Repository navigation
chore(deps): Bump @sentry/nextjs from 10.74.0 to 11.4.0 in /js - #1571
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@sentry/nextjs](https://github.com/getsentry/sentry-javascript) from 10.74.0 to 11.4.0. - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@10.74.0...11.4.0) --- updated-dependencies: - dependency-name: "@sentry/nextjs" dependency-version: 11.4.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
iamcxa
left a comment
There was a problem hiding this comment.
@dependabot[bot] Automated review of the @sentry/nextjs 10.74.0 → 11.4.0 bump.
Verification Summary
| Check | Result |
|---|---|
pnpm install --frozen-lockfile |
pass |
pnpm type:check |
clean |
pnpm lint |
clean |
pnpm test |
pass |
pnpm run build |
pass |
Findings
- MEDIUM — this bump leaves two Sentry majors in the OSS app. Only
@sentry/nextjsmoves to v11.@sentry/reactstays at^10.74.0, and so does the@datarecce/uipeer range^10.0.0. The lockfile now holds both@sentry/core@10.74.0and@sentry/core@11.4.0(see inline comment).
Notes
- The new transitive
sentry@0.45.0package comes from@sentry/bundler-plugins@11.4.0, which is Sentry's own package. It has no install scripts in the lockfile. - The OSS app has no
Sentry.initorwithSentryConfig, so the runtime impact today is limited to thecaptureExceptioncalls inapp/error.tsxandapp/global-error.tsx.
The event is COMMENT rather than APPROVE because of the version-alignment finding above. Suggest closing this PR and doing the v11 migration in the next recce-dev:address-dependabot consolidation, with @sentry/react and the @datarecce/ui peer range updated together.
| "@mui/system": "^9.4.0", | ||
| "@next/third-parties": "16.3.6", | ||
| "@sentry/nextjs": "^10.74.0", | ||
| "@sentry/nextjs": "^11.4.0", |
There was a problem hiding this comment.
MEDIUM — mixed Sentry SDK majors. @sentry/nextjs moves to ^11.4.0, but @sentry/react on the next line stays at ^10.74.0. js/packages/ui/package.json also still declares the peer "@sentry/react": "^10.0.0". As a result, the lockfile now resolves both @sentry/core@10.74.0 and @sentry/core@11.4.0.
Sentry requires every @sentry/* package to be on the same version. Each major keeps its own versioned global carrier. If a client is ever initialized through @sentry/nextjs v11, captureException calls from @sentry/react v10 will not reach it. Those calls come from ErrorBoundary.tsx and useInlineProfileDistribution.ts in @datarecce/ui, and they would be dropped silently. The two copies also add bundle weight.
Suggested fix: bump @sentry/react to ^11.4.0 in the same change. Widen the @datarecce/ui peer range to ^10.0.0 || ^11.0.0, or move it to v11 only. Then check the v11 migration notes for the ErrorBoundary/FallbackRender APIs.
Bumps @sentry/nextjs from 10.74.0 to 11.4.0.
Release notes
Sourced from @sentry/nextjs's releases.
... (truncated)
Changelog
Sourced from @sentry/nextjs's changelog.
... (truncated)
Commits
7f13c61release: 11.4.0fb73adbMerge pull request #25010 from getsentry/prepare-release/11.4.0de3fb96meta(changelog): Update changelog for 11.4.04f0fd84feat(sveltekit): Support stable SvelteKit 3 (#25009)ba4db28fix(remix): Match the Remix 3.0.0 package versions (#25008)c8738fbMerge pull request #24991 from getsentry/master5f88a0bMerge commit '1e82c8f33488bc54364d343a7c5ab33ed9056f39'1e82c8frelease: 11.3.0481c43cMerge pull request #24987 from getsentry/prepare-release/11.3.01c7308dmeta(changelog): Update changelog for 11.3.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)