chore(deps): update dependency @microsoft/applicationinsights-web to v3 - #62
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency @microsoft/applicationinsights-web to v3#62renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
May 28, 2023 09:36
f1f0d19 to
52170fe
Compare
renovate
Bot
restored the
renovate/microsoft-applicationinsights-web-3.x
branch
August 4, 2023 18:45
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
August 4, 2023 18:45
52170fe to
3033ceb
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
September 20, 2023 23:12
3033ceb to
01833aa
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
October 24, 2023 00:34
01833aa to
dd2bc98
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
November 2, 2023 04:44
dd2bc98 to
f37a0eb
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
2 times, most recently
from
December 14, 2023 20:33
eebbaab to
72a4ae2
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
February 7, 2024 18:56
72a4ae2 to
41ce0ae
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
February 15, 2024 20:10
41ce0ae to
15400c8
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
March 13, 2024 04:00
15400c8 to
d36bce2
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
March 22, 2024 00:24
d36bce2 to
f36e7ce
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
April 23, 2024 21:35
f36e7ce to
2d82889
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
May 10, 2024 04:57
2d82889 to
790e74c
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
June 11, 2024 20:01
790e74c to
e9d2e57
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
July 2, 2024 01:52
e9d2e57 to
022182f
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
August 9, 2024 00:44
022182f to
804a31d
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
September 3, 2024 19:48
804a31d to
24353a7
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
September 24, 2024 15:38
24353a7 to
73f07d7
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
October 30, 2024 17:17
73f07d7 to
750e5d0
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
February 4, 2025 03:25
750e5d0 to
330ed09
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
March 4, 2025 20:30
330ed09 to
790200b
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
May 9, 2025 01:22
790200b to
5470ee4
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
May 22, 2025 19:23
5470ee4 to
7db0e68
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
June 26, 2025 09:40
7db0e68 to
cc35f13
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
September 23, 2025 19:04
cc35f13 to
49cf8dc
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
2 times, most recently
from
January 13, 2026 03:02
29e3962 to
600aa12
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
February 12, 2026 12:43
600aa12 to
bf9ffaf
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
March 5, 2026 16:15
bf9ffaf to
3f485e2
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
April 7, 2026 22:42
3f485e2 to
8537860
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
2 times, most recently
from
June 1, 2026 23:53
8c1a193 to
d5d5dd8
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
June 20, 2026 00:58
d5d5dd8 to
bdad52f
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
July 2, 2026 20:54
bdad52f to
bc81f2c
Compare
renovate
Bot
force-pushed
the
renovate/microsoft-applicationinsights-web-3.x
branch
from
July 21, 2026 00:07
bc81f2c to
3f06acf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.8.7→^3.4.3Release Notes
microsoft/ApplicationInsights-JS (@microsoft/applicationinsights-web)
v3.4.3This is a maintenance release for the 3.4.x version line adding a new SDK statistics feature, a PostChannel reliability fix, and dependency security hardening. The
@microsoft/1ds-post-jschannel is numbered 4.4.3 and requires v3.4.3.Significant Changes (since 3.4.2)
Customer SDK Stats: Added a new
SdkStatsfeature that periodically collects internal SDK usage/health statistics. It is enabled by default and can be disabled (or explicitly configured) via thefeatureOptInconfiguration (e.g.featureOptIn: { SdkStats: { mode: FeatureOptInMode.disable } }); the collection interval defaults to 15 minutes (sdkStats.int).PostChannel Auto-Flush Stall Fix: Fixed a permanent stall in
@microsoft/1ds-post-jswhere, under sustained intermittent send failures (e.g. a load balancer returning occasional 503s), auto flush could wedge behind theflush()wait-for-idle timer and permanently stop draining the in-memory queue — causing telemetry to be silently dropped asQueueFulluntil the process was restarted. Auto flush is now fire-and-forget and no longer parks the scheduler waiting for the manager to become completely idle.Dependency Security Hardening: Pinned
tarto>=7.5.16to remediate CVE-2026-53655 and resolved the remainingnpm auditfindings in build tooling via dependency overrides (js-yaml,yaml,markdown-it,linkify-it). These are build/tooling changes and do not affect the published runtime packages.Changelog
Full Changelog: microsoft/ApplicationInsights-JS@3.4.2...3.4.3
v3.4.2This is a maintenance release for the 3.4.x version line containing security hardening, bug fixes, build tooling improvements, and CI updates. The
@microsoft/1ds-post-jschannel is numbered 4.4.2 and requires v3.4.2.Significant Changes (since 3.4.1)
Prototype Pollution Hardening: The
extend()andobjExtend()helpers now filter unsafe keys (__proto__,constructor,prototype) to prevent prototype pollution when merging untrusted objects.Dependency Vulnerability Resolution: Migrated the repository from npm to pnpm for dependency management and resolved all known dependency vulnerabilities. This is a build/tooling change and does not affect the published runtime packages.
OsPlugin Field Name Correction: The OsPlugin now emits the correct Common Schema 4.0 field names (
ext.os.nameandext.os.ver). Telemetry consumers relying on the previously emitted (incorrect) field names should update to the corrected names.RequestEnvelopeCreator Envelope Name Fix: Fixed
RequestEnvelopeCreatorso request telemetry is sent with the correct envelope name (Microsoft.ApplicationInsights.{ikey}.Request) instead ofRequestData.Offline Channel Reliability: Fixed a missing
returnafterreject()in the offline channel that could lead to a null provider dereference.Fixed
[INVALID_ANNOTATION]warnings in Rolldown / Vite 8 consumers (#2736): The per-moduledist-es5output (the packagemoduleentry that modern bundlers import) emitted parenthesized PURE tree-shaking annotations with whitespace after the opening parenthesis (e.g.( /*#__PURE__*/"http.")), which stricter bundlers such as Rolldown (Vite 8) rejected. The build now canonicalizes these annotations to the flush form ((/*#__PURE__*/"http.")) in thedist-es5output, accepted by all bundlers while preserving the wrapping parentheses required for older Rollup / Webpack / Terser to tree-shake the constants. This complements #2737, which only normalized the rollup-bundleddist/es5(main) output.CI / Tooling
puppeteer,@pnpm/error) now require Node.js 18 or later. The CI pipeline no longer runs against Node.js 16.Changelog
Full Changelog: microsoft/ApplicationInsights-JS@3.4.1...3.4.2
v3.4.1Compare Source
This is the first full supported release of the 3.4.x version line. While a 3.4.0-beta was previously released for early testing and validation, version 3.4.0 was not released as a standard supported version — 3.4.1 is the first production-ready release in this series. The
@microsoft/1ds-post-jschannel is numbered 4.4.1 and requires v3.4.1.Significant Changes (since 3.3.11)
W3C Trace State Support: Added full support for managing W3C Trace State and sending headers in distributed tracing, including new distributed tracing modes
AI_AND_W3C_TRACEandW3C_TRACEthat enable thetracestateheader to be sent with requests when trace state information is available, the existing states will continue to not send the header.New Distributed Tracing Modes: Added new
eDistributedTracingModesenum values:AI_AND_W3C_TRACE(17): Sends Application Insights headers + W3Ctraceparent+ W3Ctracestateheaders (if state value is present)W3C_TRACE(18): Sends only W3Ctraceparent+ W3Ctracestateheaders (if state value is present)Enhanced Distributed Tracing: Refactored the distributed tracing implementation to provide better support for the W3C Trace Context specification and prepare for future OpenTelemetry Span-style API integration.
