feat(deno): Add orchestrion deno runtime hook - #21451

Merged
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion
Jun 18, 2026
Merged

feat(deno): Add orchestrion deno runtime hook#21451
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion loader hook defined in server-utils, and create a loader for Deno that detects the presence of the hooks, and instruments the channels added to the mysql module.

Documentation added to call out the caveat of usage in Deno v2.8.0 through 2.8.2, which is fixed in 2.8.3.

@isaacs
isaacs requested a review from a team as a code ownerJune 10, 2026 18:55
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 10, 2026 18:55
Comment threadpackages/deno/src/sdk.ts Outdated
Comment threadpackages/deno/test/orchestrion-mysql.test.ts
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from d6de7a3 to 0ceae6aCompareJune 10, 2026 19:20
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 0ceae6a to 2011bb7CompareJune 10, 2026 19:34
Comment threadpackages/deno/src/integrations/mysql.ts Outdated
Comment threadpackages/deno/src/import.mjs Outdated
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 2011bb7 to 8ab5b64CompareJune 10, 2026 20:07
Comment threadpackages/deno/src/integrations/mysql.ts
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just two minor comments

```

> [!NOTE]
> In Deno versions **2.8.0** through **2.8.2**, a bug causes Deno

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Is it worth to mention that it works in these two versions? I would be fine of just saying we are supporting everything after 2.8.3 with the --import option and don't go into much detail - but this is also ok.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I generally agree that I'd just say "we support deno 2.8.3 and above" and not really go into details for anything below that?

* orchestrion runtime hook (`@sentry/deno/import`) needs to transform libraries
* like `mysql` so they publish to their tracing channels.
*/
export const MODULE_REGISTER_HOOKS_SUPPORTED = gte(2, 8, 0);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q/l: Connected to the other comment. Should we actually start supporting it form 2.8.3?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, it's fine, I guess? Probably no one's going to be using Deno 2.8.0, but they did make a big announcement about it when it came out, and haven't been as noisy about the patches, so it's possible someone upgraded right away, but then is lagging behind, I guess?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok if they made big announcements it might be better as is.

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 8ab5b64 to 4f35ab9CompareJune 15, 2026 18:54
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4f35ab9 to e54572fCompareJune 15, 2026 19:01
@github-actions

github-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.91 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.16 kB--
@sentry/browser (incl. Tracing, Profiling)50.69 kB--
@sentry/browser (incl. Tracing, Replay)85.1 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.71 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.8 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.47 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.21 kB--
@sentry/vue32.58 kB--
@sentry/vue (incl. Tracing)47.78 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.32 kB--
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.62 kB--
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.64 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.9 kB--
CDN Bundle (incl. Tracing, Replay, Feedback)91.49 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.73 kB--
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.13 kB--
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.1 kB--
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.99 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.95 kB--
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.69 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.64 kB--
@sentry/nextjs (client)50.61 kB--
@sentry/sveltekit (client)46.3 kB--
@sentry/core/server76.21 kB--
@sentry/core/browser63.34 kB--
@sentry/node-core61.9 kB-0.01%-1 B 🔽
@sentry/node124.68 kB-0.01%-1 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.97 kB-0.01%-1 B 🔽
@sentry/node - without tracing74.27 kB--
@sentry/aws-serverless85.37 kB-0.01%-1 B 🔽
@sentry/cloudflare (withSentry) - minified174.55 kB--
@sentry/cloudflare (withSentry)436.86 kB--

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from e54572f to 21830a7CompareJune 15, 2026 19:46

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21830a7. Configure here.

Comment threadpackages/deno/test/orchestrion-mysql.test.ts
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 21830a7 to 1caca4fCompareJune 15, 2026 22:46
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1caca4f to 4be4406CompareJune 16, 2026 03:22
Comment threadpackages/deno/package.json
isaacs added a commit that referenced this pull request Jun 17, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4793bdc to 6b86f67CompareJune 17, 2026 06:29
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 6b86f67 to 1714284CompareJune 18, 2026 04:20
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1714284 to 79c1076CompareJune 18, 2026 04:51
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 79c1076 to 43ae63aCompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 43ae63a to 116ecbdCompareJune 18, 2026 17:25
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 116ecbd to 3acab72CompareJune 18, 2026 17:34
Base automatically changed from isaacs/bun-orchestrion to developJune 18, 2026 21:20
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 3acab72 to 26e55bdCompareJune 18, 2026 21:43
@isaacs
isaacs merged commit cb69761 into developJun 18, 2026
221 of 225 checks passed
@isaacs
isaacs deleted the isaacs/deno-orchestrion branch June 18, 2026 23:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(deno): Add orchestrion deno runtime hook - #21451

Merged
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion
Jun 18, 2026
Merged

feat(deno): Add orchestrion deno runtime hook#21451
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion loader hook defined in server-utils, and create a loader for Deno that detects the presence of the hooks, and instruments the channels added to the mysql module.

Documentation added to call out the caveat of usage in Deno v2.8.0 through 2.8.2, which is fixed in 2.8.3.

@isaacs
isaacs requested a review from a team as a code ownerJune 10, 2026 18:55
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 10, 2026 18:55
Comment threadpackages/deno/src/sdk.ts Outdated
Comment threadpackages/deno/test/orchestrion-mysql.test.ts
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from d6de7a3 to 0ceae6aCompareJune 10, 2026 19:20
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 0ceae6a to 2011bb7CompareJune 10, 2026 19:34
Comment threadpackages/deno/src/integrations/mysql.ts Outdated
Comment threadpackages/deno/src/import.mjs Outdated
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 2011bb7 to 8ab5b64CompareJune 10, 2026 20:07
Comment threadpackages/deno/src/integrations/mysql.ts
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just two minor comments

```

> [!NOTE]
> In Deno versions **2.8.0** through **2.8.2**, a bug causes Deno

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Is it worth to mention that it works in these two versions? I would be fine of just saying we are supporting everything after 2.8.3 with the --import option and don't go into much detail - but this is also ok.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I generally agree that I'd just say "we support deno 2.8.3 and above" and not really go into details for anything below that?

* orchestrion runtime hook (`@sentry/deno/import`) needs to transform libraries
* like `mysql` so they publish to their tracing channels.
*/
export const MODULE_REGISTER_HOOKS_SUPPORTED = gte(2, 8, 0);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q/l: Connected to the other comment. Should we actually start supporting it form 2.8.3?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, it's fine, I guess? Probably no one's going to be using Deno 2.8.0, but they did make a big announcement about it when it came out, and haven't been as noisy about the patches, so it's possible someone upgraded right away, but then is lagging behind, I guess?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok if they made big announcements it might be better as is.

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 8ab5b64 to 4f35ab9CompareJune 15, 2026 18:54
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4f35ab9 to e54572fCompareJune 15, 2026 19:01
@github-actions

github-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.91 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.16 kB--
@sentry/browser (incl. Tracing, Profiling)50.69 kB--
@sentry/browser (incl. Tracing, Replay)85.1 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.71 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.8 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.47 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.21 kB--
@sentry/vue32.58 kB--
@sentry/vue (incl. Tracing)47.78 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.32 kB--
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.62 kB--
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.64 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.9 kB--
CDN Bundle (incl. Tracing, Replay, Feedback)91.49 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.73 kB--
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.13 kB--
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.1 kB--
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.99 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.95 kB--
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.69 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.64 kB--
@sentry/nextjs (client)50.61 kB--
@sentry/sveltekit (client)46.3 kB--
@sentry/core/server76.21 kB--
@sentry/core/browser63.34 kB--
@sentry/node-core61.9 kB-0.01%-1 B 🔽
@sentry/node124.68 kB-0.01%-1 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.97 kB-0.01%-1 B 🔽
@sentry/node - without tracing74.27 kB--
@sentry/aws-serverless85.37 kB-0.01%-1 B 🔽
@sentry/cloudflare (withSentry) - minified174.55 kB--
@sentry/cloudflare (withSentry)436.86 kB--

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from e54572f to 21830a7CompareJune 15, 2026 19:46

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21830a7. Configure here.

Comment threadpackages/deno/test/orchestrion-mysql.test.ts
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 21830a7 to 1caca4fCompareJune 15, 2026 22:46
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1caca4f to 4be4406CompareJune 16, 2026 03:22
Comment threadpackages/deno/package.json
isaacs added a commit that referenced this pull request Jun 17, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4793bdc to 6b86f67CompareJune 17, 2026 06:29
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 6b86f67 to 1714284CompareJune 18, 2026 04:20
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1714284 to 79c1076CompareJune 18, 2026 04:51
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 79c1076 to 43ae63aCompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 43ae63a to 116ecbdCompareJune 18, 2026 17:25
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 116ecbd to 3acab72CompareJune 18, 2026 17:34
Base automatically changed from isaacs/bun-orchestrion to developJune 18, 2026 21:20
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 3acab72 to 26e55bdCompareJune 18, 2026 21:43
@isaacs
isaacs merged commit cb69761 into developJun 18, 2026
221 of 225 checks passed
@isaacs
isaacs deleted the isaacs/deno-orchestrion branch June 18, 2026 23:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(deno): Add orchestrion deno runtime hook - #21451

Merged
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion
Jun 18, 2026
Merged

feat(deno): Add orchestrion deno runtime hook#21451
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion loader hook defined in server-utils, and create a loader for Deno that detects the presence of the hooks, and instruments the channels added to the mysql module.

Documentation added to call out the caveat of usage in Deno v2.8.0 through 2.8.2, which is fixed in 2.8.3.

@isaacs
isaacs requested a review from a team as a code ownerJune 10, 2026 18:55
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 10, 2026 18:55
Comment threadpackages/deno/src/sdk.ts Outdated
Comment threadpackages/deno/test/orchestrion-mysql.test.ts
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from d6de7a3 to 0ceae6aCompareJune 10, 2026 19:20
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 0ceae6a to 2011bb7CompareJune 10, 2026 19:34
Comment threadpackages/deno/src/integrations/mysql.ts Outdated
Comment threadpackages/deno/src/import.mjs Outdated
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 2011bb7 to 8ab5b64CompareJune 10, 2026 20:07
Comment threadpackages/deno/src/integrations/mysql.ts
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just two minor comments

```

> [!NOTE]
> In Deno versions **2.8.0** through **2.8.2**, a bug causes Deno

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Is it worth to mention that it works in these two versions? I would be fine of just saying we are supporting everything after 2.8.3 with the --import option and don't go into much detail - but this is also ok.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I generally agree that I'd just say "we support deno 2.8.3 and above" and not really go into details for anything below that?

* orchestrion runtime hook (`@sentry/deno/import`) needs to transform libraries
* like `mysql` so they publish to their tracing channels.
*/
export const MODULE_REGISTER_HOOKS_SUPPORTED = gte(2, 8, 0);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q/l: Connected to the other comment. Should we actually start supporting it form 2.8.3?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, it's fine, I guess? Probably no one's going to be using Deno 2.8.0, but they did make a big announcement about it when it came out, and haven't been as noisy about the patches, so it's possible someone upgraded right away, but then is lagging behind, I guess?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok if they made big announcements it might be better as is.

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 8ab5b64 to 4f35ab9CompareJune 15, 2026 18:54
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4f35ab9 to e54572fCompareJune 15, 2026 19:01
@github-actions

github-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.91 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.16 kB--
@sentry/browser (incl. Tracing, Profiling)50.69 kB--
@sentry/browser (incl. Tracing, Replay)85.1 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.71 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.8 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.47 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.21 kB--
@sentry/vue32.58 kB--
@sentry/vue (incl. Tracing)47.78 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.32 kB--
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.62 kB--
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.64 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.9 kB--
CDN Bundle (incl. Tracing, Replay, Feedback)91.49 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.73 kB--
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.13 kB--
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.1 kB--
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.99 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.95 kB--
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.69 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.64 kB--
@sentry/nextjs (client)50.61 kB--
@sentry/sveltekit (client)46.3 kB--
@sentry/core/server76.21 kB--
@sentry/core/browser63.34 kB--
@sentry/node-core61.9 kB-0.01%-1 B 🔽
@sentry/node124.68 kB-0.01%-1 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.97 kB-0.01%-1 B 🔽
@sentry/node - without tracing74.27 kB--
@sentry/aws-serverless85.37 kB-0.01%-1 B 🔽
@sentry/cloudflare (withSentry) - minified174.55 kB--
@sentry/cloudflare (withSentry)436.86 kB--

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from e54572f to 21830a7CompareJune 15, 2026 19:46

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21830a7. Configure here.

Comment threadpackages/deno/test/orchestrion-mysql.test.ts
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 21830a7 to 1caca4fCompareJune 15, 2026 22:46
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1caca4f to 4be4406CompareJune 16, 2026 03:22
Comment threadpackages/deno/package.json
isaacs added a commit that referenced this pull request Jun 17, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4793bdc to 6b86f67CompareJune 17, 2026 06:29
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 6b86f67 to 1714284CompareJune 18, 2026 04:20
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1714284 to 79c1076CompareJune 18, 2026 04:51
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 79c1076 to 43ae63aCompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 43ae63a to 116ecbdCompareJune 18, 2026 17:25
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 116ecbd to 3acab72CompareJune 18, 2026 17:34
Base automatically changed from isaacs/bun-orchestrion to developJune 18, 2026 21:20
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 3acab72 to 26e55bdCompareJune 18, 2026 21:43
@isaacs
isaacs merged commit cb69761 into developJun 18, 2026
221 of 225 checks passed
@isaacs
isaacs deleted the isaacs/deno-orchestrion branch June 18, 2026 23:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(deno): Add orchestrion deno runtime hook - #21451

Merged
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion
Jun 18, 2026
Merged

feat(deno): Add orchestrion deno runtime hook#21451
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion loader hook defined in server-utils, and create a loader for Deno that detects the presence of the hooks, and instruments the channels added to the mysql module.

Documentation added to call out the caveat of usage in Deno v2.8.0 through 2.8.2, which is fixed in 2.8.3.

@isaacs
isaacs requested a review from a team as a code ownerJune 10, 2026 18:55
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 10, 2026 18:55
Comment threadpackages/deno/src/sdk.ts Outdated
Comment threadpackages/deno/test/orchestrion-mysql.test.ts
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from d6de7a3 to 0ceae6aCompareJune 10, 2026 19:20
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 0ceae6a to 2011bb7CompareJune 10, 2026 19:34
Comment threadpackages/deno/src/integrations/mysql.ts Outdated
Comment threadpackages/deno/src/import.mjs Outdated
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 2011bb7 to 8ab5b64CompareJune 10, 2026 20:07
Comment threadpackages/deno/src/integrations/mysql.ts
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just two minor comments

```

> [!NOTE]
> In Deno versions **2.8.0** through **2.8.2**, a bug causes Deno

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Is it worth to mention that it works in these two versions? I would be fine of just saying we are supporting everything after 2.8.3 with the --import option and don't go into much detail - but this is also ok.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I generally agree that I'd just say "we support deno 2.8.3 and above" and not really go into details for anything below that?

* orchestrion runtime hook (`@sentry/deno/import`) needs to transform libraries
* like `mysql` so they publish to their tracing channels.
*/
export const MODULE_REGISTER_HOOKS_SUPPORTED = gte(2, 8, 0);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q/l: Connected to the other comment. Should we actually start supporting it form 2.8.3?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, it's fine, I guess? Probably no one's going to be using Deno 2.8.0, but they did make a big announcement about it when it came out, and haven't been as noisy about the patches, so it's possible someone upgraded right away, but then is lagging behind, I guess?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok if they made big announcements it might be better as is.

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 8ab5b64 to 4f35ab9CompareJune 15, 2026 18:54
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4f35ab9 to e54572fCompareJune 15, 2026 19:01
@github-actions

github-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.91 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.16 kB--
@sentry/browser (incl. Tracing, Profiling)50.69 kB--
@sentry/browser (incl. Tracing, Replay)85.1 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.71 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.8 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.47 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.21 kB--
@sentry/vue32.58 kB--
@sentry/vue (incl. Tracing)47.78 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.32 kB--
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.62 kB--
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.64 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.9 kB--
CDN Bundle (incl. Tracing, Replay, Feedback)91.49 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.73 kB--
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.13 kB--
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.1 kB--
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.99 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.95 kB--
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.69 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.64 kB--
@sentry/nextjs (client)50.61 kB--
@sentry/sveltekit (client)46.3 kB--
@sentry/core/server76.21 kB--
@sentry/core/browser63.34 kB--
@sentry/node-core61.9 kB-0.01%-1 B 🔽
@sentry/node124.68 kB-0.01%-1 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.97 kB-0.01%-1 B 🔽
@sentry/node - without tracing74.27 kB--
@sentry/aws-serverless85.37 kB-0.01%-1 B 🔽
@sentry/cloudflare (withSentry) - minified174.55 kB--
@sentry/cloudflare (withSentry)436.86 kB--

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from e54572f to 21830a7CompareJune 15, 2026 19:46

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21830a7. Configure here.

Comment threadpackages/deno/test/orchestrion-mysql.test.ts
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 21830a7 to 1caca4fCompareJune 15, 2026 22:46
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1caca4f to 4be4406CompareJune 16, 2026 03:22
Comment threadpackages/deno/package.json
isaacs added a commit that referenced this pull request Jun 17, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4793bdc to 6b86f67CompareJune 17, 2026 06:29
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 6b86f67 to 1714284CompareJune 18, 2026 04:20
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1714284 to 79c1076CompareJune 18, 2026 04:51
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 79c1076 to 43ae63aCompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 43ae63a to 116ecbdCompareJune 18, 2026 17:25
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 116ecbd to 3acab72CompareJune 18, 2026 17:34
Base automatically changed from isaacs/bun-orchestrion to developJune 18, 2026 21:20
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 3acab72 to 26e55bdCompareJune 18, 2026 21:43
@isaacs
isaacs merged commit cb69761 into developJun 18, 2026
221 of 225 checks passed
@isaacs
isaacs deleted the isaacs/deno-orchestrion branch June 18, 2026 23:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(deno): Add orchestrion deno runtime hook - #21451

Merged
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion
Jun 18, 2026
Merged

feat(deno): Add orchestrion deno runtime hook#21451
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion loader hook defined in server-utils, and create a loader for Deno that detects the presence of the hooks, and instruments the channels added to the mysql module.

Documentation added to call out the caveat of usage in Deno v2.8.0 through 2.8.2, which is fixed in 2.8.3.

