Skip to content

fix(deps): Bump @sentry/nextjs from 10.70.0 to 11.2.0 - #851

Open
dependabot[bot] wants to merge 1 commit into
dev-frontendfrom
dependabot/npm_and_yarn/dev-frontend/sentry/nextjs-11.2.0
Open

dependabot[bot] wants to merge 1 commit into
dev-frontendfrom
dependabot/npm_and_yarn/dev-frontend/sentry/nextjs-11.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps @sentry/nextjs from 10.70.0 to 11.2.0.

Release notes

Sourced from @​sentry/nextjs's releases.

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    @sentry/node and @sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import @sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
  • chore: Add external contributor to CHANGELOG.md (#24822)
  • chore: Add external contributor to CHANGELOG.md (#24827)
  • chore: Add external contributor to CHANGELOG.md (#24835)
  • chore: Add external contributor to CHANGELOG.md (#24850)
  • chore: Add external contributor to CHANGELOG.md (#24851)
  • chore: Add external contributor to CHANGELOG.md (#24914)
  • chore(deps): Update to Vitest 4 and Vite 8 (#24746)
  • chore(github): Add external label on PRs of external contributors (#24825)
  • chore(solidstart): Remove unused Vitest setup from e2e apps (#24789)
  • ci: shard Bun integration tests (#24771)

... (truncated)

Changelog

Sourced from @​sentry/nextjs's changelog.

11.2.0

Important Changes

  • feat(hono): add orchestrion-based auto-instrumentation (#24497)

    Hono is now instrumented automatically. Request spans are named after the matched Hono route, each middleware gets its own span, and errors thrown in handlers are captured.

  • feat(node/bun): Enable dedupeIntegration by default (#24794)

    @sentry/node and @sentry/bun now include dedupeIntegration in their default integrations, like the browser, Deno, Vercel Edge and Cloudflare SDKs. When the same error is captured two times in a row, only the first event is sent. To keep the previous behavior, remove the integration: integrations: defaults => defaults.filter(integration => integration.name !== 'Dedupe').

  • feat(remix): Instrument Remix 3 server requests via fetch-router (#24801)

    On Remix 3, the SDK now adds the matched route as http.route, the response status and a low-cardinality name to the http.server span of each fetch-router request. Start the app with --import @sentry/remix/v3/node in place of --import remix/node-tsx.

Other Changes

  • chore(bundler-plugins): Allow magic-string 1.x (#24768)
  • feat(deps): Bump oxc-parser to 0.152.0 and sentry to 0.45.0 (#24823)
  • feat(elysia): Export bunRuntimeMetricsIntegration (#24892)
  • feat(react-router): Support request-scoped CSP nonces in createSentryHandleRequest (#24826)
  • fix(aws-serverless): Keep Lambda extension polling past 300s (#24811)
  • fix(browser-utils): Stop leaking DOM instrumentation listeners on mismatched removals (#24727)
  • fix(core): Resolve escape sequences in fmt / parameterize messages (#24770)
  • fix(deno): Flush buffered metrics and logs before process exit (#24807)
  • fix(node): End Express layer spans when next is called (#24854)
  • fix(node): Flush buffered metrics on process exit (#24806)
  • fix(nuxt): Fix CommonJS interop for force-inlined instrumented packages (#24799)
  • fix(server-utils): Preserve raw Anthropic response bodies (#24902)
  • fix(server-utils): Preserve raw Groq and Together response bodies (#24906)
  • fix(server-utils): Preserve raw OpenAI embeddings and conversation responses (#24908)
  • fix(server-utils): Preserve response bodies for OpenAI parse helpers (#24783)
  • fix(solidstart): Support rolldownOptions in instrumentation file plugin (#24863)
  • fix(sveltekit): Skip trace meta tags when prerendering (#24777)
  • fix(vue): Share one root render span debounce timer across components (#24868)
  • perf(server-utils): Avoid quadratic SQL sanitizer output handling (#24834)
  • chore: Add external contributor to CHANGELOG.md (#24822)
  • chore: Add external contributor to CHANGELOG.md (#24827)
  • chore: Add external contributor to CHANGELOG.md (#24835)
  • chore: Add external contributor to CHANGELOG.md (#24850)
  • chore: Add external contributor to CHANGELOG.md (#24851)
  • chore: Add external contributor to CHANGELOG.md (#24914)
  • chore(deps): Update to Vitest 4 and Vite 8 (#24746)
  • chore(github): Add external label on PRs of external contributors (#24825)
  • chore(solidstart): Remove unused Vitest setup from e2e apps (#24789)

... (truncated)

Commits
  • e1a4316 release: 11.2.0
  • 95153b1 Merge pull request #24927 from getsentry/prepare-release/11.2.0
  • b8a90a4 meta(changelog): Update changelog for 11.2.0
  • a0faac6 fix(deps): runtime dependency security fixes (#24911)
  • b45e5b8 feat(deps): bump moment from 2.30.1 to 2.31.0 (#24890)
  • 5c82d5b feat(deps): bump hono from 4.13.5 to 4.13.7 (#24916)
  • 2651a8f test(sveltekit): Add missing prerender e2e test (#24921)
  • 8de2036 feat(deps): bump fastify from 5.12.1 to 5.12.5 (#24917)
  • 29fc37c feat(deps): bump axios from 1.18.0 to 1.20.0 (#24918)
  • 012e9bb fix(server-utils): Preserve raw OpenAI embeddings and conversation responses ...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@sentry/nextjs](https://github.com/getsentry/sentry-javascript) from 10.70.0 to 11.2.0.
- [Release notes](https://github.com/getsentry/sentry-javascript/releases)
- [Changelog](https://github.com/getsentry/sentry-javascript/blob/develop/CHANGELOG.md)
- [Commits](getsentry/sentry-javascript@10.70.0...11.2.0)

---
updated-dependencies:
- dependency-name: "@sentry/nextjs"
  dependency-version: 11.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Assignees

The following users could not be added as assignees: kellymusk. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the security Security vulnerability or hardening label Oct 5, 2026
@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
aframp Error Error Oct 5, 2026 8:36am UTC

This branch had an error being deployed

1 failed deployment
Preview — 376a9c69 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security vulnerability or hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants