Skip to content

feat(attributes): Add sentry.event.serialized_* attributes - #556

Merged
mjq merged 1 commit into
mainfrom
mjq/serialized-event-data
Aug 5, 2026
Merged

feat(attributes): Add sentry.event.serialized_* attributes#556
mjq merged 1 commit into
mainfrom
mjq/serialized-event-data

Conversation

@mjq

@mjq mjq commented Aug 5, 2026

Copy link
Copy Markdown
Member

Add:

  • sentry.event.serialized_contexts
  • sentry.event.serialized_extra
  • sentry.event.serialized_breadcrumbs

as internal attributes for storing the JSON-serialized values from incoming Sentry transactions (and maybe later other event types).

These will be populated by Relay for incoming transaction events and displayed on the Sentry frontend so that transaction-based SDK users don't lose this data.

The serialized_ prefix allows us to e.g. use a different attribute name in the future once we natively support object types.

@mjq

mjq commented Aug 5, 2026

Copy link
Copy Markdown
Member Author

@cursor review

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown

Semver Impact of This PR

🟡 Minor (new features)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


Breaking Changes 🛠

  • (op) Add gen_ai prefix to existing ops and add embeddings, generate_content, and rerank ops by msonnb in #543

New Features ✨

Attributes

  • Add sentry.event.serialized_* attributes by mjq in #556
  • Add browser.bfcache.* attributes by logaretm in #513
  • Add query, deprecated in favor of db.query.text by alexander-alderman-webb in #530
  • Add aws.operation_name, deprecated in favor of rpc.method by alexander-alderman-webb in #536
  • Add db.params, deprecated in favor of db.query.parameter.<key> by alexander-alderman-webb in #529
  • Add code, deprecated in favor of rpc.response.status_code by alexander-alderman-webb in #533
  • Add django.function_name, deprecated in favor of code.function.name by alexander-alderman-webb in #538
  • Add port, deprecated in favor of server.port by alexander-alderman-webb in #532
  • Add redis.command, deprecated in favor of db.operation.name by alexander-alderman-webb in #531
  • Add address, deprecated in favor of server.address by alexander-alderman-webb in #534
  • Add aws_region, deprecated in favor of cloud.region by alexander-alderman-webb in #537
  • Add gcp_region, deprecated in favor of cloud.region by alexander-alderman-webb in #535
  • Add django.middleware_name (deprecated) in favor of middleware.name by alexander-alderman-webb in #520
  • Add starlite.middleware_name (deprecated) in favor of middleware.name by alexander-alderman-webb in #519
  • Add aws.request.url (deprecated) in favor of url.full by sentrivana in #488
  • Add subprocess.pid (deprecated) in favor of process.pid by sentrivana in #487
  • Add litestar.middleware_name (deprecated) in favor of middleware.name by sentrivana in #486
  • Add starlette.middleware_name (deprecated) in favor of middleware.name by sentrivana in #485
  • Add redis.key (deprecated) in favor of db.redis.key by sentrivana in #484
  • Add db.mongodb.collection (deprecated) in favor of db.collection.name by sentrivana in #483
  • Add Kafka messaging attributes by chargome in #474
  • Deprecate rpc.grpc.status_code in favor of rpc.response.status_code by lucas-zimerman in #494
  • Add deprecated messaging.destination_kind by andreiborza in #509
  • Add sentry.segment.name.source attribute by Lms24 in #466
  • Add attribute transformations by constantinius in #465
  • Add stable app vitals attributes by buenaflor in #493
  • Deprecate sentry.frames.* attributes by buenaflor in #500
  • Add missing AI legacy aliases from Relay SpanData by vgrozdanic in #498

Op

  • Add general measure span operation by msonnb in #550
  • Add browser resource, timing phase, and UI span operations by msonnb in #547
  • Add object storage span operations by msonnb in #545
  • Add http.client.stream op by msonnb in #544

Other

  • (conventions) Support multiple examples by Lms24 in #505
  • (descriptions) Add http.route description template for http.server span description inference by Lms24 in #518
  • (ops) Add navigation.redirect op and update name and description rules by Lms24 in #522

Internal Changes 🔧

Attribute

  • Add more examples for valid sentry.kind values by Lms24 in #517
  • Improve db.statement example and add deprecation reason by Lms24 in #501

Attributes

  • Disambiguate http.route and url.template attributes by Lms24 in #521
  • Improve description of sentry.segment.name.source by Lms24 in #511
  • Deprecate sentry.span.source and change backfill status of sentry.source by Lms24 in #510

Deps

  • Bump postcss from 8.5.15 to 8.5.25 by dependabot in #549
  • Bump dompurify from 3.4.11 to 3.4.12 by dependabot in #525
  • Bump fast-uri from 3.1.2 to 3.1.4 by dependabot in #526
  • Bump svgo from 4.0.1 to 4.0.2 by dependabot in #524
  • Bump js-yaml from 4.2.0 to 4.3.0 by dependabot in #516
  • Bump astro from 6.4.7 to 7.1.0 in /docs by dependabot in #514

Other

  • (attrs) Backport attributes and normalizations from Relay by Dav1dde in #497
  • (codeowners) Assign telemetry-experience to gen_ai/ai attributes by vgrozdanic in #506
  • (deps-dev) Bump tar from 7.5.16 to 7.5.19 by dependabot in #515
  • (release) Show version in workflow run title by constantinius in #504

🤖 This preview updates automatically when you update the PR.

@mjq
mjq force-pushed the mjq/serialized-event-data branch from b29ace9 to 519804b Compare August 5, 2026 14:25

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit b29ace9. Configure here.

"type": "string",
"apply_scrubbing": {
"key": "never"
},

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PII scrubbing disabled for event data

High Severity

apply_scrubbing is set to never for sentry.event.serialized_breadcrumbs, sentry.event.serialized_contexts, and sentry.event.serialized_extra. These hold JSON-serialized breadcrumbs, contexts, and extra, which commonly contain PII. Per project policy and similar JSON content attributes like gen_ai.input.messages, this blocks scrubbing of sensitive data.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit b29ace9. Configure here.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These keys are special, as PII is already applied by Relay to the original data before serialization.

I was thinking exposing them to scrubbing again might corrupt the JSON, but I suppose if they were already scrubbed once a second scrubbing pass should be safe? 🤔 @Dav1dde do you have an opinion on this?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy pasta from Slack:

For now the scrubbing shouldn't matter as the segment span is extracted at the very end of the pipeline, right? If we ever change that, we must make sure this isn't broken (scrub context before serialize), so an integration test for that in Relay would be great (send tx with sensitive data, assert the serialized context is json and doesn't contain pii).

For the actual question, it shouldn't be pii = true, either maybe or false both work, since scrubbing this would actually break product features, I think it's fine to set it as never .

@mjq
mjq requested a review from Dav1dde August 5, 2026 14:26
@mjq
mjq marked this pull request as ready for review August 5, 2026 14:28
@mjq
mjq requested review from a team, Lms24, cleptric and nsdeschenes as code owners August 5, 2026 14:28
@linear-code

linear-code Bot commented Aug 5, 2026

Copy link
Copy Markdown

BROWSE-670

@mjq
mjq merged commit d95f371 into main Aug 5, 2026
16 checks passed
@mjq
mjq deleted the mjq/serialized-event-data branch August 5, 2026 20:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants