feat(core): Seal SentryTracerProvider spans against mutation after they end - #21842

Merged
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal
Jul 2, 2026
Merged

feat(core): Seal SentryTracerProvider spans against mutation after they end#21842
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal

Conversation

@andreiborza

@andreiborzaandreiborza commented Jun 29, 2026

Copy link
Copy Markdown
Member

What

Seal spans created by the SentryTracerProvider once they end. After SentrySpan.end() finishes its end-of-span processing, every mutator no-ops, gated on the spanIsTracerProviderSpan brand:

  • setAttribute / setAttributes
  • setStatus
  • updateName
  • updateStartTime
  • addLink / addLinks
  • addEvent

Spans created directly through core (e.g. the browser SDK) are never branded, so they stay mutable.

Why

OpenTelemetry SDK spans are immutable after end() (setters no-op). The SentryTracerProvider hands native SentrySpans to OTel instrumentations as OTel spans, so they must honor that contract. Some instrumentations write to a span after end() (e.g. Next.js sets a status on a render error); without sealing, those late writes overwrite the finalized values.

This matters most once segment-span capture is deferred (#21839): the transaction snapshot is then taken on a later tick, so any late post-end() write (status, attribute, name, start time, link, or event) would be serialized into it. Sealing the span on end() keeps the finalized values intact.

Notes

  • The seal applies only to provider-branded spans. The brand is set exclusively by the OTel SentryTracer, never by the browser SDK, so browser spans (including web-vitals start-time adjustments via updateStartTime) are unaffected.
  • Tests in sentrySpan.test.ts cover both directions: a branded span where all mutators no-op after end(), and a non-branded span that stays mutable.

Stacked on #21839 (deferred capture / orphan emission) and #21666 (which provides the spanIsTracerProviderSpan brand). Dormant until #21680 wires the provider; no provider-branded spans exist before then.

Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@github-actions

github-actionsBot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.59 kB--
@sentry/browser - with treeshaking flags26.03 kB--
@sentry/browser (incl. Tracing)46.24 kB+0.46%+209 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48 kB+0.47%+222 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.01 kB+0.41%+205 B 🔺
@sentry/browser (incl. Tracing, Replay)85.49 kB+0.27%+224 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.1 kB+0.31%+225 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.19 kB+0.26%+232 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)102.84 kB+0.23%+226 B 🔺
@sentry/browser (incl. Feedback)44.76 kB--
@sentry/browser (incl. sendFeedback)32.38 kB--
@sentry/browser (incl. FeedbackAsync)37.51 kB--
@sentry/browser (incl. Metrics)28.67 kB--
@sentry/browser (incl. Logs)28.91 kB--
@sentry/browser (incl. Metrics & Logs)29.59 kB--
@sentry/react29.38 kB--
@sentry/react (incl. Tracing)48.51 kB+0.35%+169 B 🔺
@sentry/vue33.03 kB+0.64%+207 B 🔺
@sentry/vue (incl. Tracing)48.11 kB+0.43%+205 B 🔺
@sentry/svelte27.61 kB--
CDN Bundle30 kB--
CDN Bundle (incl. Tracing)48.22 kB+0.46%+219 B 🔺
CDN Bundle (incl. Logs, Metrics)31.57 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.53 kB+0.4%+194 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.77 kB--
CDN Bundle (incl. Tracing, Replay)85.68 kB+0.24%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.97 kB+0.24%+204 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.5 kB+0.22%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.77 kB+0.24%+222 B 🔺
CDN Bundle - uncompressed89.35 kB--
CDN Bundle (incl. Tracing) - uncompressed145.92 kB+0.45%+649 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.05 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed149.89 kB+0.44%+649 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.59 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.93 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.89 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.63 kB+0.24%+651 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.58 kB+0.24%+651 B 🔺
@sentry/nextjs (client)50.95 kB+0.43%+218 B 🔺
@sentry/sveltekit (client)46.65 kB+0.49%+226 B 🔺
@sentry/core/server78.28 kB+0.72%+552 B 🔺
@sentry/core/browser64.62 kB+0.88%+563 B 🔺
@sentry/node-core62.7 kB+0.53%+328 B 🔺
@sentry/node121.53 kB+0.26%+306 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.95 kB--
@sentry/node/light50.7 kB+0.47%+233 B 🔺
@sentry/node - without tracing73.05 kB+0.5%+358 B 🔺
@sentry/aws-serverless83.86 kB+0.35%+290 B 🔺
@sentry/cloudflare (withSentry) - minified181.52 kB+0.5%+900 B 🔺
@sentry/cloudflare (withSentry)449.12 kB+0.52%+2.29 kB 🔺

View base workflow run

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 920659d to 8d1b3beCompareJune 29, 2026 12:36

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dumb q but is there anything we could do to avoid having this logic hard-baked into SentrySpan? No super strong opinion, but maybe medium-strong: Ideally we can keep our SentrySpan as size-efficient as possible and rather special-case provider-emitted spans. wdyt? I might be missing something that makes this more complicated/infeasible, so feel free to disregard

@andreiborza

Copy link
Copy Markdown
MemberAuthor

@Lms24 as discussed, this adds a lot of extra code. The SentryTracerProvider doesn't instantiate spans itself, it calls core startSpan apis so there's not an easy way to instantiate spans that have this logic in them just for the tracer provider path.

This change is about 60 bytes gzipped, so I think the impact shouldn't be too bad. Also, spans should probably be finalized for core and browser as well, but that's something we can take a look at a later point.

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8d1b3be to bb677d7CompareJune 29, 2026 14:12

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @internal
*/
public updateStartTime(timeInput: SpanTimeInput): void {
if (this._frozen) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(After looking at other functions the following is a bad idea, but I'll keep it here for food for thoughts)

q: This might be an issue for a future method when we forget to add this._frozen. Would it make sense to add an this._update() function where we update certain fields and protect that?

E.g. here we would update the startTime with this._update({ startTime: '' }), while the this._update is guarded with the this._frozen check.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd rather not add more code to the SentrySpan, see Lukas' original objection. I think this kind of issue of forgetting to add is easily caught by review bots nowadays.

Also, realistically, I don't think we'll expose much more api on this class.

@andreiborza
andreiborza requested a review from a team as a code ownerJune 29, 2026 15:46
@andreiborza
andreiborza requested review from mydea and removed request for a teamJune 29, 2026 15:46
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from bb677d7 to c1392dfCompareJune 29, 2026 15:47
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from c1392df to 8fdd6d8CompareJune 30, 2026 08:13
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8fdd6d8 to 3ce0cf9CompareJune 30, 2026 08:48
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 3ce0cf9 to a416506CompareJune 30, 2026 09:57
Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9a3a9c9 to 9e658ffCompareJune 30, 2026 11:58
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9e658ff to 2e18493CompareJune 30, 2026 15:17
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 3 times, most recently from b67490f to e8e0e4dCompareJuly 1, 2026 12:43
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 22c31b8 to f66f372CompareJuly 1, 2026 18:07
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from d8228e6 to 32d6519CompareJuly 1, 2026 20:40
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 974c788 to 8a1f780CompareJuly 1, 2026 22:32

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a1f780. Configure here.

