feat(cloudflare): Instrument Cloudflare rate limiter bindings - #22035

Merged
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation
Jul 17, 2026
Merged

feat(cloudflare): Instrument Cloudflare rate limiter bindings#22035
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation

Conversation

@PeterWadie

@PeterWadiePeterWadie commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Adds automatic tracing for Cloudflare Workers rate limiter bindings, mirroring the existing R2/Queue/D1 binding instrumentation. When a RateLimit binding is accessed on env, its limit() calls are wrapped in a span.

Details

  • New instrumentRateLimit wraps the binding in a Proxy and starts a span named rate_limit <binding> around limit(), with the standard auto.faas.cloudflare.rate_limit origin.
  • Detection uses a limit duck-type in isBinding, wired into instrumentEnv after the more specific Queue/R2/D1 checks so those win when a binding also happens to expose limit.
  • The rate limit key is intentionally not recorded, since it commonly contains user-identifying data (e.g. an IP address or user id).
  • Cloudflare does not emit a native span for the rate limiter binding, so no op or custom cloudflare.rate_limit.* attributes are set for now. These can be added later if/when they land in Sentry's semantic conventions.
  • Includes unit tests plus an integration suite covering both an allowed call and a rate-limited (success: false) call.

Fixes#20871

Automatically wraps limit() calls on Cloudflare rate limiter bindings in a span, mirroring the existing R2/Queue/D1 binding instrumentation. The rate-limited outcome is recorded via a span attribute rather than an error status, and the rate limit key is not recorded to avoid leaking PII.
CopilotAI review requested due to automatic review settings July 8, 2026 02:07
@PeterWadie
PeterWadie requested a review from a team as a code ownerJuly 8, 2026 02:07
@PeterWadie
PeterWadie requested review from JPeer264, andreiborza and mydea and removed request for a teamJuly 8, 2026 02:07

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 53a0a03. Configure here.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds first-class tracing support for Cloudflare Workers RateLimit bindings in @sentry/cloudflare. The implementation follows the existing env-binding model (D1 / Queue / R2) by detecting the binding on env access, proxy-wrapping it, and creating a span around each limit() call while recording the outcome as a span attribute (without capturing the key to avoid PII).

Changes:

  • Add isRateLimit duck-typing to detect RateLimit bindings (limit method + not JSRPC).
  • Instrument env access to wrap detected RateLimit bindings and cache the wrapped proxy.
  • Introduce instrumentRateLimit which creates a ratelimit span per limit() call and records cloudflare.rate_limit.success.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/cloudflare/src/utils/isBinding.tsAdds isRateLimit duck-type guard for RateLimit bindings.
packages/cloudflare/src/instrumentations/worker/instrumentRateLimit.tsNew instrumentation proxy that wraps limit() with a span and records the success outcome.
packages/cloudflare/src/instrumentations/worker/instrumentEnv.tsWires RateLimit detection into env proxying + caching alongside existing binding instrumentation.
packages/cloudflare/test/utils/isBinding.test.tsAdds unit coverage for isRateLimit behavior (including JSRPC proxy exclusion).
packages/cloudflare/test/instrumentations/worker/instrumentRateLimit.test.tsAdds unit tests for span creation/attributes, forwarding behavior, and avoiding key/PII capture.
packages/cloudflare/test/instrumentations/instrumentEnv.test.tsAdds tests for env detection, wrapping, forwarding, and caching of RateLimit bindings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Adds an integration suite that exercises a real rate limiter binding through wrangler and asserts the emitted ratelimit span and its attributes, matching the coverage of the R2 and Queue binding instrumentations.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the spy creation into beforeEach with vi.restoreAllMocks() in afterEach, so each test gets a fresh spy.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

return startSpan(
{
op: OP,
name: `rate_limit ${bindingName}`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Did you cross-check with Cloudflare's own spans if these are the same there? We try to be as close to span naming as possible to what Cloudflare produces.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-checked: Cloudflare doesn't emit a native span for the rate limiter binding. It's not among their auto-traced bindings (KV/R2/DO), and their docs point to HTTP 429s or Analytics Engine for rate-limit observability rather than a span. So the op and cloudflare.rate_limit.* attributes had no Cloudflare-native equivalent to match. I've removed them and kept just the span plus the standard auto.faas.cloudflare.rate_limit origin.

export function instrumentRateLimit<T extends RateLimit>(rateLimit: T, bindingName: string): T {
return new Proxy(rateLimit, {
get(target, prop, receiver) {
if (prop === 'limit') {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It would be nice if you could switch to a fail fast approach and start with the following:

if(prop!=='limit'){returnReflect.get(target,prop,receiver);}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — the handler now returns early: if (prop !== 'limit') return Reflect.get(target, prop, receiver);.

op: OP,
name: `rate_limit ${bindingName}`,
attributes: {
'cloudflare.rate_limit.binding': bindingName,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Before we add this we need to add it in our semantic conventions (I could add it). However, before this will be moved to semantic conventions, is this attribute in the original Cloudflare span as well? If it is not I don't think we should add it here for now

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed. It's not present in Cloudflare's native span (details in the cross-check thread), so it's out for now. Happy to re-add cloudflare.rate_limit.* if/when it's added to the semantic conventions.

import { SEMANTIC_ATTRIBUTE_SENTRY_OP, SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';

const ORIGIN = 'auto.faas.cloudflare.rate_limit';
const OP = 'ratelimit';

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: ratelimit is not part of our official span operations (yet). I have to clarify if we actually need that - but for now please remove the OP entirely. We can always add this later here and in the docs later on as a feature.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the op entirely.

},
async span => {
const outcome = await Reflect.apply(original, target, [options]);
span.setAttribute('cloudflare.rate_limit.success', outcome.success);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Same as the others, is this attribute added in Cloudflare's spans?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed for the same reason (not in Cloudflare's native span). The rate-limited (success: false) outcome is now covered by the integration test via the response instead of a span attribute.

const spans = findSpans(envelope, 'rate_limit MY_RATE_LIMITER');
expect(spans).toHaveLength(1);
const data = spanData(spans[0]!);
expect({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Please use the following syntax (I saw it slipped through in the R2 tests, I'll remove that there in a PR):

constevent=envelopeItem(envelope);expect(event.spans).toEqual([
...
])

You can check out the D1 tests, these should match the expected assertions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Switched to the D1-style assertion (const event = envelopeItem(envelope); expect(event.spans).toEqual([...])).

return span.data as Record<string, unknown>;
}

it('emits a ratelimit span with the binding name and success outcome', async ({ signal }) => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It'd be nice if there would be a case to check if the .success is also false. Right now we only check agains true, but we would never know if this would be working correctly for the ratelimit to not be active/hitting

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a /ratelimit/blocked case: the binding's limit is set to 1, so the second limit() call within the period is rate limited. The test asserts the response is { success: false } and that both calls are still instrumented. Since the success attribute was removed, the rate-limited outcome is verified via the response.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Remove the non-standard ratelimit span op and the cloudflare.rate_limit.* attributes (keeping the standard origin), fail-fast in the Proxy handler, and align the integration test with the D1 assertion style plus a rate-limited case.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.

@@ -0,0 +1,31 @@
import type { RateLimit, RateLimitOptions, RateLimitOutcome } from '@cloudflare/workers-types';
import { SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';
Comment on lines +18 to +28
return function (this: unknown, options: RateLimitOptions): Promise<RateLimitOutcome> {
return startSpan(
{
name: `rate_limit ${bindingName}`,
attributes: {
[SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN]: ORIGIN,
},
},
() => Reflect.apply(original, target, [options]),
);
};
Comment on lines +49 to +57
expect(startSpanSpy).toHaveBeenLastCalledWith(
{
name: 'rate_limit MY_RATE_LIMITER',
attributes: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
},
expect.any(Function),
);
Comment on lines +58 to +60
});

test('does not record the rate limit key (avoids leaking PII)', async () => {
Comment on lines +13 to +17
function findRateLimitSpans(envelope: Envelope): Array<Record<string, unknown>> {
if (envelopeItemType(envelope) !== 'transaction') return [];
const spans = (envelopeItem(envelope).spans as Array<Record<string, unknown>>) || [];
return spans.filter(s => s.origin === 'auto.faas.cloudflare.rate_limit');
}
Comment on lines +22 to +40
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
const event = envelopeItem(envelope);

expect(event.spans).toEqual([
{
data: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
description: 'rate_limit MY_RATE_LIMITER',
origin: 'auto.faas.cloudflare.rate_limit',
parent_span_id: expect.any(String),
span_id: expect.any(String),
start_timestamp: expect.any(Number),
timestamp: expect.any(Number),
trace_id: expect.any(String),
},
]);
})
Comment on lines +51 to +55
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
// Both `limit()` calls on the blocked endpoint are instrumented.
expect(findRateLimitSpans(envelope)).toHaveLength(2);
})
@PeterWadie
PeterWadie requested a review from CopilotJuly 13, 2026 23:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@PeterWadie
PeterWadie requested a review from JPeer264July 13, 2026 23:35
@PeterWadie
PeterWadie requested a review from CopilotJuly 14, 2026 20:27

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks a lot for your contributions.

@JPeer264
JPeer264 merged commit ea3764e into getsentry:developJul 17, 2026
154 of 156 checks passed
nicohrubec pushed a commit that referenced this pull request Jul 17, 2026
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #22035
Co-authored-by: JPeer264 <10677263+JPeer264@users.noreply.github.com>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloudflare instrument rate limiter

3 participants

@PeterWadie@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(cloudflare): Instrument Cloudflare rate limiter bindings - #22035

Merged
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation
Jul 17, 2026
Merged

feat(cloudflare): Instrument Cloudflare rate limiter bindings#22035
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation

Conversation

@PeterWadie

@PeterWadiePeterWadie commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Adds automatic tracing for Cloudflare Workers rate limiter bindings, mirroring the existing R2/Queue/D1 binding instrumentation. When a RateLimit binding is accessed on env, its limit() calls are wrapped in a span.

Details

  • New instrumentRateLimit wraps the binding in a Proxy and starts a span named rate_limit <binding> around limit(), with the standard auto.faas.cloudflare.rate_limit origin.
  • Detection uses a limit duck-type in isBinding, wired into instrumentEnv after the more specific Queue/R2/D1 checks so those win when a binding also happens to expose limit.
  • The rate limit key is intentionally not recorded, since it commonly contains user-identifying data (e.g. an IP address or user id).
  • Cloudflare does not emit a native span for the rate limiter binding, so no op or custom cloudflare.rate_limit.* attributes are set for now. These can be added later if/when they land in Sentry's semantic conventions.
  • Includes unit tests plus an integration suite covering both an allowed call and a rate-limited (success: false) call.

Fixes#20871

Automatically wraps limit() calls on Cloudflare rate limiter bindings in a span, mirroring the existing R2/Queue/D1 binding instrumentation. The rate-limited outcome is recorded via a span attribute rather than an error status, and the rate limit key is not recorded to avoid leaking PII.
CopilotAI review requested due to automatic review settings July 8, 2026 02:07
@PeterWadie
PeterWadie requested a review from a team as a code ownerJuly 8, 2026 02:07
@PeterWadie
PeterWadie requested review from JPeer264, andreiborza and mydea and removed request for a teamJuly 8, 2026 02:07

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 53a0a03. Configure here.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds first-class tracing support for Cloudflare Workers RateLimit bindings in @sentry/cloudflare. The implementation follows the existing env-binding model (D1 / Queue / R2) by detecting the binding on env access, proxy-wrapping it, and creating a span around each limit() call while recording the outcome as a span attribute (without capturing the key to avoid PII).

Changes:

  • Add isRateLimit duck-typing to detect RateLimit bindings (limit method + not JSRPC).
  • Instrument env access to wrap detected RateLimit bindings and cache the wrapped proxy.
  • Introduce instrumentRateLimit which creates a ratelimit span per limit() call and records cloudflare.rate_limit.success.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/cloudflare/src/utils/isBinding.tsAdds isRateLimit duck-type guard for RateLimit bindings.
packages/cloudflare/src/instrumentations/worker/instrumentRateLimit.tsNew instrumentation proxy that wraps limit() with a span and records the success outcome.
packages/cloudflare/src/instrumentations/worker/instrumentEnv.tsWires RateLimit detection into env proxying + caching alongside existing binding instrumentation.
packages/cloudflare/test/utils/isBinding.test.tsAdds unit coverage for isRateLimit behavior (including JSRPC proxy exclusion).
packages/cloudflare/test/instrumentations/worker/instrumentRateLimit.test.tsAdds unit tests for span creation/attributes, forwarding behavior, and avoiding key/PII capture.
packages/cloudflare/test/instrumentations/instrumentEnv.test.tsAdds tests for env detection, wrapping, forwarding, and caching of RateLimit bindings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Adds an integration suite that exercises a real rate limiter binding through wrangler and asserts the emitted ratelimit span and its attributes, matching the coverage of the R2 and Queue binding instrumentations.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the spy creation into beforeEach with vi.restoreAllMocks() in afterEach, so each test gets a fresh spy.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

return startSpan(
{
op: OP,
name: `rate_limit ${bindingName}`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Did you cross-check with Cloudflare's own spans if these are the same there? We try to be as close to span naming as possible to what Cloudflare produces.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-checked: Cloudflare doesn't emit a native span for the rate limiter binding. It's not among their auto-traced bindings (KV/R2/DO), and their docs point to HTTP 429s or Analytics Engine for rate-limit observability rather than a span. So the op and cloudflare.rate_limit.* attributes had no Cloudflare-native equivalent to match. I've removed them and kept just the span plus the standard auto.faas.cloudflare.rate_limit origin.

export function instrumentRateLimit<T extends RateLimit>(rateLimit: T, bindingName: string): T {
return new Proxy(rateLimit, {
get(target, prop, receiver) {
if (prop === 'limit') {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It would be nice if you could switch to a fail fast approach and start with the following:

if(prop!=='limit'){returnReflect.get(target,prop,receiver);}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — the handler now returns early: if (prop !== 'limit') return Reflect.get(target, prop, receiver);.

op: OP,
name: `rate_limit ${bindingName}`,
attributes: {
'cloudflare.rate_limit.binding': bindingName,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Before we add this we need to add it in our semantic conventions (I could add it). However, before this will be moved to semantic conventions, is this attribute in the original Cloudflare span as well? If it is not I don't think we should add it here for now

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed. It's not present in Cloudflare's native span (details in the cross-check thread), so it's out for now. Happy to re-add cloudflare.rate_limit.* if/when it's added to the semantic conventions.

import { SEMANTIC_ATTRIBUTE_SENTRY_OP, SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';

const ORIGIN = 'auto.faas.cloudflare.rate_limit';
const OP = 'ratelimit';

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: ratelimit is not part of our official span operations (yet). I have to clarify if we actually need that - but for now please remove the OP entirely. We can always add this later here and in the docs later on as a feature.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the op entirely.

},
async span => {
const outcome = await Reflect.apply(original, target, [options]);
span.setAttribute('cloudflare.rate_limit.success', outcome.success);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Same as the others, is this attribute added in Cloudflare's spans?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed for the same reason (not in Cloudflare's native span). The rate-limited (success: false) outcome is now covered by the integration test via the response instead of a span attribute.

const spans = findSpans(envelope, 'rate_limit MY_RATE_LIMITER');
expect(spans).toHaveLength(1);
const data = spanData(spans[0]!);
expect({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Please use the following syntax (I saw it slipped through in the R2 tests, I'll remove that there in a PR):

constevent=envelopeItem(envelope);expect(event.spans).toEqual([
...
])

You can check out the D1 tests, these should match the expected assertions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Switched to the D1-style assertion (const event = envelopeItem(envelope); expect(event.spans).toEqual([...])).

return span.data as Record<string, unknown>;
}

it('emits a ratelimit span with the binding name and success outcome', async ({ signal }) => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It'd be nice if there would be a case to check if the .success is also false. Right now we only check agains true, but we would never know if this would be working correctly for the ratelimit to not be active/hitting

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a /ratelimit/blocked case: the binding's limit is set to 1, so the second limit() call within the period is rate limited. The test asserts the response is { success: false } and that both calls are still instrumented. Since the success attribute was removed, the rate-limited outcome is verified via the response.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Remove the non-standard ratelimit span op and the cloudflare.rate_limit.* attributes (keeping the standard origin), fail-fast in the Proxy handler, and align the integration test with the D1 assertion style plus a rate-limited case.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.

@@ -0,0 +1,31 @@
import type { RateLimit, RateLimitOptions, RateLimitOutcome } from '@cloudflare/workers-types';
import { SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';
Comment on lines +18 to +28
return function (this: unknown, options: RateLimitOptions): Promise<RateLimitOutcome> {
return startSpan(
{
name: `rate_limit ${bindingName}`,
attributes: {
[SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN]: ORIGIN,
},
},
() => Reflect.apply(original, target, [options]),
);
};
Comment on lines +49 to +57
expect(startSpanSpy).toHaveBeenLastCalledWith(
{
name: 'rate_limit MY_RATE_LIMITER',
attributes: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
},
expect.any(Function),
);
Comment on lines +58 to +60
});

test('does not record the rate limit key (avoids leaking PII)', async () => {
Comment on lines +13 to +17
function findRateLimitSpans(envelope: Envelope): Array<Record<string, unknown>> {
if (envelopeItemType(envelope) !== 'transaction') return [];
const spans = (envelopeItem(envelope).spans as Array<Record<string, unknown>>) || [];
return spans.filter(s => s.origin === 'auto.faas.cloudflare.rate_limit');
}
Comment on lines +22 to +40
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
const event = envelopeItem(envelope);

expect(event.spans).toEqual([
{
data: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
description: 'rate_limit MY_RATE_LIMITER',
origin: 'auto.faas.cloudflare.rate_limit',
parent_span_id: expect.any(String),
span_id: expect.any(String),
start_timestamp: expect.any(Number),
timestamp: expect.any(Number),
trace_id: expect.any(String),
},
]);
})
Comment on lines +51 to +55
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
// Both `limit()` calls on the blocked endpoint are instrumented.
expect(findRateLimitSpans(envelope)).toHaveLength(2);
})
@PeterWadie
PeterWadie requested a review from CopilotJuly 13, 2026 23:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@PeterWadie
PeterWadie requested a review from JPeer264July 13, 2026 23:35
@PeterWadie
PeterWadie requested a review from CopilotJuly 14, 2026 20:27

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks a lot for your contributions.

@JPeer264
JPeer264 merged commit ea3764e into getsentry:developJul 17, 2026
154 of 156 checks passed
nicohrubec pushed a commit that referenced this pull request Jul 17, 2026
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #22035
Co-authored-by: JPeer264 <10677263+JPeer264@users.noreply.github.com>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloudflare instrument rate limiter

3 participants

@PeterWadie@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(cloudflare): Instrument Cloudflare rate limiter bindings - #22035

Merged
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation
Jul 17, 2026
Merged

feat(cloudflare): Instrument Cloudflare rate limiter bindings#22035
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation

Conversation

@PeterWadie

@PeterWadiePeterWadie commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Adds automatic tracing for Cloudflare Workers rate limiter bindings, mirroring the existing R2/Queue/D1 binding instrumentation. When a RateLimit binding is accessed on env, its limit() calls are wrapped in a span.

