bump: Upgrade @sentry/browser from 8.33.1 to 10.38.0 - #42867
Conversation
Agent-Logs-Url: https://github.com/MetaMask/metamask-extension/sessions/66deb05c-d6c0-4fae-953c-8842d8e47c25 Co-authored-by: MajorLift <34228073+MajorLift@users.noreply.github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning MetaMask internal reviewing guidelines:
Ignoring alerts on:
|
Agent-Logs-Url: https://github.com/MetaMask/metamask-extension/sessions/66deb05c-d6c0-4fae-953c-8842d8e47c25 Co-authored-by: MajorLift <34228073+MajorLift@users.noreply.github.com>
Agent-Logs-Url: https://github.com/MetaMask/metamask-extension/sessions/66deb05c-d6c0-4fae-953c-8842d8e47c25 Co-authored-by: MajorLift <34228073+MajorLift@users.noreply.github.com>
Agent-Logs-Url: https://github.com/MetaMask/metamask-extension/sessions/66deb05c-d6c0-4fae-953c-8842d8e47c25 Co-authored-by: MajorLift <34228073+MajorLift@users.noreply.github.com>
Agent-Logs-Url: https://github.com/MetaMask/metamask-extension/sessions/66deb05c-d6c0-4fae-953c-8842d8e47c25 Co-authored-by: MajorLift <34228073+MajorLift@users.noreply.github.com>
|
@metamaskbot update-policies |
|
Policies updated. Tip Follow the policy review process outlined in the LavaMoat Policy Review Process doc before expecting an approval from Policy Reviewers. 👀 lavamoat/browserify/beta/policy.json changes differ from lavamoat/browserify/main/policy.json changes |
✨ Files requiring CODEOWNER review ✨🫰 @MetaMask/core-platform (1 files, +9 -4)
👨🔧 @MetaMask/extension-platform (2 files, +14 -4)
📜 @MetaMask/policy-reviewers (8 files, +216 -296)
Tip Follow the policy review process outlined in the LavaMoat Policy Review Process doc before expecting an approval from Policy Reviewers. 🧪 @MetaMask/qa (3 files, +62 -14)
👨🔧 @itsyoboieltr (1 files, +5 -0)
|
Builds ready [5c7e650]
⚡ Performance Benchmarks (Total: 🟢 17 pass · 🟡 0 warn · 🔴 0 fail)
Bundle size diffs [🚀 Bundle size reduced!]
|
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
Builds ready [393b097]
⚡ Performance Benchmarks (Total: 🟢 17 pass · 🟡 0 warn · 🔴 0 fail)
Bundle size diffs
|
`browserSessionIntegration.setupOnce` runs once per process, so the init-time session belongs to the first `Sentry.init` in a jest worker; a dedicated file makes that observable. The test proves the integration stays wired in this init config and that the init session survives the transport's async opt-in gate. Test inits now pass `skipBrowserExtensionCheck` instead of the test-scoped `globalThis.nw` shims: jsdom mocks `chrome.runtime.id`, so without an escape the SDK's embedded-extension detection disables `init` entirely in unit tests.
Builds ready [94feaed]
⚡ Performance Benchmarks (Total: 🟢 16 pass · 🟡 6 warn · 🔴 2 fail)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
CI adjudicated the removal: the Bitcoin discovery retry storm returned through the onboarding benchmark (`openAccountMenuToAccountListLoaded` mean +325.8%) rather than the discovery specs. The regtest proxy from main cannot cover this path, since discovery runs in every spec without a Bitcoin node. Reverts the removal commit.
Builds ready [b4fa1a8]
⚡ Performance Benchmarks (Total: 🟢 13 pass · 🟡 9 warn · 🔴 1 fail)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
The mock is the durable Bitcoin discovery fix carried by this branch, not an interim workaround: the Solana-mock completion work is scoped to the Solana RPC methods only and does not provide the Esplora response, so no upstream change makes this mock redundant.
|
@SocketSecurity ignore npm/@opentelemetry/core@2.5.0 We already have a yarn resolution entry for |
Drops adjudication history and mechanism narration from the Esplora mock, perf-DSN interceptor, non-EVM icon TODO, `snap_startTrace`, and the two Sentry test-file headers; each now states only why the code must stay as written.
