (<a href="https://redirect.github.com/axios/axios/issues/11036">#11036</a>, <a href="https://redirect.github.com/axios/axios/issues/11037">#11037</a>)</p> </li> <li> <p>URL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (<a href="https://redirect.github.com/axios/axios/issues/11008">#11008</a>, <a href="https://redirect.github.com/axios/axios/issues/11038">#11038</a>)</p> </li> <li> <p>Progress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (<a href="https://redirect.github.com/axios/axios/issues/11039">#11039</a>, <a href="https://redirect.github.com/axios/axios/issues/11040">#11040</a>)</p> </li> <li> <p>Error and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (<a href="https://redirect.github.com/axios/axios/issues/11044">#11044</a>, <a href="https://redirect.github.com/axios/axios/issues/11059">#11059</a>)</p> </li> <li> <p>Content-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (<a href="https://redirect.github.com/axios/axios/issues/11061">#11061</a>)</p> </li> <li> <p>Synchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (<a href="https://redirect.github.com/axios/axios/issues/11071">#11071</a>)</p> </li> </ul> <h2>🔧 Maintenance & Chores</h2> <ul> <li>Dependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (<a href="https://redirect.github.com/axios/axios/issues/11031">#11031</a>, <a href="https://redirect.github.com/axios/axios/issues/11055">#11055</a>, <a href="https://redirect.github.com/axios/axios/issues/11056">#11056</a>, <a href="https://redirect.github.com/axios/axios/issues/11058">#11058</a>, <a href="https://redirect.github.com/axios/axios/issues/11079">#11079</a>, <a href="https://redirect.github.com/axios/axios/issues/11080">#11080</a>, <a href="https://redirect.github.com/axios/axios/issues/11088">#11088</a>, <a href="https://redirect.github.com/axios/axios/issues/11089">#11089</a>, <a href="https://redirect.github.com/axios/axios/issues/11090">#11090</a>)</li> <li>Build Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (<a href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li> <li>Form Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (<a href="https://redirect.github.com/axios/axios/issues/11062">#11062</a>)</li> <li>Developer Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (<a href="https://redirect.github.com/axios/axios/issues/11032">#11032</a>, <a href="https://redirect.github.com/axios/axios/issues/11073">#11073</a>)</li> <li>Documentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (<a href="https://redirect.github.com/axios/axios/issues/11041">#11041</a>, <a href="https://redirect.github.com/axios/axios/issues/11068">#11068</a>, <a href="https://redirect.github.com/axios/axios/issues/11076">#11076</a>, <a href="https://redirect.github.com/axios/axios/issues/11078">#11078</a>)</li> <li>Publishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (<a href="https://redirect.github.com/axios/axios/issues/11083">#11083</a>, <a href="https://redirect.github.com/axios/axios/issues/11095">#11095</a>)</li> </ul> <h2>🌟 New Contributors</h2> <p>We are thrilled to welcome our new contributors. Thank you for helping improve Axios:</p> <ul> <li><a href="https://github.com/afonsojramos"><code>@afonsojramos</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li> <li><a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>)</li> <li><a href="https://github.com/yassertawfik4"><code>@yassertawfik4</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11024">#11024</a>)</li> <li><a href="https://github.com/AnandSundar"><code>@AnandSundar</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>)</li> <li><a href="https://github.com/lin-hongkuan"><code>@lin-hongkuan</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</li> <li><a href="https://github.com/Wali007-lab"><code>@Wali007-lab</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li> <li><a