Bump Sentry from 4.11.0 to 6.7.0#42
Conversation
--- updated-dependencies: - dependency-name: Sentry dependency-version: 6.7.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Skipping PR review because a bot author is detected. If you want to trigger CodeAnt AI, comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
|
|
||
| <!-- Error tracking --> | ||
| <PackageReference Include="Sentry" Version="4.11.0" /> | ||
| <PackageReference Include="Sentry" Version="6.7.0" /> |
There was a problem hiding this comment.
CRITICAL: Bumping Sentry 4.x → 6.x introduces a new transitive dependency (k4os.compression.lz4 via blake3) that Socket for GitHub has flagged as a HIGH-severity license policy violation. This brings an unapproved license into the project's dependency graph.
Sentry itself is unused code — no Sentry.* API calls exist anywhere in the C# codebase. The cleanest resolution is to remove this PackageReference entirely rather than upgrade it, which also eliminates the transitive license violation.
If Sentry error tracking is genuinely needed, verify the license policy with your security team before merging, and audit the Sentry 4→6 migration guide for any breaking API changes.
Fix these issues in Kilo Cloud
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
| } | ||
| }, | ||
| "MinVer": { | ||
| "type": "Direct", |
There was a problem hiding this comment.
WARNING: MinVer appears as type: "Direct" in the lockfile, meaning it ships in the application's runtime dependency graph. MinVer is a build-time-only MSBuild package for deriving assembly versions from git tags — it has no runtime purpose and should not be a Direct dependency.
No corresponding <PackageReference Include="MinVer" .../> exists in the csproj, making this entry anomalous. If MinVer is being pulled in via MSBuild targets integration, it should be marked with PrivateAssets="all" or excluded from the lockfile's Direct set. Shipping it as a runtime dependency inflates the output and widens the attack surface unnecessarily.
Fix these issues in Kilo Cloud
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
Code Review SummaryStatus: 2 Issues Found | Recommendation: Address before merge Overview| Severity | Count | Issue Details (click to expand)CRITICAL
WARNING
Files Reviewed (2 files)
Fix these issues in Kilo Cloud Reviewed by step-3.7-flash · Input: 86.5K · Output: 10.2K · Cached: 1.1M |
Updated Sentry from 4.11.0 to 6.7.0.
Release notes
Sourced from Sentry's releases.
6.7.0
Features ✨
IgnoreTransactionsoption to filter out transactions by name, matching substrings or regular expressions against the transaction name (#5377) by @Adham-Kiwan in #5377SentryEventExtensions.IsFromUnhandledException) and terminal exceptions (SentryEventExtensions.IsFromTerminalException) by @jamescrosswell in #5177Fixes 🐛
Dependencies ⬆️
Deps
Other
Sentry.Extensions.LoggingFilters by @Flash0ver in #52976.6.0
Features ✨
sentry-androidandsentry-cocoaby @bitsandfoxes in #5244Fixes 🐛
Dependencies ⬆️
Deps
Other
6.5.0
Features ✨
Fixes 🐛
SentryEventto haveIsCapturedto allow dropping screenshots of filtered events by @JoshuaMoelans in #5162PruneFilteredSpansruns by @jamescrosswell in #5186Dependencies ⬆️
Deps
Other
6.4.1
Fixes 🐛
Dependencies ⬆️
Deps
6.4.0
Features ✨
Fixes 🐛
options.Native.ExperimentalOptions.SignalHandlerStrategytoSentry.Android.SignalHandlerStrategy.ChainAtStartDependencies ⬆️
Deps
6.3.2
Dependencies ⬆️
6.3.1
Fixes 🐛
CaptureFeedbacknow supports multiple attachments correctly by @bitsandfoxes in #5077Dependencies ⬆️
Deps
Other
6.3.0
Features
ExperimentalfromSentrySdk,SentryOptionsandIHub(#5023)SENTRY1001) when a Metrics-API is invoked with an unsupported numeric type (#4840)Fixes
EnvironmentandReleaseand custom event processors are all now correctly applied to CaptureFeedback events (#4942)Dataset viaITransactionTracerinSentryTransaction(#4148)Dependencies
6.2.0
Features
Fixes
Warninginstead of anErrorwhen being ratelimited (#4927)libmonosgenandlibxamarinframes no longer show as in-app (#4960)Dependencies