Comment threadpackages/core/test/lib/tracing/sentrySpan.test.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8a1f780 to be600f0CompareJuly 1, 2026 23:09
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from be600f0 to e7d7388CompareJuly 2, 2026 11:25
@andreiborza
andreiborza merged commit af79a23 into developJul 2, 2026
568 of 599 checks passed
@andreiborza
andreiborza deleted the ab/sentry-trace-provider-seal branch July 2, 2026 12:12
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@andreiborza@mydea@Lms24@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(core): Seal SentryTracerProvider spans against mutation after they end - #21842

Merged
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal
Jul 2, 2026
Merged

feat(core): Seal SentryTracerProvider spans against mutation after they end#21842
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal

Conversation

@andreiborza

@andreiborzaandreiborza commented Jun 29, 2026

Copy link
Copy Markdown
Member

What

Seal spans created by the SentryTracerProvider once they end. After SentrySpan.end() finishes its end-of-span processing, every mutator no-ops, gated on the spanIsTracerProviderSpan brand:

  • setAttribute / setAttributes
  • setStatus
  • updateName
  • updateStartTime
  • addLink / addLinks
  • addEvent

Spans created directly through core (e.g. the browser SDK) are never branded, so they stay mutable.

Why

OpenTelemetry SDK spans are immutable after end() (setters no-op). The SentryTracerProvider hands native SentrySpans to OTel instrumentations as OTel spans, so they must honor that contract. Some instrumentations write to a span after end() (e.g. Next.js sets a status on a render error); without sealing, those late writes overwrite the finalized values.

This matters most once segment-span capture is deferred (#21839): the transaction snapshot is then taken on a later tick, so any late post-end() write (status, attribute, name, start time, link, or event) would be serialized into it. Sealing the span on end() keeps the finalized values intact.

Notes

  • The seal applies only to provider-branded spans. The brand is set exclusively by the OTel SentryTracer, never by the browser SDK, so browser spans (including web-vitals start-time adjustments via updateStartTime) are unaffected.
  • Tests in sentrySpan.test.ts cover both directions: a branded span where all mutators no-op after end(), and a non-branded span that stays mutable.

Stacked on #21839 (deferred capture / orphan emission) and #21666 (which provides the spanIsTracerProviderSpan brand). Dormant until #21680 wires the provider; no provider-branded spans exist before then.

Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@github-actions

github-actionsBot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.59 kB--
@sentry/browser - with treeshaking flags26.03 kB--
@sentry/browser (incl. Tracing)46.24 kB+0.46%+209 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48 kB+0.47%+222 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.01 kB+0.41%+205 B 🔺
@sentry/browser (incl. Tracing, Replay)85.49 kB+0.27%+224 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.1 kB+0.31%+225 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.19 kB+0.26%+232 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)102.84 kB+0.23%+226 B 🔺
@sentry/browser (incl. Feedback)44.76 kB--
@sentry/browser (incl. sendFeedback)32.38 kB--
@sentry/browser (incl. FeedbackAsync)37.51 kB--
@sentry/browser (incl. Metrics)28.67 kB--
@sentry/browser (incl. Logs)28.91 kB--
@sentry/browser (incl. Metrics & Logs)29.59 kB--
@sentry/react29.38 kB--
@sentry/react (incl. Tracing)48.51 kB+0.35%+169 B 🔺
@sentry/vue33.03 kB+0.64%+207 B 🔺
@sentry/vue (incl. Tracing)48.11 kB+0.43%+205 B 🔺
@sentry/svelte27.61 kB--
CDN Bundle30 kB--
CDN Bundle (incl. Tracing)48.22 kB+0.46%+219 B 🔺
CDN Bundle (incl. Logs, Metrics)31.57 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.53 kB+0.4%+194 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.77 kB--
CDN Bundle (incl. Tracing, Replay)85.68 kB+0.24%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.97 kB+0.24%+204 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.5 kB+0.22%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.77 kB+0.24%+222 B 🔺
CDN Bundle - uncompressed89.35 kB--
CDN Bundle (incl. Tracing) - uncompressed145.92 kB+0.45%+649 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.05 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed149.89 kB+0.44%+649 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.59 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.93 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.89 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.63 kB+0.24%+651 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.58 kB+0.24%+651 B 🔺
@sentry/nextjs (client)50.95 kB+0.43%+218 B 🔺
@sentry/sveltekit (client)46.65 kB+0.49%+226 B 🔺
@sentry/core/server78.28 kB+0.72%+552 B 🔺
@sentry/core/browser64.62 kB+0.88%+563 B 🔺
@sentry/node-core62.7 kB+0.53%+328 B 🔺
@sentry/node121.53 kB+0.26%+306 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.95 kB--
@sentry/node/light50.7 kB+0.47%+233 B 🔺
@sentry/node - without tracing73.05 kB+0.5%+358 B 🔺
@sentry/aws-serverless83.86 kB+0.35%+290 B 🔺
@sentry/cloudflare (withSentry) - minified181.52 kB+0.5%+900 B 🔺
@sentry/cloudflare (withSentry)449.12 kB+0.52%+2.29 kB 🔺

View base workflow run

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 920659d to 8d1b3beCompareJune 29, 2026 12:36

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dumb q but is there anything we could do to avoid having this logic hard-baked into SentrySpan? No super strong opinion, but maybe medium-strong: Ideally we can keep our SentrySpan as size-efficient as possible and rather special-case provider-emitted spans. wdyt? I might be missing something that makes this more complicated/infeasible, so feel free to disregard

@andreiborza

Copy link
Copy Markdown
MemberAuthor

@Lms24 as discussed, this adds a lot of extra code. The SentryTracerProvider doesn't instantiate spans itself, it calls core startSpan apis so there's not an easy way to instantiate spans that have this logic in them just for the tracer provider path.

This change is about 60 bytes gzipped, so I think the impact shouldn't be too bad. Also, spans should probably be finalized for core and browser as well, but that's something we can take a look at a later point.

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8d1b3be to bb677d7CompareJune 29, 2026 14:12

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @internal
*/
public updateStartTime(timeInput: SpanTimeInput): void {
if (this._frozen) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(After looking at other functions the following is a bad idea, but I'll keep it here for food for thoughts)

q: This might be an issue for a future method when we forget to add this._frozen. Would it make sense to add an this._update() function where we update certain fields and protect that?

E.g. here we would update the startTime with this._update({ startTime: '' }), while the this._update is guarded with the this._frozen check.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd rather not add more code to the SentrySpan, see Lukas' original objection. I think this kind of issue of forgetting to add is easily caught by review bots nowadays.

Also, realistically, I don't think we'll expose much more api on this class.

@andreiborza
andreiborza requested a review from a team as a code ownerJune 29, 2026 15:46
@andreiborza
andreiborza requested review from mydea and removed request for a teamJune 29, 2026 15:46
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from bb677d7 to c1392dfCompareJune 29, 2026 15:47
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from c1392df to 8fdd6d8CompareJune 30, 2026 08:13
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8fdd6d8 to 3ce0cf9CompareJune 30, 2026 08:48
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 3ce0cf9 to a416506CompareJune 30, 2026 09:57
Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9a3a9c9 to 9e658ffCompareJune 30, 2026 11:58
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9e658ff to 2e18493CompareJune 30, 2026 15:17
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 3 times, most recently from b67490f to e8e0e4dCompareJuly 1, 2026 12:43
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 22c31b8 to f66f372CompareJuly 1, 2026 18:07
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from d8228e6 to 32d6519CompareJuly 1, 2026 20:40
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 974c788 to 8a1f780CompareJuly 1, 2026 22:32

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a1f780. Configure here.

Comment threadpackages/core/test/lib/tracing/sentrySpan.test.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8a1f780 to be600f0CompareJuly 1, 2026 23:09
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from be600f0 to e7d7388CompareJuly 2, 2026 11:25
@andreiborza
andreiborza merged commit af79a23 into developJul 2, 2026
568 of 599 checks passed
@andreiborza
andreiborza deleted the ab/sentry-trace-provider-seal branch July 2, 2026 12:12
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@andreiborza@mydea@Lms24@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(core): Seal SentryTracerProvider spans against mutation after they end - #21842

Merged
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal
Jul 2, 2026
Merged

feat(core): Seal SentryTracerProvider spans against mutation after they end#21842
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal

Conversation

@andreiborza

@andreiborzaandreiborza commented Jun 29, 2026

Copy link
Copy Markdown
Member

What

Seal spans created by the SentryTracerProvider once they end. After SentrySpan.end() finishes its end-of-span processing, every mutator no-ops, gated on the spanIsTracerProviderSpan brand:

  • setAttribute / setAttributes
  • setStatus
  • updateName
  • updateStartTime
  • addLink / addLinks
  • addEvent

Spans created directly through core (e.g. the browser SDK) are never branded, so they stay mutable.

Why

OpenTelemetry SDK spans are immutable after end() (setters no-op). The SentryTracerProvider hands native SentrySpans to OTel instrumentations as OTel spans, so they must honor that contract. Some instrumentations write to a span after end() (e.g. Next.js sets a status on a render error); without sealing, those late writes overwrite the finalized values.

This matters most once segment-span capture is deferred (#21839): the transaction snapshot is then taken on a later tick, so any late post-end() write (status, attribute, name, start time, link, or event) would be serialized into it. Sealing the span on end() keeps the finalized values intact.

Notes

  • The seal applies only to provider-branded spans. The brand is set exclusively by the OTel SentryTracer, never by the browser SDK, so browser spans (including web-vitals start-time adjustments via updateStartTime) are unaffected.
  • Tests in sentrySpan.test.ts cover both directions: a branded span where all mutators no-op after end(), and a non-branded span that stays mutable.

Stacked on #21839 (deferred capture / orphan emission) and #21666 (which provides the spanIsTracerProviderSpan brand). Dormant until #21680 wires the provider; no provider-branded spans exist before then.

Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@github-actions

github-actionsBot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.59 kB--
@sentry/browser - with treeshaking flags26.03 kB--
@sentry/browser (incl. Tracing)46.24 kB+0.46%+209 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48 kB+0.47%+222 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.01 kB+0.41%+205 B 🔺
@sentry/browser (incl. Tracing, Replay)85.49 kB+0.27%+224 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.1 kB+0.31%+225 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.19 kB+0.26%+232 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)102.84 kB+0.23%+226 B 🔺
@sentry/browser (incl. Feedback)44.76 kB--
@sentry/browser (incl. sendFeedback)32.38 kB--
@sentry/browser (incl. FeedbackAsync)37.51 kB--
@sentry/browser (incl. Metrics)28.67 kB--
@sentry/browser (incl. Logs)28.91 kB--
@sentry/browser (incl. Metrics & Logs)29.59 kB--
@sentry/react29.38 kB--
@sentry/react (incl. Tracing)48.51 kB+0.35%+169 B 🔺
@sentry/vue33.03 kB+0.64%+207 B 🔺
@sentry/vue (incl. Tracing)48.11 kB+0.43%+205 B 🔺
@sentry/svelte27.61 kB--
CDN Bundle30 kB--
CDN Bundle (incl. Tracing)48.22 kB+0.46%+219 B 🔺
CDN Bundle (incl. Logs, Metrics)31.57 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.53 kB+0.4%+194 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.77 kB--
CDN Bundle (incl. Tracing, Replay)85.68 kB+0.24%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.97 kB+0.24%+204 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.5 kB+0.22%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.77 kB+0.24%+222 B 🔺
CDN Bundle - uncompressed89.35 kB--
CDN Bundle (incl. Tracing) - uncompressed145.92 kB+0.45%+649 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.05 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed149.89 kB+0.44%+649 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.59 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.93 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.89 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.63 kB+0.24%+651 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.58 kB+0.24%+651 B 🔺
@sentry/nextjs (client)50.95 kB+0.43%+218 B 🔺
@sentry/sveltekit (client)46.65 kB+0.49%+226 B 🔺
@sentry/core/server78.28 kB+0.72%+552 B 🔺
@sentry/core/browser64.62 kB+0.88%+563 B 🔺
@sentry/node-core62.7 kB+0.53%+328 B 🔺
@sentry/node121.53 kB+0.26%+306 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.95 kB--
@sentry/node/light50.7 kB+0.47%+233 B 🔺
@sentry/node - without tracing73.05 kB+0.5%+358 B 🔺
@sentry/aws-serverless83.86 kB+0.35%+290 B 🔺
@sentry/cloudflare (withSentry) - minified181.52 kB+0.5%+900 B 🔺
@sentry/cloudflare (withSentry)449.12 kB+0.52%+2.29 kB 🔺

View base workflow run

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 920659d to 8d1b3beCompareJune 29, 2026 12:36

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dumb q but is there anything we could do to avoid having this logic hard-baked into SentrySpan? No super strong opinion, but maybe medium-strong: Ideally we can keep our SentrySpan as size-efficient as possible and rather special-case provider-emitted spans. wdyt? I might be missing something that makes this more complicated/infeasible, so feel free to disregard

@andreiborza

Copy link
Copy Markdown
MemberAuthor

@Lms24 as discussed, this adds a lot of extra code. The SentryTracerProvider doesn't instantiate spans itself, it calls core startSpan apis so there's not an easy way to instantiate spans that have this logic in them just for the tracer provider path.

This change is about 60 bytes gzipped, so I think the impact shouldn't be too bad. Also, spans should probably be finalized for core and browser as well, but that's something we can take a look at a later point.

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8d1b3be to bb677d7CompareJune 29, 2026 14:12

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @internal
*/
public updateStartTime(timeInput: SpanTimeInput): void {
if (this._frozen) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(After looking at other functions the following is a bad idea, but I'll keep it here for food for thoughts)

q: This might be an issue for a future method when we forget to add this._frozen. Would it make sense to add an this._update() function where we update certain fields and protect that?

E.g. here we would update the startTime with this._update({ startTime: '' }), while the this._update is guarded with the this._frozen check.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd rather not add more code to the SentrySpan, see Lukas' original objection. I think this kind of issue of forgetting to add is easily caught by review bots nowadays.

Also, realistically, I don't think we'll expose much more api on this class.

@andreiborza
andreiborza requested a review from a team as a code ownerJune 29, 2026 15:46
@andreiborza
andreiborza requested review from mydea and removed request for a teamJune 29, 2026 15:46
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from bb677d7 to c1392dfCompareJune 29, 2026 15:47
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from c1392df to 8fdd6d8CompareJune 30, 2026 08:13
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8fdd6d8 to 3ce0cf9CompareJune 30, 2026 08:48
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 3ce0cf9 to a416506CompareJune 30, 2026 09:57
Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9a3a9c9 to 9e658ffCompareJune 30, 2026 11:58
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9e658ff to 2e18493CompareJune 30, 2026 15:17
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 3 times, most recently from b67490f to e8e0e4dCompareJuly 1, 2026 12:43
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 22c31b8 to f66f372CompareJuly 1, 2026 18:07
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from d8228e6 to 32d6519CompareJuly 1, 2026 20:40
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 974c788 to 8a1f780CompareJuly 1, 2026 22:32

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a1f780. Configure here.

Comment threadpackages/core/test/lib/tracing/sentrySpan.test.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8a1f780 to be600f0CompareJuly 1, 2026 23:09
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from be600f0 to e7d7388CompareJuly 2, 2026 11:25
@andreiborza
andreiborza merged commit af79a23 into developJul 2, 2026
568 of 599 checks passed
@andreiborza
andreiborza deleted the ab/sentry-trace-provider-seal branch July 2, 2026 12:12
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@andreiborza@mydea@Lms24@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(core): Seal SentryTracerProvider spans against mutation after they end - #21842

Merged
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal
Jul 2, 2026
Merged

feat(core): Seal SentryTracerProvider spans against mutation after they end#21842
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal

Conversation

@andreiborza

@andreiborzaandreiborza commented Jun 29, 2026

Copy link
Copy Markdown
Member

What

Seal spans created by the SentryTracerProvider once they end. After SentrySpan.end() finishes its end-of-span processing, every mutator no-ops, gated on the spanIsTracerProviderSpan brand:

  • setAttribute / setAttributes
  • setStatus
  • updateName
  • updateStartTime
  • addLink / addLinks
  • addEvent

Spans created directly through core (e.g. the browser SDK) are never branded, so they stay mutable.

Why

OpenTelemetry SDK spans are immutable after end() (setters no-op). The SentryTracerProvider hands native SentrySpans to OTel instrumentations as OTel spans, so they must honor that contract. Some instrumentations write to a span after end() (e.g. Next.js sets a status on a render error); without sealing, those late writes overwrite the finalized values.

This matters most once segment-span capture is deferred (#21839): the transaction snapshot is then taken on a later tick, so any late post-end() write (status, attribute, name, start time, link, or event) would be serialized into it. Sealing the span on end() keeps the finalized values intact.

Notes

  • The seal applies only to provider-branded spans. The brand is set exclusively by the OTel SentryTracer, never by the browser SDK, so browser spans (including web-vitals start-time adjustments via updateStartTime) are unaffected.
  • Tests in sentrySpan.test.ts cover both directions: a branded span where all mutators no-op after end(), and a non-branded span that stays mutable.

Stacked on #21839 (deferred capture / orphan emission) and #21666 (which provides the spanIsTracerProviderSpan brand). Dormant until #21680 wires the provider; no provider-branded spans exist before then.

Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@github-actions

github-actionsBot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.59 kB--
@sentry/browser - with treeshaking flags26.03 kB--
@sentry/browser (incl. Tracing)46.24 kB+0.46%+209 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48 kB+0.47%+222 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.01 kB+0.41%+205 B 🔺
@sentry/browser (incl. Tracing, Replay)85.49 kB+0.27%+224 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.1 kB+0.31%+225 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.19 kB+0.26%+232 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)102.84 kB+0.23%+226 B 🔺
@sentry/browser (incl. Feedback)44.76 kB--
@sentry/browser (incl. sendFeedback)32.38 kB--
@sentry/browser (incl. FeedbackAsync)37.51 kB--
@sentry/browser (incl. Metrics)28.67 kB--
@sentry/browser (incl. Logs)28.91 kB--
@sentry/browser (incl. Metrics & Logs)29.59 kB--
@sentry/react29.38 kB--
@sentry/react (incl. Tracing)48.51 kB+0.35%+169 B 🔺
@sentry/vue33.03 kB+0.64%+207 B 🔺
@sentry/vue (incl. Tracing)48.11 kB+0.43%+205 B 🔺
@sentry/svelte27.61 kB--
CDN Bundle30 kB--
CDN Bundle (incl. Tracing)48.22 kB+0.46%+219 B 🔺
CDN Bundle (incl. Logs, Metrics)31.57 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.53 kB+0.4%+194 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.77 kB--
CDN Bundle (incl. Tracing, Replay)85.68 kB+0.24%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.97 kB+0.24%+204 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.5 kB+0.22%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.77 kB+0.24%+222 B 🔺
CDN Bundle - uncompressed89.35 kB--
CDN Bundle (incl. Tracing) - uncompressed145.92 kB+0.45%+649 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.05 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed149.89 kB+0.44%+649 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.59 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.93 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.89 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.63 kB+0.24%+651 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.58 kB+0.24%+651 B 🔺
@sentry/nextjs (client)50.95 kB+0.43%+218 B 🔺
@sentry/sveltekit (client)46.65 kB+0.49%+226 B 🔺
@sentry/core/server78.28 kB+0.72%+552 B 🔺
@sentry/core/browser64.62 kB+0.88%+563 B 🔺
@sentry/node-core62.7 kB+0.53%+328 B 🔺
@sentry/node121.53 kB+0.26%+306 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.95 kB--
@sentry/node/light50.7 kB+0.47%+233 B 🔺
@sentry/node - without tracing73.05 kB+0.5%+358 B 🔺
@sentry/aws-serverless83.86 kB+0.35%+290 B 🔺
@sentry/cloudflare (withSentry) - minified181.52 kB+0.5%+900 B 🔺
@sentry/cloudflare (withSentry)449.12 kB+0.52%+2.29 kB 🔺

View base workflow run

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 920659d to 8d1b3beCompareJune 29, 2026 12:36

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dumb q but is there anything we could do to avoid having this logic hard-baked into SentrySpan? No super strong opinion, but maybe medium-strong: Ideally we can keep our SentrySpan as size-efficient as possible and rather special-case provider-emitted spans. wdyt? I might be missing something that makes this more complicated/infeasible, so feel free to disregard

@andreiborza

Copy link
Copy Markdown
MemberAuthor

@Lms24 as discussed, this adds a lot of extra code. The SentryTracerProvider doesn't instantiate spans itself, it calls core startSpan apis so there's not an easy way to instantiate spans that have this logic in them just for the tracer provider path.

This change is about 60 bytes gzipped, so I think the impact shouldn't be too bad. Also, spans should probably be finalized for core and browser as well, but that's something we can take a look at a later point.

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8d1b3be to bb677d7CompareJune 29, 2026 14:12

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @internal
*/
public updateStartTime(timeInput: SpanTimeInput): void {
if (this._frozen) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(After looking at other functions the following is a bad idea, but I'll keep it here for food for thoughts)

q: This might be an issue for a future method when we forget to add this._frozen. Would it make sense to add an this._update() function where we update certain fields and protect that?

E.g. here we would update the startTime with this._update({ startTime: '' }), while the this._update is guarded with the this._frozen check.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd rather not add more code to the SentrySpan, see Lukas' original objection. I think this kind of issue of forgetting to add is easily caught by review bots nowadays.

Also, realistically, I don't think we'll expose much more api on this class.

@andreiborza
andreiborza requested a review from a team as a code ownerJune 29, 2026 15:46
@andreiborza
andreiborza requested review from mydea and removed request for a teamJune 29, 2026 15:46
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from bb677d7 to c1392dfCompareJune 29, 2026 15:47
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from c1392df to 8fdd6d8CompareJune 30, 2026 08:13
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8fdd6d8 to 3ce0cf9CompareJune 30, 2026 08:48
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 3ce0cf9 to a416506CompareJune 30, 2026 09:57
Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9a3a9c9 to 9e658ffCompareJune 30, 2026 11:58
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9e658ff to 2e18493CompareJune 30, 2026 15:17
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 3 times, most recently from b67490f to e8e0e4dCompareJuly 1, 2026 12:43
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 22c31b8 to f66f372CompareJuly 1, 2026 18:07
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from d8228e6 to 32d6519CompareJuly 1, 2026 20:40
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 974c788 to 8a1f780CompareJuly 1, 2026 22:32

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a1f780. Configure here.

Comment threadpackages/core/test/lib/tracing/sentrySpan.test.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8a1f780 to be600f0CompareJuly 1, 2026 23:09
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from be600f0 to e7d7388CompareJuly 2, 2026 11:25
@andreiborza
andreiborza merged commit af79a23 into developJul 2, 2026
568 of 599 checks passed
@andreiborza
andreiborza deleted the ab/sentry-trace-provider-seal branch July 2, 2026 12:12
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@andreiborza@mydea@Lms24@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(core): Seal SentryTracerProvider spans against mutation after they end - #21842

Merged
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal
Jul 2, 2026
Merged

feat(core): Seal SentryTracerProvider spans against mutation after they end#21842
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal

Conversation

@andreiborza

@andreiborzaandreiborza commented Jun 29, 2026

Copy link
Copy Markdown
Member

What

Seal spans created by the SentryTracerProvider once they end. After SentrySpan.end() finishes its end-of-span processing, every mutator no-ops, gated on the spanIsTracerProviderSpan brand:

  • setAttribute / setAttributes
  • setStatus
  • updateName
  • updateStartTime
  • addLink / addLinks
  • addEvent

Spans created directly through core (e.g. the browser SDK) are never branded, so they stay mutable.

