Skip to content

build(deps): bump sentry-ruby and sentry-rails - #161

Open
dependabot[bot] wants to merge 8 commits into
mainfrom
dependabot/bundler/multi-e12fb54b59
Open

build(deps): bump sentry-ruby and sentry-rails#161
dependabot[bot] wants to merge 8 commits into
mainfrom
dependabot/bundler/multi-e12fb54b59

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 14, 2026

Copy link
Copy Markdown
Contributor

Bumps sentry-ruby and sentry-rails. These dependencies needed to be updated together.
Updates sentry-ruby from 5.28.1 to 7.0.0

Changelog

Sourced from sentry-ruby's changelog.

7.0.0

Breaking Changes 🛠

  • Logs are now enabled by default and enable_logs is removed. by @​sl0thentr0py in #3053

    Using sentry-rails will automatically turn on automatic structured logging from Rails. if you want to turn it off, use:

    Sentry.init do |config
      # ...
      config.rails.structured_logging.enabled = false
    end
  • Metrics are now enabled by default and enable_metrics is removed. by @​sl0thentr0py in #3061

  • config.otlp.setup_otlp_traces_exporter and config.otlp.setup_propagator now default to false. by @​sl0thentr0py in #3063

New Features ✨

Data Collection

We are moving away from send_default_pii to a more granular configuration called data_collection.
It allows you to precisely control the data that Sentry collects from your app.

Sentry.init do |config|
  # ...
  config.data_collection.user_info = false
  config.data_collection.http_bodies = []
end

send_default_pii is deprecated but will continue to default to false.
data_collection will be backfilled when send_default_pii = false with the following values in 7.0.0:

data_collection.user_info = false
data_collection.cookies.mode = :off
data_collection.http_headers.request.mode = :deny_list
data_collection.http_headers.request.terms = %w[forwarded -ip _ip remote via _user -user]
data_collection.http_headers.response.mode = :deny_list
data_collection.http_headers.response.terms = %w[forwarded -ip _ip remote via _user -user]
data_collection.http_bodies = []
data_collection.url_query_params.mode = :off
data_collection.graphql.document = false
data_collection.graphql.variables = false
data_collection.database_query_data = false
data_collection.queues = false
data_collection.frame_context_lines = 3

... (truncated)

Commits
  • 28e4246 release: 7.0.0
  • 3bf6552 feat(data-collection): Change stack_frame_variables to KeyValueCollection (#3...
  • 2f8328f feat(data-collection): Allow booleans as shorthand for KeyValueCollection fie...
  • caa1b0c feat(data-collection): Gate ActiveJob arguments and ExecutionContext inclusio...
  • 685e82a ci: 🤖 Update pinned CI lockfiles (#3060)
  • d3f1ff4 feat! Remove enable_metrics (#3061)
  • 100cdc9 feat!: Remove enable_logs (#3053)
  • f34bffb ci: 🤖 Update pinned CI lockfiles (#3054)
  • c071bcd feat(data-collection): Port Rails log subscribers (#3034)
  • 5a2f1ed feat(data-collection): Port Rails controller and ActiveStorage (#3033)
  • Additional commits viewable in compare view

Updates sentry-rails from 5.28.1 to 7.0.0

Changelog

Sourced from sentry-rails's changelog.

7.0.0

Breaking Changes 🛠

  • Logs are now enabled by default and enable_logs is removed. by @​sl0thentr0py in #3053

    Using sentry-rails will automatically turn on automatic structured logging from Rails. if you want to turn it off, use:

    Sentry.init do |config
      # ...
      config.rails.structured_logging.enabled = false
    end
  • Metrics are now enabled by default and enable_metrics is removed. by @​sl0thentr0py in #3061

  • config.otlp.setup_otlp_traces_exporter and config.otlp.setup_propagator now default to false. by @​sl0thentr0py in #3063

New Features ✨

Data Collection

We are moving away from send_default_pii to a more granular configuration called data_collection.
It allows you to precisely control the data that Sentry collects from your app.

Sentry.init do |config|
  # ...
  config.data_collection.user_info = false
  config.data_collection.http_bodies = []
end

send_default_pii is deprecated but will continue to default to false.
data_collection will be backfilled when send_default_pii = false with the following values in 7.0.0:

data_collection.user_info = false
data_collection.cookies.mode = :off
data_collection.http_headers.request.mode = :deny_list
data_collection.http_headers.request.terms = %w[forwarded -ip _ip remote via _user -user]
data_collection.http_headers.response.mode = :deny_list
data_collection.http_headers.response.terms = %w[forwarded -ip _ip remote via _user -user]
data_collection.http_bodies = []
data_collection.url_query_params.mode = :off
data_collection.graphql.document = false
data_collection.graphql.variables = false
data_collection.database_query_data = false
data_collection.queues = false
data_collection.frame_context_lines = 3

... (truncated)

Commits
  • 28e4246 release: 7.0.0
  • b6c4ddd feat(data-collection): Make rails breadcrumbs respect data collection (#3068)
  • 3bf6552 feat(data-collection): Change stack_frame_variables to KeyValueCollection (#3...
  • caa1b0c feat(data-collection): Gate ActiveJob arguments and ExecutionContext inclusio...
  • 685e82a ci: 🤖 Update pinned CI lockfiles (#3060)
  • 100cdc9 feat!: Remove enable_logs (#3053)
  • 040fb0d fix(rails): set dummy rails app before calling initializers (#3055)
  • f34bffb ci: 🤖 Update pinned CI lockfiles (#3054)
  • c071bcd feat(data-collection): Port Rails log subscribers (#3034)
  • 5a2f1ed feat(data-collection): Port Rails controller and ActiveStorage (#3033)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Jan 14, 2026
dependabot Bot added 7 commits September 6, 2026 11:53
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: dependabot[bot] <support@github.com>
@3kh0

3kh0 commented Sep 6, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [sentry-ruby](https://github.com/getsentry/sentry-ruby) and [sentry-rails](https://github.com/getsentry/sentry-ruby). These dependencies needed to be updated together.

Updates `sentry-ruby` from 5.28.1 to 7.0.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-ruby@5.28.1...7.0.0)

Updates `sentry-rails` from 5.28.1 to 7.0.0
- [Release notes](https://github.com/getsentry/sentry-ruby/releases)
- [Changelog](https://github.com/getsentry/sentry-ruby/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-ruby@5.28.1...7.0.0)

---
updated-dependencies:
- dependency-name: sentry-rails
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: sentry-ruby
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump sentry-ruby and sentry-rails build(deps): bump sentry-ruby and sentry-rails Sep 6, 2026
@dependabot
dependabot Bot force-pushed the dependabot/bundler/multi-e12fb54b59 branch from df41188 to f8f8c4a Compare September 6, 2026 16:22
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgem/​sentry-ruby@​5.28.1 ⏵ 7.0.096 +1100100100100
Updatedgem/​sentry-rails@​5.28.1 ⏵ 7.0.097 +1100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant