Skip to content

Update dependency io.sentry:sentry-android to v8.58.0 - #5877

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/io.sentry-sentry-android-8.x
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/io.sentry-sentry-android-8.x

Conversation

@renovate

@renovate renovate Bot commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
io.sentry:sentry-android 8.57.0 → 8.58.0 age confidence

Release Notes

getsentry/sentry-java (io.sentry:sentry-android)

v8.58.0

Compare Source

Features
  • Add LocalSentrySpan to sentry-compose so apps can provide a parent ISpan to a composable subtree and have nested SentryTraced spans attach to it ([#​6112]#​6112)
  • Add dataCollection, a fine-grained replacement for sendDefaultPii, for controlling data collected automatically by SDK integrations (#​5759)

[!WARNING]
sendDefaultPii will be removed in the next major SDK version. Migrate to dataCollection before upgrading.

  • Until then, when dataCollection is not configured, the SDK preserves the existing sendDefaultPii behavior.
  • Configuring any dataCollection option makes it the source of truth. sendDefaultPii is then ignored, and omitted dataCollection options use the defaults below.
  • The Logback appender is a compatibility exception. When an encoder is configured, sendDefaultPii=true continues to include the original message template and parameters. To opt in independently of sendDefaultPii, set <includeUnencodedMessage>true</includeUnencodedMessage> on the Sentry appender in logback.xml or logback-spring.xml.
  • Data explicitly supplied through APIs such as Sentry.setUser, scopes, event processors, or beforeSend is not affected.

To opt in to the documented dataCollection defaults without configuring an individual option:

Sentry.init(options -> options.getDataCollection().forceDataCollection());
Option Default Behavior
userInfo true Allows integrations to populate user identity and IP address information automatically.
cookies { mode: DENY_LIST, terms: [] } Collects cookies while filtering sensitive values.
httpHeaders.request { mode: DENY_LIST, terms: [] } Collects request headers while filtering sensitive values.
httpHeaders.response { mode: DENY_LIST, terms: [] } Collects response headers while filtering sensitive values.
httpBodies All supported body types Collects supported incoming and outgoing request and response bodies. An empty set disables body collection.
urlQueryParams { mode: DENY_LIST, terms: [] } Collects URL query parameters while filtering sensitive values.
graphql.document true Collects GraphQL documents.
graphql.variables true Collects GraphQL variables.
databaseQueryData true Allows collection of associated query data, such as bound parameters, write payloads, and results, where supported. Sanitized query statements and structural database metadata remain available.
filePaths true Allows file-system instrumentation to collect file and directory paths. File extensions and byte counts remain available when disabled.

Cookies, HTTP headers, and URL query parameters support three modes:

  • OFF: Do not collect the category.
  • DENY_LIST: Collect values except those matching the built-in sensitive deny-list or additional configured terms.
  • ALLOW_LIST: Only send plaintext values for matching terms. The built-in sensitive deny-list still applies.

Matching is case-insensitive and partial. The built-in sensitive deny-list contains auth, token, secret, password, passwd, pwd, key, jwt, bearer, sso, saml, csrf, xsrf, credentials, session, sid, and identity. Filtered values are replaced with "[Filtered]". Custom deny-list terms extend rather than replace this list.

Configure all HTTP body types, a custom cookie deny-list, a request-header allow-list, and disable URL query parameter and file path collection in an options callback:

Sentry.init(
    options -> {
      options
          .getDataCollection()
          .setHttpBodies(
              EnumSet.of(
                  HttpBodyType.INCOMING_REQUEST,
                  HttpBodyType.OUTGOING_REQUEST,
                  HttpBodyType.INCOMING_RESPONSE,
                  HttpBodyType.OUTGOING_RESPONSE));
      options
          .getDataCollection()
          .setCookies(
              KeyValueCollectionBehavior.denyList(
                  "forwarded", "-ip", "remote-", "via", "-user"));
      options
          .getDataCollection()
          .getHttpHeaders()
          .setRequest(
              KeyValueCollectionBehavior.allowList("content-type", "x-request-id"));
      options
          .getDataCollection()
          .setUrlQueryParams(KeyValueCollectionBehavior.off());
      options.getDataCollection().setFilePaths(false);
    });

Configure the same options in sentry.properties:

data-collection.http-bodies=incoming_request,outgoing_request,incoming_response,outgoing_response
data-collection.cookies.mode=deny_list
data-collection.cookies.terms=forwarded,-ip,remote-,via,-user
data-collection.http-headers.request.mode=allow_list
data-collection.http-headers.request.terms=content-type,x-request-id
data-collection.url-query-params.mode=off
data-collection.file-paths=false

Configure them with Spring Boot properties:

sentry.data-collection.http-bodies=incoming-request,outgoing-request,incoming-response,outgoing-response
sentry.data-collection.cookies.mode=deny-list
sentry.data-collection.cookies.terms=forwarded,-ip,remote-,via,-user
sentry.data-collection.http-headers.request.mode=allow-list
sentry.data-collection.http-headers.request.terms=content-type,x-request-id
sentry.data-collection.url-query-params.mode=off
sentry.data-collection.file-paths=false

Configure them in AndroidManifest.xml:

<meta-data
    android:name="io.sentry.data-collection.http-bodies"
    android:value="incoming_request,outgoing_request,incoming_response,outgoing_response" />
<meta-data
    android:name="io.sentry.data-collection.cookies.mode"
    android:value="deny_list" />
<meta-data
    android:name="io.sentry.data-collection.cookies.terms"
    android:value="forwarded,-ip,remote-,via,-user" />
<meta-data
    android:name="io.sentry.data-collection.http-headers.request.mode"
    android:value="allow_list" />
<meta-data
    android:name="io.sentry.data-collection.http-headers.request.terms"
    android:value="content-type,x-request-id" />
<meta-data
    android:name="io.sentry.data-collection.url-query-params.mode"
    android:value="off" />
<meta-data
    android:name="io.sentry.data-collection.file-paths"
    android:value="false" />

See the Data Collection documentation for all configuration keys, supported integrations, and migration guidance.

Fixes
  • Disable URL caching when reading META-INF/MANIFEST.MF files during version detection so that the SDK no longer keeps jar file handles open for the life of the process (#​6124
  • Keep the EventListener wrapped by SentryOkHttpEventListener per Call (#​6003)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@simple-services
simple-services requested review from a team and siddh1004 and removed request for a team August 1, 2026 11:47
@github-actions
github-actions Bot enabled auto-merge (squash) August 1, 2026 11:47
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.51.0 Update dependency io.sentry:sentry-android to v8.51.0 - autoclosed Aug 3, 2026
@renovate renovate Bot closed this Aug 3, 2026
auto-merge was automatically disabled August 3, 2026 09:41

Pull request was closed

@renovate
renovate Bot deleted the renovate/io.sentry-sentry-android-8.x branch August 3, 2026 09:41
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.51.0 - autoclosed Update dependency io.sentry:sentry-android to v8.52.0 Aug 5, 2026
@renovate renovate Bot reopened this Aug 5, 2026
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch 3 times, most recently from a24bede to 642e1c2 Compare August 10, 2026 08:19
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.52.0 Update dependency io.sentry:sentry-android to v8.52.0 - autoclosed Aug 11, 2026
@renovate renovate Bot closed this Aug 11, 2026
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.52.0 - autoclosed Update dependency io.sentry:sentry-android to v8.53.0 Aug 16, 2026
@renovate renovate Bot reopened this Aug 16, 2026
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch 3 times, most recently from b57a955 to 5941249 Compare August 20, 2026 12:47
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch from 5941249 to 8f860a6 Compare August 25, 2026 13:58
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.53.0 Update dependency io.sentry:sentry-android to v8.54.0 Aug 27, 2026
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch from 8f860a6 to 52a95d2 Compare August 27, 2026 12:36
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.54.0 Update dependency io.sentry:sentry-android to v8.54.0 - autoclosed Sep 1, 2026
@renovate renovate Bot closed this Sep 1, 2026
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.54.0 - autoclosed Update dependency io.sentry:sentry-android to v8.55.0 Sep 3, 2026
@renovate renovate Bot reopened this Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch 3 times, most recently from 4c4ed73 to 9e2b86d Compare September 3, 2026 09:51
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch from 9e2b86d to 277631f Compare September 3, 2026 10:15
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch from 277631f to 254e1fb Compare September 11, 2026 16:31
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.55.0 Update dependency io.sentry:sentry-android to v8.56.0 Sep 11, 2026
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch from 254e1fb to ecf4fce Compare September 16, 2026 18:56
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.56.0 Update dependency io.sentry:sentry-android to v8.57.0 Sep 16, 2026
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch 4 times, most recently from 11ef8a0 to 86db20d Compare September 23, 2026 22:32
@renovate renovate Bot changed the title Update dependency io.sentry:sentry-android to v8.57.0 Update dependency io.sentry:sentry-android to v8.58.0 Sep 23, 2026
@renovate
renovate Bot force-pushed the renovate/io.sentry-sentry-android-8.x branch from 86db20d to 5595d40 Compare September 24, 2026 07:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

0 participants