Update dependency posthog-js to v1.435.5 - #334
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 20, 2026 15:55
cdbe3a2 to
e2b64fa
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 20, 2026 21:55
e2b64fa to
65b6061
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 21, 2026 15:32
65b6061 to
38d57fe
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 25, 2026 12:46
38d57fe to
793275b
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 25, 2026 22:03
793275b to
1a3138b
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 26, 2026 11:45
1a3138b to
9a3076e
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 26, 2026 22:21
9a3076e to
e2c60ea
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 27, 2026 11:56
e2c60ea to
ffa44de
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
August 27, 2026 16:54
ffa44de to
a9c1e04
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 1, 2026 22:08
2b95db8 to
49c673c
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 2, 2026 11:59
49c673c to
815e220
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 2, 2026 21:49
815e220 to
80824d7
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 4, 2026 00:54
80824d7 to
1910d88
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 4, 2026 10:17
1910d88 to
c6a205c
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 4, 2026 13:23
c6a205c to
b7b14fc
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 4, 2026 20:48
b7b14fc to
f048bca
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 7, 2026 18:54
f048bca to
b215ba5
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 8, 2026 00:55
b215ba5 to
45f75d3
Compare
renovate
Bot
force-pushed
the
renovate/posthog-js-1.x-lockfile
branch
from
September 8, 2026 10:28
45f75d3 to
e7b802a
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.363.6→1.435.5Release Notes
PostHog/posthog-js (posthog-js)
v1.435.5Compare Source
1.435.5
Patch Changes
59b93a3Thanks @dustinbyrne! - Preserve session attribution and registered properties across initialization and configuration updates when persistence writes are debounced.(2026-09-30)
v1.435.4Compare Source
1.435.4
Patch Changes
5c92e83Thanks @posthog! - Fix aDataCloneErrorwhen session replay records network timing inside a cross-origin iframe.(2026-09-30)
v1.435.3Compare Source
1.435.3
Patch Changes
47db7ceThanks @posthog! - Start session recording atDOMContentLoaded, so a page whoseloadevent is late or never fires still records, and report$sdk_debug_rrweb_attachedfrom rrweb's own recording state(2026-09-30)
v1.435.2Compare Source
1.435.2
Patch Changes
bd66ceeThanks @marandaneto! - Reduce replay debug properties on captured events while preserving recording status and capture diagnostics. Report cumulative mutation-drop counts and dropped bytes on$snapshotevents only when greater than zero.(2026-09-30)
v1.435.1Compare Source
1.435.1
Patch Changes
5929eabThanks @breken-ai! - PostHogFeature withoutmatchshows the fallback when the flag evaluates to false.(2026-09-29)
v1.435.0Compare Source
1.435.0
Minor Changes
e89d224Thanks @AyobamiH! - AddonActiveMatchingSurveysChangedto subscribe to survey eligibility updates with safe unsubscribe and recoverable load-error reporting.(2026-09-29)
Patch Changes
e89d224]:v1.434.18Compare Source
1.434.18
Patch Changes
#5125
69a55c0Thanks @marandaneto! - Prevent analytics persistence writes during initialization when persistence is disabled or opted out.(2026-09-29)
#5133
fbf3990Thanks @marandaneto! - Isolate replay network masking callback errors so unrelated network records continue to be captured.(2026-09-29)
#5126
5775575Thanks @marandaneto! - Preserve equals signs in survey URL prefill values and ignore malformed URL parameters without blocking surveys.(2026-09-29)
v1.434.17Compare Source
1.434.17
Patch Changes
#5063
799e84cThanks @arnohillen! - fix(replay): keep a held recording epoch's buffered data when it hits the size cap(2026-09-28)
#5118
3212630Thanks @TueHaulund! - fix(replay): keep CSS-in-JS styles after a large DOM change in the page head(2026-09-28)
v1.434.16Compare Source
1.434.16
Patch Changes
d48c783Thanks @marandaneto! - Honor the modern replay network masking callback when both modern and deprecated hooks are configured.(2026-09-28)
v1.434.15Compare Source
1.434.15
Patch Changes
8531e40Thanks @turnipdabeets! - Fix SPA$pageviewevents frompushState/replaceStatenavigations carrying the previous page'stitle(2026-09-26)
v1.434.14Compare Source
1.434.14
Patch Changes
ae954abThanks @turnipdabeets! - FixuseThumbSurveyfrom@posthog/react/surveysandposthog-js/react/surveysignoring the client passed toPostHogProvider, which left it capturing no survey events.(2026-09-25)
v1.434.13Compare Source
1.434.13
Patch Changes
a7250f0Thanks @Piccirello! - Replay loads a recorded font under the replay iframe's content security policy, not the embedding page's.(2026-09-24)
v1.434.12Compare Source
1.434.12
Patch Changes
60bd968Thanks @ksvat! - The replayer no longer freezes the tab on a mutation that adds tens of thousands of nodes at once. It now applies a batch of 1,000 or more adds against a detached subtree, so the document updates style and layout once instead of per insert. A recorded batch of 25,746 style elements went from 92 seconds of blocked main thread to 1.5 seconds.(2026-09-23)
v1.434.11Compare Source
1.434.11
Patch Changes
1549919Thanks @DeepanshuPal! - Avoid cross-domain cookie probes when cross-subdomain cookies are disabled.(2026-09-23)
v1.434.10Compare Source
1.434.10
Patch Changes
a9c40ecThanks @marandaneto! - Fix SDK initialization when a script loader pre-creates window.posthog as a placeholder object.(2026-09-23)
v1.434.9Compare Source
1.434.9
Patch Changes
708a5f7Thanks @Christian2702! - Session replay no longer defers its input setter hooks on zone.js's patchedsetTimeout. In Angular apps each of those timers ended a zone task and triggered another change detection, so any component writing an input property on every cycle drove the tab into an endless loop at 100% CPU.(2026-09-22)
v1.434.8Compare Source
1.434.8
Patch Changes
#5054
36f356dThanks @posthog! - fix(dead-clicks): survive a denied property access in FirefoxFirefox denies property access on a DOM node from another origin or from a realm that was torn down. The detector reads
isConnectedandnodeTypeon mutation records and on composed paths, and readsgetRootNodeon selection endpoints, so the denial escaped the MutationObserver callback and stopped the rest of the batch from refreshing the liveness timestamp. A node that cannot be read is now treated as a node that cannot be inspected. (2026-09-22)v1.434.7Compare Source
1.434.7
Patch Changes
c551218Thanks @posthog! - Session replay network capture no longer fails to start in frames withoutPerformanceObserveror itssupportedEntryTypes; those frames record without live network timing.(2026-09-22)
v1.434.6Compare Source
1.434.6
Patch Changes
4770179Thanks @posthog! - Keep session recording active when a cross-origin image or video taints a canvas.(2026-09-22)
v1.434.5Compare Source
1.434.5
Patch Changes
9cd834cThanks @posthog! - Stop reporting dead clicks on controls inside open shadow roots (such as web components or micro-frontends) when the click updates content inside the shadow root.(2026-09-21)
v1.434.4Compare Source
1.434.4
Patch Changes
ed9fc04Thanks @ioannisj! - Fix$session_idbeing sent asnullwhen a sibling tab resets the session before this tab captures its first event (#5036)(2026-09-21)
v1.434.3Compare Source
1.434.3
Patch Changes
3a8035fThanks @nachogarcia! - Retry/flagsin the browser SDK on HTTP 502/504 and on request timeouts, bounded by the newfeature_flag_request_max_retriesconfig (default 1, set 0 to disable). Plain transport failures are deliberately left to the existing status-zero circuit breaker.(2026-09-21)
3a8035f]:v1.434.2Compare Source
1.434.2
Patch Changes
5cfec8bThanks @lucasheriques! - Share survey answer snapshots and response event properties with React Native for consistent partial response reporting.(2026-09-18)
5cfec8b]:v1.434.1Compare Source
1.434.1
Patch Changes
7e07338Thanks @posthog! - Capture the document navigation timing in the replay network waterfall when recording starts after the page has loaded, and stop recording a partial duplicate of that entry when recording starts while the page is still loading(2026-09-18)
v1.434.0Compare Source
1.434.0
Minor Changes
5e86154Thanks @pauldambra! - Rename themetrics.networkdefault attributes to the OTel HTTP client semantic conventions:http.request.method,server.address,server.port,url.scheme,url.template,http.response.status_codeanderror.typereplacemethod,host,pathandstatus_class.(2026-09-17)
Patch Changes
5e86154]:v1.433.10Compare Source
1.433.10
Patch Changes
#4960
c8e53faThanks @posthog! - Log a console warning when session replay stops capturing canvas frames (browser withoutOffscreenCanvas, a CSP that blocksblob:workers, or a failingcanvasCapture.maskRegionsFn), and stop changing WebGL and WebGPU canvas settings when canvas capture fails to start(2026-09-17)
#4977
0257a29Thanks @lucasheriques! - Share survey choice and question shuffling between web and React Native through surveys core. Use Fisher-Yates for web questions, preserve Other-last choice ordering, and avoid mutating configured choices.(2026-09-17)
Updated dependencies [
0257a29]:v1.433.9Compare Source
1.433.9
Patch Changes
c3043f4Thanks @marandaneto! - Add a session diagnostic when stale replay configuration cannot be refreshed, without changing recording behavior.(2026-09-17)
v1.433.8Compare Source
1.433.8
Patch Changes
c1d1fafThanks @posthog! - Prefer synchronous compression for events captured withsend_instantly, including the initial$pageview, to avoid delaying request dispatch on asynchronous compression.(2026-09-17)
v1.433.7Compare Source
1.433.7
Patch Changes
c767b98Thanks @darkopia! - fix(surveys): keep URL prefill working when localStorage is unavailable, such as on a page with an opaque origin or in private browsing(2026-09-16)
2828b6b]:v1.433.6Compare Source
1.433.6
Patch Changes
ec4062bThanks @posthog! - Stop treating a<link rel=preload as=style>resource hint as a stylesheet when recording. Because it carries the URL of the sheet it preloads, the recorder matched it to the loaded stylesheet and inlined the whole sheet onto it, putting the CSS in every full snapshot twice and reporting a failed stylesheet deferral on every snapshot.(2026-09-16)
v1.433.5Compare Source
1.433.5
Patch Changes
85b775aThanks @posthog! - Docstrings foridentity_hashandsetIdentity()now say the hash is signed with the Secret API key from Support settings, not a project secret API key or a personal API key.(2026-09-15)
85b775a]:v1.433.4Compare Source
1.433.4
Patch Changes
#4941
07c1045Thanks @marandaneto! - Capture causes and AggregateError members with relationship metadata and individual stacks, limiting output to 50 entries and 1,000 member inspections.(2026-09-15)
#4898
372afbaThanks @posthog! - Contain a throw from a third-party patchedAbortController.abort()when our own fetch timeout fires, so it is retried instead of escaping as an uncaught error, and report a single outcome per request.(2026-09-15)
#4910
38b61f9Thanks @posthog! - Keep the end of a session recording when one replay event is too large to stringify: that event is dropped and the rest of the buffer still ships, instead of the size estimate throwing and stopping the unload flush.(2026-09-15)
#4909
5d4f1f7Thanks @posthog! - Keep the session recording observers that started when one of them fails to initialize, and report the failed observers in the recorder debug properties.(2026-09-15)
Updated dependencies [
07c1045]:v1.433.3Compare Source
1.433.3
Patch Changes
79f02e7Thanks @marandaneto! - Default Fetch requests to strict-origin so referrers omit page paths and query strings.(2026-09-14)
v1.433.2Compare Source
1.433.2
Patch Changes
#4846
bd4543eThanks @posthog! - Keep session recording snapshots from different windows of the same session in separate uploads to preserve their window attribution.(2026-09-14)
#4954
3c68c08Thanks @marandaneto! - Respect Retry-After, including repeated headers, up to 30 seconds on retryable browser responses without shortening exponential backoff.(2026-09-14)
Updated dependencies [
3c68c08]:v1.433.1Compare Source
1.433.1
Patch Changes
8f11f5fThanks @marandaneto! - Respect autocapture attribute masks for link URLs and legacy class properties.(2026-09-14)
v1.433.0Compare Source
1.433.0
Minor Changes
d037ea1Thanks @mayteio! - Read Meta's_fbcand_fbpcookies for the Conversions API. When the Meta pixel is on the page, its_fbccookie holds the true ad click time, so that value now wins over the time PostHog stamps on the pageview that follows the click, and a click that landed before the SDK loaded is no longer lost. The_fbpbrowser ID is captured as the$fbpperson property, which makes it available to a conversion sent later from a backend. Both cookies are read under the same switches as the URL click ID:save_campaign_params: falseturns the reads off, and cookieless mode skips them.(2026-09-14)