SentryApiKey, you need to generate an Auth Token and useSentryAuthToken, instead.6.2.0-alpha.0
Features
Dependencies
6.1.0
Features
SentryThreadbyMainto allow indication whether the thread is considered the current main thread (#4807)Fixes
EnvironmentandRelease(#4883)Dependencies
6.1.0-alpha.2
BREAKING CHANGES
AddCountertoEmitCounterRecordDistributiontoEmitDistributionRecordGaugetoEmitGaugeFeatures
Fixes
SetBeforeSendLogcallback (#4834)decimal) for Trace-connected Metrics (#4834)6.1.0-alpha.1
Features
SentryThreadbyMainto allow indication whether the thread is considered the current main thread (#4807)Dependencies
6.0.0
BREAKING CHANGES
SentryLoggingOptions.ExperimentalLogging.MinimumLogLevel. Structured Logs can now be configured via the"Sentry"logging provider (e.g. inappsettings.jsonandappsettings.{HostEnvironment}.json) (#4700)SentryLog.ParentSpanIdtoSentryLog.SpanIdreflecting the protocol change (#4778)IDisposableso that they can be used withusingstatements/declarations that will automatically finish the span with a status of OK when it passes out of scope, if it has not already been finished, to be consistent withActivityclasses when using OpenTelemetry (#4627)sealed(see also #4627)ExperimentalfromSentryOptions(#4699)SentryIdand aCaptureFeedbackResultout parameter that indicate whether feedback was captured successfully and what the reason for failure was otherwise (#4613)Sentry.Azure.Functions.Workeras very few people were using it and the functionality can easily be replaced with OpenTelemetry. We've replaced our integration with a sample showing how to do this using our OpenTelemetry package instead. (#4693)BreadcrumbLevel.Criticalhas been renamed toBreadcrumbLevel.Fatalfor consistency with the other Sentry SDKs (#4605)Sentry.Maui.BreadcrumbEventthat had been marked as obsolete. That constructor expected aIEnumerable<(string Key, string Value)>[]argument (i.e. an array of IEnumerable of tuples). If you were using this constructor, you should instead use the alternate constructor that expects just an IEnumerable of tuples:IEnumerable<(string Key, string Value)>.SentrySdk.CaptureUserFeedbackand all associated members. Use the newerSentrySdk.CaptureFeedbackinstead.Features
Sentry.Extensions.AIwhich allows LLM usage instrumentation viaMicrosoft.Extensions.AI(#4657)Sentry.Google.Cloud.Functions(#4700)IsSessionActiveto allow checking the session state (#4662)Unhandledwhen capturing an unhandled but non-terminal exception, i.e. through the UnobservedTaskExceptionIntegration (#4633, #4653)app_memorythat can hold the amount of memory used by the application in bytes. (#4707)PropagateTraceparent = truewhen initializing the SDK if to include the W3C traceparent header on outgoing requests.Fixes
Serilogintegration captures Structured Logs (when enabled) independently of captured Events and added Breadcrumbs (#4691)Sentry.Extensions.Logging,Sentry.AspNetCore,Sentry.MauiandSentry.Google.Cloud.Functionsappsettings.json)SentryLoggingOptions.MinimumBreadcrumbLevel,SentryLoggingOptions.MinimumEventLevel, or add filter functions viaSentryLoggingOptionsExtensions.AddLogEntryFilterappsettings.json)SentryOptions.EnableLogs/NODEFAULTLIB:MSVCRTto NativeAOT linker arguments on Windows when targetting non-Windows platforms (Android, Browser) (#4760)... (truncated)
6.0.0-rc.2
Fixes
Dependencies
6.0.0-rc.1
BREAKING CHANGES
This release adds support for .NET 10 and drops support for net8.0-android, net8.0-ios, net8.0-maccatalyst and net8.0-windows10.0.19041.0 (#4461)
Backpressure handling is now enabled by default, meaning that the SDK will monitor system health and reduce the sampling rate of events and transactions when the system is under load. When the system is determined to be healthy again, the sampling rates are returned to their original levels. (#4615)
QOL improvement: Spans and Transactions now implement
IDisposableso that they can be used withusingstatements/declarations that will automatically finish the span with a status of OK when it passes out of scope, if it has not already been finished, to be consistent withActivityclasses when using OpenTelemetry (#4627)Add support for W3C traceparent header for outgoing requests (#4661)
This feature is disabled by default. Set
PropagateTraceparent = truewhen initializing the SDK if to include the W3C traceparent header on outgoing requests.The Structured Logs APIs are now stable: removed
ExperimentalfromSentryOptions(#4699)Added support for v3 of the Android AssemblyStore format that is used in .NET 10 and dropped support for v1 that was used in .NET 8 (#4583)
CaptureFeedback now returns a
SentryIdand aCaptureFeedbackResultout parameter that indicate whether feedback was captured successfully and what the reason for failure was otherwise (#4613)Deprecated
Sentry.Azure.Functions.Workeras very few people were using it and the functionality can easily be replaced with OpenTelemetry. We've replaced our integration with a sample showing how to do this using our OpenTelemetry package instead. (#4693)UWP support has been dropped. Future efforts will likely focus on WinUI 3, in line with Microsoft's recommendations for building Windows UI apps. (#4686)
BreadcrumbLevel.Criticalhas been renamed toBreadcrumbLevel.Fatalfor consistency with the other Sentry SDKs (#4605)SentryOptions.IsEnvironmentUser now defaults to false on MAUI. The means the User.Name will no longer be set, by default, to the name of the device (#4606)
Remove unnecessary files from SentryCocoaFramework before packing (#4602)
Removed obsolete APIs (#4619)
Sentry.Maui.BreadcrumbEventthat had been marked as obsolete. That constructor expected aIEnumerable<(string Key, string Value)>[]argument (i.e. an array of IEnumerable of tuples). If you were using this constructor, you should instead use the alternate constructor that expects just an IEnumerable of tuples:IEnumerable<(string Key, string Value)>.SentrySdk.CaptureUserFeedbackand all associated members. Use the newerSentrySdk.CaptureFeedbackinstead.SpanTracer and TransactionTracer are still public but these are now
sealed(see also #4627)ScopeExtensions.Populate is now internal (#4611)
See https://develop.sentry.dev/sdk/telemetry/traces/distributed-tracing/#w3c-trace-context-header for more details.
Features
IsSessionActiveto allow checking the session state (#4662)Unhandledwhen capturing an unhandled but non-terminal exception, i.e. through the UnobservedTaskExceptionIntegration (#4633, #4653)app_memorythat can hold the amount of memory used by the application in bytes. (#4707)Fixes
Serilogintegration captures Structured Logs (when enabled) independently of captured Events and added Breadcrumbs (#4691)Dependencies
... (truncated)
6.0.0-preview.2
BREAKING CHANGES
BreadcrumbLevel.Criticalhas been renamed toBreadcrumbLevel.Fatalfor consistency with the other Sentry SDKs (#4605)SentryOptions.IsEnvironmentUser now defaults to false on MAUI. The means the User.Name will no longer be set, by default, to the name of the device (#4606)
Remove unnecessary files from SentryCocoaFramework before packing (#4602)
Removed obsolete APIs (#4619)
Sentry.Maui.BreadcrumbEventthat had been marked as obsolete. That constructor expected aIEnumerable<(string Key, string Value)>[]argument (i.e. an array of IEnumerable of tuples). If you were using this constructor, you should instead use the alternate constructor that expects just an IEnumerable of tuples:IEnumerable<(string Key, string Value)>.SentrySdk.CaptureUserFeedbackand all associated members. Use the newerSentrySdk.CaptureFeedbackinstead.Backpressure handling is now enabled by default, meaning that the SDK will monitor system health and reduce the sampling rate of events and transactions when the system is under load. When the system is determined to be healthy again, the sampling rates are returned to their original levels. (#4615)
ScopeExtensions.Populate is now internal (#4611)
Add support for W3C traceparent header for outgoing requests (#4661)
This feature is disabled by default. When enabled, outgoing requests will include the W3C traceparent header.