New W3C TraceState API: Introduced the
IW3cTraceStateinterface that provides a mutable, ordered list of key/value pairs for trace state information with proper parent-child relationships.OpenTelemetry Integration Preparation: Added foundational OpenTelemetry interfaces (
IOTelSpanContext,IOTelTraceState) to provide OpenTelemetry API compatibility.Additional Configuration: Added new configuration properties for W3C trace state support:
traceHdrMode: Controls if the SDK should look for thetraceparentand/ortracestatevalues from service timing headers or meta tags from the initial page load (inIConfiguration)distributedTracingModeproperty to support the new W3C trace state modes (inICorrelationConfig)Dependencies Extension: The dependency tracking extension now includes additional logic for W3C trace state handling, which may affect custom dependency listeners or initializers. The following interfaces and functions have been enhanced with W3C trace state support:
IDependencyListenerDetailsinterface now also includes a readonlytraceStatealong with the previoustraceId,spanId,traceFlagspropertiesaddDependencyListener()function now provides access to W3C trace state information through the enhanced details objectaddDependencyInitializer()function continues to work with existing dependency telemetry processingEnhanced Cookie Management: Cookie values are now cached in memory when cookies are disabled instead of being lost, enabling support for consent banner workflows where cookies must be temporarily disabled until user approval. Automatic flushing occurs when cookies are re-enabled.
OsPlugin Reliability Improvements: Improved OsPlugin with proactive OS retrieval, unload handling, and session caching for more reliable OS detection.
URL Redaction Enhancements: Made URL redaction more dynamic for improved flexibility in field redaction scenarios.
Package Deprecation
The following packages have been merged into
@microsoft/applicationinsights-core-jsand are now deprecated. They continue to be published as backward-compatible shims (re-exporting from Core) so existing code will not break, but they are no longer used as dependencies by the main SDK packages. You should stop importing from these packages and migrate to@microsoft/applicationinsights-core-jsdirectly.@microsoft/applicationinsights-common— All exports have been merged into@microsoft/applicationinsights-core-js. The package is now a compatibility shim that re-exports from Core. See the Migration Guide for details on updating your imports. This package will be removed in a future major release (4.0.0).@microsoft/1ds-core-js— All exports have been merged into@microsoft/applicationinsights-core-js. The package is now a compatibility shim that re-exports from Core. See the 1DS Core Migration Guide for class/import name changes and migration steps. Consumers should update their imports to reference@microsoft/applicationinsights-core-jsdirectly. This package will be removed in a future major release (4.0.0).Breaking Changes
The following is a list of known breaking changes for anyone attempting to implement the interfaces, for end-users / consumers of the existing interface this is considered to be only a potential breaking change as the existing functions are still provided and provide the same level of functionality. The breaking nature of these changes is for anyone attempting to provide their own implementation of these changes.
Interface Changes
IDistributedTraceContextinterface has been significantly expanded to include W3C trace state management capabilities, which may affect custom telemetry processors that interact with distributed tracing context.pageName,traceId,spanIdandtraceFlags).Potential Breaking Changes
Class Removal: The
TelemetryTraceclass has been removed and is no longer exported as part of the distributed tracing refactoring, with its functionality integrated into the new W3C trace state implementation.telemetryTraceis now a complete adpater to the existingcore.getTraceCtx()value and as such is now marked as deprecated and will be removed in a future release.appInsights.context.telemetryTraceis no longer an instance of this removed class.Trace Context Initialization: Due to the distributed tracing refactoring, the core instance and SDK will now always have a valid
traceIdavailable throughcore.getTraceCtx(). ThetraceIdwill be either a newly generated random value or inherited from any detected parent trace context. This ensures consistent trace context availability but may affect applications that previously relied on the absence of atraceIdto determine if distributed tracing was active.Dependencies Extension - ajaxRecord Class Removal: The internal