Details

  • New instrumentRateLimit wraps the binding in a Proxy and starts a span named rate_limit <binding> around limit(), with the standard auto.faas.cloudflare.rate_limit origin.
  • Detection uses a limit duck-type in isBinding, wired into instrumentEnv after the more specific Queue/R2/D1 checks so those win when a binding also happens to expose limit.
  • The rate limit key is intentionally not recorded, since it commonly contains user-identifying data (e.g. an IP address or user id).
  • Cloudflare does not emit a native span for the rate limiter binding, so no op or custom cloudflare.rate_limit.* attributes are set for now. These can be added later if/when they land in Sentry's semantic conventions.
  • Includes unit tests plus an integration suite covering both an allowed call and a rate-limited (success: false) call.

Fixes#20871

Automatically wraps limit() calls on Cloudflare rate limiter bindings in a span, mirroring the existing R2/Queue/D1 binding instrumentation. The rate-limited outcome is recorded via a span attribute rather than an error status, and the rate limit key is not recorded to avoid leaking PII.
CopilotAI review requested due to automatic review settings July 8, 2026 02:07
@PeterWadie
PeterWadie requested a review from a team as a code ownerJuly 8, 2026 02:07
@PeterWadie
PeterWadie requested review from JPeer264, andreiborza and mydea and removed request for a teamJuly 8, 2026 02:07

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 53a0a03. Configure here.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds first-class tracing support for Cloudflare Workers RateLimit bindings in @sentry/cloudflare. The implementation follows the existing env-binding model (D1 / Queue / R2) by detecting the binding on env access, proxy-wrapping it, and creating a span around each limit() call while recording the outcome as a span attribute (without capturing the key to avoid PII).

Changes:

  • Add isRateLimit duck-typing to detect RateLimit bindings (limit method + not JSRPC).
  • Instrument env access to wrap detected RateLimit bindings and cache the wrapped proxy.
  • Introduce instrumentRateLimit which creates a ratelimit span per limit() call and records cloudflare.rate_limit.success.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/cloudflare/src/utils/isBinding.tsAdds isRateLimit duck-type guard for RateLimit bindings.
packages/cloudflare/src/instrumentations/worker/instrumentRateLimit.tsNew instrumentation proxy that wraps limit() with a span and records the success outcome.
packages/cloudflare/src/instrumentations/worker/instrumentEnv.tsWires RateLimit detection into env proxying + caching alongside existing binding instrumentation.
packages/cloudflare/test/utils/isBinding.test.tsAdds unit coverage for isRateLimit behavior (including JSRPC proxy exclusion).
packages/cloudflare/test/instrumentations/worker/instrumentRateLimit.test.tsAdds unit tests for span creation/attributes, forwarding behavior, and avoiding key/PII capture.
packages/cloudflare/test/instrumentations/instrumentEnv.test.tsAdds tests for env detection, wrapping, forwarding, and caching of RateLimit bindings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Adds an integration suite that exercises a real rate limiter binding through wrangler and asserts the emitted ratelimit span and its attributes, matching the coverage of the R2 and Queue binding instrumentations.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the spy creation into beforeEach with vi.restoreAllMocks() in afterEach, so each test gets a fresh spy.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

return startSpan(
{
op: OP,
name: `rate_limit ${bindingName}`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Did you cross-check with Cloudflare's own spans if these are the same there? We try to be as close to span naming as possible to what Cloudflare produces.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-checked: Cloudflare doesn't emit a native span for the rate limiter binding. It's not among their auto-traced bindings (KV/R2/DO), and their docs point to HTTP 429s or Analytics Engine for rate-limit observability rather than a span. So the op and cloudflare.rate_limit.* attributes had no Cloudflare-native equivalent to match. I've removed them and kept just the span plus the standard auto.faas.cloudflare.rate_limit origin.

export function instrumentRateLimit<T extends RateLimit>(rateLimit: T, bindingName: string): T {
return new Proxy(rateLimit, {
get(target, prop, receiver) {
if (prop === 'limit') {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It would be nice if you could switch to a fail fast approach and start with the following:

if(prop!=='limit'){returnReflect.get(target,prop,receiver);}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — the handler now returns early: if (prop !== 'limit') return Reflect.get(target, prop, receiver);.

op: OP,
name: `rate_limit ${bindingName}`,
attributes: {
'cloudflare.rate_limit.binding': bindingName,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Before we add this we need to add it in our semantic conventions (I could add it). However, before this will be moved to semantic conventions, is this attribute in the original Cloudflare span as well? If it is not I don't think we should add it here for now

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed. It's not present in Cloudflare's native span (details in the cross-check thread), so it's out for now. Happy to re-add cloudflare.rate_limit.* if/when it's added to the semantic conventions.

import { SEMANTIC_ATTRIBUTE_SENTRY_OP, SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';

const ORIGIN = 'auto.faas.cloudflare.rate_limit';
const OP = 'ratelimit';

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: ratelimit is not part of our official span operations (yet). I have to clarify if we actually need that - but for now please remove the OP entirely. We can always add this later here and in the docs later on as a feature.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the op entirely.

},
async span => {
const outcome = await Reflect.apply(original, target, [options]);
span.setAttribute('cloudflare.rate_limit.success', outcome.success);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Same as the others, is this attribute added in Cloudflare's spans?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed for the same reason (not in Cloudflare's native span). The rate-limited (success: false) outcome is now covered by the integration test via the response instead of a span attribute.

const spans = findSpans(envelope, 'rate_limit MY_RATE_LIMITER');
expect(spans).toHaveLength(1);
const data = spanData(spans[0]!);
expect({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Please use the following syntax (I saw it slipped through in the R2 tests, I'll remove that there in a PR):

constevent=envelopeItem(envelope);expect(event.spans).toEqual([
...
])

You can check out the D1 tests, these should match the expected assertions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Switched to the D1-style assertion (const event = envelopeItem(envelope); expect(event.spans).toEqual([...])).

return span.data as Record<string, unknown>;
}

it('emits a ratelimit span with the binding name and success outcome', async ({ signal }) => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It'd be nice if there would be a case to check if the .success is also false. Right now we only check agains true, but we would never know if this would be working correctly for the ratelimit to not be active/hitting

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a /ratelimit/blocked case: the binding's limit is set to 1, so the second limit() call within the period is rate limited. The test asserts the response is { success: false } and that both calls are still instrumented. Since the success attribute was removed, the rate-limited outcome is verified via the response.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Remove the non-standard ratelimit span op and the cloudflare.rate_limit.* attributes (keeping the standard origin), fail-fast in the Proxy handler, and align the integration test with the D1 assertion style plus a rate-limited case.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.

@@ -0,0 +1,31 @@
import type { RateLimit, RateLimitOptions, RateLimitOutcome } from '@cloudflare/workers-types';
import { SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';
Comment on lines +18 to +28
return function (this: unknown, options: RateLimitOptions): Promise<RateLimitOutcome> {
return startSpan(
{
name: `rate_limit ${bindingName}`,
attributes: {
[SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN]: ORIGIN,
},
},
() => Reflect.apply(original, target, [options]),
);
};
Comment on lines +49 to +57
expect(startSpanSpy).toHaveBeenLastCalledWith(
{
name: 'rate_limit MY_RATE_LIMITER',
attributes: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
},
expect.any(Function),
);
Comment on lines +58 to +60
});

test('does not record the rate limit key (avoids leaking PII)', async () => {
Comment on lines +13 to +17
function findRateLimitSpans(envelope: Envelope): Array<Record<string, unknown>> {
if (envelopeItemType(envelope) !== 'transaction') return [];
const spans = (envelopeItem(envelope).spans as Array<Record<string, unknown>>) || [];
return spans.filter(s => s.origin === 'auto.faas.cloudflare.rate_limit');
}
Comment on lines +22 to +40
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
const event = envelopeItem(envelope);

expect(event.spans).toEqual([
{
data: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
description: 'rate_limit MY_RATE_LIMITER',
origin: 'auto.faas.cloudflare.rate_limit',
parent_span_id: expect.any(String),
span_id: expect.any(String),
start_timestamp: expect.any(Number),
timestamp: expect.any(Number),
trace_id: expect.any(String),
},
]);
})
Comment on lines +51 to +55
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
// Both `limit()` calls on the blocked endpoint are instrumented.
expect(findRateLimitSpans(envelope)).toHaveLength(2);
})
@PeterWadie
PeterWadie requested a review from CopilotJuly 13, 2026 23:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@PeterWadie
PeterWadie requested a review from JPeer264July 13, 2026 23:35
@PeterWadie
PeterWadie requested a review from CopilotJuly 14, 2026 20:27

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks a lot for your contributions.

@JPeer264
JPeer264 merged commit ea3764e into getsentry:developJul 17, 2026
154 of 156 checks passed
nicohrubec pushed a commit that referenced this pull request Jul 17, 2026
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #22035
Co-authored-by: JPeer264 <10677263+JPeer264@users.noreply.github.com>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloudflare instrument rate limiter

3 participants

@PeterWadie@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(cloudflare): Instrument Cloudflare rate limiter bindings - #22035

Merged
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation
Jul 17, 2026
Merged

feat(cloudflare): Instrument Cloudflare rate limiter bindings#22035
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation

Conversation

@PeterWadie

@PeterWadiePeterWadie commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Adds automatic tracing for Cloudflare Workers rate limiter bindings, mirroring the existing R2/Queue/D1 binding instrumentation. When a RateLimit binding is accessed on env, its limit() calls are wrapped in a span.

Details

  • New instrumentRateLimit wraps the binding in a Proxy and starts a span named rate_limit <binding> around limit(), with the standard auto.faas.cloudflare.rate_limit origin.
  • Detection uses a limit duck-type in isBinding, wired into instrumentEnv after the more specific Queue/R2/D1 checks so those win when a binding also happens to expose limit.
  • The rate limit key is intentionally not recorded, since it commonly contains user-identifying data (e.g. an IP address or user id).
  • Cloudflare does not emit a native span for the rate limiter binding, so no op or custom cloudflare.rate_limit.* attributes are set for now. These can be added later if/when they land in Sentry's semantic conventions.
  • Includes unit tests plus an integration suite covering both an allowed call and a rate-limited (success: false) call.

Fixes#20871

Automatically wraps limit() calls on Cloudflare rate limiter bindings in a span, mirroring the existing R2/Queue/D1 binding instrumentation. The rate-limited outcome is recorded via a span attribute rather than an error status, and the rate limit key is not recorded to avoid leaking PII.
CopilotAI review requested due to automatic review settings July 8, 2026 02:07
@PeterWadie
PeterWadie requested a review from a team as a code ownerJuly 8, 2026 02:07
@PeterWadie
PeterWadie requested review from JPeer264, andreiborza and mydea and removed request for a teamJuly 8, 2026 02:07

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 53a0a03. Configure here.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds first-class tracing support for Cloudflare Workers RateLimit bindings in @sentry/cloudflare. The implementation follows the existing env-binding model (D1 / Queue / R2) by detecting the binding on env access, proxy-wrapping it, and creating a span around each limit() call while recording the outcome as a span attribute (without capturing the key to avoid PII).

Changes:

  • Add isRateLimit duck-typing to detect RateLimit bindings (limit method + not JSRPC).
  • Instrument env access to wrap detected RateLimit bindings and cache the wrapped proxy.
  • Introduce instrumentRateLimit which creates a ratelimit span per limit() call and records cloudflare.rate_limit.success.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/cloudflare/src/utils/isBinding.tsAdds isRateLimit duck-type guard for RateLimit bindings.
packages/cloudflare/src/instrumentations/worker/instrumentRateLimit.tsNew instrumentation proxy that wraps limit() with a span and records the success outcome.
packages/cloudflare/src/instrumentations/worker/instrumentEnv.tsWires RateLimit detection into env proxying + caching alongside existing binding instrumentation.
packages/cloudflare/test/utils/isBinding.test.tsAdds unit coverage for isRateLimit behavior (including JSRPC proxy exclusion).
packages/cloudflare/test/instrumentations/worker/instrumentRateLimit.test.tsAdds unit tests for span creation/attributes, forwarding behavior, and avoiding key/PII capture.
packages/cloudflare/test/instrumentations/instrumentEnv.test.tsAdds tests for env detection, wrapping, forwarding, and caching of RateLimit bindings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Adds an integration suite that exercises a real rate limiter binding through wrangler and asserts the emitted ratelimit span and its attributes, matching the coverage of the R2 and Queue binding instrumentations.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the spy creation into beforeEach with vi.restoreAllMocks() in afterEach, so each test gets a fresh spy.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

return startSpan(
{
op: OP,
name: `rate_limit ${bindingName}`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Did you cross-check with Cloudflare's own spans if these are the same there? We try to be as close to span naming as possible to what Cloudflare produces.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-checked: Cloudflare doesn't emit a native span for the rate limiter binding. It's not among their auto-traced bindings (KV/R2/DO), and their docs point to HTTP 429s or Analytics Engine for rate-limit observability rather than a span. So the op and cloudflare.rate_limit.* attributes had no Cloudflare-native equivalent to match. I've removed them and kept just the span plus the standard auto.faas.cloudflare.rate_limit origin.

export function instrumentRateLimit<T extends RateLimit>(rateLimit: T, bindingName: string): T {
return new Proxy(rateLimit, {
get(target, prop, receiver) {
if (prop === 'limit') {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It would be nice if you could switch to a fail fast approach and start with the following:

if(prop!=='limit'){returnReflect.get(target,prop,receiver);}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — the handler now returns early: if (prop !== 'limit') return Reflect.get(target, prop, receiver);.

op: OP,
name: `rate_limit ${bindingName}`,
attributes: {
'cloudflare.rate_limit.binding': bindingName,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Before we add this we need to add it in our semantic conventions (I could add it). However, before this will be moved to semantic conventions, is this attribute in the original Cloudflare span as well? If it is not I don't think we should add it here for now

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed. It's not present in Cloudflare's native span (details in the cross-check thread), so it's out for now. Happy to re-add cloudflare.rate_limit.* if/when it's added to the semantic conventions.

import { SEMANTIC_ATTRIBUTE_SENTRY_OP, SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';

const ORIGIN = 'auto.faas.cloudflare.rate_limit';
const OP = 'ratelimit';

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: ratelimit is not part of our official span operations (yet). I have to clarify if we actually need that - but for now please remove the OP entirely. We can always add this later here and in the docs later on as a feature.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the op entirely.

},
async span => {
const outcome = await Reflect.apply(original, target, [options]);
span.setAttribute('cloudflare.rate_limit.success', outcome.success);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Same as the others, is this attribute added in Cloudflare's spans?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed for the same reason (not in Cloudflare's native span). The rate-limited (success: false) outcome is now covered by the integration test via the response instead of a span attribute.

const spans = findSpans(envelope, 'rate_limit MY_RATE_LIMITER');
expect(spans).toHaveLength(1);
const data = spanData(spans[0]!);
expect({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Please use the following syntax (I saw it slipped through in the R2 tests, I'll remove that there in a PR):

constevent=envelopeItem(envelope);expect(event.spans).toEqual([
...
])

You can check out the D1 tests, these should match the expected assertions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Switched to the D1-style assertion (const event = envelopeItem(envelope); expect(event.spans).toEqual([...])).

return span.data as Record<string, unknown>;
}

it('emits a ratelimit span with the binding name and success outcome', async ({ signal }) => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It'd be nice if there would be a case to check if the .success is also false. Right now we only check agains true, but we would never know if this would be working correctly for the ratelimit to not be active/hitting

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a /ratelimit/blocked case: the binding's limit is set to 1, so the second limit() call within the period is rate limited. The test asserts the response is { success: false } and that both calls are still instrumented. Since the success attribute was removed, the rate-limited outcome is verified via the response.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Remove the non-standard ratelimit span op and the cloudflare.rate_limit.* attributes (keeping the standard origin), fail-fast in the Proxy handler, and align the integration test with the D1 assertion style plus a rate-limited case.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.

@@ -0,0 +1,31 @@
import type { RateLimit, RateLimitOptions, RateLimitOutcome } from '@cloudflare/workers-types';
import { SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';
Comment on lines +18 to +28
return function (this: unknown, options: RateLimitOptions): Promise<RateLimitOutcome> {
return startSpan(
{
name: `rate_limit ${bindingName}`,
attributes: {
[SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN]: ORIGIN,
},
},
() => Reflect.apply(original, target, [options]),
);
};
Comment on lines +49 to +57
expect(startSpanSpy).toHaveBeenLastCalledWith(
{
name: 'rate_limit MY_RATE_LIMITER',
attributes: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
},
expect.any(Function),
);
Comment on lines +58 to +60
});

test('does not record the rate limit key (avoids leaking PII)', async () => {
Comment on lines +13 to +17
function findRateLimitSpans(envelope: Envelope): Array<Record<string, unknown>> {
if (envelopeItemType(envelope) !== 'transaction') return [];
const spans = (envelopeItem(envelope).spans as Array<Record<string, unknown>>) || [];
return spans.filter(s => s.origin === 'auto.faas.cloudflare.rate_limit');
}
Comment on lines +22 to +40
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
const event = envelopeItem(envelope);

expect(event.spans).toEqual([
{
data: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
description: 'rate_limit MY_RATE_LIMITER',
origin: 'auto.faas.cloudflare.rate_limit',
parent_span_id: expect.any(String),
span_id: expect.any(String),
start_timestamp: expect.any(Number),
timestamp: expect.any(Number),
trace_id: expect.any(String),
},
]);
})
Comment on lines +51 to +55
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
// Both `limit()` calls on the blocked endpoint are instrumented.
expect(findRateLimitSpans(envelope)).toHaveLength(2);
})
@PeterWadie
PeterWadie requested a review from CopilotJuly 13, 2026 23:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@PeterWadie
PeterWadie requested a review from JPeer264July 13, 2026 23:35
@PeterWadie
PeterWadie requested a review from CopilotJuly 14, 2026 20:27

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks a lot for your contributions.

@JPeer264
JPeer264 merged commit ea3764e into getsentry:developJul 17, 2026
154 of 156 checks passed
nicohrubec pushed a commit that referenced this pull request Jul 17, 2026
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #22035
Co-authored-by: JPeer264 <10677263+JPeer264@users.noreply.github.com>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloudflare instrument rate limiter

3 participants

@PeterWadie@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(cloudflare): Instrument Cloudflare rate limiter bindings - #22035

Merged
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation
Jul 17, 2026
Merged

feat(cloudflare): Instrument Cloudflare rate limiter bindings#22035
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation

Conversation

@PeterWadie

@PeterWadiePeterWadie commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Adds automatic tracing for Cloudflare Workers rate limiter bindings, mirroring the existing R2/Queue/D1 binding instrumentation. When a RateLimit binding is accessed on env, its limit() calls are wrapped in a span.

Details

  • New instrumentRateLimit wraps the binding in a Proxy and starts a span named rate_limit <binding> around limit(), with the standard auto.faas.cloudflare.rate_limit origin.
  • Detection uses a limit duck-type in isBinding, wired into instrumentEnv after the more specific Queue/R2/D1 checks so those win when a binding also happens to expose limit.
  • The rate limit key is intentionally not recorded, since it commonly contains user-identifying data (e.g. an IP address or user id).
  • Cloudflare does not emit a native span for the rate limiter binding, so no op or custom cloudflare.rate_limit.* attributes are set for now. These can be added later if/when they land in Sentry's semantic conventions.
  • Includes unit tests plus an integration suite covering both an allowed call and a rate-limited (success: false) call.

Fixes#20871

Automatically wraps limit() calls on Cloudflare rate limiter bindings in a span, mirroring the existing R2/Queue/D1 binding instrumentation. The rate-limited outcome is recorded via a span attribute rather than an error status, and the rate limit key is not recorded to avoid leaking PII.
CopilotAI review requested due to automatic review settings July 8, 2026 02:07
@PeterWadie
PeterWadie requested a review from a team as a code ownerJuly 8, 2026 02:07
@PeterWadie
PeterWadie requested review from JPeer264, andreiborza and mydea and removed request for a teamJuly 8, 2026 02:07

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 53a0a03. Configure here.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds first-class tracing support for Cloudflare Workers RateLimit bindings in @sentry/cloudflare. The implementation follows the existing env-binding model (D1 / Queue / R2) by detecting the binding on env access, proxy-wrapping it, and creating a span around each limit() call while recording the outcome as a span attribute (without capturing the key to avoid PII).

Changes:

  • Add isRateLimit duck-typing to detect RateLimit bindings (limit method + not JSRPC).
  • Instrument env access to wrap detected RateLimit bindings and cache the wrapped proxy.
  • Introduce instrumentRateLimit which creates a ratelimit span per limit() call and records cloudflare.rate_limit.success.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/cloudflare/src/utils/isBinding.tsAdds isRateLimit duck-type guard for RateLimit bindings.
packages/cloudflare/src/instrumentations/worker/instrumentRateLimit.tsNew instrumentation proxy that wraps limit() with a span and records the success outcome.
packages/cloudflare/src/instrumentations/worker/instrumentEnv.tsWires RateLimit detection into env proxying + caching alongside existing binding instrumentation.
packages/cloudflare/test/utils/isBinding.test.tsAdds unit coverage for isRateLimit behavior (including JSRPC proxy exclusion).
packages/cloudflare/test/instrumentations/worker/instrumentRateLimit.test.tsAdds unit tests for span creation/attributes, forwarding behavior, and avoiding key/PII capture.
packages/cloudflare/test/instrumentations/instrumentEnv.test.tsAdds tests for env detection, wrapping, forwarding, and caching of RateLimit bindings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Adds an integration suite that exercises a real rate limiter binding through wrangler and asserts the emitted ratelimit span and its attributes, matching the coverage of the R2 and Queue binding instrumentations.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the spy creation into beforeEach with vi.restoreAllMocks() in afterEach, so each test gets a fresh spy.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

return startSpan(
{
op: OP,
name: `rate_limit ${bindingName}`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Did you cross-check with Cloudflare's own spans if these are the same there? We try to be as close to span naming as possible to what Cloudflare produces.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-checked: Cloudflare doesn't emit a native span for the rate limiter binding. It's not among their auto-traced bindings (KV/R2/DO), and their docs point to HTTP 429s or Analytics Engine for rate-limit observability rather than a span. So the op and cloudflare.rate_limit.* attributes had no Cloudflare-native equivalent to match. I've removed them and kept just the span plus the standard auto.faas.cloudflare.rate_limit origin.

export function instrumentRateLimit<T extends RateLimit>(rateLimit: T, bindingName: string): T {
return new Proxy(rateLimit, {
get(target, prop, receiver) {
if (prop === 'limit') {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It would be nice if you could switch to a fail fast approach and start with the following:

if(prop!=='limit'){returnReflect.get(target,prop,receiver);}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — the handler now returns early: if (prop !== 'limit') return Reflect.get(target, prop, receiver);.

op: OP,
name: `rate_limit ${bindingName}`,
attributes: {
'cloudflare.rate_limit.binding': bindingName,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Before we add this we need to add it in our semantic conventions (I could add it). However, before this will be moved to semantic conventions, is this attribute in the original Cloudflare span as well? If it is not I don't think we should add it here for now

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed. It's not present in Cloudflare's native span (details in the cross-check thread), so it's out for now. Happy to re-add cloudflare.rate_limit.* if/when it's added to the semantic conventions.

import { SEMANTIC_ATTRIBUTE_SENTRY_OP, SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';

const ORIGIN = 'auto.faas.cloudflare.rate_limit';
const OP = 'ratelimit';

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: ratelimit is not part of our official span operations (yet). I have to clarify if we actually need that - but for now please remove the OP entirely. We can always add this later here and in the docs later on as a feature.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the op entirely.

},
async span => {
const outcome = await Reflect.apply(original, target, [options]);
span.setAttribute('cloudflare.rate_limit.success', outcome.success);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Same as the others, is this attribute added in Cloudflare's spans?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed for the same reason (not in Cloudflare's native span). The rate-limited (success: false) outcome is now covered by the integration test via the response instead of a span attribute.

const spans = findSpans(envelope, 'rate_limit MY_RATE_LIMITER');
expect(spans).toHaveLength(1);
const data = spanData(spans[0]!);
expect({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Please use the following syntax (I saw it slipped through in the R2 tests, I'll remove that there in a PR):

constevent=envelopeItem(envelope);expect(event.spans).toEqual([
...
])

You can check out the D1 tests, these should match the expected assertions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Switched to the D1-style assertion (const event = envelopeItem(envelope); expect(event.spans).toEqual([...])).

return span.data as Record<string, unknown>;
}

it('emits a ratelimit span with the binding name and success outcome', async ({ signal }) => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It'd be nice if there would be a case to check if the .success is also false. Right now we only check agains true, but we would never know if this would be working correctly for the ratelimit to not be active/hitting

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a /ratelimit/blocked case: the binding's limit is set to 1, so the second limit() call within the period is rate limited. The test asserts the response is { success: false } and that both calls are still instrumented. Since the success attribute was removed, the rate-limited outcome is verified via the response.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Remove the non-standard ratelimit span op and the cloudflare.rate_limit.* attributes (keeping the standard origin), fail-fast in the Proxy handler, and align the integration test with the D1 assertion style plus a rate-limited case.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.

@@ -0,0 +1,31 @@
import type { RateLimit, RateLimitOptions, RateLimitOutcome } from '@cloudflare/workers-types';
import { SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';
Comment on lines +18 to +28
return function (this: unknown, options: RateLimitOptions): Promise<RateLimitOutcome> {
return startSpan(
{
name: `rate_limit ${bindingName}`,
attributes: {
[SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN]: ORIGIN,
},
},
() => Reflect.apply(original, target, [options]),
);
};
Comment on lines +49 to +57
expect(startSpanSpy).toHaveBeenLastCalledWith(
{
name: 'rate_limit MY_RATE_LIMITER',
attributes: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
},
expect.any(Function),
);
Comment on lines +58 to +60
});

test('does not record the rate limit key (avoids leaking PII)', async () => {
Comment on lines +13 to +17
function findRateLimitSpans(envelope: Envelope): Array<Record<string, unknown>> {
if (envelopeItemType(envelope) !== 'transaction') return [];
const spans = (envelopeItem(envelope).spans as Array<Record<string, unknown>>) || [];
return spans.filter(s => s.origin === 'auto.faas.cloudflare.rate_limit');
}
Comment on lines +22 to +40
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
const event = envelopeItem(envelope);

expect(event.spans).toEqual([
{
data: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
description: 'rate_limit MY_RATE_LIMITER',
origin: 'auto.faas.cloudflare.rate_limit',
parent_span_id: expect.any(String),
span_id: expect.any(String),
start_timestamp: expect.any(Number),
timestamp: expect.any(Number),
trace_id: expect.any(String),
},
]);
})
Comment on lines +51 to +55
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
// Both `limit()` calls on the blocked endpoint are instrumented.
expect(findRateLimitSpans(envelope)).toHaveLength(2);
})
@PeterWadie
PeterWadie requested a review from CopilotJuly 13, 2026 23:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@PeterWadie
PeterWadie requested a review from JPeer264July 13, 2026 23:35
@PeterWadie
PeterWadie requested a review from CopilotJuly 14, 2026 20:27

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks a lot for your contributions.

@JPeer264
JPeer264 merged commit ea3764e into getsentry:developJul 17, 2026
154 of 156 checks passed
nicohrubec pushed a commit that referenced this pull request Jul 17, 2026
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #22035
Co-authored-by: JPeer264 <10677263+JPeer264@users.noreply.github.com>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloudflare instrument rate limiter

3 participants

@PeterWadie@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(cloudflare): Instrument Cloudflare rate limiter bindings - #22035

Merged
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation
Jul 17, 2026
Merged

feat(cloudflare): Instrument Cloudflare rate limiter bindings#22035
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation

Conversation

@PeterWadie

@PeterWadiePeterWadie commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Adds automatic tracing for Cloudflare Workers rate limiter bindings, mirroring the existing R2/Queue/D1 binding instrumentation. When a RateLimit binding is accessed on env, its limit() calls are wrapped in a span.

Details

  • New instrumentRateLimit wraps the binding in a Proxy and starts a span named rate_limit <binding> around limit(), with the standard auto.faas.cloudflare.rate_limit origin.
  • Detection uses a limit duck-type in isBinding, wired into instrumentEnv after the more specific Queue/R2/D1 checks so those win when a binding also happens to expose limit.
  • The rate limit key is intentionally not recorded, since it commonly contains user-identifying data (e.g. an IP address or user id).
  • Cloudflare does not emit a native span for the rate limiter binding, so no op or custom cloudflare.rate_limit.* attributes are set for now. These can be added later if/when they land in Sentry's semantic conventions.
  • Includes unit tests plus an integration suite covering both an allowed call and a rate-limited (success: false) call.

Fixes#20871

Automatically wraps limit() calls on Cloudflare rate limiter bindings in a span, mirroring the existing R2/Queue/D1 binding instrumentation. The rate-limited outcome is recorded via a span attribute rather than an error status, and the rate limit key is not recorded to avoid leaking PII.
CopilotAI review requested due to automatic review settings July 8, 2026 02:07
@PeterWadie
PeterWadie requested a review from a team as a code ownerJuly 8, 2026 02:07
@PeterWadie
PeterWadie requested review from JPeer264, andreiborza and mydea and removed request for a teamJuly 8, 2026 02:07

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 53a0a03. Configure here.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds first-class tracing support for Cloudflare Workers RateLimit bindings in @sentry/cloudflare. The implementation follows the existing env-binding model (D1 / Queue / R2) by detecting the binding on env access, proxy-wrapping it, and creating a span around each limit() call while recording the outcome as a span attribute (without capturing the key to avoid PII).

Changes:

  • Add isRateLimit duck-typing to detect RateLimit bindings (limit method + not JSRPC).
  • Instrument env access to wrap detected RateLimit bindings and cache the wrapped proxy.
  • Introduce instrumentRateLimit which creates a ratelimit span per limit() call and records cloudflare.rate_limit.success.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/cloudflare/src/utils/isBinding.tsAdds isRateLimit duck-type guard for RateLimit bindings.
packages/cloudflare/src/instrumentations/worker/instrumentRateLimit.tsNew instrumentation proxy that wraps limit() with a span and records the success outcome.
packages/cloudflare/src/instrumentations/worker/instrumentEnv.tsWires RateLimit detection into env proxying + caching alongside existing binding instrumentation.
packages/cloudflare/test/utils/isBinding.test.tsAdds unit coverage for isRateLimit behavior (including JSRPC proxy exclusion).
packages/cloudflare/test/instrumentations/worker/instrumentRateLimit.test.tsAdds unit tests for span creation/attributes, forwarding behavior, and avoiding key/PII capture.
packages/cloudflare/test/instrumentations/instrumentEnv.test.tsAdds tests for env detection, wrapping, forwarding, and caching of RateLimit bindings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Adds an integration suite that exercises a real rate limiter binding through wrangler and asserts the emitted ratelimit span and its attributes, matching the coverage of the R2 and Queue binding instrumentations.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the spy creation into beforeEach with vi.restoreAllMocks() in afterEach, so each test gets a fresh spy.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

return startSpan(
{
op: OP,
name: `rate_limit ${bindingName}`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Did you cross-check with Cloudflare's own spans if these are the same there? We try to be as close to span naming as possible to what Cloudflare produces.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-checked: Cloudflare doesn't emit a native span for the rate limiter binding. It's not among their auto-traced bindings (KV/R2/DO), and their docs point to HTTP 429s or Analytics Engine for rate-limit observability rather than a span. So the op and cloudflare.rate_limit.* attributes had no Cloudflare-native equivalent to match. I've removed them and kept just the span plus the standard auto.faas.cloudflare.rate_limit origin.

export function instrumentRateLimit<T extends RateLimit>(rateLimit: T, bindingName: string): T {
return new Proxy(rateLimit, {
get(target, prop, receiver) {
if (prop === 'limit') {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It would be nice if you could switch to a fail fast approach and start with the following:

if(prop!=='limit'){returnReflect.get(target,prop,receiver);}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — the handler now returns early: if (prop !== 'limit') return Reflect.get(target, prop, receiver);.

op: OP,
name: `rate_limit ${bindingName}`,
attributes: {
'cloudflare.rate_limit.binding': bindingName,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Before we add this we need to add it in our semantic conventions (I could add it). However, before this will be moved to semantic conventions, is this attribute in the original Cloudflare span as well? If it is not I don't think we should add it here for now

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed. It's not present in Cloudflare's native span (details in the cross-check thread), so it's out for now. Happy to re-add cloudflare.rate_limit.* if/when it's added to the semantic conventions.

import { SEMANTIC_ATTRIBUTE_SENTRY_OP, SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';

const ORIGIN = 'auto.faas.cloudflare.rate_limit';
const OP = 'ratelimit';

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: ratelimit is not part of our official span operations (yet). I have to clarify if we actually need that - but for now please remove the OP entirely. We can always add this later here and in the docs later on as a feature.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the op entirely.

},
async span => {
const outcome = await Reflect.apply(original, target, [options]);
span.setAttribute('cloudflare.rate_limit.success', outcome.success);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Same as the others, is this attribute added in Cloudflare's spans?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed for the same reason (not in Cloudflare's native span). The rate-limited (success: false) outcome is now covered by the integration test via the response instead of a span attribute.

const spans = findSpans(envelope, 'rate_limit MY_RATE_LIMITER');
expect(spans).toHaveLength(1);
const data = spanData(spans[0]!);
expect({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Please use the following syntax (I saw it slipped through in the R2 tests, I'll remove that there in a PR):

constevent=envelopeItem(envelope);expect(event.spans).toEqual([
...
])

You can check out the D1 tests, these should match the expected assertions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Switched to the D1-style assertion (const event = envelopeItem(envelope); expect(event.spans).toEqual([...])).

return span.data as Record<string, unknown>;
}

it('emits a ratelimit span with the binding name and success outcome', async ({ signal }) => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It'd be nice if there would be a case to check if the .success is also false. Right now we only check agains true, but we would never know if this would be working correctly for the ratelimit to not be active/hitting

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a /ratelimit/blocked case: the binding's limit is set to 1, so the second limit() call within the period is rate limited. The test asserts the response is { success: false } and that both calls are still instrumented. Since the success attribute was removed, the rate-limited outcome is verified via the response.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Remove the non-standard ratelimit span op and the cloudflare.rate_limit.* attributes (keeping the standard origin), fail-fast in the Proxy handler, and align the integration test with the D1 assertion style plus a rate-limited case.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.

@@ -0,0 +1,31 @@
import type { RateLimit, RateLimitOptions, RateLimitOutcome } from '@cloudflare/workers-types';
import { SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';
Comment on lines +18 to +28
return function (this: unknown, options: RateLimitOptions): Promise<RateLimitOutcome> {
return startSpan(
{
name: `rate_limit ${bindingName}`,
attributes: {
[SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN]: ORIGIN,
},
},
() => Reflect.apply(original, target, [options]),
);
};
Comment on lines +49 to +57
expect(startSpanSpy).toHaveBeenLastCalledWith(
{
name: 'rate_limit MY_RATE_LIMITER',
attributes: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
},
expect.any(Function),
);
Comment on lines +58 to +60
});

test('does not record the rate limit key (avoids leaking PII)', async () => {
Comment on lines +13 to +17
function findRateLimitSpans(envelope: Envelope): Array<Record<string, unknown>> {
if (envelopeItemType(envelope) !== 'transaction') return [];
const spans = (envelopeItem(envelope).spans as Array<Record<string, unknown>>) || [];
return spans.filter(s => s.origin === 'auto.faas.cloudflare.rate_limit');
}
Comment on lines +22 to +40
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
const event = envelopeItem(envelope);

expect(event.spans).toEqual([
{
data: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
description: 'rate_limit MY_RATE_LIMITER',
origin: 'auto.faas.cloudflare.rate_limit',
parent_span_id: expect.any(String),
span_id: expect.any(String),
start_timestamp: expect.any(Number),
timestamp: expect.any(Number),
trace_id: expect.any(String),
},
]);
})
Comment on lines +51 to +55
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
// Both `limit()` calls on the blocked endpoint are instrumented.
expect(findRateLimitSpans(envelope)).toHaveLength(2);
})
@PeterWadie
PeterWadie requested a review from CopilotJuly 13, 2026 23:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@PeterWadie
PeterWadie requested a review from JPeer264July 13, 2026 23:35
@PeterWadie
PeterWadie requested a review from CopilotJuly 14, 2026 20:27

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks a lot for your contributions.

@JPeer264
JPeer264 merged commit ea3764e into getsentry:developJul 17, 2026
154 of 156 checks passed
nicohrubec pushed a commit that referenced this pull request Jul 17, 2026
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #22035
Co-authored-by: JPeer264 <10677263+JPeer264@users.noreply.github.com>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloudflare instrument rate limiter

3 participants

@PeterWadie@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(cloudflare): Instrument Cloudflare rate limiter bindings - #22035

Merged
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation
Jul 17, 2026
Merged

feat(cloudflare): Instrument Cloudflare rate limiter bindings#22035
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation

Conversation

@PeterWadie

@PeterWadiePeterWadie commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Adds automatic tracing for Cloudflare Workers rate limiter bindings, mirroring the existing R2/Queue/D1 binding instrumentation. When a RateLimit binding is accessed on env, its limit() calls are wrapped in a span.

Details

  • New instrumentRateLimit wraps the binding in a Proxy and starts a span named rate_limit <binding> around limit(), with the standard auto.faas.cloudflare.rate_limit origin.
  • Detection uses a limit duck-type in isBinding, wired into instrumentEnv after the more specific Queue/R2/D1 checks so those win when a binding also happens to expose limit.
  • The rate limit key is intentionally not recorded, since it commonly contains user-identifying data (e.g. an IP address or user id).
  • Cloudflare does not emit a native span for the rate limiter binding, so no op or custom cloudflare.rate_limit.* attributes are set for now. These can be added later if/when they land in Sentry's semantic conventions.
  • Includes unit tests plus an integration suite covering both an allowed call and a rate-limited (success: false) call.

