Skip to content

chore(deps): update Java SDK to v8.59.0 - #5661

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
deps/scripts/update-java.ps1
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
deps/scripts/update-java.ps1

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps scripts/update-java.ps1 from 8.58.0 to 8.59.0.

Auto-generated by a dependency updater.

Changelog

8.59.0

Breaking Changes

  • Capture direct Sentry.logger() and Sentry.metrics() calls regardless of options.getLogs().isEnabled() and options.getMetrics().isEnabled() (#6184)
    • Automatic logging integrations still only capture logs when options.getLogs().isEnabled() is true. options.getMetrics().setEnabled(...) currently has no effect because there are no automatic Metrics integrations. Both enable options will be removed in the upcoming major release, and each logging integration will then have a separate opt-in flag.
    • Use options.getLogs().setBeforeSend(...) and options.getMetrics().setBeforeSend(...) to filter manually emitted telemetry. Return null from either callback to drop it.

Fixes

  • Keep the videos of already captured session replay segments when the replay stops, so segments that are still queued are no longer sent without their video (#6177)

Features

  • Deprecate sendDefaultPii in favor of dataCollection ahead of its removal in 9.0 (#6158)
  • Make the tombstone merge time threshold configurable via SentryAndroidOptions.setTombstoneMergeTimeThresholdMillis and the io.sentry.tombstone.merge-time-threshold-millis manifest option (#6154)
  • Add sentry-apollo-5 integration for Apollo Kotlin 5, providing HTTP tracing and failed GraphQL request reporting (#6074)
  • Add OkHttp autoconfiguration for Spring Boot (#5797)

Fixes

  • Prevent infinite loops when capturing exceptions with cyclic cause chains (#6073)

Improvements

  • Recover Android 17 MemoryLimiter app exits recorded as ApplicationExitInfo.REASON_MEMORY_LIMITER (#6174)

Dependencies

8.58.0

Features

  • Add LocalSentrySpan to sentry-compose so apps can provide a parent ISpan to a composable subtree and have nested SentryTraced spans attach to it ([#6112]feat(compose): Introduce LocalSentrySpan sentry-java#6112)
  • Add dataCollection, a fine-grained replacement for sendDefaultPii, for controlling data collected automatically by SDK integrations. See the Data Collection documentation for Android, Java, and Spring Boot (#5759)

Warning

sendDefaultPii will be removed in the next major SDK version. Migrate to dataCollection before upgrading.

  • Clear the persisted replay id on SDK init, so a replay id from a previous process is no longer attached to ANR events from the current one (#6033)
Full CHANGELOG.md diff
 -1,128 +1,47 
 # Changelog
 
-## 8.58.0
-
-### Features
-
-- Add `LocalSentrySpan` to `sentry-compose` so apps can provide a parent `ISpan` to a composable subtree and have nested `SentryTraced` spans attach to it ([#6112]https://github.com/getsentry/sentry-java/pull/6112)
-- Add `dataCollection`, a fine-grained replacement for `sendDefaultPii`, for controlling data collected automatically by SDK integrations ([#5759](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/5759))
-
-  > [!WARNING]
-  > `sendDefaultPii` will be removed in the next major SDK version. Migrate to `dataCollection` before upgrading.
+## 8.59.0
 
-  - Until then, when `dataCollection` is not configured, the SDK preserves the existing `sendDefaultPii` behavior.
-  - Configuring any `dataCollection` option makes it the source of truth. `sendDefaultPii` is then ignored, and omitted `dataCollection` options use the defaults below.
-  - The Logback appender is a compatibility exception. When an encoder is configured, `sendDefaultPii=true` continues to include the original message template and parameters. To opt in independently of `sendDefaultPii`, set `<includeUnencodedMessage>true</includeUnencodedMessage>` on the Sentry appender in `logback.xml` or `logback-spring.xml`.
-  - Data explicitly supplied through APIs such as `Sentry.setUser`, scopes, event processors, or `beforeSend` is not affected.
+### Breaking Changes
 
-  To opt in to the documented `dataCollection` defaults without configuring an individual option:
+- Capture direct `Sentry.logger()` and `Sentry.metrics()` calls regardless of `options.getLogs().isEnabled()` and `options.getMetrics().isEnabled()` ([#6184](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6184))
+  - Automatic logging integrations still only capture logs when `options.getLogs().isEnabled()` is `true`. `options.getMetrics().setEnabled(...)` currently has no effect because there are no automatic Metrics integrations. Both enable options will be removed in the upcoming major release, and each logging integration will then have a separate opt-in flag.
+  - Use `options.getLogs().setBeforeSend(...)` and `options.getMetrics().setBeforeSend(...)` to filter manually emitted telemetry. Return `null` from either callback to drop it.
 
-  ```java
-  Sentry.init(options -> options.getDataCollection().forceDataCollection());
-  ```
+### Fixes
 