ajaxRecordclass has been removed and is no longer exported from the dependencies extension (@microsoft/applicationinsights-dependencies-js). The internal implementation now implements the newIAjaxRecordDatainterface. This class was previously used internally for AJAX request tracking and was referenced in theIInstrumentationRequirements.includeCorrelationHeaders()function signature. Important: The previous exporting of theajaxRecordclass was unintentional and was never meant to be part of the public API - it was an internal implementation detail that inadvertently became accessible to external code.includeCorrelationHeaders(ajaxData: ajaxRecord, input?: Request | string, init?: RequestInit, xhr?: XMLHttpRequestInstrumented): anyincludeCorrelationHeaders(ajaxData: IAjaxRecordData, input?: Request | string, init?: RequestInit, xhr?: XMLHttpRequestInstrumented): anyIAjaxRecordDatainterface has been introduced to replace theajaxRecordclass in public API signatures and provides access to essential AJAX request properties:getAbsoluteUrl(): string | null- Gets the absolute URL for the requestgetPathName(): string | null- Gets the sanitized path name for the request URLtraceCtx: IDistributedTraceContext- The distributed trace context for the requestrequestHeaders: { [key: string]: string }- Object containing request headersaborted?: number- Indicates whether the request was abortedcontext?: { [key: string]: any }- Optional context object for dependency listenersajaxRecordclass or implemented theIInstrumentationRequirementsinterface. Standard SDK usage and most custom dependency listeners/initializers are unaffected.ajaxRecordor implementedIInstrumentationRequirements, update it to use the newIAjaxRecordDatainterface, which provides the same essential properties with proper TypeScript definitions and comprehensive JSDoc documentation.Flush Method Signature Change: Renamed
flushmethod parameter fromasynctoisAsyncinIChannelControlsinterface to avoid potential keyword conflicts (only affects code that relies on named parameters).flushmethod to properly includebooleanwhen callbacks complete synchronouslyPotential behavioral changes
This release enhances the cookie management behavior when cookies are disabled. Previously, when cookies were disabled, calls to
cookieMgr.set()would returnfalseand cookie values would be lost. Now, these operations are cached in memory and automatically applied when cookies are re-enabled to allow for cookie compliance banners and delayed approval.Behavior changes:
cookieMgr.set()now returnstruewhen cookies are disabled (because values are cached), instead offalsecookieMgr.get()now returns cached values when cookies are disabled, instead of empty stringscookieMgr.del()operations are now cached and applied when cookies are re-enabledThese changes improve data persistence and are considered enhancements rather than breaking changes. If your application logic depends on the previous behavior of
set()returningfalsewhen cookies are disabled, you may need to checkcookieMgr.isEnabled()instead, or configuredisableCookieCache: truein yourcookieCfgto maintain the previous behavior.Known Limitations
msieortrident/user agent strings), it automatically rewrites the CDN URL to load the v2.x SDK instead of v3.x (e.g.ai.3.gbl.min.jsbecomesai.2.gbl.min.js). This means any v3.x-only APIs — including the new OpenTelemetry-based APIs — will not be available for users on Internet Explorer. If your code uses these newer APIs, you should check for their existence before calling them. This fallback does not apply when using the NPM package directly.Changelog
flushmethod parameter fromasynctoisAsyncinIChannelControlsinterface to avoid potential keyword conflicts (only affects code that relies on named parameters)flushmethod to properly includebooleanwhen callbacks complete synchronously_doSend()couldn't handle asynchronous callbacks frompreparePayload()when compression is enabledawait applicationInsights.flush()now works correctly with compression enabledsetEnabled(true)or dynamic configuration changesdisableCookieDeferconfiguration option to maintain backward compatibility with previous behavior (defaults to false)cookieMgr.set()now returnstruewhen disabled (cached) instead offalsecookieMgr.get()now returns cached values when disabled instead of empty stringsFull Changelog: microsoft/ApplicationInsights-JS@3.3.11...3.4.1
v3.3.11Compare Source
Changelog
Infrastructure changes
Web snippet 1.2.3 (November 10, 2025)
v3.3.10Compare Source
Interface changes
This release includes:
customProviderandcustomUnloadProviderinterfaces to theIOfflineChannelConfiguration.IAnalyticsConfigis exported for Analytics extension.redactUrlsandredactQueryParamsare added toIConfigurationto support URL redaction.Changelog
2792261: Provide Custom Provider Under Web Worker for Offline Channel3447059: Update Async Tests Under Dependencies Extension To Use the Modern AsyncQueue Pattern3447059: Update AISKU Async Tests To Use the Modern AsyncQueue Patternv3.3.9Compare Source
This release contains an important fix for a change introduced in v3.3.7 that caused the
autoCaptureHandlerto incorrectly evaluate elements withintrackElementsType, resulting in some click events not being auto-captured. See more details here.Changelog
3324697: Update Readme on Error Handlerv3.3.8Compare Source
This release contains an important fix for a change introduced in v3.3.7 that caused a ReferenceError exception to be thrown when running in strict mode. See more details here.