href="https://github.com/magicdawn"><code>@magicdawn</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/axios/axios/commit/84a9f3b9a4f3244b8c8e818f557d64c7b964fb25"><code>84a9f3b</code></a> chore(release): prepare release 1.20.0 (<a href="https://redirect.github.com/axios/axios/issues/11152">#11152</a>)</li> <li><a href="https://github.com/axios/axios/commit/e6824eec5fcf9da467a9792724396badc490c469"><code>e6824ee</code></a> fix: core methodList, HTTP adapter errors, and add tests (<a href="https://redirect.github.com/axios/axios/issues/11096">#11096</a>)</li> <li><a href="https://github.com/axios/axios/commit/d8a919fd81403d59058c0e9dbefc540407dee83f"><code>d8a919f</code></a> fix(xhr): flush final progress during the live loadend dispatch (<a href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li> <li><a href="https://github.com/axios/axios/commit/2d2a21af8a433089474a2149781799c93acbcf3c"><code>2d2a21a</code></a> fix(interceptors): tolerate nullish handlers in syncHandlerEntries (<a href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li> <li><a href="https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"><code>d19040b</code></a> fix: harden runtime option handling (<a href="https://redirect.github.com/axios/axios/issues/11141">#11141</a>)</li> <li><a href="https://github.com/axios/axios/commit/e0a02dd16671deabe2b809334d4c2ebede29a233"><code>e0a02dd</code></a> chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...</li> <li><a href="https://github.com/axios/axios/commit/d10cb3aa3cda1d78721ddf96be590478df26cd81"><code>d10cb3a</code></a> chore(deps-dev): bump the development_dependencies group with 4 updates (<a href="https://redirect.github.com/axios/axios/issues/11143">#11143</a>)</li> <li><a href="https://github.com/axios/axios/commit/2c94646eb7cb7ab9dcb2aefdb04ab1b040c28e16"><code>2c94646</code></a> chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (<a href="https://redirect.github.com/axios/axios/issues/11133">#11133</a>)</li> <li><a href="https://github.com/axios/axios/commit/76c12bce5a4fe9a45bef9a5bf2baaf599d7d382e"><code>76c12bc</code></a> chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (<a href="https://redirect.github.com/axios/axios/issues/11140">#11140</a>)</li> <li><a href="https://github.com/axios/axios/commit/ba98559a7f5a18e531b5762387e5957bd281af3d"><code>ba98559</code></a> docs: add ScrapingBee sponsor (<a href="https://redirect.github.com/axios/axios/issues/11137">#11137</a>)</li> <li>Additional commits viewable in <a href="https://github.com/axios/axios/compare/v1.18.0...v1.20.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/getsentry/sentry-javascript/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fastify](https://github.com/fastify/fastify) from 5.12.1 to 5.12.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/fastify/fastify/releases">fastify's releases</a>.</em></p> <blockquote> <h2>v5.12.5</h2> <h2>⚠️ Security release</h2> <ul> <li>Fix for <a href="https://github.com/fastify/fastify/security/advisories/GHSA-4mh8-r7rc-xpvc">https://github.com/fastify/fastify/security/advisories/GHSA-4mh8-r7rc-xpvc</a></li> </ul> <h2>What's Changed</h2> <ul> <li>[Backport 5.x] perf: reduce content-type parser overhead by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/fastify/fastify/pull/7019">fastify/fastify#7019</a></li> <li>[Backport 5.x] perf: avoid redundant request-part reads during validation by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/fastify/fastify/pull/7020">fastify/fastify#7020</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/fastify/fastify/compare/v5.12.4...v5.12.5">https://github.com/fastify/fastify/compare/v5.12.4...v5.12.5</a></p> <h2>v5.12.4</h2> <p>Fixed the <code>fastify.js</code> version mismatch.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/fastify/fastify/compare/v5.12.2...v5.12.4">https://github.com/fastify/fastify/compare/v5.12.2...v5.12.4</a></p> <h2>v5.12.2</h2> <h2>⚠️ Security release</h2> <ul> <li>Fix for <a href="https://github.com/fastify/fastify/security/advisories/GHSA-9q9j-q6p8-xq58">https://github.com/fastify/fastify/security/advisories/GHSA-9q9j-q6p8-xq58</a></li> <li>Fix for <a href="https://github.com/fastify/fastify/security/advisories/GHSA-hwr6-493r-vm6h">https://github.com/fastify/fastify/security/advisories/GHSA-hwr6-493r-vm6h</a></li> <li>Fix for <a href="https://github.com/fastify/fastify/security/advisories/GHSA-p68q-wchp-6fh7">https://github.com/fastify/fastify/security/advisories/GHSA-p68q-wchp-6fh7</a></li> <li>Fix for <a href="https://github.com/fastify/fastify/security/advisories/GHSA-667r-xxjv-c9mm">https://github.com/fastify/fastify/security/advisories/GHSA-667r-xxjv-c9mm</a></li> </ul> <h2>What's Changed</h2> <ul> <li>[Backport 5.x] fix: callNotFound should run not-found preHandler regardless of registration order by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/fastify/fastify/pull/6973">fastify/fastify#6973</a></li> <li>[Backport 5.x] chore: npm ignore remaining agent files by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/fastify/fastify/pull/7003">fastify/fastify#7003</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/fastify/fastify/compare/v5.12.1...v5.12.2">https://github.com/fastify/fastify/compare/v5.12.1...v5.12.2</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/fastify/fastify/commit/ba235fdcd9a83a4c7ccf793f7b2596a8f65389b6"><code>ba235fd</code></a> Bumped v5.12.5</li> <li><a href="https://github.com/fastify/fastify/commit/ad06a4c3fe8a944a904f38068249b18b8f552e90"><code>ad06a4c</code></a> Merge commit from fork</li> <li><a href="https://github.com/fastify/fastify/commit/7af0d7719d928cb7f24a074e831e83a819b4f626"><code>7af0d77</code></a> [Backport 5.x] perf: avoid redundant request-part reads during validation (<a href="https://redirect.github.com/fastify/fastify/issues/7">#7</a>...</li> <li><a href="https://github.com/fastify/fastify/commit/990ebef15d54b87b531c40aaeb1fe6314797b8bb"><code>990ebef</code></a> [Backport 5.x] perf: reduce content-type parser overhead (<a href="https://redirect.github.com/fastify/fastify/issues/7019">#7019</a>)</li> <li><a href="https://github.com/fastify/fastify/commit/1690e350121afa6eedce8ada46ac07d1a423ce75"><code>1690e35</code></a> Bumped v5.12.4</li> <li><a href="https://github.com/fastify/fastify/commit/1c991c40f9615e8d33f8004c8f8cbe35d4be7f4f"><code>1c991c4</code></a> Bumped v5.12.3</li> <li><a href="https://github.com/fastify/fastify/commit/942a2be8704244db778f8db9a0bb4951b8825156"><code>942a2be</code></a> Bumped v5.12.2</li> <li><a href="https://github.com/fastify/fastify/commit/853f6e2538e46e5aafe163f7deeb2866f3ef6841"><code>853f6e2</code></a> test(validation): cover normalization and async branches</li> <li><a href="https://github.com/fastify/fastify/commit/f02d8d4ab1ab208f10819c4dc213595b06497833"><code>f02d8d4</code></a> fix(validation): do not unwrap async validator results</li> <li><a href="https://github.com/fastify/fastify/commit/93c239a380f3f2778bb7565fcdf777e91cfe1fbc"><code>93c239a</code></a> fix: reject malformed URLs before custom 404 handlers</li> <li>Additional commits viewable in <a href="https://github.com/fastify/fastify/compare/v5.12.1...v5.12.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/getsentry/sentry-javascript/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Forgot to push an e2e test in #24777 for Sveltekit 2. Since the added plugin there has different logic for Kit 2 and 3 I think we should still add this test for Kit 2. There is an e2e test for Kit 2 in static mode but once we get rid of transactions, this test might be removed. so can't hurt to add it here.