Fixes#20871

Automatically wraps limit() calls on Cloudflare rate limiter bindings in a span, mirroring the existing R2/Queue/D1 binding instrumentation. The rate-limited outcome is recorded via a span attribute rather than an error status, and the rate limit key is not recorded to avoid leaking PII.
CopilotAI review requested due to automatic review settings July 8, 2026 02:07
@PeterWadie
PeterWadie requested a review from a team as a code ownerJuly 8, 2026 02:07
@PeterWadie
PeterWadie requested review from JPeer264, andreiborza and mydea and removed request for a teamJuly 8, 2026 02:07

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 53a0a03. Configure here.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds first-class tracing support for Cloudflare Workers RateLimit bindings in @sentry/cloudflare. The implementation follows the existing env-binding model (D1 / Queue / R2) by detecting the binding on env access, proxy-wrapping it, and creating a span around each limit() call while recording the outcome as a span attribute (without capturing the key to avoid PII).

Changes:

  • Add isRateLimit duck-typing to detect RateLimit bindings (limit method + not JSRPC).
  • Instrument env access to wrap detected RateLimit bindings and cache the wrapped proxy.
  • Introduce instrumentRateLimit which creates a ratelimit span per limit() call and records cloudflare.rate_limit.success.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/cloudflare/src/utils/isBinding.tsAdds isRateLimit duck-type guard for RateLimit bindings.
packages/cloudflare/src/instrumentations/worker/instrumentRateLimit.tsNew instrumentation proxy that wraps limit() with a span and records the success outcome.
packages/cloudflare/src/instrumentations/worker/instrumentEnv.tsWires RateLimit detection into env proxying + caching alongside existing binding instrumentation.
packages/cloudflare/test/utils/isBinding.test.tsAdds unit coverage for isRateLimit behavior (including JSRPC proxy exclusion).
packages/cloudflare/test/instrumentations/worker/instrumentRateLimit.test.tsAdds unit tests for span creation/attributes, forwarding behavior, and avoiding key/PII capture.
packages/cloudflare/test/instrumentations/instrumentEnv.test.tsAdds tests for env detection, wrapping, forwarding, and caching of RateLimit bindings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Adds an integration suite that exercises a real rate limiter binding through wrangler and asserts the emitted ratelimit span and its attributes, matching the coverage of the R2 and Queue binding instrumentations.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the spy creation into beforeEach with vi.restoreAllMocks() in afterEach, so each test gets a fresh spy.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

return startSpan(
{
op: OP,
name: `rate_limit ${bindingName}`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Did you cross-check with Cloudflare's own spans if these are the same there? We try to be as close to span naming as possible to what Cloudflare produces.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-checked: Cloudflare doesn't emit a native span for the rate limiter binding. It's not among their auto-traced bindings (KV/R2/DO), and their docs point to HTTP 429s or Analytics Engine for rate-limit observability rather than a span. So the op and cloudflare.rate_limit.* attributes had no Cloudflare-native equivalent to match. I've removed them and kept just the span plus the standard auto.faas.cloudflare.rate_limit origin.

export function instrumentRateLimit<T extends RateLimit>(rateLimit: T, bindingName: string): T {
return new Proxy(rateLimit, {
get(target, prop, receiver) {
if (prop === 'limit') {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It would be nice if you could switch to a fail fast approach and start with the following:

if(prop!=='limit'){returnReflect.get(target,prop,receiver);}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — the handler now returns early: if (prop !== 'limit') return Reflect.get(target, prop, receiver);.

op: OP,
name: `rate_limit ${bindingName}`,
attributes: {
'cloudflare.rate_limit.binding': bindingName,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Before we add this we need to add it in our semantic conventions (I could add it). However, before this will be moved to semantic conventions, is this attribute in the original Cloudflare span as well? If it is not I don't think we should add it here for now

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed. It's not present in Cloudflare's native span (details in the cross-check thread), so it's out for now. Happy to re-add cloudflare.rate_limit.* if/when it's added to the semantic conventions.

import { SEMANTIC_ATTRIBUTE_SENTRY_OP, SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';

const ORIGIN = 'auto.faas.cloudflare.rate_limit';
const OP = 'ratelimit';

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: ratelimit is not part of our official span operations (yet). I have to clarify if we actually need that - but for now please remove the OP entirely. We can always add this later here and in the docs later on as a feature.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the op entirely.

},
async span => {
const outcome = await Reflect.apply(original, target, [options]);
span.setAttribute('cloudflare.rate_limit.success', outcome.success);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Same as the others, is this attribute added in Cloudflare's spans?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed for the same reason (not in Cloudflare's native span). The rate-limited (success: false) outcome is now covered by the integration test via the response instead of a span attribute.

const spans = findSpans(envelope, 'rate_limit MY_RATE_LIMITER');
expect(spans).toHaveLength(1);
const data = spanData(spans[0]!);
expect({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Please use the following syntax (I saw it slipped through in the R2 tests, I'll remove that there in a PR):

constevent=envelopeItem(envelope);expect(event.spans).toEqual([
...
])

You can check out the D1 tests, these should match the expected assertions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Switched to the D1-style assertion (const event = envelopeItem(envelope); expect(event.spans).toEqual([...])).

return span.data as Record<string, unknown>;
}

it('emits a ratelimit span with the binding name and success outcome', async ({ signal }) => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It'd be nice if there would be a case to check if the .success is also false. Right now we only check agains true, but we would never know if this would be working correctly for the ratelimit to not be active/hitting

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a /ratelimit/blocked case: the binding's limit is set to 1, so the second limit() call within the period is rate limited. The test asserts the response is { success: false } and that both calls are still instrumented. Since the success attribute was removed, the rate-limited outcome is verified via the response.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Remove the non-standard ratelimit span op and the cloudflare.rate_limit.* attributes (keeping the standard origin), fail-fast in the Proxy handler, and align the integration test with the D1 assertion style plus a rate-limited case.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.

@@ -0,0 +1,31 @@
import type { RateLimit, RateLimitOptions, RateLimitOutcome } from '@cloudflare/workers-types';
import { SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';
Comment on lines +18 to +28
return function (this: unknown, options: RateLimitOptions): Promise<RateLimitOutcome> {
return startSpan(
{
name: `rate_limit ${bindingName}`,
attributes: {
[SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN]: ORIGIN,
},
},
() => Reflect.apply(original, target, [options]),
);
};
Comment on lines +49 to +57
expect(startSpanSpy).toHaveBeenLastCalledWith(
{
name: 'rate_limit MY_RATE_LIMITER',
attributes: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
},
expect.any(Function),
);
Comment on lines +58 to +60
});

test('does not record the rate limit key (avoids leaking PII)', async () => {
Comment on lines +13 to +17
function findRateLimitSpans(envelope: Envelope): Array<Record<string, unknown>> {
if (envelopeItemType(envelope) !== 'transaction') return [];
const spans = (envelopeItem(envelope).spans as Array<Record<string, unknown>>) || [];
return spans.filter(s => s.origin === 'auto.faas.cloudflare.rate_limit');
}
Comment on lines +22 to +40
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
const event = envelopeItem(envelope);

expect(event.spans).toEqual([
{
data: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
description: 'rate_limit MY_RATE_LIMITER',
origin: 'auto.faas.cloudflare.rate_limit',
parent_span_id: expect.any(String),
span_id: expect.any(String),
start_timestamp: expect.any(Number),
timestamp: expect.any(Number),
trace_id: expect.any(String),
},
]);
})
Comment on lines +51 to +55
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
// Both `limit()` calls on the blocked endpoint are instrumented.
expect(findRateLimitSpans(envelope)).toHaveLength(2);
})
@PeterWadie
PeterWadie requested a review from CopilotJuly 13, 2026 23:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@PeterWadie
PeterWadie requested a review from JPeer264July 13, 2026 23:35
@PeterWadie
PeterWadie requested a review from CopilotJuly 14, 2026 20:27

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks a lot for your contributions.

@JPeer264
JPeer264 merged commit ea3764e into getsentry:developJul 17, 2026
154 of 156 checks passed
nicohrubec pushed a commit that referenced this pull request Jul 17, 2026
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #22035
Co-authored-by: JPeer264 <10677263+JPeer264@users.noreply.github.com>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloudflare instrument rate limiter

3 participants

@PeterWadie@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(cloudflare): Instrument Cloudflare rate limiter bindings - #22035

Merged
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation
Jul 17, 2026
Merged

feat(cloudflare): Instrument Cloudflare rate limiter bindings#22035
JPeer264 merged 5 commits into
getsentry:developfrom
PeterWadie:feat/cloudflare-rate-limit-instrumentation

Conversation

@PeterWadie

@PeterWadiePeterWadie commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Adds automatic tracing for Cloudflare Workers rate limiter bindings, mirroring the existing R2/Queue/D1 binding instrumentation. When a RateLimit binding is accessed on env, its limit() calls are wrapped in a span.

Details

  • New instrumentRateLimit wraps the binding in a Proxy and starts a span named rate_limit <binding> around limit(), with the standard auto.faas.cloudflare.rate_limit origin.
  • Detection uses a limit duck-type in isBinding, wired into instrumentEnv after the more specific Queue/R2/D1 checks so those win when a binding also happens to expose limit.
  • The rate limit key is intentionally not recorded, since it commonly contains user-identifying data (e.g. an IP address or user id).
  • Cloudflare does not emit a native span for the rate limiter binding, so no op or custom cloudflare.rate_limit.* attributes are set for now. These can be added later if/when they land in Sentry's semantic conventions.
  • Includes unit tests plus an integration suite covering both an allowed call and a rate-limited (success: false) call.

Fixes#20871

Automatically wraps limit() calls on Cloudflare rate limiter bindings in a span, mirroring the existing R2/Queue/D1 binding instrumentation. The rate-limited outcome is recorded via a span attribute rather than an error status, and the rate limit key is not recorded to avoid leaking PII.
CopilotAI review requested due to automatic review settings July 8, 2026 02:07
@PeterWadie
PeterWadie requested a review from a team as a code ownerJuly 8, 2026 02:07
@PeterWadie
PeterWadie requested review from JPeer264, andreiborza and mydea and removed request for a teamJuly 8, 2026 02:07

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 53a0a03. Configure here.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds first-class tracing support for Cloudflare Workers RateLimit bindings in @sentry/cloudflare. The implementation follows the existing env-binding model (D1 / Queue / R2) by detecting the binding on env access, proxy-wrapping it, and creating a span around each limit() call while recording the outcome as a span attribute (without capturing the key to avoid PII).

Changes:

  • Add isRateLimit duck-typing to detect RateLimit bindings (limit method + not JSRPC).
  • Instrument env access to wrap detected RateLimit bindings and cache the wrapped proxy.
  • Introduce instrumentRateLimit which creates a ratelimit span per limit() call and records cloudflare.rate_limit.success.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
packages/cloudflare/src/utils/isBinding.tsAdds isRateLimit duck-type guard for RateLimit bindings.
packages/cloudflare/src/instrumentations/worker/instrumentRateLimit.tsNew instrumentation proxy that wraps limit() with a span and records the success outcome.
packages/cloudflare/src/instrumentations/worker/instrumentEnv.tsWires RateLimit detection into env proxying + caching alongside existing binding instrumentation.
packages/cloudflare/test/utils/isBinding.test.tsAdds unit coverage for isRateLimit behavior (including JSRPC proxy exclusion).
packages/cloudflare/test/instrumentations/worker/instrumentRateLimit.test.tsAdds unit tests for span creation/attributes, forwarding behavior, and avoiding key/PII capture.
packages/cloudflare/test/instrumentations/instrumentEnv.test.tsAdds tests for env detection, wrapping, forwarding, and caching of RateLimit bindings.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Adds an integration suite that exercises a real rate limiter binding through wrangler and asserts the emitted ratelimit span and its attributes, matching the coverage of the R2 and Queue binding instrumentations.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the spy creation into beforeEach with vi.restoreAllMocks() in afterEach, so each test gets a fresh spy.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

return startSpan(
{
op: OP,
name: `rate_limit ${bindingName}`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Did you cross-check with Cloudflare's own spans if these are the same there? We try to be as close to span naming as possible to what Cloudflare produces.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-checked: Cloudflare doesn't emit a native span for the rate limiter binding. It's not among their auto-traced bindings (KV/R2/DO), and their docs point to HTTP 429s or Analytics Engine for rate-limit observability rather than a span. So the op and cloudflare.rate_limit.* attributes had no Cloudflare-native equivalent to match. I've removed them and kept just the span plus the standard auto.faas.cloudflare.rate_limit origin.

export function instrumentRateLimit<T extends RateLimit>(rateLimit: T, bindingName: string): T {
return new Proxy(rateLimit, {
get(target, prop, receiver) {
if (prop === 'limit') {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It would be nice if you could switch to a fail fast approach and start with the following:

if(prop!=='limit'){returnReflect.get(target,prop,receiver);}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done — the handler now returns early: if (prop !== 'limit') return Reflect.get(target, prop, receiver);.

op: OP,
name: `rate_limit ${bindingName}`,
attributes: {
'cloudflare.rate_limit.binding': bindingName,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Before we add this we need to add it in our semantic conventions (I could add it). However, before this will be moved to semantic conventions, is this attribute in the original Cloudflare span as well? If it is not I don't think we should add it here for now

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed. It's not present in Cloudflare's native span (details in the cross-check thread), so it's out for now. Happy to re-add cloudflare.rate_limit.* if/when it's added to the semantic conventions.

import { SEMANTIC_ATTRIBUTE_SENTRY_OP, SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';

const ORIGIN = 'auto.faas.cloudflare.rate_limit';
const OP = 'ratelimit';

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: ratelimit is not part of our official span operations (yet). I have to clarify if we actually need that - but for now please remove the OP entirely. We can always add this later here and in the docs later on as a feature.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the op entirely.

},
async span => {
const outcome = await Reflect.apply(original, target, [options]);
span.setAttribute('cloudflare.rate_limit.success', outcome.success);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Same as the others, is this attribute added in Cloudflare's spans?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed for the same reason (not in Cloudflare's native span). The rate-limited (success: false) outcome is now covered by the integration test via the response instead of a span attribute.

const spans = findSpans(envelope, 'rate_limit MY_RATE_LIMITER');
expect(spans).toHaveLength(1);
const data = spanData(spans[0]!);
expect({

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Please use the following syntax (I saw it slipped through in the R2 tests, I'll remove that there in a PR):

constevent=envelopeItem(envelope);expect(event.spans).toEqual([
...
])

You can check out the D1 tests, these should match the expected assertions.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Switched to the D1-style assertion (const event = envelopeItem(envelope); expect(event.spans).toEqual([...])).

return span.data as Record<string, unknown>;
}

it('emits a ratelimit span with the binding name and success outcome', async ({ signal }) => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: It'd be nice if there would be a case to check if the .success is also false. Right now we only check agains true, but we would never know if this would be working correctly for the ratelimit to not be active/hitting

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a /ratelimit/blocked case: the binding's limit is set to 1, so the second limit() call within the period is rate limited. The test asserts the response is { success: false } and that both calls are still instrumented. Since the success attribute was removed, the rate-limited outcome is verified via the response.

Comment on lines +1 to +18
import type { RateLimit } from '@cloudflare/workers-types';
import * as SentryCore from '@sentry/core';
import { beforeEach, describe, expect, test, vi } from 'vitest';
import { instrumentRateLimit } from '../../../src/instrumentations/worker/instrumentRateLimit';

function createMockRateLimit(success = true): RateLimit {
return {
limit: vi.fn().mockResolvedValue({ success }),
} as unknown as RateLimit;
}

describe('instrumentRateLimit', () => {
beforeEach(() => {
vi.clearAllMocks();
});

const startSpanSpy = vi.spyOn(SentryCore, 'startSpan');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like copilot mentioned you could either do this, or move/copy startSpanSpy in every test individually as well.

Remove the non-standard ratelimit span op and the cloudflare.rate_limit.* attributes (keeping the standard origin), fail-fast in the Proxy handler, and align the integration test with the D1 assertion style plus a rate-limited case.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.

@@ -0,0 +1,31 @@
import type { RateLimit, RateLimitOptions, RateLimitOutcome } from '@cloudflare/workers-types';
import { SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN, startSpan } from '@sentry/core';
Comment on lines +18 to +28
return function (this: unknown, options: RateLimitOptions): Promise<RateLimitOutcome> {
return startSpan(
{
name: `rate_limit ${bindingName}`,
attributes: {
[SEMANTIC_ATTRIBUTE_SENTRY_ORIGIN]: ORIGIN,
},
},
() => Reflect.apply(original, target, [options]),
);
};
Comment on lines +49 to +57
expect(startSpanSpy).toHaveBeenLastCalledWith(
{
name: 'rate_limit MY_RATE_LIMITER',
attributes: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
},
expect.any(Function),
);
Comment on lines +58 to +60
});

test('does not record the rate limit key (avoids leaking PII)', async () => {
Comment on lines +13 to +17
function findRateLimitSpans(envelope: Envelope): Array<Record<string, unknown>> {
if (envelopeItemType(envelope) !== 'transaction') return [];
const spans = (envelopeItem(envelope).spans as Array<Record<string, unknown>>) || [];
return spans.filter(s => s.origin === 'auto.faas.cloudflare.rate_limit');
}
Comment on lines +22 to +40
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
const event = envelopeItem(envelope);

expect(event.spans).toEqual([
{
data: {
'sentry.origin': 'auto.faas.cloudflare.rate_limit',
},
description: 'rate_limit MY_RATE_LIMITER',
origin: 'auto.faas.cloudflare.rate_limit',
parent_span_id: expect.any(String),
span_id: expect.any(String),
start_timestamp: expect.any(Number),
timestamp: expect.any(Number),
trace_id: expect.any(String),
},
]);
})
Comment on lines +51 to +55
.expect((envelope: Envelope) => {
expect(envelopeItemType(envelope)).toBe('transaction');
// Both `limit()` calls on the blocked endpoint are instrumented.
expect(findRateLimitSpans(envelope)).toHaveLength(2);
})
@PeterWadie
PeterWadie requested a review from CopilotJuly 13, 2026 23:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@PeterWadie
PeterWadie requested a review from JPeer264July 13, 2026 23:35
@PeterWadie
PeterWadie requested a review from CopilotJuly 14, 2026 20:27

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @JPeer264, @andreiborza — Please review this PR when you get a chance!

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks a lot for your contributions.

@JPeer264
JPeer264 merged commit ea3764e into getsentry:developJul 17, 2026
154 of 156 checks passed
nicohrubec pushed a commit that referenced this pull request Jul 17, 2026
This PR adds the external contributor to the CHANGELOG.md file, so that
they are credited for their contribution. See #22035
Co-authored-by: JPeer264 <10677263+JPeer264@users.noreply.github.com>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloudflare instrument rate limiter

3 participants

@PeterWadie@JPeer264