v1.432.0Compare Source
1.432.0
Minor Changes
4a46fabThanks @marandaneto! - Add a resetError callback to React error-boundary fallbacks so applications can retry rendering without remounting the boundary.(2026-09-14)
Patch Changes
62fc60bThanks @marandaneto! - Fix lost event retries after restoring a page from the back-forward cache.(2026-09-14)
v1.431.8Compare Source
1.431.8
Patch Changes
6a78625Thanks @marandaneto! - Fix false dead clicks after synchronous DOM updates. Clicks stopped from bubbling are now evaluated too, which may increase dead-click counts for inert controls.(2026-09-14)
v1.431.7Compare Source
1.431.7
Patch Changes
a5d094fThanks @marandaneto! - Avoid fetch keepalive quota failures when multiple event requests are in flight.(2026-09-14)
v1.431.6Compare Source
1.431.6
Patch Changes
ee6fd02Thanks @marandaneto! - Prevent buffered session replay data from crossing projects that share a persistence name during page navigation.(2026-09-14)
v1.431.5Compare Source
1.431.5
Patch Changes
3e12f1dThanks @marandaneto! - Discard pending replay network captures after recording stops or restarts.(2026-09-14)
v1.431.4Compare Source
1.431.4
Patch Changes
#4952
4f8076bThanks @marandaneto! - Support clickable[label](url)links in Conversations widget greetings.(2026-09-14)
#4835
03e45b6Thanks @posthog! - Fix identical person property retries being dropped after the original capture was rejected.(2026-09-14)
v1.431.3Compare Source
1.431.3
Patch Changes
3acf287Thanks @marandaneto! - Fix replay cleanup when the host's children are removed before destroying the player.(2026-09-14)
v1.431.2Compare Source
1.431.2
Patch Changes
fea443aThanks @marandaneto! - Mark console-captured exceptions as handled and identify their console origin.(2026-09-14)
v1.431.1Compare Source
1.431.1
Patch Changes
b15ae1fThanks @marandaneto! - Exclude internal SDK console diagnostics from exception autocapture and report recoverable recorder diagnostics as warnings.(2026-09-14)
v1.431.0Compare Source
1.431.0
Minor Changes
c666606Thanks @pauldambra! - Addmetrics.networkconfig to record HTTP and HTTPSfetchandXMLHttpRequestdurations as histograms, with an optional custom metric name and attributes.(2026-09-14)
Patch Changes
d81541bThanks @posthog! - Contain replay errors during playback and seeking so a failed event does not stall the remaining events.(2026-09-14)
c666606]:v1.430.4Compare Source
1.430.4
Patch Changes
aeaea15Thanks @marandaneto! - Fix console capture continuing after stop or duplicating after restart when another library wraps the console.(2026-09-14)
v1.430.3Compare Source
1.430.3
Patch Changes
2ae0f26Thanks @marandaneto! - Fix session recording failing to restart after capturing events while stopped with expired config.(2026-09-12)
v1.430.2Compare Source
1.430.2
Patch Changes
a140fa7Thanks @fasyy612! - Send each replay session's snapshots in their own request so a session rotation no longer files the new session's first snapshot under the old session.(2026-09-11)
v1.430.1Compare Source
1.430.1
Patch Changes
0224a83Thanks @github-actions! - Fix scroll depth metrics carrying over between pages after client-side navigation.(2026-09-11)
v1.430.0Compare Source
1.430.0
Minor Changes
5f2b0feThanks @posthog! - Addposthog-js/full,posthog-js/no-externalandposthog-js/full/no-externalentry points, so desktop apps and other CSP-restricted builds canrequirea bundle instead of deep-importing an ES module fromdist/(2026-09-11)
Patch Changes
#4860
8207df8Thanks @posthog! - Back off automatic feature flag refreshes on idle visible pages only whenremote_config_refresh_interval_msis omitted, preserving explicitly configured intervals.(2026-09-11)
#4901
65aafccThanks @marandaneto! - Preserve batched event timestamps so delayed retries do not shift event times and prevent deduplication.(2026-09-11)
Updated dependencies [
8207df8]:v1.429.5Compare Source
1.429.5
Patch Changes
#4579
19e78ccThanks @turnipdabeets! - Cap the retry delay for log exports at 30 seconds, the ceiling the logs contract states. It previously doubled to 64 times the flush interval — 192s on web, 640s on React Native — so a log export now resumes within 30 seconds of a failing endpoint recovering, at the cost of more retry requests while that endpoint is down.(2026-09-10)