Bumps [hono](https://github.com/honojs/hono) from 4.13.5 to 4.13.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/honojs/hono/releases">hono's releases</a>.</em></p> <blockquote> <h2>v4.13.7</h2> <h2>Security fixes</h2> <p>This release includes a fix for the following security issue:</p> <h3><code>hono/jsx</code> renders plain strings unescaped in boundary components, leading to XSS</h3> <p>Affects: <code>Suspense</code>, <code>ErrorBoundary</code>, and <code>Context.Provider</code> in <code>hono/jsx</code>, and <code>renderToString()</code> / <code>renderToReadableStream()</code> in <code>hono/jsx/dom/server</code>. Fixes missing HTML escaping for a plain string placed directly as a child or <code>fallback</code> of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv</p> <hr /> <p>Users who render untrusted strings inside <code>Suspense</code>, <code>ErrorBoundary</code>, or <code>Context.Provider</code>, or pass them directly to <code>hono/jsx/dom/server</code>, are strongly encouraged to upgrade to this version.</p> <h2>v4.13.6</h2> <h2>What's Changed</h2> <ul> <li>fix(client): keep a param value of "index" in $url() and $path() in <a href="https://redirect.github.com/honojs/hono/pull/5297">honojs/hono#5297</a></li> <li>fix(client): normalize root WebSocket URLs in <a href="https://redirect.github.com/honojs/hono/pull/5291">honojs/hono#5291</a></li> <li>fix(types): allow symbol keys in Context<!-- raw HTML omitted --> get and set fallbacks in <a href="https://redirect.github.com/honojs/hono/pull/5300">honojs/hono#5300</a></li> <li>chore: bump <code>editorconfig-checker</code> in <a href="https://redirect.github.com/honojs/hono/pull/5336">honojs/hono#5336</a></li> <li>refactor(on-handler): use forEach for consistent handler iteration in <a href="https://redirect.github.com/honojs/hono/pull/5326">honojs/hono#5326</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/honojs/hono/compare/v4.13.5...v4.13.6">https://github.com/honojs/hono/compare/v4.13.5...v4.13.6</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/honojs/hono/commit/eebdf7be39abf0a872671835ccce0c4f03ea497a"><code>eebdf7b</code></a> 4.13.7</li> <li><a href="https://github.com/honojs/hono/commit/2b8ed402cdab6dfc5e829b480806dcd8db94161e"><code>2b8ed40</code></a> Merge commit from fork</li> <li><a href="https://github.com/honojs/hono/commit/cac0c4d3fe29aca4e426031067cbbb3b9131e30c"><code>cac0c4d</code></a> 4.13.6</li> <li><a href="https://github.com/honojs/hono/commit/dac5d5794c6134711e469c5e69d09cd6274e1fc1"><code>dac5d57</code></a> refactor(on-handler): use forEach for consistent handler iteration (<a href="https://redirect.github.com/honojs/hono/issues/5326">#5326</a>)</li> <li><a href="https://github.com/honojs/hono/commit/ec648d683768ec5093315e5dc694c05594fec185"><code>ec648d6</code></a> chore: bump <code>editorconfig-checker</code> (<a href="https://redirect.github.com/honojs/hono/issues/5336">#5336</a>)</li> <li><a href="https://github.com/honojs/hono/commit/e2740d5a1bd0b4254e517e3af8b60789284bc7bd"><code>e2740d5</code></a> fix(types): allow symbol keys in Context<any> get and set fallbacks (<a href="https://redirect.github.com/honojs/hono/issues/5300">#5300</a>)</li> <li><a href="https://github.com/honojs/hono/commit/499c35ebda35777fd35a7dd1906dd4f2687da61e"><code>499c35e</code></a> fix(client): normalize root WebSocket URLs (<a href="https://redirect.github.com/honojs/hono/issues/5291">#5291</a>)</li> <li><a href="https://github.com/honojs/hono/commit/50b8788cf54cb60112b7cd93642bc5094901475c"><code>50b8788</code></a> fix(client): keep a param value of "index" in $url() and $path() (<a href="https://redirect.github.com/honojs/hono/issues/5297">#5297</a>)</li> <li>See full diff in <a href="https://github.com/honojs/hono/compare/v4.13.5...v4.13.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/getsentry/sentry-javascript/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [moment](https://github.com/moment/moment) from 2.30.1 to 2.31.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/moment/moment/releases">moment's releases</a>.</em></p> <blockquote> <h2>2.31.0</h2> <p><em>Released Sep 14, 2026</em></p> <h4>Security fixes</h4> <ul> <li>Fix <a href="https://www.cve.org/CVERecord?id=CVE-2026-17495">CVE-2026-17495</a> (<a href="https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw">GHSA-4p3w-j4w9-5jqw</a>)</li> </ul> <h4>Bug fixes</h4> <ul> <li><a href="https://redirect.github.com/moment/moment/pull/6376">#6376</a> Prevent object prototype properties from being used as format tokens</li> <li><a href="https://redirect.github.com/moment/moment/pull/6386">#6386</a> Normalize lazy-loaded locale names</li> <li><a href="https://redirect.github.com/moment/moment/pull/6404">#6404</a> Fix parsing issue with <code>eHHmm</code> format</li> <li><a href="https://redirect.github.com/moment/moment/pull/6433">#6433</a> Ignore non-Moment arguments in min and max</li> <li><a href="https://redirect.github.com/moment/moment/pull/6434">#6434</a> Fix inherited lowercase long date formats</li> <li><a href="https://redirect.github.com/moment/moment/pull/6436">#6436</a> Reset locale parsing caches after updates</li> <li><a href="https://redirect.github.com/moment/moment/pull/6437">#6437</a> Fix weekday mismatch when the format only has part of a date</li> <li><a href="https://redirect.github.com/moment/moment/pull/6442">#6442</a> Fix <code>locale('__proto__')</code> corrupting the global locale</li> <li><a href="https://redirect.github.com/moment/moment/pull/6443">#6443</a> Avoid <code>Object.assign</code> in <code>duration.humanize</code></li> <li><a href="https://redirect.github.com/moment/moment/pull/6446">#6446</a> Validate range when parsing a time zone offset</li> <li><a href="https://redirect.github.com/moment/moment/pull/6447">#6447</a> Include metadata in all-locales bundle</li> <li><a href="https://redirect.github.com/moment/moment/pull/6448">#6448</a> Apply postformat to locale relative time methods</li> <li><a href="https://redirect.github.com/moment/moment/pull/6450">#6450</a> Add stack traces to conditional deprecation warnings</li> </ul> <h4>New features</h4> <ul> <li><a href="https://redirect.github.com/moment/moment/pull/6451">#6451</a> Add internal date-default hook for Moment Timezone</li> </ul> <h5>New locales</h5> <ul> <li><a href="https://redirect.github.com/moment/moment/pull/6000">#6000</a>: Pashto ('ps')</li> <li><a href="https://redirect.github.com/moment/moment/pull/6278">#6278</a>, <a href="https://redirect.github.com/moment/moment/pull/6379">#6379</a>: Amharic (Ethiopia) ('am-et')</li> </ul> <h4>Updates to existing locales</h4> <ul> <li><a href="https://redirect.github.com/moment/moment/pull/5404">#5404</a> Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time</li> <li><a href="https://redirect.github.com/moment/moment/pull/6197">#6197</a> Indonesian ('id'): Correct the abbreviation for August</li> <li><a href="https://redirect.github.com/moment/moment/pull/6217">#6217</a> Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct <code>L</code> date formats</li> <li><a href="https://redirect.github.com/moment/moment/pull/6289">#6289</a> Swedish ('sv'): Correct the abbreviation for Thursday</li> <li><a href="https://redirect.github.com/moment/moment/pull/6306">#6306</a> Catalan ('ca'): Use typographic apostrophes in relative time</li> <li><a href="https://redirect.github.com/moment/moment/pull/6347">#6347</a> Swahili ('sw'): Correct the spelling of hour in calendar output</li> <li><a href="https://redirect.github.com/moment/moment/pull/6360">#6360</a> Ukrainian ('uk'): Use ISO week numbering</li> <li><a href="https://redirect.github.com/moment/moment/pull/6370">#6370</a> Ukrainian ('uk'): Use U+02BC apostrophes in Friday names</li> <li><a