Builds ready [4a5115a]
⚡ Performance Benchmarks (Total: 🟢 16 pass · 🟡 8 warn · 🔴 0 fail)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
|
@SocketSecurity ignore npm/@sentry-internal/feedback@10.38.0 npm/@sentry/browser@10.38.0 npm/@sentry/core@10.38.0 npm/@sentry/node-core@10.38.0 Sentry SDK is proprietary. Obfuscation is expected. |
Resolves the browserify-removal conflicts by accepting main's deletion of `development/build/index.js` and `development/build/scripts.js`; the branch's browserify-side Sentry wiring is obsolete with that pipeline gone, and the webpack path carries its own equivalent.
Builds ready [bf889e6]
⚡ Performance Benchmarks (Total: 🟢 14 pass · 🟡 9 warn · 🔴 1 fail)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
The v10 Sentry SDK's per-request breadcrumb and flush work competes with the background `addNetwork` call, so on 2-core CI the confirmation dialog outlives the default 3s `clickElementAndWaitToDisappear`. `saveEditedNetwork` takes an optional timeout; this spec passes 15s. Bisect: the stall reproduces with the SDK initialized but tracing stripped and disappears with `enabled: false`, so it is init cost, not the tracing runtime or the LavaMoat exception changes.
Builds ready [bc1577d]
⚡ Performance Benchmarks (Total: 🟢 17 pass · 🟡 6 warn · 🔴 1 fail)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
Builds ready [bc1577d]
⚡ Performance Benchmarks (Total: 🟢 17 pass · 🟡 6 warn · 🔴 1 fail)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
|
Builds ready [5219443]
⚡ Performance Benchmarks (Total: 🟢 16 pass · 🟡 7 warn · 🔴 1 fail)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
|
No release label on PR. Adding release label release-13.42.0 on PR, as PR was added to branch 13.42.0 when release was cut. |
🧪 Validation RunVerdict: ℹ️ capability expanded — Claim: the @sentry/browser major bump grants no new capability D3 supply-chain capability diff —
|


Changelog
CHANGELOG entry: Upgrades Sentry SDK from v8 to v10, improving telemetry and enabling full incorporation of backend instrumentation (API, RPC, DB, Cache, CDN domains) into Sentry distributed tracing.
Description
lazyLoadIntegrationpatch — re-applied for v10. The v8 patch is removed and replaced by.yarn/patches/@sentry-browser-npm-10.38.0-d1e984c1c7.patch, which stubslazyLoadIntegration(CDN-based remote-code loading, not permitted in extension stores) across v10's four build variants (cjs/dev,cjs/prod,esm/dev,esm/prod).setupSentry.js— adapted to v10 (loggernow imported from@sentry/corerather than@sentry/utils,propagateTraceparent, transport wiring); tests updated (setupSentry.test.js,sentry-make-transport.test.ts).@sentry/utilsremoval — v10 folded@sentry/utilsinto@sentry/core. PortedaddFetchInstrumentationHandlerimport to@sentry/coreand adapted propagation context's renamedspanId→propagationSpanId(sentry-trace-propagation.ts+ test).traceparentparent-linkage fix — replacing the manual header injection withpropagateTraceparentalso fixes distributed-trace parent linkage, where backend spans do not nest under their client request span and instead are attached as siblings.01on deferred decisions with a span id no real span carries (69% of backend entry spans orphaned), or the enclosing custom root's id instead of the request span's (31% attached as siblings of their ownhttp.clientspan).00, and a recorded request span propagates its own id. Pinned against the unmocked SDK insentry-traceparent-semantics.test.ts(eafb4e5).setupSentry.test.jsenforces thatshouldCreateSpanForRequestnever filters aBACKEND_TRACE_PROPAGATION_TARGETSURL, since a filtered span propagated as atraceparentparent re-orphans the backend subtree (7ca3ead; constraint note atsetupSentry.js#L326-L334).-01parents (today ~5% of client-kept traces get backend halves; tracked SRE-side), and rooting background fetches in their own traces is MetaMask-planning#7354.Validation
The upgrade must preserve equivalent coverage — the same errors, transactions, tags, scrubbing, and sampling, with no unexplained volume change — not just a green suite. Verified at three layers (plan in #43819, tooling in #43820):
1 — Snapshot equivalence (always-on).
test/e2e/tests/metrics/{errors,traces}.spec.tscapture the real envelopes sent to a mocked DSN anddeepStrictEqualthe attached state against committed fixtures (state-snapshots/errors-*), pinning which state fields are sent / masked / removed and which transactions fire (UI Startup,/home.html). Green on v10; the only required fixture change was a benign timing race (pendingShieldCohort/srpSessionData), not a behavioral regression.2 — Envelope capture-and-diff. The fixed flow — unlock → developer-options error → home pageload — runs against a v8 (CI run) and a v10 (CI run) build. A high-priority mock intercepts every Sentry POST (both DSNs), so each side's full per-flow set is captured (~40 envelopes: sessions, ~30 transactions, several error events) regardless of the per-build mock setup, then normalized (volatile ids/timestamps stripped) and compared by type, signature, and tag coverage — on the same browser engine, to exclude engine-specific noise (e.g. Firefox omits CLS). Result — equivalent:
UI Startup,/home.html, the multichain account-creation suite (Provider Create Accounts,Create {Solana,Bitcoin} Account Batch,Wallet Alignment,Multichain Account Syncing, …),AggregatedBalanceSelector, the developer-optionsTestErrorevent, andsession— is present in v8 with identical tag coverage, includingotelTraceId(distributed-trace correlation) and thewallet.*/ web-vitals tags on the UI traces.BackendWebSocketService Connectiontrace present in one of three captured runs) and aservicetag on incidental background RPC errors are timing artifacts, not v10 behavior.test/e2e/mock-e2e.js(~800 performance-DSN envelopes in a heavy multichain run) is scenario-specific — the quota axis tracked in [Epic] Sentry Quota Breach — Extension Telemetry (May 2026 – ongoing) #43410, not exercised by this flow.3 — Production staged-rollout validation (post-ship). Compare the
metamaskSentry project's last-v8 vs first-v10 release: error volume & grouping, transaction/span volume & perf-unit consumption (quota — #43410), tag/trace completeness, and sampling ≈ 0.75%.v10-specific deltas asserted explicitly: (a) privacy-critical state masking unchanged (no unmasked field leaks); (b) span serialization — the snap
startTraceRPC returns theSerializedTraceContextshape (_traceId/_spanId), so the result round-trips into a laterstartTracecall'sparentContextand nests; (c)propagateTraceparentemits exactly onetraceparent(consensysTracePropagationIntegrationappends only Consensysbaggage, no header injection of its own); (d)beforeSend/rewriteReportscrubbing intact; (e)traceparentcontents — deferred and negatively sampled decisions propagate trace-flags00, and a recorded request span propagates its own span id, not the enclosing root's (sentry-traceparent-semantics.test.ts, real SDK, no mocks — complements #44053's gating/scoping assertions).Related issues
setupDefaultNonEvmDiscoveryMocks#43958 (snap discovery mock gap, open)01flag; fix account menu width #7354 owns rooting the remaining orphan half)Manual testing steps
yarn build:testandyarn build:test:webpack) and load it — it should boot to the home screen with no.controller-loadedtimeout and noinaccessible under scuttling mode/addEventListener is not a functionerrors in the console.browser.sentry-cdn.comis absent from the builtdist/output (thelazyLoadIntegrationstub must hold — store compliance).Screenshots/Recordings
N/A — no user-facing UI change.
Before
After
Pre-merge author checklist
Pre-merge reviewer checklist
Note
Medium Risk
Large SDK bump touches error reporting, sampling, distributed tracing, and extension scuttling/LavaMoat policy; behavioral fixes to traceparent propagation affect backend correlation, though equivalence is heavily tested.
Overview
Upgrades
@sentry/browserto 10.38.0 (and aligns@sentry/core/@sentry/node), drops@sentry/utils, and replaces the v8 Yarn patch with a v10 patch that stubslazyLoadIntegrationso the extension cannot load integrations frombrowser.sentry-cdn.com.Distributed tracing now relies on the SDK’s
propagateTraceparent: trueinstead of manual W3Ctraceparentinjection inconsensysTracePropagationIntegration, which only appends Consensysbaggage.setupSentry.jsdocuments that backend trace-propagation URLs must not be filtered byshouldCreateSpanForRequest, so client request spans stay linked to backend traces. SnapstartTracereturns a JSON-safe{ _traceId, _spanId }instead of spreading a Sentry span.Init / bundling: removes the
globalThis.nwshared-environment workaround; addsskipBrowserExtensionCheckin unit tests; extends LavaMoat globals (WebAssembly,Request,requestIdleCallback) and build env vars to satisfy v10 serverless checks; refreshes LavaMoat Sentry policies for@sentry/core.Tests & E2E: imports move to
@sentry/core; newsentry-traceparent-semantics.test.tsandsentry-session-lifecycle.test.ts; transport/session tests updated for v10 async sessions; metrics snapshots relax timing-sensitive fields; E2E mocks add Bitcoin genesis verification, mock performance Sentry envelopes, and longer waits where v10 background work competes with UI.Reviewed by Cursor Bugbot for commit bc1577d. Bugbot is set up for automated code reviews on this repo. Configure here.