Why

OpenTelemetry SDK spans are immutable after end() (setters no-op). The SentryTracerProvider hands native SentrySpans to OTel instrumentations as OTel spans, so they must honor that contract. Some instrumentations write to a span after end() (e.g. Next.js sets a status on a render error); without sealing, those late writes overwrite the finalized values.

This matters most once segment-span capture is deferred (#21839): the transaction snapshot is then taken on a later tick, so any late post-end() write (status, attribute, name, start time, link, or event) would be serialized into it. Sealing the span on end() keeps the finalized values intact.

Notes

  • The seal applies only to provider-branded spans. The brand is set exclusively by the OTel SentryTracer, never by the browser SDK, so browser spans (including web-vitals start-time adjustments via updateStartTime) are unaffected.
  • Tests in sentrySpan.test.ts cover both directions: a branded span where all mutators no-op after end(), and a non-branded span that stays mutable.

Stacked on #21839 (deferred capture / orphan emission) and #21666 (which provides the spanIsTracerProviderSpan brand). Dormant until #21680 wires the provider; no provider-branded spans exist before then.

Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@github-actions

github-actionsBot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.59 kB--
@sentry/browser - with treeshaking flags26.03 kB--
@sentry/browser (incl. Tracing)46.24 kB+0.46%+209 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48 kB+0.47%+222 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.01 kB+0.41%+205 B 🔺
@sentry/browser (incl. Tracing, Replay)85.49 kB+0.27%+224 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.1 kB+0.31%+225 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.19 kB+0.26%+232 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)102.84 kB+0.23%+226 B 🔺
@sentry/browser (incl. Feedback)44.76 kB--
@sentry/browser (incl. sendFeedback)32.38 kB--
@sentry/browser (incl. FeedbackAsync)37.51 kB--
@sentry/browser (incl. Metrics)28.67 kB--
@sentry/browser (incl. Logs)28.91 kB--
@sentry/browser (incl. Metrics & Logs)29.59 kB--
@sentry/react29.38 kB--
@sentry/react (incl. Tracing)48.51 kB+0.35%+169 B 🔺
@sentry/vue33.03 kB+0.64%+207 B 🔺
@sentry/vue (incl. Tracing)48.11 kB+0.43%+205 B 🔺
@sentry/svelte27.61 kB--
CDN Bundle30 kB--
CDN Bundle (incl. Tracing)48.22 kB+0.46%+219 B 🔺
CDN Bundle (incl. Logs, Metrics)31.57 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.53 kB+0.4%+194 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.77 kB--
CDN Bundle (incl. Tracing, Replay)85.68 kB+0.24%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.97 kB+0.24%+204 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.5 kB+0.22%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.77 kB+0.24%+222 B 🔺
CDN Bundle - uncompressed89.35 kB--
CDN Bundle (incl. Tracing) - uncompressed145.92 kB+0.45%+649 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.05 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed149.89 kB+0.44%+649 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.59 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.93 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.89 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.63 kB+0.24%+651 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.58 kB+0.24%+651 B 🔺
@sentry/nextjs (client)50.95 kB+0.43%+218 B 🔺
@sentry/sveltekit (client)46.65 kB+0.49%+226 B 🔺
@sentry/core/server78.28 kB+0.72%+552 B 🔺
@sentry/core/browser64.62 kB+0.88%+563 B 🔺
@sentry/node-core62.7 kB+0.53%+328 B 🔺
@sentry/node121.53 kB+0.26%+306 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.95 kB--
@sentry/node/light50.7 kB+0.47%+233 B 🔺
@sentry/node - without tracing73.05 kB+0.5%+358 B 🔺
@sentry/aws-serverless83.86 kB+0.35%+290 B 🔺
@sentry/cloudflare (withSentry) - minified181.52 kB+0.5%+900 B 🔺
@sentry/cloudflare (withSentry)449.12 kB+0.52%+2.29 kB 🔺

View base workflow run

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 920659d to 8d1b3beCompareJune 29, 2026 12:36

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dumb q but is there anything we could do to avoid having this logic hard-baked into SentrySpan? No super strong opinion, but maybe medium-strong: Ideally we can keep our SentrySpan as size-efficient as possible and rather special-case provider-emitted spans. wdyt? I might be missing something that makes this more complicated/infeasible, so feel free to disregard

@andreiborza

Copy link
Copy Markdown
MemberAuthor

@Lms24 as discussed, this adds a lot of extra code. The SentryTracerProvider doesn't instantiate spans itself, it calls core startSpan apis so there's not an easy way to instantiate spans that have this logic in them just for the tracer provider path.

This change is about 60 bytes gzipped, so I think the impact shouldn't be too bad. Also, spans should probably be finalized for core and browser as well, but that's something we can take a look at a later point.

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8d1b3be to bb677d7CompareJune 29, 2026 14:12

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @internal
*/
public updateStartTime(timeInput: SpanTimeInput): void {
if (this._frozen) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(After looking at other functions the following is a bad idea, but I'll keep it here for food for thoughts)

q: This might be an issue for a future method when we forget to add this._frozen. Would it make sense to add an this._update() function where we update certain fields and protect that?

E.g. here we would update the startTime with this._update({ startTime: '' }), while the this._update is guarded with the this._frozen check.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd rather not add more code to the SentrySpan, see Lukas' original objection. I think this kind of issue of forgetting to add is easily caught by review bots nowadays.

Also, realistically, I don't think we'll expose much more api on this class.

@andreiborza
andreiborza requested a review from a team as a code ownerJune 29, 2026 15:46
@andreiborza
andreiborza requested review from mydea and removed request for a teamJune 29, 2026 15:46
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from bb677d7 to c1392dfCompareJune 29, 2026 15:47
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from c1392df to 8fdd6d8CompareJune 30, 2026 08:13
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8fdd6d8 to 3ce0cf9CompareJune 30, 2026 08:48
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 3ce0cf9 to a416506CompareJune 30, 2026 09:57
Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9a3a9c9 to 9e658ffCompareJune 30, 2026 11:58
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9e658ff to 2e18493CompareJune 30, 2026 15:17
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 3 times, most recently from b67490f to e8e0e4dCompareJuly 1, 2026 12:43
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 22c31b8 to f66f372CompareJuly 1, 2026 18:07
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from d8228e6 to 32d6519CompareJuly 1, 2026 20:40
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 974c788 to 8a1f780CompareJuly 1, 2026 22:32

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a1f780. Configure here.

Comment threadpackages/core/test/lib/tracing/sentrySpan.test.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8a1f780 to be600f0CompareJuly 1, 2026 23:09
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from be600f0 to e7d7388CompareJuly 2, 2026 11:25
@andreiborza
andreiborza merged commit af79a23 into developJul 2, 2026
568 of 599 checks passed
@andreiborza
andreiborza deleted the ab/sentry-trace-provider-seal branch July 2, 2026 12:12
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@andreiborza@mydea@Lms24@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(core): Seal SentryTracerProvider spans against mutation after they end - #21842

Merged
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal
Jul 2, 2026
Merged

feat(core): Seal SentryTracerProvider spans against mutation after they end#21842
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal

Conversation

@andreiborza

@andreiborzaandreiborza commented Jun 29, 2026

Copy link
Copy Markdown
Member

What

Seal spans created by the SentryTracerProvider once they end. After SentrySpan.end() finishes its end-of-span processing, every mutator no-ops, gated on the spanIsTracerProviderSpan brand:

  • setAttribute / setAttributes
  • setStatus
  • updateName
  • updateStartTime
  • addLink / addLinks
  • addEvent

Spans created directly through core (e.g. the browser SDK) are never branded, so they stay mutable.