See https://develop.sentry.dev/sdk/telemetry/traces/distributed-tracing/#w3c-trace-context-header for more details.
Fixes
6.0.0-preview.1
BREAKING CHANGES
5.16.3
Fixes
Dependencies
5.16.2
Fixes
sentry.proguard-uuidmetadata to be set in Android manifest (#4647)Dependencies
5.16.1
Fixes
sentry.originattribute to so it's clearer where these come from (#4566)Dependencies
5.16.0
Features
EnableBackpressureHandlingoption for Automatic backpressure handling. When enabled this automatically reduces the sample rate when the SDK detects events being dropped. (#4452)Serilog(#4462)Fixes
API Changes
ExperimentalAttributefrom all Structured Logs APIs, and removeExperimentalproperty fromSentrySdk, but keepExperimentalproperty onSentryOptions(#4567)Dependencies
5.15.1
Fixes
SentryOptions.Native.SuppressSignalAbortsandSuppressExcBadAccesson iOS (#4521)Dependencies
5.15.1-maxpath.1
Fixes
SentryOptions.Native.SuppressSignalAbortsandSuppressExcBadAccesson iOS (#4521)Dependencies
5.15.0
Features
params(#4451)keynames ofMicrosoft.Extensions.Loggingattributes (#4450)Fixes
IDisposablefromSentryStructuredLogger. Disposal is intended through the owningIHubinstance (#4424)InvalidOperationExceptionpotentially thrown during a race condition, especially in concurrent high-volume logging scenarios (#4428)Dependencies
5.14.1
Fixes
Dependencies
5.14.0
Features
Sentry.Extensions.Logging,Sentry.AspNetCoreandSentry.Maui(#4193)Fixes
sample_rateof Dynamic Sampling Context (DSC) when making sampling decisions (#4374)5.14.0-alpha.1
Dependencies
5.14.0-alpha.0
Fixes
sample_rateof Dynamic Sampling Context (DSC) when making sampling decisions (#4374)5.13.0
Features
SentryStackTraceFactory. However, it may provide better results if you are compiling your application AOT and not getting useful stack traces from the full stack trace factory. (#4362)Fixes
linux-musl-arm64(#4365)Dependencies
5.12.0
API changes
Features
Fixes
lzmaon Linux/MUSL (#4326)Dependencies
5.12.0-alpha.0
Features
SentrySdk.Experimental.Logger(#4158)Sentry.AspNetCore, enabled viaSentryAspNetCoreOptions.Experimental.EnableLogsSentry.Extensions.Logging, enabled viaSentryLoggingOptions.Experimental.EnableLogsSentry.Maui, enabled viaSentryMauiOptions.Experimental.EnableLogsAPI changes
Features
SentrySdk.Experimental.Logger(#4158)Fixes
lzmaon Linux/MUSL (#4326)Dependencies
5.11.2
Fixes
5.11.1
Fixes
5.11.0
Features
ConfigureScopeandConfigureScopeAsyncoverloads (#4244)AutomationIdelement information to breadcrumbs (#4248)Fixes
Sentry.Maui.BreadcrumbEvent, while keeping an Obsolete constructor for backward compatibility.Dependencies
5.11.0-alpha.3
Features
ConfigureScopeandConfigureScopeAsyncoverloads (#4244)AutomationIdelement information to breadcrumbs (#4248)Fixes
Dependencies
5.11.0-alpha.1
Fixes
Dependencies
5.10.0
Features
Fixes
5.9.0
Features
Fixes
Dependencies
5.8.2-beta.1
Fixes
Dependencies
5.8.1
Fixes
SentryNative=falseat runtime (#4220)5.8.0
Features
Fixes
Dependencies
5.8.0-alpha.0
Features
SentrySdk.Logger(#4158)Sentry.AspNetCore, enabled viaSentryAspNetCoreOptions.EnableLogsSentry.Extensions.Logging, enabled viaSentryLoggingOptions.EnableLogsSentry.Maui, enabled viaSentryMauiOptions.EnableLogs5.7.0
Features
_...
Description has been truncated