feat(core): Add and use dataCollection.graphQL - #22221

Merged
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL
Jul 14, 2026
Merged

feat(core): Add and use dataCollection.graphQL#22221
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Sets the default collection behavior to true as it has been collected already.

@s1gr1d
s1gr1d requested review from a team as code ownersJuly 13, 2026 10:50
@s1gr1d
s1gr1d requested review from Lms24, andreiborza, chargome, isaacs, logaretm, mydea and nicohrubec and removed request for a teamJuly 13, 2026 10:50
Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH

Suggested Fix

Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

github-actionsBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.65 kB+0.15%+40 B 🔺
@sentry/browser - with treeshaking flags26.1 kB+0.19%+48 B 🔺
@sentry/browser (incl. Tracing)46.42 kB+0.13%+56 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.21 kB+0.11%+51 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.2 kB+0.11%+52 B 🔺
@sentry/browser (incl. Tracing, Replay)85.67 kB+0.05%+39 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.31 kB+0.06%+44 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.38 kB+0.05%+42 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)103.04 kB+0.04%+40 B 🔺
@sentry/browser (incl. Feedback)44.83 kB+0.11%+46 B 🔺
@sentry/browser (incl. sendFeedback)32.45 kB+0.14%+44 B 🔺
@sentry/browser (incl. FeedbackAsync)37.58 kB+0.12%+44 B 🔺
@sentry/browser (incl. Metrics)28.74 kB+0.18%+50 B 🔺
@sentry/browser (incl. Logs)28.98 kB+0.15%+42 B 🔺
@sentry/browser (incl. Metrics & Logs)29.67 kB+0.16%+47 B 🔺
@sentry/react29.45 kB+0.18%+50 B 🔺
@sentry/react (incl. Tracing)48.68 kB+0.1%+46 B 🔺
@sentry/vue33.08 kB+0.14%+44 B 🔺
@sentry/vue (incl. Tracing)48.4 kB+0.13%+59 B 🔺
@sentry/svelte27.67 kB+0.15%+40 B 🔺
CDN Bundle30.05 kB+0.16%+47 B 🔺
CDN Bundle (incl. Tracing)48.41 kB+0.14%+64 B 🔺
CDN Bundle (incl. Logs, Metrics)31.64 kB+0.16%+49 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics)49.71 kB+0.11%+53 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.87 kB+0.07%+43 B 🔺
CDN Bundle (incl. Tracing, Replay)85.9 kB+0.07%+56 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)87.21 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.7 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.97 kB+0.05%+45 B 🔺
CDN Bundle - uncompressed89.58 kB+0.25%+216 B 🔺
CDN Bundle (incl. Tracing) - uncompressed146.33 kB+0.15%+216 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.29 kB+0.23%+216 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.31 kB+0.15%+216 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed219.02 kB+0.1%+216 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed265.54 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed269.5 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.24 kB+0.08%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed283.19 kB+0.08%+216 B 🔺
@sentry/nextjs (client)51.22 kB+0.09%+46 B 🔺
@sentry/sveltekit (client)46.86 kB+0.13%+57 B 🔺
@sentry/core/server78.47 kB+0.07%+53 B 🔺
@sentry/core/browser64.82 kB+0.08%+50 B 🔺
@sentry/node-core62.79 kB+0.11%+65 B 🔺
@sentry/node125.2 kB+0.09%+111 B 🔺
@sentry/node (incl. diagnostics channel injection)139.76 kB+0.08%+100 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.96 kB--
@sentry/node/light50.8 kB+0.14%+67 B 🔺
@sentry/node - without tracing74.17 kB+0.1%+71 B 🔺
@sentry/aws-serverless83.39 kB+0.08%+60 B 🔺
@sentry/cloudflare (withSentry) - minified181.79 kB+0.12%+216 B 🔺
@sentry/cloudflare (withSentry)449.98 kB+0.11%+490 B 🔺

View base workflow run

Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.

It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.

An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.

Maybe we should make this more clear in the JSDoc?

@logaretmlogaretmJul 13, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.

Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.

@s1gr1d
s1gr1d enabled auto-merge (squash) July 14, 2026 07:48
Comment on lines +30 to +32
// The GraphQL document has literal values redacted at collection time, so it was historically
// always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior.
graphQL: { document: true, variables: true },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH

Suggested Fix

Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.

@s1gr1d
s1gr1d merged commit f14b258 into developJul 14, 2026
311 checks passed
@s1gr1d
s1gr1d deleted the sig/add-dataCollection-graphQL branch July 14, 2026 08:05
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(core): Add and use dataCollection.graphQL - #22221

Merged
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL
Jul 14, 2026
Merged

feat(core): Add and use dataCollection.graphQL#22221
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Sets the default collection behavior to true as it has been collected already.

@s1gr1d
s1gr1d requested review from a team as code ownersJuly 13, 2026 10:50
@s1gr1d
s1gr1d requested review from Lms24, andreiborza, chargome, isaacs, logaretm, mydea and nicohrubec and removed request for a teamJuly 13, 2026 10:50
Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH

Suggested Fix

Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

github-actionsBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.65 kB+0.15%+40 B 🔺
@sentry/browser - with treeshaking flags26.1 kB+0.19%+48 B 🔺
@sentry/browser (incl. Tracing)46.42 kB+0.13%+56 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.21 kB+0.11%+51 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.2 kB+0.11%+52 B 🔺
@sentry/browser (incl. Tracing, Replay)85.67 kB+0.05%+39 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.31 kB+0.06%+44 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.38 kB+0.05%+42 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)103.04 kB+0.04%+40 B 🔺
@sentry/browser (incl. Feedback)44.83 kB+0.11%+46 B 🔺
@sentry/browser (incl. sendFeedback)32.45 kB+0.14%+44 B 🔺
@sentry/browser (incl. FeedbackAsync)37.58 kB+0.12%+44 B 🔺
@sentry/browser (incl. Metrics)28.74 kB+0.18%+50 B 🔺
@sentry/browser (incl. Logs)28.98 kB+0.15%+42 B 🔺
@sentry/browser (incl. Metrics & Logs)29.67 kB+0.16%+47 B 🔺
@sentry/react29.45 kB+0.18%+50 B 🔺
@sentry/react (incl. Tracing)48.68 kB+0.1%+46 B 🔺
@sentry/vue33.08 kB+0.14%+44 B 🔺
@sentry/vue (incl. Tracing)48.4 kB+0.13%+59 B 🔺
@sentry/svelte27.67 kB+0.15%+40 B 🔺
CDN Bundle30.05 kB+0.16%+47 B 🔺
CDN Bundle (incl. Tracing)48.41 kB+0.14%+64 B 🔺
CDN Bundle (incl. Logs, Metrics)31.64 kB+0.16%+49 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics)49.71 kB+0.11%+53 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.87 kB+0.07%+43 B 🔺
CDN Bundle (incl. Tracing, Replay)85.9 kB+0.07%+56 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)87.21 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.7 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.97 kB+0.05%+45 B 🔺
CDN Bundle - uncompressed89.58 kB+0.25%+216 B 🔺
CDN Bundle (incl. Tracing) - uncompressed146.33 kB+0.15%+216 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.29 kB+0.23%+216 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.31 kB+0.15%+216 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed219.02 kB+0.1%+216 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed265.54 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed269.5 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.24 kB+0.08%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed283.19 kB+0.08%+216 B 🔺
@sentry/nextjs (client)51.22 kB+0.09%+46 B 🔺
@sentry/sveltekit (client)46.86 kB+0.13%+57 B 🔺
@sentry/core/server78.47 kB+0.07%+53 B 🔺
@sentry/core/browser64.82 kB+0.08%+50 B 🔺
@sentry/node-core62.79 kB+0.11%+65 B 🔺
@sentry/node125.2 kB+0.09%+111 B 🔺
@sentry/node (incl. diagnostics channel injection)139.76 kB+0.08%+100 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.96 kB--
@sentry/node/light50.8 kB+0.14%+67 B 🔺
@sentry/node - without tracing74.17 kB+0.1%+71 B 🔺
@sentry/aws-serverless83.39 kB+0.08%+60 B 🔺
@sentry/cloudflare (withSentry) - minified181.79 kB+0.12%+216 B 🔺
@sentry/cloudflare (withSentry)449.98 kB+0.11%+490 B 🔺

View base workflow run

Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.

It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.

An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.

Maybe we should make this more clear in the JSDoc?

@logaretmlogaretmJul 13, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.

Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.

@s1gr1d
s1gr1d enabled auto-merge (squash) July 14, 2026 07:48
Comment on lines +30 to +32
// The GraphQL document has literal values redacted at collection time, so it was historically
// always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior.
graphQL: { document: true, variables: true },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH

Suggested Fix

Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.

@s1gr1d
s1gr1d merged commit f14b258 into developJul 14, 2026
311 checks passed
@s1gr1d
s1gr1d deleted the sig/add-dataCollection-graphQL branch July 14, 2026 08:05
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(core): Add and use dataCollection.graphQL - #22221

Merged
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL
Jul 14, 2026
Merged

feat(core): Add and use dataCollection.graphQL#22221
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Sets the default collection behavior to true as it has been collected already.

@s1gr1d
s1gr1d requested review from a team as code ownersJuly 13, 2026 10:50
@s1gr1d
s1gr1d requested review from Lms24, andreiborza, chargome, isaacs, logaretm, mydea and nicohrubec and removed request for a teamJuly 13, 2026 10:50
Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH

Suggested Fix

Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

github-actionsBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.65 kB+0.15%+40 B 🔺
@sentry/browser - with treeshaking flags26.1 kB+0.19%+48 B 🔺
@sentry/browser (incl. Tracing)46.42 kB+0.13%+56 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.21 kB+0.11%+51 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.2 kB+0.11%+52 B 🔺
@sentry/browser (incl. Tracing, Replay)85.67 kB+0.05%+39 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.31 kB+0.06%+44 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.38 kB+0.05%+42 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)103.04 kB+0.04%+40 B 🔺
@sentry/browser (incl. Feedback)44.83 kB+0.11%+46 B 🔺
@sentry/browser (incl. sendFeedback)32.45 kB+0.14%+44 B 🔺
@sentry/browser (incl. FeedbackAsync)37.58 kB+0.12%+44 B 🔺
@sentry/browser (incl. Metrics)28.74 kB+0.18%+50 B 🔺
@sentry/browser (incl. Logs)28.98 kB+0.15%+42 B 🔺
@sentry/browser (incl. Metrics & Logs)29.67 kB+0.16%+47 B 🔺
@sentry/react29.45 kB+0.18%+50 B 🔺
@sentry/react (incl. Tracing)48.68 kB+0.1%+46 B 🔺
@sentry/vue33.08 kB+0.14%+44 B 🔺
@sentry/vue (incl. Tracing)48.4 kB+0.13%+59 B 🔺
@sentry/svelte27.67 kB+0.15%+40 B 🔺
CDN Bundle30.05 kB+0.16%+47 B 🔺
CDN Bundle (incl. Tracing)48.41 kB+0.14%+64 B 🔺
CDN Bundle (incl. Logs, Metrics)31.64 kB+0.16%+49 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics)49.71 kB+0.11%+53 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.87 kB+0.07%+43 B 🔺
CDN Bundle (incl. Tracing, Replay)85.9 kB+0.07%+56 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)87.21 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.7 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.97 kB+0.05%+45 B 🔺
CDN Bundle - uncompressed89.58 kB+0.25%+216 B 🔺
CDN Bundle (incl. Tracing) - uncompressed146.33 kB+0.15%+216 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.29 kB+0.23%+216 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.31 kB+0.15%+216 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed219.02 kB+0.1%+216 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed265.54 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed269.5 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.24 kB+0.08%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed283.19 kB+0.08%+216 B 🔺
@sentry/nextjs (client)51.22 kB+0.09%+46 B 🔺
@sentry/sveltekit (client)46.86 kB+0.13%+57 B 🔺
@sentry/core/server78.47 kB+0.07%+53 B 🔺
@sentry/core/browser64.82 kB+0.08%+50 B 🔺
@sentry/node-core62.79 kB+0.11%+65 B 🔺
@sentry/node125.2 kB+0.09%+111 B 🔺
@sentry/node (incl. diagnostics channel injection)139.76 kB+0.08%+100 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.96 kB--
@sentry/node/light50.8 kB+0.14%+67 B 🔺
@sentry/node - without tracing74.17 kB+0.1%+71 B 🔺
@sentry/aws-serverless83.39 kB+0.08%+60 B 🔺
@sentry/cloudflare (withSentry) - minified181.79 kB+0.12%+216 B 🔺
@sentry/cloudflare (withSentry)449.98 kB+0.11%+490 B 🔺

View base workflow run

Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.

It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.

An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.

Maybe we should make this more clear in the JSDoc?

@logaretmlogaretmJul 13, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.

Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.

@s1gr1d
s1gr1d enabled auto-merge (squash) July 14, 2026 07:48
Comment on lines +30 to +32
// The GraphQL document has literal values redacted at collection time, so it was historically
// always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior.
graphQL: { document: true, variables: true },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH

Suggested Fix

Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.

@s1gr1d
s1gr1d merged commit f14b258 into developJul 14, 2026
311 checks passed
@s1gr1d
s1gr1d deleted the sig/add-dataCollection-graphQL branch July 14, 2026 08:05
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(core): Add and use dataCollection.graphQL - #22221

Merged
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL
Jul 14, 2026
Merged

feat(core): Add and use dataCollection.graphQL#22221
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Sets the default collection behavior to true as it has been collected already.

@s1gr1d
s1gr1d requested review from a team as code ownersJuly 13, 2026 10:50
@s1gr1d
s1gr1d requested review from Lms24, andreiborza, chargome, isaacs, logaretm, mydea and nicohrubec and removed request for a teamJuly 13, 2026 10:50
Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH

Suggested Fix

Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

github-actionsBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.65 kB+0.15%+40 B 🔺
@sentry/browser - with treeshaking flags26.1 kB+0.19%+48 B 🔺
@sentry/browser (incl. Tracing)46.42 kB+0.13%+56 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.21 kB+0.11%+51 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.2 kB+0.11%+52 B 🔺
@sentry/browser (incl. Tracing, Replay)85.67 kB+0.05%+39 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.31 kB+0.06%+44 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.38 kB+0.05%+42 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)103.04 kB+0.04%+40 B 🔺
@sentry/browser (incl. Feedback)44.83 kB+0.11%+46 B 🔺
@sentry/browser (incl. sendFeedback)32.45 kB+0.14%+44 B 🔺
@sentry/browser (incl. FeedbackAsync)37.58 kB+0.12%+44 B 🔺
@sentry/browser (incl. Metrics)28.74 kB+0.18%+50 B 🔺
@sentry/browser (incl. Logs)28.98 kB+0.15%+42 B 🔺
@sentry/browser (incl. Metrics & Logs)29.67 kB+0.16%+47 B 🔺
@sentry/react29.45 kB+0.18%+50 B 🔺
@sentry/react (incl. Tracing)48.68 kB+0.1%+46 B 🔺
@sentry/vue33.08 kB+0.14%+44 B 🔺
@sentry/vue (incl. Tracing)48.4 kB+0.13%+59 B 🔺
@sentry/svelte27.67 kB+0.15%+40 B 🔺
CDN Bundle30.05 kB+0.16%+47 B 🔺
CDN Bundle (incl. Tracing)48.41 kB+0.14%+64 B 🔺
CDN Bundle (incl. Logs, Metrics)31.64 kB+0.16%+49 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics)49.71 kB+0.11%+53 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.87 kB+0.07%+43 B 🔺
CDN Bundle (incl. Tracing, Replay)85.9 kB+0.07%+56 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)87.21 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.7 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.97 kB+0.05%+45 B 🔺
CDN Bundle - uncompressed89.58 kB+0.25%+216 B 🔺
CDN Bundle (incl. Tracing) - uncompressed146.33 kB+0.15%+216 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.29 kB+0.23%+216 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.31 kB+0.15%+216 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed219.02 kB+0.1%+216 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed265.54 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed269.5 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.24 kB+0.08%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed283.19 kB+0.08%+216 B 🔺
@sentry/nextjs (client)51.22 kB+0.09%+46 B 🔺
@sentry/sveltekit (client)46.86 kB+0.13%+57 B 🔺
@sentry/core/server78.47 kB+0.07%+53 B 🔺
@sentry/core/browser64.82 kB+0.08%+50 B 🔺
@sentry/node-core62.79 kB+0.11%+65 B 🔺
@sentry/node125.2 kB+0.09%+111 B 🔺
@sentry/node (incl. diagnostics channel injection)139.76 kB+0.08%+100 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.96 kB--
@sentry/node/light50.8 kB+0.14%+67 B 🔺
@sentry/node - without tracing74.17 kB+0.1%+71 B 🔺
@sentry/aws-serverless83.39 kB+0.08%+60 B 🔺
@sentry/cloudflare (withSentry) - minified181.79 kB+0.12%+216 B 🔺
@sentry/cloudflare (withSentry)449.98 kB+0.11%+490 B 🔺

View base workflow run

Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.

It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.

An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.

Maybe we should make this more clear in the JSDoc?

@logaretmlogaretmJul 13, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.

Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.

@s1gr1d
s1gr1d enabled auto-merge (squash) July 14, 2026 07:48
Comment on lines +30 to +32
// The GraphQL document has literal values redacted at collection time, so it was historically
// always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior.
graphQL: { document: true, variables: true },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH

Suggested Fix

Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.

@s1gr1d
s1gr1d merged commit f14b258 into developJul 14, 2026
311 checks passed
@s1gr1d
s1gr1d deleted the sig/add-dataCollection-graphQL branch July 14, 2026 08:05
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(core): Add and use dataCollection.graphQL - #22221

Merged
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL
Jul 14, 2026
Merged

feat(core): Add and use dataCollection.graphQL#22221
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Sets the default collection behavior to true as it has been collected already.

@s1gr1d
s1gr1d requested review from a team as code ownersJuly 13, 2026 10:50
@s1gr1d
s1gr1d requested review from Lms24, andreiborza, chargome, isaacs, logaretm, mydea and nicohrubec and removed request for a teamJuly 13, 2026 10:50
Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH

Suggested Fix

Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

github-actionsBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.65 kB+0.15%+40 B 🔺
@sentry/browser - with treeshaking flags26.1 kB+0.19%+48 B 🔺
@sentry/browser (incl. Tracing)46.42 kB+0.13%+56 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.21 kB+0.11%+51 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.2 kB+0.11%+52 B 🔺
@sentry/browser (incl. Tracing, Replay)85.67 kB+0.05%+39 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.31 kB+0.06%+44 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.38 kB+0.05%+42 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)103.04 kB+0.04%+40 B 🔺
@sentry/browser (incl. Feedback)44.83 kB+0.11%+46 B 🔺
@sentry/browser (incl. sendFeedback)32.45 kB+0.14%+44 B 🔺
@sentry/browser (incl. FeedbackAsync)37.58 kB+0.12%+44 B 🔺
@sentry/browser (incl. Metrics)28.74 kB+0.18%+50 B 🔺
@sentry/browser (incl. Logs)28.98 kB+0.15%+42 B 🔺
@sentry/browser (incl. Metrics & Logs)29.67 kB+0.16%+47 B 🔺
@sentry/react29.45 kB+0.18%+50 B 🔺
@sentry/react (incl. Tracing)48.68 kB+0.1%+46 B 🔺
@sentry/vue33.08 kB+0.14%+44 B 🔺
@sentry/vue (incl. Tracing)48.4 kB+0.13%+59 B 🔺
@sentry/svelte27.67 kB+0.15%+40 B 🔺
CDN Bundle30.05 kB+0.16%+47 B 🔺
CDN Bundle (incl. Tracing)48.41 kB+0.14%+64 B 🔺
CDN Bundle (incl. Logs, Metrics)31.64 kB+0.16%+49 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics)49.71 kB+0.11%+53 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.87 kB+0.07%+43 B 🔺
CDN Bundle (incl. Tracing, Replay)85.9 kB+0.07%+56 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)87.21 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.7 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.97 kB+0.05%+45 B 🔺
CDN Bundle - uncompressed89.58 kB+0.25%+216 B 🔺
CDN Bundle (incl. Tracing) - uncompressed146.33 kB+0.15%+216 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.29 kB+0.23%+216 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.31 kB+0.15%+216 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed219.02 kB+0.1%+216 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed265.54 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed269.5 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.24 kB+0.08%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed283.19 kB+0.08%+216 B 🔺
@sentry/nextjs (client)51.22 kB+0.09%+46 B 🔺
@sentry/sveltekit (client)46.86 kB+0.13%+57 B 🔺
@sentry/core/server78.47 kB+0.07%+53 B 🔺
@sentry/core/browser64.82 kB+0.08%+50 B 🔺
@sentry/node-core62.79 kB+0.11%+65 B 🔺
@sentry/node125.2 kB+0.09%+111 B 🔺
@sentry/node (incl. diagnostics channel injection)139.76 kB+0.08%+100 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.96 kB--
@sentry/node/light50.8 kB+0.14%+67 B 🔺
@sentry/node - without tracing74.17 kB+0.1%+71 B 🔺
@sentry/aws-serverless83.39 kB+0.08%+60 B 🔺
@sentry/cloudflare (withSentry) - minified181.79 kB+0.12%+216 B 🔺
@sentry/cloudflare (withSentry)449.98 kB+0.11%+490 B 🔺

View base workflow run

Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.

It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.

An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.

Maybe we should make this more clear in the JSDoc?

@logaretmlogaretmJul 13, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.

Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.

@s1gr1d
s1gr1d enabled auto-merge (squash) July 14, 2026 07:48
Comment on lines +30 to +32
// The GraphQL document has literal values redacted at collection time, so it was historically
// always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior.
graphQL: { document: true, variables: true },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH

Suggested Fix

Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.

@s1gr1d
s1gr1d merged commit f14b258 into developJul 14, 2026
311 checks passed
@s1gr1d
s1gr1d deleted the sig/add-dataCollection-graphQL branch July 14, 2026 08:05
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(core): Add and use dataCollection.graphQL - #22221

Merged
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL
Jul 14, 2026
Merged

feat(core): Add and use dataCollection.graphQL#22221
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Sets the default collection behavior to true as it has been collected already.

@s1gr1d
s1gr1d requested review from a team as code ownersJuly 13, 2026 10:50
@s1gr1d
s1gr1d requested review from Lms24, andreiborza, chargome, isaacs, logaretm, mydea and nicohrubec and removed request for a teamJuly 13, 2026 10:50
Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH

Suggested Fix

Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

github-actionsBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.65 kB+0.15%+40 B 🔺
@sentry/browser - with treeshaking flags26.1 kB+0.19%+48 B 🔺
@sentry/browser (incl. Tracing)46.42 kB+0.13%+56 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.21 kB+0.11%+51 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.2 kB+0.11%+52 B 🔺
@sentry/browser (incl. Tracing, Replay)85.67 kB+0.05%+39 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.31 kB+0.06%+44 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.38 kB+0.05%+42 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)103.04 kB+0.04%+40 B 🔺
@sentry/browser (incl. Feedback)44.83 kB+0.11%+46 B 🔺
@sentry/browser (incl. sendFeedback)32.45 kB+0.14%+44 B 🔺
@sentry/browser (incl. FeedbackAsync)37.58 kB+0.12%+44 B 🔺
@sentry/browser (incl. Metrics)28.74 kB+0.18%+50 B 🔺
@sentry/browser (incl. Logs)28.98 kB+0.15%+42 B 🔺
@sentry/browser (incl. Metrics & Logs)29.67 kB+0.16%+47 B 🔺
@sentry/react29.45 kB+0.18%+50 B 🔺
@sentry/react (incl. Tracing)48.68 kB+0.1%+46 B 🔺
@sentry/vue33.08 kB+0.14%+44 B 🔺
@sentry/vue (incl. Tracing)48.4 kB+0.13%+59 B 🔺
@sentry/svelte27.67 kB+0.15%+40 B 🔺
CDN Bundle30.05 kB+0.16%+47 B 🔺
CDN Bundle (incl. Tracing)48.41 kB+0.14%+64 B 🔺
CDN Bundle (incl. Logs, Metrics)31.64 kB+0.16%+49 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics)49.71 kB+0.11%+53 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.87 kB+0.07%+43 B 🔺
CDN Bundle (incl. Tracing, Replay)85.9 kB+0.07%+56 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)87.21 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.7 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.97 kB+0.05%+45 B 🔺
CDN Bundle - uncompressed89.58 kB+0.25%+216 B 🔺
CDN Bundle (incl. Tracing) - uncompressed146.33 kB+0.15%+216 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.29 kB+0.23%+216 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.31 kB+0.15%+216 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed219.02 kB+0.1%+216 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed265.54 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed269.5 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.24 kB+0.08%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed283.19 kB+0.08%+216 B 🔺
@sentry/nextjs (client)51.22 kB+0.09%+46 B 🔺
@sentry/sveltekit (client)46.86 kB+0.13%+57 B 🔺
@sentry/core/server78.47 kB+0.07%+53 B 🔺
@sentry/core/browser64.82 kB+0.08%+50 B 🔺
@sentry/node-core62.79 kB+0.11%+65 B 🔺
@sentry/node125.2 kB+0.09%+111 B 🔺
@sentry/node (incl. diagnostics channel injection)139.76 kB+0.08%+100 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.96 kB--
@sentry/node/light50.8 kB+0.14%+67 B 🔺
@sentry/node - without tracing74.17 kB+0.1%+71 B 🔺
@sentry/aws-serverless83.39 kB+0.08%+60 B 🔺
@sentry/cloudflare (withSentry) - minified181.79 kB+0.12%+216 B 🔺
@sentry/cloudflare (withSentry)449.98 kB+0.11%+490 B 🔺

View base workflow run

Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.

It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.

An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.

Maybe we should make this more clear in the JSDoc?

@logaretmlogaretmJul 13, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.

Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.

@s1gr1d
s1gr1d enabled auto-merge (squash) July 14, 2026 07:48
Comment on lines +30 to +32
// The GraphQL document has literal values redacted at collection time, so it was historically
// always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior.
graphQL: { document: true, variables: true },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH

Suggested Fix

Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.

@s1gr1d
s1gr1d merged commit f14b258 into developJul 14, 2026
311 checks passed
@s1gr1d
s1gr1d deleted the sig/add-dataCollection-graphQL branch July 14, 2026 08:05
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(core): Add and use dataCollection.graphQL - #22221

Merged
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL
Jul 14, 2026
Merged

feat(core): Add and use dataCollection.graphQL#22221
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Sets the default collection behavior to true as it has been collected already.

@s1gr1d
s1gr1d requested review from a team as code ownersJuly 13, 2026 10:50
@s1gr1d
s1gr1d requested review from Lms24, andreiborza, chargome, isaacs, logaretm, mydea and nicohrubec and removed request for a teamJuly 13, 2026 10:50
Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH

Suggested Fix

Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

github-actionsBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.65 kB+0.15%+40 B 🔺
@sentry/browser - with treeshaking flags26.1 kB+0.19%+48 B 🔺
@sentry/browser (incl. Tracing)46.42 kB+0.13%+56 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.21 kB+0.11%+51 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.2 kB+0.11%+52 B 🔺
@sentry/browser (incl. Tracing, Replay)85.67 kB+0.05%+39 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.31 kB+0.06%+44 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.38 kB+0.05%+42 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)103.04 kB+0.04%+40 B 🔺
@sentry/browser (incl. Feedback)44.83 kB+0.11%+46 B 🔺
@sentry/browser (incl. sendFeedback)32.45 kB+0.14%+44 B 🔺
@sentry/browser (incl. FeedbackAsync)37.58 kB+0.12%+44 B 🔺
@sentry/browser (incl. Metrics)28.74 kB+0.18%+50 B 🔺
@sentry/browser (incl. Logs)28.98 kB+0.15%+42 B 🔺
@sentry/browser (incl. Metrics & Logs)29.67 kB+0.16%+47 B 🔺
@sentry/react29.45 kB+0.18%+50 B 🔺
@sentry/react (incl. Tracing)48.68 kB+0.1%+46 B 🔺
@sentry/vue33.08 kB+0.14%+44 B 🔺
@sentry/vue (incl. Tracing)48.4 kB+0.13%+59 B 🔺
@sentry/svelte27.67 kB+0.15%+40 B 🔺
CDN Bundle30.05 kB+0.16%+47 B 🔺
CDN Bundle (incl. Tracing)48.41 kB+0.14%+64 B 🔺
CDN Bundle (incl. Logs, Metrics)31.64 kB+0.16%+49 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics)49.71 kB+0.11%+53 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.87 kB+0.07%+43 B 🔺
CDN Bundle (incl. Tracing, Replay)85.9 kB+0.07%+56 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)87.21 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.7 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.97 kB+0.05%+45 B 🔺
CDN Bundle - uncompressed89.58 kB+0.25%+216 B 🔺
CDN Bundle (incl. Tracing) - uncompressed146.33 kB+0.15%+216 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.29 kB+0.23%+216 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.31 kB+0.15%+216 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed219.02 kB+0.1%+216 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed265.54 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed269.5 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.24 kB+0.08%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed283.19 kB+0.08%+216 B 🔺
@sentry/nextjs (client)51.22 kB+0.09%+46 B 🔺
@sentry/sveltekit (client)46.86 kB+0.13%+57 B 🔺
@sentry/core/server78.47 kB+0.07%+53 B 🔺
@sentry/core/browser64.82 kB+0.08%+50 B 🔺
@sentry/node-core62.79 kB+0.11%+65 B 🔺
@sentry/node125.2 kB+0.09%+111 B 🔺
@sentry/node (incl. diagnostics channel injection)139.76 kB+0.08%+100 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.96 kB--
@sentry/node/light50.8 kB+0.14%+67 B 🔺
@sentry/node - without tracing74.17 kB+0.1%+71 B 🔺
@sentry/aws-serverless83.39 kB+0.08%+60 B 🔺
@sentry/cloudflare (withSentry) - minified181.79 kB+0.12%+216 B 🔺
@sentry/cloudflare (withSentry)449.98 kB+0.11%+490 B 🔺

View base workflow run

Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.

It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.

An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.

Maybe we should make this more clear in the JSDoc?

@logaretmlogaretmJul 13, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.

Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.

@s1gr1d
s1gr1d enabled auto-merge (squash) July 14, 2026 07:48
Comment on lines +30 to +32
// The GraphQL document has literal values redacted at collection time, so it was historically
// always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior.
graphQL: { document: true, variables: true },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH

Suggested Fix

Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.

@s1gr1d
s1gr1d merged commit f14b258 into developJul 14, 2026
311 checks passed
@s1gr1d
s1gr1d deleted the sig/add-dataCollection-graphQL branch July 14, 2026 08:05
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@logaretm
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(core): Add and use dataCollection.graphQL - #22221

Merged
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL
Jul 14, 2026
Merged

feat(core): Add and use dataCollection.graphQL#22221
s1gr1d merged 3 commits into
developfrom
sig/add-dataCollection-graphQL

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Sets the default collection behavior to true as it has been collected already.

@s1gr1d
s1gr1d requested review from a team as code ownersJuly 13, 2026 10:50
@s1gr1d
s1gr1d requested review from Lms24, andreiborza, chargome, isaacs, logaretm, mydea and nicohrubec and removed request for a teamJuly 13, 2026 10:50
Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The graphQL.variables configuration option is defined but never used, making the feature to control GraphQL variable collection non-functional.
Severity: HIGH

Suggested Fix

Implement the logic to read the getDataCollectionOptions().graphQL.variables setting. Based on its value, conditionally collect or suppress the variables field from GraphQL requests. This logic should be added where GraphQL bodies are processed, such as in packages/browser/src/integrations/graphqlClient.ts and packages/server-utils/src/graphql/utils.ts.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: packages/core/src/types/datacollection.ts#L59-L62
Potential issue: The `graphQL.variables` configuration option is defined and documented,
but its value is never read in the production codebase. No code checks
`getDataCollectionOptions().graphQL.variables` before collecting GraphQL variables.
Since no variable collection code exists, the setting has no effect. Users who set
`graphQL: { variables: false }` believing they are suppressing variable collection are
not actually having variables collected (as the feature is missing), and users who set
`variables: true` believing variables will be captured find they are not. The API
contract is unfulfilled as the implementation is missing.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

github-actionsBot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser27.65 kB+0.15%+40 B 🔺
@sentry/browser - with treeshaking flags26.1 kB+0.19%+48 B 🔺
@sentry/browser (incl. Tracing)46.42 kB+0.13%+56 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.21 kB+0.11%+51 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.2 kB+0.11%+52 B 🔺
@sentry/browser (incl. Tracing, Replay)85.67 kB+0.05%+39 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags75.31 kB+0.06%+44 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)90.38 kB+0.05%+42 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)103.04 kB+0.04%+40 B 🔺
@sentry/browser (incl. Feedback)44.83 kB+0.11%+46 B 🔺
@sentry/browser (incl. sendFeedback)32.45 kB+0.14%+44 B 🔺
@sentry/browser (incl. FeedbackAsync)37.58 kB+0.12%+44 B 🔺
@sentry/browser (incl. Metrics)28.74 kB+0.18%+50 B 🔺
@sentry/browser (incl. Logs)28.98 kB+0.15%+42 B 🔺
@sentry/browser (incl. Metrics & Logs)29.67 kB+0.16%+47 B 🔺
@sentry/react29.45 kB+0.18%+50 B 🔺
@sentry/react (incl. Tracing)48.68 kB+0.1%+46 B 🔺
@sentry/vue33.08 kB+0.14%+44 B 🔺
@sentry/vue (incl. Tracing)48.4 kB+0.13%+59 B 🔺
@sentry/svelte27.67 kB+0.15%+40 B 🔺
CDN Bundle30.05 kB+0.16%+47 B 🔺
CDN Bundle (incl. Tracing)48.41 kB+0.14%+64 B 🔺
CDN Bundle (incl. Logs, Metrics)31.64 kB+0.16%+49 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics)49.71 kB+0.11%+53 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)70.87 kB+0.07%+43 B 🔺
CDN Bundle (incl. Tracing, Replay)85.9 kB+0.07%+56 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)87.21 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)91.7 kB+0.06%+49 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)92.97 kB+0.05%+45 B 🔺
CDN Bundle - uncompressed89.58 kB+0.25%+216 B 🔺
CDN Bundle (incl. Tracing) - uncompressed146.33 kB+0.15%+216 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed94.29 kB+0.23%+216 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed150.31 kB+0.15%+216 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed219.02 kB+0.1%+216 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed265.54 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed269.5 kB+0.09%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.24 kB+0.08%+216 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed283.19 kB+0.08%+216 B 🔺
@sentry/nextjs (client)51.22 kB+0.09%+46 B 🔺
@sentry/sveltekit (client)46.86 kB+0.13%+57 B 🔺
@sentry/core/server78.47 kB+0.07%+53 B 🔺
@sentry/core/browser64.82 kB+0.08%+50 B 🔺
@sentry/node-core62.79 kB+0.11%+65 B 🔺
@sentry/node125.2 kB+0.09%+111 B 🔺
@sentry/node (incl. diagnostics channel injection)139.76 kB+0.08%+100 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)69.96 kB--
@sentry/node/light50.8 kB+0.14%+67 B 🔺
@sentry/node - without tracing74.17 kB+0.1%+71 B 🔺
@sentry/aws-serverless83.39 kB+0.08%+60 B 🔺
@sentry/cloudflare (withSentry) - minified181.79 kB+0.12%+216 B 🔺
@sentry/cloudflare (withSentry)449.98 kB+0.11%+490 B 🔺

View base workflow run

Comment on lines +59 to +62
graphQL?: {
document?: boolean;
variables?: boolean;
};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker but something I was discussing with @ericapisani, this creates the expectation that the SDK is going to apply these options to all GraphQL requests which is not accurate.

It would only apply if the user is using the client or the server GraphQL integrations. GraphQL requests outside of the integrations coverage won't be covered by these options which I find weird. I know the gen AI spans is already a precedent, so I don't have strong opinions here.

An alternative I considered is adding the dataCollection option to the integrations themselves rather than a top-level option.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The core idea of the top-level option is to have only one place where all of this is defined in an on/off switch manner (like: this is allowed to be sent, but you also need the integration to be enabled). This makes it easier to see it all at once. According to the spec, it's also possible to add it on integration level, which would overwrite the option set on the root-level.

Maybe we should make this more clear in the JSDoc?

@logaretmlogaretmJul 13, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's fine, we already have a precedent for it with gen AI stuff so not feeling too strongly about it but it is something that I wanted to bring up is all.

Maybe adding a line or two in the JS doc to explain what "it won't do" will help here.

@s1gr1d
s1gr1d enabled auto-merge (squash) July 14, 2026 07:48
Comment on lines +30 to +32
// The GraphQL document has literal values redacted at collection time, so it was historically
// always attached regardless of `sendDefaultPii`; keep it on to preserve that behavior.
graphQL: { document: true, variables: true },

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: When sendDefaultPii is false, graphQL.variables is incorrectly set to true. This contradicts the goal of minimizing PII collection and sets up a potential future PII leak.
Severity: HIGH

Suggested Fix

Change the default setting for graphQL.variables to false when sendDefaultPii is false in defaultPiiToCollectionOptions.ts. This aligns the behavior with other PII-sensitive settings and prevents a future potential PII leak. The line should be changed to graphQL: { document: true, variables: false }.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location:
packages/core/src/utils/data-collection/defaultPiiToCollectionOptions.ts#L30-L32
Potential issue: The default data collection options set `graphQL.variables` to `true`
even when `sendDefaultPii` is `false`. The purpose of `sendDefaultPii: false` is to
prevent the collection of Personally Identifiable Information (PII). GraphQL variables
can contain sensitive user data, and unlike `graphQL.document`, they are not redacted.
While no code currently consumes the `graphQL.variables` setting, this configuration is
a design error. It creates a high risk that future code implementing GraphQL variable
collection will inadvertently capture and send PII for users who have opted out, as the
default setting will be assumed to be safe.