Why

OpenTelemetry SDK spans are immutable after end() (setters no-op). The SentryTracerProvider hands native SentrySpans to OTel instrumentations as OTel spans, so they must honor that contract. Some instrumentations write to a span after end() (e.g. Next.js sets a status on a render error); without sealing, those late writes overwrite the finalized values.

This matters most once segment-span capture is deferred (#21839): the transaction snapshot is then taken on a later tick, so any late post-end() write (status, attribute, name, start time, link, or event) would be serialized into it. Sealing the span on end() keeps the finalized values intact.

Notes

  • The seal applies only to provider-branded spans. The brand is set exclusively by the OTel SentryTracer, never by the browser SDK, so browser spans (including web-vitals start-time adjustments via updateStartTime) are unaffected.
  • Tests in sentrySpan.test.ts cover both directions: a branded span where all mutators no-op after end(), and a non-branded span that stays mutable.

Stacked on #21839 (deferred capture / orphan emission) and #21666 (which provides the spanIsTracerProviderSpan brand). Dormant until #21680 wires the provider; no provider-branded spans exist before then.

Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@github-actions

github-actionsBot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.59 kB--
@sentry/browser - with treeshaking flags26.03 kB--
@sentry/browser (incl. Tracing)46.24 kB+0.46%+209 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48 kB+0.47%+222 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.01 kB+0.41%+205 B 🔺
@sentry/browser (incl. Tracing, Replay)85.49 kB+0.27%+224 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.1 kB+0.31%+225 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.19 kB+0.26%+232 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)102.84 kB+0.23%+226 B 🔺
@sentry/browser (incl. Feedback)44.76 kB--
@sentry/browser (incl. sendFeedback)32.38 kB--
@sentry/browser (incl. FeedbackAsync)37.51 kB--
@sentry/browser (incl. Metrics)28.67 kB--
@sentry/browser (incl. Logs)28.91 kB--
@sentry/browser (incl. Metrics & Logs)29.59 kB--
@sentry/react29.38 kB--
@sentry/react (incl. Tracing)48.51 kB+0.35%+169 B 🔺
@sentry/vue33.03 kB+0.64%+207 B 🔺
@sentry/vue (incl. Tracing)48.11 kB+0.43%+205 B 🔺
@sentry/svelte27.61 kB--
CDN Bundle30 kB--
CDN Bundle (incl. Tracing)48.22 kB+0.46%+219 B 🔺
CDN Bundle (incl. Logs, Metrics)31.57 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.53 kB+0.4%+194 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.77 kB--
CDN Bundle (incl. Tracing, Replay)85.68 kB+0.24%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.97 kB+0.24%+204 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.5 kB+0.22%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.77 kB+0.24%+222 B 🔺
CDN Bundle - uncompressed89.35 kB--
CDN Bundle (incl. Tracing) - uncompressed145.92 kB+0.45%+649 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.05 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed149.89 kB+0.44%+649 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.59 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.93 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.89 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.63 kB+0.24%+651 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.58 kB+0.24%+651 B 🔺
@sentry/nextjs (client)50.95 kB+0.43%+218 B 🔺
@sentry/sveltekit (client)46.65 kB+0.49%+226 B 🔺
@sentry/core/server78.28 kB+0.72%+552 B 🔺
@sentry/core/browser64.62 kB+0.88%+563 B 🔺
@sentry/node-core62.7 kB+0.53%+328 B 🔺
@sentry/node121.53 kB+0.26%+306 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.95 kB--
@sentry/node/light50.7 kB+0.47%+233 B 🔺
@sentry/node - without tracing73.05 kB+0.5%+358 B 🔺
@sentry/aws-serverless83.86 kB+0.35%+290 B 🔺
@sentry/cloudflare (withSentry) - minified181.52 kB+0.5%+900 B 🔺
@sentry/cloudflare (withSentry)449.12 kB+0.52%+2.29 kB 🔺

View base workflow run

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 920659d to 8d1b3beCompareJune 29, 2026 12:36

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dumb q but is there anything we could do to avoid having this logic hard-baked into SentrySpan? No super strong opinion, but maybe medium-strong: Ideally we can keep our SentrySpan as size-efficient as possible and rather special-case provider-emitted spans. wdyt? I might be missing something that makes this more complicated/infeasible, so feel free to disregard

@andreiborza

Copy link
Copy Markdown
MemberAuthor

@Lms24 as discussed, this adds a lot of extra code. The SentryTracerProvider doesn't instantiate spans itself, it calls core startSpan apis so there's not an easy way to instantiate spans that have this logic in them just for the tracer provider path.

This change is about 60 bytes gzipped, so I think the impact shouldn't be too bad. Also, spans should probably be finalized for core and browser as well, but that's something we can take a look at a later point.

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8d1b3be to bb677d7CompareJune 29, 2026 14:12

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @internal
*/
public updateStartTime(timeInput: SpanTimeInput): void {
if (this._frozen) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(After looking at other functions the following is a bad idea, but I'll keep it here for food for thoughts)

q: This might be an issue for a future method when we forget to add this._frozen. Would it make sense to add an this._update() function where we update certain fields and protect that?

E.g. here we would update the startTime with this._update({ startTime: '' }), while the this._update is guarded with the this._frozen check.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd rather not add more code to the SentrySpan, see Lukas' original objection. I think this kind of issue of forgetting to add is easily caught by review bots nowadays.

Also, realistically, I don't think we'll expose much more api on this class.

@andreiborza
andreiborza requested a review from a team as a code ownerJune 29, 2026 15:46
@andreiborza
andreiborza requested review from mydea and removed request for a teamJune 29, 2026 15:46
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from bb677d7 to c1392dfCompareJune 29, 2026 15:47
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from c1392df to 8fdd6d8CompareJune 30, 2026 08:13
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8fdd6d8 to 3ce0cf9CompareJune 30, 2026 08:48
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 3ce0cf9 to a416506CompareJune 30, 2026 09:57
Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9a3a9c9 to 9e658ffCompareJune 30, 2026 11:58
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9e658ff to 2e18493CompareJune 30, 2026 15:17
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 3 times, most recently from b67490f to e8e0e4dCompareJuly 1, 2026 12:43
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 22c31b8 to f66f372CompareJuly 1, 2026 18:07
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from d8228e6 to 32d6519CompareJuly 1, 2026 20:40
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 974c788 to 8a1f780CompareJuly 1, 2026 22:32

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a1f780. Configure here.

Comment threadpackages/core/test/lib/tracing/sentrySpan.test.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8a1f780 to be600f0CompareJuly 1, 2026 23:09
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from be600f0 to e7d7388CompareJuly 2, 2026 11:25
@andreiborza
andreiborza merged commit af79a23 into developJul 2, 2026
568 of 599 checks passed
@andreiborza
andreiborza deleted the ab/sentry-trace-provider-seal branch July 2, 2026 12:12
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@andreiborza@mydea@Lms24@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(core): Seal SentryTracerProvider spans against mutation after they end - #21842

Merged
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal
Jul 2, 2026
Merged

feat(core): Seal SentryTracerProvider spans against mutation after they end#21842
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal

Conversation

@andreiborza

@andreiborzaandreiborza commented Jun 29, 2026

Copy link
Copy Markdown
Member

What

Seal spans created by the SentryTracerProvider once they end. After SentrySpan.end() finishes its end-of-span processing, every mutator no-ops, gated on the spanIsTracerProviderSpan brand:

  • setAttribute / setAttributes
  • setStatus
  • updateName
  • updateStartTime
  • addLink / addLinks
  • addEvent

Spans created directly through core (e.g. the browser SDK) are never branded, so they stay mutable.

Why

OpenTelemetry SDK spans are immutable after end() (setters no-op). The SentryTracerProvider hands native SentrySpans to OTel instrumentations as OTel spans, so they must honor that contract. Some instrumentations write to a span after end() (e.g. Next.js sets a status on a render error); without sealing, those late writes overwrite the finalized values.

This matters most once segment-span capture is deferred (#21839): the transaction snapshot is then taken on a later tick, so any late post-end() write (status, attribute, name, start time, link, or event) would be serialized into it. Sealing the span on end() keeps the finalized values intact.

Notes

  • The seal applies only to provider-branded spans. The brand is set exclusively by the OTel SentryTracer, never by the browser SDK, so browser spans (including web-vitals start-time adjustments via updateStartTime) are unaffected.
  • Tests in sentrySpan.test.ts cover both directions: a branded span where all mutators no-op after end(), and a non-branded span that stays mutable.

Stacked on #21839 (deferred capture / orphan emission) and #21666 (which provides the spanIsTracerProviderSpan brand). Dormant until #21680 wires the provider; no provider-branded spans exist before then.

Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@github-actions

github-actionsBot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.59 kB--
@sentry/browser - with treeshaking flags26.03 kB--
@sentry/browser (incl. Tracing)46.24 kB+0.46%+209 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48 kB+0.47%+222 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.01 kB+0.41%+205 B 🔺
@sentry/browser (incl. Tracing, Replay)85.49 kB+0.27%+224 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.1 kB+0.31%+225 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.19 kB+0.26%+232 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)102.84 kB+0.23%+226 B 🔺
@sentry/browser (incl. Feedback)44.76 kB--
@sentry/browser (incl. sendFeedback)32.38 kB--
@sentry/browser (incl. FeedbackAsync)37.51 kB--
@sentry/browser (incl. Metrics)28.67 kB--
@sentry/browser (incl. Logs)28.91 kB--
@sentry/browser (incl. Metrics & Logs)29.59 kB--
@sentry/react29.38 kB--
@sentry/react (incl. Tracing)48.51 kB+0.35%+169 B 🔺
@sentry/vue33.03 kB+0.64%+207 B 🔺
@sentry/vue (incl. Tracing)48.11 kB+0.43%+205 B 🔺
@sentry/svelte27.61 kB--
CDN Bundle30 kB--
CDN Bundle (incl. Tracing)48.22 kB+0.46%+219 B 🔺
CDN Bundle (incl. Logs, Metrics)31.57 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.53 kB+0.4%+194 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.77 kB--
CDN Bundle (incl. Tracing, Replay)85.68 kB+0.24%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.97 kB+0.24%+204 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.5 kB+0.22%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.77 kB+0.24%+222 B 🔺
CDN Bundle - uncompressed89.35 kB--
CDN Bundle (incl. Tracing) - uncompressed145.92 kB+0.45%+649 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.05 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed149.89 kB+0.44%+649 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.59 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.93 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.89 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.63 kB+0.24%+651 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.58 kB+0.24%+651 B 🔺
@sentry/nextjs (client)50.95 kB+0.43%+218 B 🔺
@sentry/sveltekit (client)46.65 kB+0.49%+226 B 🔺
@sentry/core/server78.28 kB+0.72%+552 B 🔺
@sentry/core/browser64.62 kB+0.88%+563 B 🔺
@sentry/node-core62.7 kB+0.53%+328 B 🔺
@sentry/node121.53 kB+0.26%+306 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.95 kB--
@sentry/node/light50.7 kB+0.47%+233 B 🔺
@sentry/node - without tracing73.05 kB+0.5%+358 B 🔺
@sentry/aws-serverless83.86 kB+0.35%+290 B 🔺
@sentry/cloudflare (withSentry) - minified181.52 kB+0.5%+900 B 🔺
@sentry/cloudflare (withSentry)449.12 kB+0.52%+2.29 kB 🔺

View base workflow run

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 920659d to 8d1b3beCompareJune 29, 2026 12:36

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dumb q but is there anything we could do to avoid having this logic hard-baked into SentrySpan? No super strong opinion, but maybe medium-strong: Ideally we can keep our SentrySpan as size-efficient as possible and rather special-case provider-emitted spans. wdyt? I might be missing something that makes this more complicated/infeasible, so feel free to disregard

@andreiborza

Copy link
Copy Markdown
MemberAuthor

@Lms24 as discussed, this adds a lot of extra code. The SentryTracerProvider doesn't instantiate spans itself, it calls core startSpan apis so there's not an easy way to instantiate spans that have this logic in them just for the tracer provider path.

This change is about 60 bytes gzipped, so I think the impact shouldn't be too bad. Also, spans should probably be finalized for core and browser as well, but that's something we can take a look at a later point.

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8d1b3be to bb677d7CompareJune 29, 2026 14:12

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @internal
*/
public updateStartTime(timeInput: SpanTimeInput): void {
if (this._frozen) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(After looking at other functions the following is a bad idea, but I'll keep it here for food for thoughts)

q: This might be an issue for a future method when we forget to add this._frozen. Would it make sense to add an this._update() function where we update certain fields and protect that?

E.g. here we would update the startTime with this._update({ startTime: '' }), while the this._update is guarded with the this._frozen check.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd rather not add more code to the SentrySpan, see Lukas' original objection. I think this kind of issue of forgetting to add is easily caught by review bots nowadays.

Also, realistically, I don't think we'll expose much more api on this class.

@andreiborza
andreiborza requested a review from a team as a code ownerJune 29, 2026 15:46
@andreiborza
andreiborza requested review from mydea and removed request for a teamJune 29, 2026 15:46
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from bb677d7 to c1392dfCompareJune 29, 2026 15:47
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from c1392df to 8fdd6d8CompareJune 30, 2026 08:13
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8fdd6d8 to 3ce0cf9CompareJune 30, 2026 08:48
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 3ce0cf9 to a416506CompareJune 30, 2026 09:57
Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9a3a9c9 to 9e658ffCompareJune 30, 2026 11:58
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9e658ff to 2e18493CompareJune 30, 2026 15:17
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 3 times, most recently from b67490f to e8e0e4dCompareJuly 1, 2026 12:43
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 22c31b8 to f66f372CompareJuly 1, 2026 18:07
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from d8228e6 to 32d6519CompareJuly 1, 2026 20:40
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 974c788 to 8a1f780CompareJuly 1, 2026 22:32

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a1f780. Configure here.

Comment threadpackages/core/test/lib/tracing/sentrySpan.test.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8a1f780 to be600f0CompareJuly 1, 2026 23:09
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from be600f0 to e7d7388CompareJuly 2, 2026 11:25
@andreiborza
andreiborza merged commit af79a23 into developJul 2, 2026
568 of 599 checks passed
@andreiborza
andreiborza deleted the ab/sentry-trace-provider-seal branch July 2, 2026 12:12
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@andreiborza@mydea@Lms24@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(core): Seal SentryTracerProvider spans against mutation after they end - #21842

Merged
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal
Jul 2, 2026
Merged

feat(core): Seal SentryTracerProvider spans against mutation after they end#21842
andreiborza merged 2 commits into
ab/sentry-trace-provider-core-capturefrom
ab/sentry-trace-provider-seal

Conversation

@andreiborza

@andreiborzaandreiborza commented Jun 29, 2026

Copy link
Copy Markdown
Member

What

Seal spans created by the SentryTracerProvider once they end. After SentrySpan.end() finishes its end-of-span processing, every mutator no-ops, gated on the spanIsTracerProviderSpan brand:

  • setAttribute / setAttributes
  • setStatus
  • updateName
  • updateStartTime
  • addLink / addLinks
  • addEvent

Spans created directly through core (e.g. the browser SDK) are never branded, so they stay mutable.