Changelog
v3.3.7Compare Source
Potential breaking change
This release contains a potential breaking change due to the new compress api feaure added. If you are using a Proxy to redirect your telemetry to your own endpoint or are relying on the events to be uncompressed (this feature is initially disabled and it is intended to be enabled by the service in the near future), it is recommended to either update collection endpoint to support GZip or to explicitly disable the feature. See more details here.
Changelog
maxEvtPerBatchis added to the post channelIChannelConfiguration.requestLimitis added to the post channelIChannelConfiguration.DependencyListenerFunctiontrackElementTypesis added toIClickAnalyticsConfigurationto allow additional, configurable HTML element types to be tracked in addition to the default setzipPayloadand is currently disabled by default. See how to enable this feature and more details.v3.3.6Compare Source
Changelog
v3.3.5Compare Source
Changelog
Issues
Commits
v3.3.4Compare Source
Changelog
v3.3.3Compare Source
Changelog
splitEvtsis added to Offline Channel Config. By enabling it, offline events will be batched and saved separately based on persistence level2944563: Fix Promise Initialization Sender Config Issuev3.3.2Compare Source
Changelog
expCfgis moved fromIConfigtoIConfiguration(this change is going to cause the TypeScript type error).v3.3.1Compare Source
Interface changes
This release includes:
customProviderandcustomUnloadProviderinterfaces to theIOfflineChannelConfiguration.IAnalyticsConfigis exported for Analytics extension.redactUrlsandredactQueryParamsare added toIConfigurationto support URL redaction.Changelog
2792261: Provide Custom Provider Under Web Worker for Offline Channel3447059: Update Async Tests Under Dependencies Extension To Use the Modern AsyncQueue Pattern3447059: Update AISKU Async Tests To Use the Modern AsyncQueue Patternv3.3.0Compare Source
Potential breaking change
This release contains a potential break change due to enhancing the definition of the IConfiguration to support Promise types for the connectionString, instrumentationKey and endpointURL; any extension that relies on these base interfaces will VERY likely cause TypeScript to fail with potential warnings about the types being different.
Changelog
!! potential breaking changes. IConfiguration support Promise types for the connectionString, instrumentationKey and endpointURL
v3.2.2Compare Source
Changelog
v3.2.1Compare Source
Changelog
v3.2.0Compare Source
!! CfgSync plugin is turned on. Throttling Ikey depreciation message is enabled with sampling rate 0.0001%
##2317
!! Sender has breaking changes. The key used for session storage is changed and items stored in the storage now contain retry counts.
##2324
Changelog
v3.1.2Compare Source
!! Critical Bug fix for Memoery Leak !!
#2311
It also contains a packaging fix for webpack #2307 (caused by [#2306]](#2306) ) and
Changelog
v3.1.1Compare Source
Changelog
Web snippet additional update to 1.1.2 (March 1st, 2024)
Refer to #2284 [Web-Snippet] [BUG] @microsoft/applicationinsights-web-snippet version 1.1.1 type problem
Web snippet additional update to 1.1.1 (Feb 16th, 2024)
Refer to #2277 [Web-Snippet] dependency chain issues
v3.1.0Compare Source
Interface changes / Breaking changes
This release includes support for a new Offline Channel which has changed the
IChannelsControlsinterface to include additional support for the newofflinechannel. This change is to support the newConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.