-  | Option | Default | Behavior |
-  | --- | --- | --- |
-  | `userInfo` | `true` | Allows integrations to populate user identity and IP address information automatically. |
-  | `cookies` | `{ mode: DENY_LIST, terms: [] }` | Collects cookies while filtering sensitive values. |
-  | `httpHeaders.request` | `{ mode: DENY_LIST, terms: [] }` | Collects request headers while filtering sensitive values. |
-  | `httpHeaders.response` | `{ mode: DENY_LIST, terms: [] }` | Collects response headers while filtering sensitive values. |
-  | `httpBodies` | All supported body types | Collects supported incoming and outgoing request and response bodies. An empty set disables body collection. |
-  | `urlQueryParams` | `{ mode: DENY_LIST, terms: [] }` | Collects URL query parameters while filtering sensitive values. |
-  | `graphql.document` | `true` | Collects GraphQL documents. |
-  | `graphql.variables` | `true` | Collects GraphQL variables. |
-  | `databaseQueryData` | `true` | Allows collection of associated query data, such as bound parameters, write payloads, and results, where supported. Sanitized query statements and structural database metadata remain available. |
-  | `filePaths` | `true` | Allows file-system instrumentation to collect file and directory paths. File extensions and byte counts remain available when disabled. |
+- Keep the videos of already captured session replay segments when the replay stops, so segments that are still queued are no longer sent without their video ([#6177](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6177))
 
-  Cookies, HTTP headers, and URL query parameters support three modes:
+### Features
 
-  - `OFF`: Do not collect the category.
-  - `DENY_LIST`: Collect values except those matching the built-in sensitive deny-list or additional configured terms.
-  - `ALLOW_LIST`: Only send plaintext values for matching terms. The built-in sensitive deny-list still applies.
+- Deprecate `sendDefaultPii` in favor of `dataCollection` ahead of its removal in 9.0 ([#6158](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6158))
+- Make the tombstone merge time threshold configurable via `SentryAndroidOptions.setTombstoneMergeTimeThresholdMillis` and the `io.sentry.tombstone.merge-time-threshold-millis` manifest option ([#6154](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6154))
+- Add `sentry-apollo-5` integration for Apollo Kotlin 5, providing HTTP tracing and failed GraphQL request reporting ([#6074](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6074))
+- Add OkHttp autoconfiguration for Spring Boot ([#5797](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/5797))
 
-  Matching is case-insensitive and partial. The built-in sensitive deny-list contains `auth`, `token`, `secret`, `password`, `passwd`, `pwd`, `key`, `jwt`, `bearer`, `sso`, `saml`, `csrf`, `xsrf`, `credentials`, `session`, `sid`, and `identity`. Filtered values are replaced with `"[Filtered]"`. Custom deny-list terms extend rather than replace this list.
+### Fixes
 
-  Configure all HTTP body types, a custom cookie deny-list, a request-header allow-list, and disable URL query parameter and file path collection in an options callback:
+- Prevent infinite loops when capturing exceptions with cyclic cause chains ([#6073](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6073))
 
-  ```java
-  Sentry.init(
-      options -> {
-        options
-            .getDataCollection()
-            .setHttpBodies(
-                EnumSet.of(
-                    HttpBodyType.INCOMING_REQUEST,
-                    HttpBodyType.OUTGOING_REQUEST,
-                    HttpBodyType.INCOMING_RESPONSE,
-                    HttpBodyType.OUTGOING_RESPONSE));
-        options
-            .getDataCollection()
-            .setCookies(
-                KeyValueCollectionBehavior.denyList(
-                    "forwarded", "-ip", "remote-", "via", "-user"));
-        options
-            .getDataCollection()
-            .getHttpHeaders()
-            .setRequest(
-                KeyValueCollectionBehavior.allowList("content-type", "x-request-id"));
-        options
-            .getDataCollection()
-            .setUrlQueryParams(KeyValueCollectionBehavior.off());
-        options.getDataCollection().setFilePaths(false);
-      });
-  ```
+### Improvements
 
-  Configure the same options in `sentry.properties`:
+- Recover Android 17 `MemoryLimiter` app exits recorded as `ApplicationExitInfo.REASON_MEMORY_LIMITER` ([#6174](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6174))
 
-  ```properties
-  data-collection.http-bodies=incoming_request,outgoing_request,incoming_response,outgoing_response
-  data-collection.cookies.mode=deny_list
-  data-collection.cookies.terms=forwarded,-ip,remote-,via,-user
-  data-collection.http-headers.request.mode=allow_list
-  data-collection.http-headers.request.terms=content-type,x-request-id
-  data-collection.url-query-params.mode=off
-  data-collection.file-paths=false
-  ```
+### Dependencies
 