@s1gr1d
s1gr1d merged commit f14b258 into developJul 14, 2026
311 checks passed
@s1gr1d
s1gr1d deleted the sig/add-dataCollection-graphQL branch July 14, 2026 08:05
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
botre added a commit to formspark/documentation that referenced this pull request Aug 16, 2026
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
* Bump @sentry/vue from 10.0.0 to 10.70.0
`@sentry/vue` `^10.0.0` → `^10.70.0` (dependencies).
This updates what `package.json` declares. The range may already have
permitted the newer version, in which case only the declaration was stale.
Lockfile resolved by `npm`, with no install and no lifecycle scripts.
Produced by a script, not a model — a lockfile is not something to write by hand.
<details><summary>Release notes</summary>
### 10.70.0
- feat(v10/core): Support stable MCP SDK v2 ([#22986](getsentry/sentry-javascript#22986))
- feat(v10/deps): Bump `@sentry/node-cpu-profiler` to 2.4.3 ([#22992](getsentry/sentry-javascript#22992))
- feat(v10/solid,solidstart): Support `@solidjs/router` v1 ([#23163](getsentry/sentry-javascript#23163))
- fix(v10/cloudflare): Fork the isolation scope for Durable Object methods ([#23189](getsentry/sentry-javascript#23189))
- fix(v10/cloudflare): Get original waituntil in workflows ([#23192](getsentry/sentry-javascript#23192))
- fix(v10/cloudflare): Instrument DO RPC methods on the prototype, not a Proxy ([#23190](getsentry/sentry-javascript#23190))
- fix(v10/cloudflare): Set agent conversation id on the `onRequest` path ([#22985](getsentry/sentry-javascript#22985))
- fix(v10/cloudflare): Set conversation id independent of session name ([#23193](getsentry/sentry-javascript#23193))
- fix(v10/cloudflare): Try/catch on non-configurable prototypes ([#23191](https://github.com/getsentry/sentry-javascript
…truncated; see the release link above.
### 10.69.0
### Important Changes
- **feat(v10/cloudflare): Add `instrumentAgentWithSentry` for Cloudflare Agents ([#22786](getsentry/sentry-javascript#22786
The Cloudflare SDK adds a new `instrumentAgentWithSentry` API for [Cloudflare Agents](https://agents.cloudflare.com/). It works like `instrumentDurableObjectWithSentry` for `Agent` classes from the `agents` SDK and additionally creates spans for `@callable` RPC methods and automatically sets the `conversationId` based on the agent's name. When building with the Sentry Vite plugin, Agents are instrumented automatically ([#22788](getsentry/sentry-javascript#22788)).
### Other Changes
- feat(v10/cloudflare): Add Spotlight integration for local dev event forwarding ([#22796](getsentry/sentry-javascript#22796))
- feat(v10/cloudflare): Add wranglerConfigPath to Vite options ([#22803](getsentry/sentry-javascript#22803))
- feat(v10/cloudflare): Filter framework-internal Durable Object storage spans ([#22770](getsentry/sentry-javascript#22770))
- feat(v10/cloudflare): Instrument Agents automatically ([#22788](https://gith
…truncated; see the release link above.
### 10.68.0
- feat(cloudflare): Add @sentry/cloudflare/vite orchestrion plugin ([#21967](getsentry/sentry-javascript#21967))
- feat(nestjs): Support WebSocket errors in SentryGlobalFilter ([#22224](getsentry/sentry-javascript#22224))
- feat(node,server-utils): Set `cache.key` on dataloader spans and capture redis delete operations as `cache.remove` ([#22389](getsentry/sentry-javascript#22389))
- feat(server-utils): Allow integrations to be part of marker ([#22094](getsentry/sentry-javascript#22094))
- feat(server-utils): Migrate `FirebaseInstrumentation` to orchestrion ([#22141](getsentry/sentry-javascript#22141))
- feat(server-utils): Warn when bundler config has instrumented module in external ([#22379](getsentry/sentry-javascript#22379))
- feat(v10): Add `http.route` attribute to `http.server` spans with parameterized routes ([#22564](getsentry/sentry-javascript#22564))
- feat(v10): Add `url.full` and `url.path` to `http.server` spans ([#22533](getsentry/sentry-javascript#22533))
- feat(v10/cloudflare)
…truncated; see the release link above.
### 10.67.0
### Important Changes
- **feat(sveltekit): Add support for SvelteKit 3 ([#22264](getsentry/sentry-javascript#22264
The SvelteKit SDK now supports the pre-release of SvelteKit 3, including client-side pageload and navigation tracing and server-side native tracing, alongside continued SvelteKit 2 support. No Sentry-specific setup changes are required. The SDK detects your SvelteKit version and picks the right implementation automatically.
### Other Changes
- feat(aws-serverless): Use orchestrion aws-sdk integration under diagnostics-channel opt-in ([#22143](getsentry/sentry-javascript#22143))
- feat(cloudflare): Auto-instrument Workers AI binding via env instrumentation ([#22126](getsentry/sentry-javascript#22126))
- feat(cloudflare): Instrument Cloudflare rate limiter bindings ([#22035](getsentry/sentry-javascript#22035))
- feat(core): Instrument workers-ai-provider ([#22119](getsentry/sentry-javascript#22119))
- feat(core): Rename `queryParams` to `urlQueryParams` ([#22217](getsentry/sentry-javascript#22217))
- feat(mongodb): impl
…truncated; see the release link above.
### 10.66.0
- chore(node-core): Deprecate `@sentry/node-core` package ([#22285](getsentry/sentry-javascript#22285))
- chore(tanstackstart): Deprecate `@sentry/tanstackstart` package ([#22284](getsentry/sentry-javascript#22284))
- deps(server-utils): bump @apm-js-collab/code-transformer and tracing-hooks ([#22172](getsentry/sentry-javascript#22172))
- feat(bun): Add `initWithoutDefaultIntegrations` and `getDefaultIntegrationsWithoutPerformance` ([#22036](getsentry/sentry-javascript#22036))
- feat(bundlers): Add orchestrion bundler plugins ([#22124](getsentry/sentry-javascript#22124))
- feat(cloudflare): Support Cloudflare types v5 & newer wrangler versions ([#22180](getsentry/sentry-javascript#22180))
- feat(core): Add and use `dataCollection.databaseQueryData` (for e.g. Supabase filter values and mutation bodies) ([#22219](getsentry/sentry-javascript#22219))
- feat(core): Add and use `dataCollection.graphQL` ([#22221](getsentry/sentry-javascript#22221))
- feat(core): Add stringify helper and make AI-traci
…truncated; see the release link above.
### 10.65.0
- feat(angular): Set `url` attributes on pageload and navigation spans ([#21985](getsentry/sentry-javascript#21985))
- feat(astro): Set `url.template` on pageload spans ([#22011](getsentry/sentry-javascript#22011))
- feat(aws-serverless): Replace OTel Lambda instrumentation with handler redirection ([#22079](getsentry/sentry-javascript#22079))
- feat(browser): Set `url.path` and `url.full` on pageload and navigation spans ([#21952](getsentry/sentry-javascript#21952))
- feat(bun): warn when externalizing instrumented deps ([#21999](getsentry/sentry-javascript#21999))
- feat(core): Require `attributes` on `SerializedStreamedSpan` ([#22052](getsentry/sentry-javascript#22052))
- feat(ember): Set `url.template`, `url.path` and `url.full` on router spans ([#22095](getsentry/sentry-javascript#22095))
- feat(mysql2): Instrument mysql2 >= 3.20.0 via native tracing channels ([#21824](getsentry/sentry-javascript#21824))
- feat(nextjs): Set `url` attributes on pageload and navigation spans ([#22006](https
…truncated; see the release link above.
### 10.64.0
### Important Changes
- **feat(cloudflare): Add `nodejs_compat` entrypoint ([#21881](getsentry/sentry-javascript#21881
The Cloudflare SDK now ships a dedicated `@sentry/cloudflare/nodejs_compat` entrypoint for Workers running with the `nodejs_compat` flag. This entrypoint unlocks Node SDK features on Cloudflare, including the `prismaIntegration` ([#21882](getsentry/sentry-javascript#21882)) and AI v7 support for the `vercelAiIntegration` ([#21917](getsentry/sentry-javascript#21917)).
This entrypoint is a drop-in replacement, so you can switch your imports from `@sentry/cloudflare` directly to `@sentry/cloudflare/nodejs_compat`. To use it, your Worker must set the `nodejs_compat` compatibility flag in `wrangler.toml`/`wrangler.jsonc`. This will become the default entrypoint in v11.
- **feat: Use Sentry's minimal OpenTelemetry tracer provider by default ([#21666](getsentry/sentry-javascript#21666), [#21680](getsentry/sentry-javascript#21680), [#21842](getsentry/sentry-javascript#21842
The Node SDK now registers Sentry's own
…truncated; see the release link above.
### 10.63.0
- feat(browser): Add `url.full` attribute to resource spans ([#21846](getsentry/sentry-javascript#21846))
- feat(core): Add `extendIntegration` method ([#21759](getsentry/sentry-javascript#21759))
- feat(core): Add `isTracingSuppressed` to the async context strategy ([#21785](getsentry/sentry-javascript#21785))
- feat(core): Pass normalizedRequest to the sampling context for root spans ([#21833](getsentry/sentry-javascript#21833))
- feat(node): Add lru-memoizer diagnostics-channel integration to experimentalUseDiagnosticsChannelInjection ([#21786](getsentry/sentry-javascript#21786))
- feat(node): Expose channel-based, streamlined `fastifyIntegration` ([#21706](getsentry/sentry-javascript#21706))
- fix(browser): Defer sending session envelope until browser is idle ([#21844](getsentry/sentry-javascript#21844))
- fix(core): Improve waiting for tracing channel bindings ([#21815](getsentry/sentry-javascript#21815))
- fix(core): Serialize streamed span status message to `sentry.status.message` attri
…truncated; see the release link above.
_71 earlier release(s) in this range are not shown._
Releases: https://github.com/getsentry/sentry-javascript/releases
</details>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@s1gr1d@logaretm