href="https://redirect.github.com/moment/moment/pull/6371">#6371</a> Hungarian ('hu'): Preserve numeric values in relative seconds</li> <li><a href="https://redirect.github.com/moment/moment/pull/6391">#6391</a> Swahili ('sw'): Fix weekday and relative-time grammar</li> <li><a href="https://redirect.github.com/moment/moment/pull/6396">#6396</a> German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots</li> <li><a href="https://redirect.github.com/moment/moment/pull/6409">#6409</a> Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting</li> <li><a href="https://redirect.github.com/moment/moment/pull/6410">#6410</a> Polish ('pl'): Use genitive month names in dotted day formats</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/moment/moment/blob/develop/CHANGELOG.md">moment's changelog</a>.</em></p> <blockquote> <h3>2.31.0</h3> <p><em>Released Sep 14, 2026</em></p> <h4>Security fixes</h4> <ul> <li>Fix <a href="https://www.cve.org/CVERecord?id=CVE-2026-17495">CVE-2026-17495</a> (<a href="https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw">GHSA-4p3w-j4w9-5jqw</a>)</li> </ul> <h4>Bug fixes</h4> <ul> <li><a href="https://redirect.github.com/moment/moment/pull/6376">#6376</a> Prevent object prototype properties from being used as format tokens</li> <li><a href="https://redirect.github.com/moment/moment/pull/6386">#6386</a> Normalize lazy-loaded locale names</li> <li><a href="https://redirect.github.com/moment/moment/pull/6404">#6404</a> Fix parsing issue with <code>eHHmm</code> format</li> <li><a href="https://redirect.github.com/moment/moment/pull/6433">#6433</a> Ignore non-Moment arguments in min and max</li> <li><a href="https://redirect.github.com/moment/moment/pull/6434">#6434</a> Fix inherited lowercase long date formats</li> <li><a href="https://redirect.github.com/moment/moment/pull/6436">#6436</a> Reset locale parsing caches after updates</li> <li><a href="https://redirect.github.com/moment/moment/pull/6437">#6437</a> Fix weekday mismatch when the format only has part of a date</li> <li><a href="https://redirect.github.com/moment/moment/pull/6442">#6442</a> Fix <code>locale('__proto__')</code> corrupting the global locale</li> <li><a href="https://redirect.github.com/moment/moment/pull/6443">#6443</a> Avoid <code>Object.assign</code> in <code>duration.humanize</code></li> <li><a href="https://redirect.github.com/moment/moment/pull/6446">#6446</a> Validate range when parsing a time zone offset</li> <li><a href="https://redirect.github.com/moment/moment/pull/6447">#6447</a> Include metadata in all-locales bundle</li> <li><a href="https://redirect.github.com/moment/moment/pull/6448">#6448</a> Apply postformat to locale relative time methods</li> <li><a href="https://redirect.github.com/moment/moment/pull/6450">#6450</a> Add stack traces to conditional deprecation warnings</li> </ul> <h4>New features</h4> <ul> <li><a href="https://redirect.github.com/moment/moment/pull/6451">#6451</a> Add internal date-default hook for Moment Timezone</li> </ul> <h5>New locales</h5> <ul> <li><a href="https://redirect.github.com/moment/moment/pull/6000">#6000</a>: Pashto ('ps')</li> <li><a href="https://redirect.github.com/moment/moment/pull/6278">#6278</a>, <a href="https://redirect.github.com/moment/moment/pull/6379">#6379</a>: Amharic (Ethiopia) ('am-et')</li> </ul> <h4>Updates to existing locales</h4> <ul> <li><a href="https://redirect.github.com/moment/moment/pull/5404">#5404</a> Portuguese (Brazil) ('pt-br'): Fix wrong plural usage for time</li> <li><a href="https://redirect.github.com/moment/moment/pull/6197">#6197</a> Indonesian ('id'): Correct the abbreviation for August</li> <li><a href="https://redirect.github.com/moment/moment/pull/6217">#6217</a> Georgian ('ka') and Dutch (Belgium) ('nl-be'): Correct <code>L</code> date formats</li> <li><a href="https://redirect.github.com/moment/moment/pull/6289">#6289</a> Swedish ('sv'): Correct the abbreviation for Thursday</li> <li><a href="https://redirect.github.com/moment/moment/pull/6306">#6306</a> Catalan ('ca'): Use typographic apostrophes in relative time</li> <li><a href="https://redirect.github.com/moment/moment/pull/6347">#6347</a> Swahili ('sw'): Correct the spelling of hour in calendar output</li> <li><a href="https://redirect.github.com/moment/moment/pull/6360">#6360</a> Ukrainian ('uk'): Use ISO week numbering</li> <li><a href="https://redirect.github.com/moment/moment/pull/6370">#6370</a> Ukrainian ('uk'): Use U+02BC apostrophes in Friday names</li> <li><a href="https://redirect.github.com/moment/moment/pull/6371">#6371</a> Hungarian ('hu'): Preserve numeric values in relative seconds</li> <li><a href="https://redirect.github.com/moment/moment/pull/6391">#6391</a> Swahili ('sw'): Fix weekday and relative-time grammar</li> <li><a href="https://redirect.github.com/moment/moment/pull/6396">#6396</a> German ('de', 'de-at', 'de-ch'): Parse short months without trailing dots</li> <li><a href="https://redirect.github.com/moment/moment/pull/6409">#6409</a> Uzbek ('uz', 'uz-latn'): Fix past relative-time formatting</li> <li><a href="https://redirect.github.com/moment/moment/pull/6410">#6410</a> Polish ('pl'): Use genitive month names in dotted day formats</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/moment/moment/commit/15b45d48a176312e8f34143c5a800090abf4787f"><code>15b45d4</code></a> [pkg] Build 2.31.0 (<a href="https://redirect.github.com/moment/moment/issues/6452">#6452</a>)</li> <li><a href="https://github.com/moment/moment/commit/631cd81454ee001e1f508e21270eae0b6bb62974"><code>631cd81</code></a> [pkg] Update changelog for upcoming release (<a href="https://redirect.github.com/moment/moment/issues/6394">#6394</a>)</li> <li><a href="https://github.com/moment/moment/commit/6caff9e0d54e85a63a6eb97d7361f1da35bc58f4"><code>6caff9e</code></a> Merge commit from fork</li> <li><a href="https://github.com/moment/moment/commit/710703b7eac93535ad125cbf4feb3d42afed6fb3"><code>710703b</code></a> [feature] Add internal date-default hook for Moment Timezone (<a href="https://redirect.github.com/moment/moment/issues/6451">#6451</a>)</li> <li><a href="https://github.com/moment/moment/commit/863ed940556e6e63c43de23981a4853036a003ac"><code>863ed94</code></a> [bugfix] Add stack traces to conditional deprecation warnings (<a href="https://redirect.github.com/moment/moment/issues/6450">#6450</a>)</li> <li><a href="https://github.com/moment/moment/commit/2c7abe1c42ee15445d30c2c5d536750a1e43a09a"><code>2c7abe1</code></a> [bugfix] Apply postformat to locale relative time methods (<a href="https://redirect.github.com/moment/moment/issues/6448">#6448</a>)</li> <li><a href="https://github.com/moment/moment/commit/9c45ac38690c649c95e19923276b63da5fe2be26"><code>9c45ac3</code></a> [bugfix] Include metadata in all-locales bundle (<a href="https://redirect.github.com/moment/moment/issues/6447">#6447</a>)</li> <li><a href="https://github.com/moment/moment/commit/f6eefc5fc7b44ceccbd007aeffc48ebc5eac30fa"><code>f6eefc5</code></a> [bugfix] Validate timezone offset range (<a href="https://redirect.github.com/moment/moment/issues/6446">#6446</a>)</li> <li><a href="https://github.com/moment/moment/commit/136b441794a3bb207d593add3b59e9de0e062523"><code>136b441</code></a> [bugfix] Avoid Object.assign in duration.humanize (<a href="https://redirect.github.com/moment/moment/issues/6443">#6443</a>)</li> <li><a href="https://github.com/moment/moment/commit/0d1050437b40f66ac47e14b285bb3d09676cf2e0"><code>0d10504</code></a> [bugfix] Fix locale('<strong>proto</strong>') corrupting the global locale (<a href="https://redirect.github.com/moment/moment/issues/6442">#6442</a>)</li> <li>Additional commits viewable in <a href="https://github.com/moment/moment/compare/2.30.1...2.31.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for moment since your current version.</p> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary Batched **runtime** dependency security fixes. One commit per vulnerability. ### Fixes - `brace-expansion` 1.1.18 → 1.1.21 — GHSA-q2hr-2g5m-vwhr / CVE-2026-102277 (medium) — https://github.com/getsentry/sentry-javascript/security/dependabot/2599 ### Notes `brace-expansion` is not a direct dependency anywhere in the monorepo — the only vulnerable instance was the `brace-expansion@^1.1.7` lockfile entry pulled in via `minimatch@3.x`. That range already permits the patched `1.1.21`, so this is a **lockfile-only re-resolution**: no `package.json` change and no `resolutions` override. Re-resolving the lockfile also moved two non-vulnerable entries forward within their existing semver ranges: - `brace-expansion@^2.0.1, ^2.0.2`: 2.0.2 → 2.1.7 - `brace-expansion@^5.0.5`: 5.0.6 → 5.0.12 `yarn dedupe-deps:check` passes. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
| ### Other Changes | ||
|
|
||
| - chore(bundler-plugins): Allow magic-string 1.x ([#24768](https://github.com/getsentry/sentry-javascript/pull/24768)) | ||
| - feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 ([#24823](https://github.com/getsentry/sentry-javascript/pull/24823)) |
There was a problem hiding this comment.
not really, it is dependencies which were bumped
| - fix(solidstart): Support `rolldownOptions` in instrumentation file plugin ([#24863](https://github.com/getsentry/sentry-javascript/pull/24863)) | ||
| - fix(sveltekit): Skip trace meta tags when prerendering ([#24777](https://github.com/getsentry/sentry-javascript/pull/24777)) | ||
| - fix(vue): Share one root render span debounce timer across components ([#24868](https://github.com/getsentry/sentry-javascript/pull/24868)) | ||
| - perf(server-utils): Avoid quadratic SQL sanitizer output handling ([#24834](https://github.com/getsentry/sentry-javascript/pull/24834)) |
There was a problem hiding this comment.
server-utils per se is internal, but the changes hit a public surface. I'm always in between putting server-utils being internal and public. I still like to keep this one here
size-limit report 📦
|
| function wrapRawResponse(apiPromise: ApiPromise): void { | ||
| apiPromise.asResponse = new Proxy(apiPromise.asResponse, { | ||
| apply(original, thisArg, args): Promise<Response> { | ||
| return (Reflect.apply(original, thisArg, args) as Promise<Response>).then(response => { | ||
| if (!parsing) { | ||
| onResponse(undefined); | ||
| } | ||
| return response; | ||
| }); | ||
| }, | ||
| }); |
There was a problem hiding this comment.
Bug: Calling .asResponse() on an Anthropic APIPromise results in missing response attributes on the final instrumentation span because the onResponse callback receives an undefined result.
Severity: MEDIUM
Suggested Fix
Modify the logic to ensure that the onResponse callback receives the parsed response data, not undefined, when .asResponse() is used. This might involve adjusting the proxy's .then handler in apiPromise.ts to wait for the response to be parsed before ending the span, ensuring that data.result is correctly populated.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/server-utils/src/ai/core/apiPromise.ts#L49-L59
Potential issue: When a user calls `.asResponse()` on an `APIPromise` for an Anthropic
API call, the `onResponse` callback is invoked with `undefined`. This causes the
`data.result` to be `undefined` when `beforeSpanEnd` is called. As a result, the
`addResponseAttributes` function returns early, and the final instrumentation span is
missing critical response attributes such as `GEN_AI_RESPONSE_ID`,
`GEN_AI_RESPONSE_MODEL`, and token counts. This regression affects a documented and
tested usage pattern, leading to a loss of observability for these API calls.
Did we get this right? 👍 / 👎 to inform future reviews.
No description provided.