@isaacs
isaacs requested a review from a team as a code ownerJune 10, 2026 18:55
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 10, 2026 18:55
Comment threadpackages/deno/src/sdk.ts Outdated
Comment threadpackages/deno/test/orchestrion-mysql.test.ts
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from d6de7a3 to 0ceae6aCompareJune 10, 2026 19:20
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 0ceae6a to 2011bb7CompareJune 10, 2026 19:34
Comment threadpackages/deno/src/integrations/mysql.ts Outdated
Comment threadpackages/deno/src/import.mjs Outdated
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 2011bb7 to 8ab5b64CompareJune 10, 2026 20:07
Comment threadpackages/deno/src/integrations/mysql.ts
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just two minor comments

```

> [!NOTE]
> In Deno versions **2.8.0** through **2.8.2**, a bug causes Deno

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Is it worth to mention that it works in these two versions? I would be fine of just saying we are supporting everything after 2.8.3 with the --import option and don't go into much detail - but this is also ok.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I generally agree that I'd just say "we support deno 2.8.3 and above" and not really go into details for anything below that?

* orchestrion runtime hook (`@sentry/deno/import`) needs to transform libraries
* like `mysql` so they publish to their tracing channels.
*/
export const MODULE_REGISTER_HOOKS_SUPPORTED = gte(2, 8, 0);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q/l: Connected to the other comment. Should we actually start supporting it form 2.8.3?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, it's fine, I guess? Probably no one's going to be using Deno 2.8.0, but they did make a big announcement about it when it came out, and haven't been as noisy about the patches, so it's possible someone upgraded right away, but then is lagging behind, I guess?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok if they made big announcements it might be better as is.

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 8ab5b64 to 4f35ab9CompareJune 15, 2026 18:54
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4f35ab9 to e54572fCompareJune 15, 2026 19:01
@github-actions

github-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.91 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.16 kB--
@sentry/browser (incl. Tracing, Profiling)50.69 kB--
@sentry/browser (incl. Tracing, Replay)85.1 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.71 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.8 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.47 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.21 kB--
@sentry/vue32.58 kB--
@sentry/vue (incl. Tracing)47.78 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.32 kB--
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.62 kB--
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.64 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.9 kB--
CDN Bundle (incl. Tracing, Replay, Feedback)91.49 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.73 kB--
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.13 kB--
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.1 kB--
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.99 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.95 kB--
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.69 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.64 kB--
@sentry/nextjs (client)50.61 kB--
@sentry/sveltekit (client)46.3 kB--
@sentry/core/server76.21 kB--
@sentry/core/browser63.34 kB--
@sentry/node-core61.9 kB-0.01%-1 B 🔽
@sentry/node124.68 kB-0.01%-1 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.97 kB-0.01%-1 B 🔽
@sentry/node - without tracing74.27 kB--
@sentry/aws-serverless85.37 kB-0.01%-1 B 🔽
@sentry/cloudflare (withSentry) - minified174.55 kB--
@sentry/cloudflare (withSentry)436.86 kB--

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from e54572f to 21830a7CompareJune 15, 2026 19:46

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21830a7. Configure here.

Comment threadpackages/deno/test/orchestrion-mysql.test.ts
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 21830a7 to 1caca4fCompareJune 15, 2026 22:46
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1caca4f to 4be4406CompareJune 16, 2026 03:22
Comment threadpackages/deno/package.json
isaacs added a commit that referenced this pull request Jun 17, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4793bdc to 6b86f67CompareJune 17, 2026 06:29
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 6b86f67 to 1714284CompareJune 18, 2026 04:20
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1714284 to 79c1076CompareJune 18, 2026 04:51
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 79c1076 to 43ae63aCompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 43ae63a to 116ecbdCompareJune 18, 2026 17:25
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 116ecbd to 3acab72CompareJune 18, 2026 17:34
Base automatically changed from isaacs/bun-orchestrion to developJune 18, 2026 21:20
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 3acab72 to 26e55bdCompareJune 18, 2026 21:43
@isaacs
isaacs merged commit cb69761 into developJun 18, 2026
221 of 225 checks passed
@isaacs
isaacs deleted the isaacs/deno-orchestrion branch June 18, 2026 23:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(deno): Add orchestrion deno runtime hook - #21451

Merged
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion
Jun 18, 2026
Merged

feat(deno): Add orchestrion deno runtime hook#21451
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion loader hook defined in server-utils, and create a loader for Deno that detects the presence of the hooks, and instruments the channels added to the mysql module.

Documentation added to call out the caveat of usage in Deno v2.8.0 through 2.8.2, which is fixed in 2.8.3.

@isaacs
isaacs requested a review from a team as a code ownerJune 10, 2026 18:55
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 10, 2026 18:55
Comment threadpackages/deno/src/sdk.ts Outdated
Comment threadpackages/deno/test/orchestrion-mysql.test.ts
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from d6de7a3 to 0ceae6aCompareJune 10, 2026 19:20
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 0ceae6a to 2011bb7CompareJune 10, 2026 19:34
Comment threadpackages/deno/src/integrations/mysql.ts Outdated
Comment threadpackages/deno/src/import.mjs Outdated
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 2011bb7 to 8ab5b64CompareJune 10, 2026 20:07
Comment threadpackages/deno/src/integrations/mysql.ts
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just two minor comments

```

> [!NOTE]
> In Deno versions **2.8.0** through **2.8.2**, a bug causes Deno

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Is it worth to mention that it works in these two versions? I would be fine of just saying we are supporting everything after 2.8.3 with the --import option and don't go into much detail - but this is also ok.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I generally agree that I'd just say "we support deno 2.8.3 and above" and not really go into details for anything below that?

* orchestrion runtime hook (`@sentry/deno/import`) needs to transform libraries
* like `mysql` so they publish to their tracing channels.
*/
export const MODULE_REGISTER_HOOKS_SUPPORTED = gte(2, 8, 0);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q/l: Connected to the other comment. Should we actually start supporting it form 2.8.3?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, it's fine, I guess? Probably no one's going to be using Deno 2.8.0, but they did make a big announcement about it when it came out, and haven't been as noisy about the patches, so it's possible someone upgraded right away, but then is lagging behind, I guess?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok if they made big announcements it might be better as is.

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 8ab5b64 to 4f35ab9CompareJune 15, 2026 18:54
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4f35ab9 to e54572fCompareJune 15, 2026 19:01
@github-actions

github-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.91 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.16 kB--
@sentry/browser (incl. Tracing, Profiling)50.69 kB--
@sentry/browser (incl. Tracing, Replay)85.1 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.71 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.8 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.47 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.21 kB--
@sentry/vue32.58 kB--
@sentry/vue (incl. Tracing)47.78 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.32 kB--
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.62 kB--
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.64 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.9 kB--
CDN Bundle (incl. Tracing, Replay, Feedback)91.49 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.73 kB--
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.13 kB--
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.1 kB--
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.99 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.95 kB--
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.69 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.64 kB--
@sentry/nextjs (client)50.61 kB--
@sentry/sveltekit (client)46.3 kB--
@sentry/core/server76.21 kB--
@sentry/core/browser63.34 kB--
@sentry/node-core61.9 kB-0.01%-1 B 🔽
@sentry/node124.68 kB-0.01%-1 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.97 kB-0.01%-1 B 🔽
@sentry/node - without tracing74.27 kB--
@sentry/aws-serverless85.37 kB-0.01%-1 B 🔽
@sentry/cloudflare (withSentry) - minified174.55 kB--
@sentry/cloudflare (withSentry)436.86 kB--

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from e54572f to 21830a7CompareJune 15, 2026 19:46

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21830a7. Configure here.

Comment threadpackages/deno/test/orchestrion-mysql.test.ts
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 21830a7 to 1caca4fCompareJune 15, 2026 22:46
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1caca4f to 4be4406CompareJune 16, 2026 03:22
Comment threadpackages/deno/package.json
isaacs added a commit that referenced this pull request Jun 17, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4793bdc to 6b86f67CompareJune 17, 2026 06:29
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 6b86f67 to 1714284CompareJune 18, 2026 04:20
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1714284 to 79c1076CompareJune 18, 2026 04:51
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 79c1076 to 43ae63aCompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 43ae63a to 116ecbdCompareJune 18, 2026 17:25
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 116ecbd to 3acab72CompareJune 18, 2026 17:34
Base automatically changed from isaacs/bun-orchestrion to developJune 18, 2026 21:20
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 3acab72 to 26e55bdCompareJune 18, 2026 21:43
@isaacs
isaacs merged commit cb69761 into developJun 18, 2026
221 of 225 checks passed
@isaacs
isaacs deleted the isaacs/deno-orchestrion branch June 18, 2026 23:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(deno): Add orchestrion deno runtime hook - #21451

Merged
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion
Jun 18, 2026
Merged

feat(deno): Add orchestrion deno runtime hook#21451
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion loader hook defined in server-utils, and create a loader for Deno that detects the presence of the hooks, and instruments the channels added to the mysql module.

Documentation added to call out the caveat of usage in Deno v2.8.0 through 2.8.2, which is fixed in 2.8.3.

@isaacs
isaacs requested a review from a team as a code ownerJune 10, 2026 18:55
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 10, 2026 18:55
Comment threadpackages/deno/src/sdk.ts Outdated
Comment threadpackages/deno/test/orchestrion-mysql.test.ts
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from d6de7a3 to 0ceae6aCompareJune 10, 2026 19:20
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 0ceae6a to 2011bb7CompareJune 10, 2026 19:34
Comment threadpackages/deno/src/integrations/mysql.ts Outdated
Comment threadpackages/deno/src/import.mjs Outdated
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 2011bb7 to 8ab5b64CompareJune 10, 2026 20:07
Comment threadpackages/deno/src/integrations/mysql.ts
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just two minor comments

```

> [!NOTE]
> In Deno versions **2.8.0** through **2.8.2**, a bug causes Deno

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Is it worth to mention that it works in these two versions? I would be fine of just saying we are supporting everything after 2.8.3 with the --import option and don't go into much detail - but this is also ok.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I generally agree that I'd just say "we support deno 2.8.3 and above" and not really go into details for anything below that?

* orchestrion runtime hook (`@sentry/deno/import`) needs to transform libraries
* like `mysql` so they publish to their tracing channels.
*/
export const MODULE_REGISTER_HOOKS_SUPPORTED = gte(2, 8, 0);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q/l: Connected to the other comment. Should we actually start supporting it form 2.8.3?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, it's fine, I guess? Probably no one's going to be using Deno 2.8.0, but they did make a big announcement about it when it came out, and haven't been as noisy about the patches, so it's possible someone upgraded right away, but then is lagging behind, I guess?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok if they made big announcements it might be better as is.

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 8ab5b64 to 4f35ab9CompareJune 15, 2026 18:54
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4f35ab9 to e54572fCompareJune 15, 2026 19:01
@github-actions

github-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.91 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.16 kB--
@sentry/browser (incl. Tracing, Profiling)50.69 kB--
@sentry/browser (incl. Tracing, Replay)85.1 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.71 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.8 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.47 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.21 kB--
@sentry/vue32.58 kB--
@sentry/vue (incl. Tracing)47.78 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.32 kB--
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.62 kB--
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.64 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.9 kB--
CDN Bundle (incl. Tracing, Replay, Feedback)91.49 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.73 kB--
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.13 kB--
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.1 kB--
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.99 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.95 kB--
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.69 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.64 kB--
@sentry/nextjs (client)50.61 kB--
@sentry/sveltekit (client)46.3 kB--
@sentry/core/server76.21 kB--
@sentry/core/browser63.34 kB--
@sentry/node-core61.9 kB-0.01%-1 B 🔽
@sentry/node124.68 kB-0.01%-1 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.97 kB-0.01%-1 B 🔽
@sentry/node - without tracing74.27 kB--
@sentry/aws-serverless85.37 kB-0.01%-1 B 🔽
@sentry/cloudflare (withSentry) - minified174.55 kB--
@sentry/cloudflare (withSentry)436.86 kB--

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from e54572f to 21830a7CompareJune 15, 2026 19:46

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21830a7. Configure here.

Comment threadpackages/deno/test/orchestrion-mysql.test.ts
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 21830a7 to 1caca4fCompareJune 15, 2026 22:46
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1caca4f to 4be4406CompareJune 16, 2026 03:22
Comment threadpackages/deno/package.json
isaacs added a commit that referenced this pull request Jun 17, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4793bdc to 6b86f67CompareJune 17, 2026 06:29
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 6b86f67 to 1714284CompareJune 18, 2026 04:20
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1714284 to 79c1076CompareJune 18, 2026 04:51
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 79c1076 to 43ae63aCompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 43ae63a to 116ecbdCompareJune 18, 2026 17:25
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 116ecbd to 3acab72CompareJune 18, 2026 17:34
Base automatically changed from isaacs/bun-orchestrion to developJune 18, 2026 21:20
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 3acab72 to 26e55bdCompareJune 18, 2026 21:43
@isaacs
isaacs merged commit cb69761 into developJun 18, 2026
221 of 225 checks passed
@isaacs
isaacs deleted the isaacs/deno-orchestrion branch June 18, 2026 23:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(deno): Add orchestrion deno runtime hook - #21451

Merged
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion
Jun 18, 2026
Merged

feat(deno): Add orchestrion deno runtime hook#21451
isaacs merged 1 commit into
developfrom
isaacs/deno-orchestrion

Conversation

@isaacs

Copy link
Copy Markdown
Member

Use the orchestrion loader hook defined in server-utils, and create a loader for Deno that detects the presence of the hooks, and instruments the channels added to the mysql module.

Documentation added to call out the caveat of usage in Deno v2.8.0 through 2.8.2, which is fixed in 2.8.3.

@isaacs
isaacs requested a review from a team as a code ownerJune 10, 2026 18:55
@isaacs
isaacs requested review from JPeer264 and mydea and removed request for a teamJune 10, 2026 18:55
Comment threadpackages/deno/src/sdk.ts Outdated
Comment threadpackages/deno/test/orchestrion-mysql.test.ts
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from d6de7a3 to 0ceae6aCompareJune 10, 2026 19:20
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 0ceae6a to 2011bb7CompareJune 10, 2026 19:34
Comment threadpackages/deno/src/integrations/mysql.ts Outdated
Comment threadpackages/deno/src/import.mjs Outdated
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 2011bb7 to 8ab5b64CompareJune 10, 2026 20:07
Comment threadpackages/deno/src/integrations/mysql.ts
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264 — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just two minor comments

```

> [!NOTE]
> In Deno versions **2.8.0** through **2.8.2**, a bug causes Deno

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Is it worth to mention that it works in these two versions? I would be fine of just saying we are supporting everything after 2.8.3 with the --import option and don't go into much detail - but this is also ok.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I generally agree that I'd just say "we support deno 2.8.3 and above" and not really go into details for anything below that?

* orchestrion runtime hook (`@sentry/deno/import`) needs to transform libraries
* like `mysql` so they publish to their tracing channels.
*/
export const MODULE_REGISTER_HOOKS_SUPPORTED = gte(2, 8, 0);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q/l: Connected to the other comment. Should we actually start supporting it form 2.8.3?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I mean, it's fine, I guess? Probably no one's going to be using Deno 2.8.0, but they did make a big announcement about it when it came out, and haven't been as noisy about the patches, so it's possible someone upgraded right away, but then is lagging behind, I guess?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok if they made big announcements it might be better as is.

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 8ab5b64 to 4f35ab9CompareJune 15, 2026 18:54
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4f35ab9 to e54572fCompareJune 15, 2026 19:01
@github-actions

github-actionsBot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.45 kB--
@sentry/browser - with treeshaking flags25.88 kB--
@sentry/browser (incl. Tracing)45.91 kB--
@sentry/browser (incl. Tracing + Span Streaming)48.16 kB--
@sentry/browser (incl. Tracing, Profiling)50.69 kB--
@sentry/browser (incl. Tracing, Replay)85.1 kB--
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags74.71 kB--
@sentry/browser (incl. Tracing, Replay with Canvas)89.8 kB--
@sentry/browser (incl. Tracing, Replay, Feedback)102.47 kB--
@sentry/browser (incl. Feedback)44.62 kB--
@sentry/browser (incl. sendFeedback)32.25 kB--
@sentry/browser (incl. FeedbackAsync)37.38 kB--
@sentry/browser (incl. Metrics)28.52 kB--
@sentry/browser (incl. Logs)28.76 kB--
@sentry/browser (incl. Metrics & Logs)29.45 kB--
@sentry/react29.25 kB--
@sentry/react (incl. Tracing)48.21 kB--
@sentry/vue32.58 kB--
@sentry/vue (incl. Tracing)47.78 kB--
@sentry/svelte27.48 kB--
CDN Bundle29.86 kB--
CDN Bundle (incl. Tracing)48.32 kB--
CDN Bundle (incl. Logs, Metrics)31.4 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.62 kB--
CDN Bundle (incl. Replay, Logs, Metrics)70.71 kB--
CDN Bundle (incl. Tracing, Replay)85.64 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.9 kB--
CDN Bundle (incl. Tracing, Replay, Feedback)91.49 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.73 kB--
CDN Bundle - uncompressed88.8 kB--
CDN Bundle (incl. Tracing) - uncompressed146.13 kB--
CDN Bundle (incl. Logs, Metrics) - uncompressed93.5 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.1 kB--
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.33 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.99 kB--
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.95 kB--
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.69 kB--
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.64 kB--
@sentry/nextjs (client)50.61 kB--
@sentry/sveltekit (client)46.3 kB--
@sentry/core/server76.21 kB--
@sentry/core/browser63.34 kB--
@sentry/node-core61.9 kB-0.01%-1 B 🔽
@sentry/node124.68 kB-0.01%-1 B 🔽
@sentry/node/import (ESM hook with diagnostics-channel injection)70.05 kB--
@sentry/node/light50.97 kB-0.01%-1 B 🔽
@sentry/node - without tracing74.27 kB--
@sentry/aws-serverless85.37 kB-0.01%-1 B 🔽
@sentry/cloudflare (withSentry) - minified174.55 kB--
@sentry/cloudflare (withSentry)436.86 kB--

View base workflow run

@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from e54572f to 21830a7CompareJune 15, 2026 19:46

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 21830a7. Configure here.

Comment threadpackages/deno/test/orchestrion-mysql.test.ts
isaacs added a commit that referenced this pull request Jun 15, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 21830a7 to 1caca4fCompareJune 15, 2026 22:46
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 16, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1caca4f to 4be4406CompareJune 16, 2026 03:22
Comment threadpackages/deno/package.json
isaacs added a commit that referenced this pull request Jun 17, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 4793bdc to 6b86f67CompareJune 17, 2026 06:29
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 6b86f67 to 1714284CompareJune 18, 2026 04:20
Comment threadpackages/deno/src/import.mjs
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 1714284 to 79c1076CompareJune 18, 2026 04:51
@semgrep-code-getsentry

Copy link
Copy Markdown

Semgrep found 1ssc-d17d3487-883b-46a9-bec9-dee3375f7532 finding:

Risk: Affected versions of esbuild are vulnerable to Download of Code Without Integrity Check / Untrusted Search Path. esbuild's Deno distribution module (lib/deno/mod.ts) contains an import.meta.main CLI entrypoint that calls install() directly when the module is run as a script (deno run https://deno.land/x/esbuild@vX/mod.js). This download path has no SHA-256 integrity verification: if NPM_CONFIG_REGISTRY resolves to an attacker-controlled registry, the fetched binary is executed immediately, yielding arbitrary code execution without any API call in user code.

Manual Review Advice: A vulnerability from this advisory is reachable if you invoke the esbuild Deno module directly as a CLI tool (e.g. deno run https://deno.land/x/esbuild@vX/mod.js) and the NPM_CONFIG_REGISTRY environment variable resolves the binary download to an untrusted registry

Fix: Upgrade this library to at least version 0.28.1 at sentry-javascript/yarn.lock:15987.

Reference(s): GHSA-gv7w-rqvm-qjhr

isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 79c1076 to 43ae63aCompareJune 18, 2026 14:20
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 43ae63a to 116ecbdCompareJune 18, 2026 17:25
isaacs added a commit that referenced this pull request Jun 18, 2026
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 116ecbd to 3acab72CompareJune 18, 2026 17:34
Base automatically changed from isaacs/bun-orchestrion to developJune 18, 2026 21:20
Use the orchestrion loader hook defined in server-utils, and create a
loader for Deno that detects the presence of the hooks, and instruments
the channels added to the mysql module.
Documentation added to call out the caveat of usage in Deno v2.8.0
through 2.8.2, which is fixed in 2.8.3.
@isaacs
isaacsforce-pushed the isaacs/deno-orchestrion branch from 3acab72 to 26e55bdCompareJune 18, 2026 21:43
@isaacs
isaacs merged commit cb69761 into developJun 18, 2026
221 of 225 checks passed
@isaacs
isaacs deleted the isaacs/deno-orchestrion branch June 18, 2026 23:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@isaacs@mydea@JPeer264