-  Configure them with Spring Boot properties:
+- Bump Native SDK from v0.16.6 to v0.17.1 ([#6135](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6135))
+  - [changelog](https://github-redirect.dependabot.com/getsentry/sentry-native/blob/master/CHANGELOG.md[#0171](https://github-redirect.dependabot.com/getsentry/sentry-java/issues/0171))
+  - [diff](https://github-redirect.dependabot.com/getsentry/sentry-native/compare/0.16.6...0.17.1)
 
-  ```properties
-  sentry.data-collection.http-bodies=incoming-request,outgoing-request,incoming-response,outgoing-response
-  sentry.data-collection.cookies.mode=deny-list
-  sentry.data-collection.cookies.terms=forwarded,-ip,remote-,via,-user
-  sentry.data-collection.http-headers.request.mode=allow-list
-  sentry.data-collection.http-headers.request.terms=content-type,x-request-id
-  sentry.data-collection.url-query-params.mode=off
-  sentry.data-collection.file-paths=false
-  ```
+## 8.58.0
 
-  Configure them in `AndroidManifest.xml`:
+### Features
 
-  ```xml
-  <meta-data
-      android:name="io.sentry.data-collection.http-bodies"
-      android:value="incoming_request,outgoing_request,incoming_response,outgoing_response" />
-  <meta-data
-      android:name="io.sentry.data-collection.cookies.mode"
-      android:value="deny_list" />
-  <meta-data
-      android:name="io.sentry.data-collection.cookies.terms"
-      android:value="forwarded,-ip,remote-,via,-user" />
-  <meta-data
-      android:name="io.sentry.data-collection.http-headers.request.mode"
-      android:value="allow_list" />
-  <meta-data
-      android:name="io.sentry.data-collection.http-headers.request.terms"
-      android:value="content-type,x-request-id" />
-  <meta-data
-      android:name="io.sentry.data-collection.url-query-params.mode"
-      android:value="off" />
-  <meta-data
-      android:name="io.sentry.data-collection.file-paths"
-      android:value="false" />
-  ```
+- Add `LocalSentrySpan` to `sentry-compose` so apps can provide a parent `ISpan` to a composable subtree and have nested `SentryTraced` spans attach to it ([#6112]https://github.com/getsentry/sentry-java/pull/6112)
+- Add `dataCollection`, a fine-grained replacement for `sendDefaultPii`, for controlling data collected automatically by SDK integrations. See the Data Collection documentation for [Android](https://docs.sentry.io/platforms/android/configuration/options/#dataCollection), [Java](https://docs.sentry.io/platforms/java/configuration/options/#dataCollection), and [Spring Boot](https://docs.sentry.io/platforms/java/guides/spring-boot/configuration/options/#dataCollection) ([#5759](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/5759))
 
-  See the [Data Collection documentation](https://docs.sentry.io/platforms/java/configuration/options/#dataCollection) for all configuration keys, supported integrations, and migration guidance.
+> [!WARNING]
+> `sendDefaultPii` will be removed in the next major SDK version. Migrate to `dataCollection` before upgrading.
 
 ### Fixes
 
 -218,6 +137,7 
 ### Fixes
 
 - Keep dropped tombstone and ANR events dropped, instead of reporting the same app exit again at every app start ([#6002](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6002))
+- Clear the persisted replay id on SDK init, so a replay id from a previous process is no longer attached to ANR events from the current one ([#6033](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6033))
 - Apply `Sentry.withScope` and `Sentry.withIsolationScope` data to events captured inside the callback when `globalHubMode` is enabled ([#6004](https://github-redirect.dependabot.com/getsentry/sentry-java/pull/6004))
   - `globalHubMode` is enabled by default on Android, where tags, extras, contexts and level set inside the callback were silently dropped
   - Scopes that are explicitly made current, e.g. via `Sentry.setCurrentScopes` or the `SentryContext` coroutine integration, are now also honoured when `globalHubMode` is enabled

@github-actions github-actions Bot added the Dependencies Pull requests that update a dependency file label Oct 2, 2026
@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-java.ps1 branch from 860eae0 to b15f10f Compare October 2, 2026 03:02
@github-actions github-actions Bot added the risk: medium PR risk score: medium label Oct 2, 2026
@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.84%. Comparing base (ea7fa3a) to head (2c0afc2).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #5661      +/-   ##
==========================================
+ Coverage   74.93%   77.84%   +2.90%     
==========================================
  Files         515      426      -89     
  Lines       18975    16153    -2822     
  Branches     3695     3197     -498     
==========================================
- Hits        14219    12574    -1645     
+ Misses       3876     2842    -1034     
+ Partials      880      737     -143     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@bruno-garcia
bruno-garcia force-pushed the deps/scripts/update-java.ps1 branch from b15f10f to 2c0afc2 Compare October 3, 2026 03:11

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file risk: medium PR risk score: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant