fix(deps): update dependency @sentry/browser to v7 [security] - #364
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency @sentry/browser to v7 [security]#364renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
October 4, 2024 19:38
ec7de8e to
b0bf05d
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
August 10, 2025 12:32
b0bf05d to
b4fcdc4
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
August 19, 2025 18:50
b4fcdc4 to
5504772
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
August 31, 2025 10:02
5504772 to
bd081a8
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
September 25, 2025 14:38
bd081a8 to
16b763a
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
October 21, 2025 14:00
16b763a to
faf7799
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
November 10, 2025 20:53
faf7799 to
eb6d5b8
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
November 19, 2025 00:51
eb6d5b8 to
370fb12
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
December 3, 2025 17:57
370fb12 to
c0b9797
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
December 31, 2025 13:54
c0b9797 to
19576e9
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
January 8, 2026 17:01
19576e9 to
da26215
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
January 19, 2026 20:09
da26215 to
1710ba0
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
February 2, 2026 15:12
1710ba0 to
2e4fa0c
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
February 12, 2026 11:57
2e4fa0c to
f1a49f8
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
March 13, 2026 14:52
f1a49f8 to
58d51c5
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
2 times, most recently
from
March 30, 2026 21:04
58d51c5 to
5df4c7d
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
April 8, 2026 21:43
5df4c7d to
ad41c8c
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
April 29, 2026 11:52
ad41c8c to
15d1a8a
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
May 12, 2026 12:59
15d1a8a to
b9638d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
May 18, 2026 09:46
b9638d4 to
0d6e43c
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
May 28, 2026 18:18
0d6e43c to
c9714d3
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
June 13, 2026 16:02
c9714d3 to
7a5bc1b
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
July 12, 2026 09:57
7a5bc1b to
4e56806
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
July 16, 2026 14:18
4e56806 to
04a713d
Compare
renovate
Bot
force-pushed
the
renovate/npm-sentry-browser-vulnerability
branch
from
July 30, 2026 19:01
04a713d to
e9291f5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.19.7→7.119.1Sentry SDK Prototype Pollution gadget in JavaScript SDKs
GHSA-593m-55hh-j8gv
More information
Details
Impact
In case a Prototype Pollution vulnerability is present in a user's application or bundled libraries, the Sentry SDK could potentially serve as a gadget to exploit that vulnerability. The exploitability depends on the specific details of the underlying Prototype Pollution issue.
Patches
The issue was patched in all Sentry JavaScript SDKs starting from the 8.33.0 version.
Also, the fix was backported to SDK v7 in 7.119.1.
References
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
getsentry/sentry-javascript (@sentry/browser)
v7.119.1Compare Source
Work in this release contributed by @legobeat. Thank you for your contribution!
v7.119.0Compare Source
Bundle size 📦
v7.118.0Compare Source
window.Sentry(#12579)Bundle size 📦
v7.117.0Compare Source
v7tag to@sentry/replay(#12304)v7.116.0Compare Source
This release publishes a new AWS Lambda layer under the name
SentryNodeServerlessSDKv7that users still running v7 canuse instead of pinning themselves to
SentryNodeServerlessSDK:235.Bundle size 📦
v7.115.0Compare Source
start()(#12003)lastEventIddeprecation warnings (#12042)Bundle size 📦
v7.114.0Compare Source
Important Changes
This release fixes a bug that caused the cumulative layout shift (CLS) web vital not to be reported in a majority of the
cases where it should have been reported. With this change, the CLS web vital should now always be reported for
pageloads with layout shift. If a pageload did not have layout shift, no CLS web vital should be reported.
Please note that upgrading the SDK to this version may cause data in your dashboards to drastically change.
Other Changes
tunnelsupport to multiplexed transport (#11851)HTTP_REQUEST_METHODattribute (#11929)v7.113.0Compare Source
Important Changes
This release adds support for Node 22! 🎉
It also adds prebuilt-binaries for Node 22 to
@sentry/profiling-node.Other Changes
v7.112.2Compare Source
browserTracingIntegration(#11765)v7.112.1Compare Source
v7.112.0Compare Source
Important Changes
Instead of installing
@sentry/integrations, you can now import the pluggable integrations directly from your SDKpackage:
Note that only the functional integrations (e.g.
xxxIntegration()) are re-exported.Other Changes
Bundle size 📦
v7.111.0Compare Source
server.addressto browserhttp.clientspans (#11663)browserTracingIntegration(#11647)Bundle size 📦
v7.110.1Compare Source
tunnelRoutematching logic for hybrid cloud (#11577)Bundle size 📦
v7.110.0Compare Source
Important Changes
You can now use a
interactionsSampleRateto control the sample rate of INP spans.interactionsSampleRateis appliedon top of the global
tracesSampleRate. Therefore ifinteractionsSampleRateis0.5andtracesSampleRateis0.1,then the actual sample rate for interactions is
0.05.This release deprecates the
Hubclass, as well as theaddRequestDataToTransactionmethod. ThetrpcMiddlewaremethod is no longer on the
Handlersexport, but instead is a standalone export.Please see the detailed Migration docs on how to migrate to the new APIs.
trpcMiddleware(#11389)Hubclass (#11528)Hubinterface (#11530)addRequestDataToTransaction(#11368)Other Changes
OPTIONSandHEADrequest. (#11485)statsdtometric_bucket(#11505)Bundle size 📦
v7.109.0Compare Source
This release deprecates some exports from the
@sentry/replaypackage. These exports have been moved to the browser SDK(or related framework SDKs like
@sentry/react).rrwebto 2.12.0 (#11317)@sentry/replayexports (#11242)Work in this release contributed by @soerface. Thank you for your contribution!
Bundle size 📦
v7.108.0Compare Source
This release fixes issues with Time to First Byte (TTFB) calculation in the SDK that was introduced with
7.95.0. Italso fixes some bugs with Interaction to First Paint (INP) instrumentation. This may impact your Sentry Performance
Score calculation.
ResizeObserverandgoogletagdefault filters (#11210)cron(#11225)sampledtype onTransaction(#11146)Work in this release contributed by @quisido and @joshkel. Thank you for your contributions!
Bundle size 📦
v7.107.0Compare Source
This release fixes issues with INP instrumentation with the Next.js SDK and adds support for the
enableInpoption inthe deprecated
BrowserTracingintegration for backwards compatibility.handledvalue in ErrorBoundary depending on fallback [v7] (#11037)Bundle size 📦
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.