#4579
19e78ccThanks @turnipdabeets! - Keep backing off a failing log flush while new records arrive, instead of the next record resetting the retry to the flush interval.(2026-09-10)
#4579
19e78ccThanks @turnipdabeets! - Logs and metrics now always sendservice.nameandtelemetry.sdk.*, even when aresourceAttributesvalue is too large to encode in full. Previously that value could crowd them out, and the records reached PostHog with no service attribution.(2026-09-10)
Updated dependencies [
19e78cc,19e78cc,19e78cc,19e78cc,19e78cc,19e78cc,19e78cc]:v1.429.4Compare Source
1.429.4
Patch Changes
#4862
3278cd0Thanks @pauldambra! - Call the original console method with the console as its receiver when recording console logs. The wrapper passedundefinedinstead, and passed no receiver at all when reporting its own failures, which a console implementation is free to reject.(2026-09-10)
#4887
0da006cThanks @posthog! - Error tracking no longer counts an injected script as your own code. A stack frame isin_apponly when its filename names a script your app was served —http(s),file,blob,app,capacitor,ionic, a bundler scheme, or a bare path. A frame served over any other scheme, such as an in-app browser bridge oniabjs://or an extension content script onchrome-extension://, is kept for context but no longer groups the issue under your code.(2026-09-10)
#4837
99b4fc7Thanks @pauldambra! - Stop recordingautoplayattribute mutations on<video>and<audio>during session replay. The check compared a lowercase tag name againstElement.tagName, which is uppercase for HTML elements, so a looping background video emitted a mutation for everyautoplaytoggle.(2026-09-10)
Updated dependencies [
0da006c]:v1.429.3Compare Source
1.429.3
Patch Changes
#4878
14ba783Thanks @dustinbyrne! - Allow null bootstrap values and treat null or empty distinct IDs as missing.(2026-09-10)
#4831
9498567Thanks @posthog! - Log a console message when advanced_disable_feature_flags stops surveys from displaying(2026-09-10)
Updated dependencies [
14ba783,9498567]:v1.429.2Compare Source
1.429.2
Patch Changes
412c97cThanks @marandaneto! - Fix recording package exports, native ESM loading, and strict TypeScript 4.7 consumer compatibility.(2026-09-10)
412c97c]:v1.429.1Compare Source
1.429.1
Patch Changes
61b92f9Thanks @pauldambra! - Disable browser autofill on input and textarea fields during session replay.(2026-09-09)
v1.429.0Compare Source
1.429.0
Minor Changes
b441eb2Thanks @posthog! - Segment integration: allowsegmentto accept an integration config withfilterProperties, so customers can filter PostHog-generated enrichment properties before Segment sends an event to its destinations. Returningnullor throwing leaves the original Segment event unenriched.(2026-09-09)
Patch Changes
#4876
0c2a15fThanks @dustinbyrne! - Fix dead-click detection for text selection and editable caret gestures when mouse release is delayed, while continuing to report inert text clicks.(2026-09-09)
#4733
24fa541Thanks @dustinbyrne! - fix(web): avoid reporting clicks that select or unselect text as dead clicks(2026-09-09)
#4882
4bd37b7Thanks @lucasheriques! - Fix TypeScript compatibility between public replay events and the replay player.(2026-09-09)
#4833
f1395b6Thanks @posthog! - Keep surveys hidden while capture is disabled and preserve answers if capture stops before submission.(2026-09-09)
Updated dependencies [
0c2a15f,24fa541,b441eb2]:v1.428.11Compare Source
1.428.11
Patch Changes
d5abeceThanks @bs1180! - fix(surveys): don't show the default "Start typing..." placeholder when the survey's placeholder text is empty(2026-09-09)
v1.428.10Compare Source
1.428.10
Patch Changes
891eefaThanks @robbie-c! - Apply replay URL privacy settings to URL values in captured JSON-LD payloads.(2026-09-09)
891eefa,891eefa]:v1.428.9Compare Source
1.428.9
Patch Changes
e8b2be1Thanks @robbie-c! - Include the masked page URL with JSON-LD replay events.(2026-09-09)
e8b2be1]:v1.428.8Compare Source
v1.428.7Compare Source
1.428.7
Patch Changes
f93160dThanks @marandaneto! - Restore retry queue connectivity tracking when a page returns from the back-forward cache, without reactivating it after an expliciConfiguration
📅 Schedule: (in timezone America/New_York)
* 0-23 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.