Why

OpenTelemetry SDK spans are immutable after end() (setters no-op). The SentryTracerProvider hands native SentrySpans to OTel instrumentations as OTel spans, so they must honor that contract. Some instrumentations write to a span after end() (e.g. Next.js sets a status on a render error); without sealing, those late writes overwrite the finalized values.

This matters most once segment-span capture is deferred (#21839): the transaction snapshot is then taken on a later tick, so any late post-end() write (status, attribute, name, start time, link, or event) would be serialized into it. Sealing the span on end() keeps the finalized values intact.

Notes

  • The seal applies only to provider-branded spans. The brand is set exclusively by the OTel SentryTracer, never by the browser SDK, so browser spans (including web-vitals start-time adjustments via updateStartTime) are unaffected.
  • Tests in sentrySpan.test.ts cover both directions: a branded span where all mutators no-op after end(), and a non-branded span that stays mutable.

Stacked on #21839 (deferred capture / orphan emission) and #21666 (which provides the spanIsTracerProviderSpan brand). Dormant until #21680 wires the provider; no provider-branded spans exist before then.

Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@github-actions

github-actionsBot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.59 kB--
@sentry/browser - with treeshaking flags26.03 kB--
@sentry/browser (incl. Tracing)46.24 kB+0.46%+209 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48 kB+0.47%+222 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.01 kB+0.41%+205 B 🔺
@sentry/browser (incl. Tracing, Replay)85.49 kB+0.27%+224 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.1 kB+0.31%+225 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.19 kB+0.26%+232 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)102.84 kB+0.23%+226 B 🔺
@sentry/browser (incl. Feedback)44.76 kB--
@sentry/browser (incl. sendFeedback)32.38 kB--
@sentry/browser (incl. FeedbackAsync)37.51 kB--
@sentry/browser (incl. Metrics)28.67 kB--
@sentry/browser (incl. Logs)28.91 kB--
@sentry/browser (incl. Metrics & Logs)29.59 kB--
@sentry/react29.38 kB--
@sentry/react (incl. Tracing)48.51 kB+0.35%+169 B 🔺
@sentry/vue33.03 kB+0.64%+207 B 🔺
@sentry/vue (incl. Tracing)48.11 kB+0.43%+205 B 🔺
@sentry/svelte27.61 kB--
CDN Bundle30 kB--
CDN Bundle (incl. Tracing)48.22 kB+0.46%+219 B 🔺
CDN Bundle (incl. Logs, Metrics)31.57 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)49.53 kB+0.4%+194 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.77 kB--
CDN Bundle (incl. Tracing, Replay)85.68 kB+0.24%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)86.97 kB+0.24%+204 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.5 kB+0.22%+200 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.77 kB+0.24%+222 B 🔺
CDN Bundle - uncompressed89.35 kB--
CDN Bundle (incl. Tracing) - uncompressed145.92 kB+0.45%+649 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.05 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed149.89 kB+0.44%+649 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed218.59 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed264.93 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed268.89 kB+0.25%+649 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed278.63 kB+0.24%+651 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed282.58 kB+0.24%+651 B 🔺
@sentry/nextjs (client)50.95 kB+0.43%+218 B 🔺
@sentry/sveltekit (client)46.65 kB+0.49%+226 B 🔺
@sentry/core/server78.28 kB+0.72%+552 B 🔺
@sentry/core/browser64.62 kB+0.88%+563 B 🔺
@sentry/node-core62.7 kB+0.53%+328 B 🔺
@sentry/node121.53 kB+0.26%+306 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.95 kB--
@sentry/node/light50.7 kB+0.47%+233 B 🔺
@sentry/node - without tracing73.05 kB+0.5%+358 B 🔺
@sentry/aws-serverless83.86 kB+0.35%+290 B 🔺
@sentry/cloudflare (withSentry) - minified181.52 kB+0.5%+900 B 🔺
@sentry/cloudflare (withSentry)449.12 kB+0.52%+2.29 kB 🔺

View base workflow run

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 920659d to 8d1b3beCompareJune 29, 2026 12:36

@Lms24Lms24 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

dumb q but is there anything we could do to avoid having this logic hard-baked into SentrySpan? No super strong opinion, but maybe medium-strong: Ideally we can keep our SentrySpan as size-efficient as possible and rather special-case provider-emitted spans. wdyt? I might be missing something that makes this more complicated/infeasible, so feel free to disregard

@andreiborza

Copy link
Copy Markdown
MemberAuthor

@Lms24 as discussed, this adds a lot of extra code. The SentryTracerProvider doesn't instantiate spans itself, it calls core startSpan apis so there's not an easy way to instantiate spans that have this logic in them just for the tracer provider path.

This change is about 60 bytes gzipped, so I think the impact shouldn't be too bad. Also, spans should probably be finalized for core and browser as well, but that's something we can take a look at a later point.

@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8d1b3be to bb677d7CompareJune 29, 2026 14:12

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

* @internal
*/
public updateStartTime(timeInput: SpanTimeInput): void {
if (this._frozen) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(After looking at other functions the following is a bad idea, but I'll keep it here for food for thoughts)

q: This might be an issue for a future method when we forget to add this._frozen. Would it make sense to add an this._update() function where we update certain fields and protect that?

E.g. here we would update the startTime with this._update({ startTime: '' }), while the this._update is guarded with the this._frozen check.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd rather not add more code to the SentrySpan, see Lukas' original objection. I think this kind of issue of forgetting to add is easily caught by review bots nowadays.

Also, realistically, I don't think we'll expose much more api on this class.

@andreiborza
andreiborza requested a review from a team as a code ownerJune 29, 2026 15:46
@andreiborza
andreiborza requested review from mydea and removed request for a teamJune 29, 2026 15:46
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from bb677d7 to c1392dfCompareJune 29, 2026 15:47
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from c1392df to 8fdd6d8CompareJune 30, 2026 08:13
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8fdd6d8 to 3ce0cf9CompareJune 30, 2026 08:48
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 3ce0cf9 to a416506CompareJune 30, 2026 09:57
Comment threadpackages/core/src/tracing/sentrySpan.ts
Comment threadpackages/core/src/tracing/sentrySpan.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9a3a9c9 to 9e658ffCompareJune 30, 2026 11:58
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 9e658ff to 2e18493CompareJune 30, 2026 15:17
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 3 times, most recently from b67490f to e8e0e4dCompareJuly 1, 2026 12:43
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 22c31b8 to f66f372CompareJuly 1, 2026 18:07
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from d8228e6 to 32d6519CompareJuly 1, 2026 20:40
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch 2 times, most recently from 974c788 to 8a1f780CompareJuly 1, 2026 22:32

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8a1f780. Configure here.

Comment threadpackages/core/test/lib/tracing/sentrySpan.test.ts
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from 8a1f780 to be600f0CompareJuly 1, 2026 23:09
@andreiborza
andreiborzaforce-pushed the ab/sentry-trace-provider-seal branch from be600f0 to e7d7388CompareJuly 2, 2026 11:25
@andreiborza
andreiborza merged commit af79a23 into developJul 2, 2026
568 of 599 checks passed
@andreiborza
andreiborza deleted the ab/sentry-trace-provider-seal branch July 2, 2026 12:12
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@andreiborza@mydea@Lms24@JPeer264@nicohrubec