Added the OpenTelemetry packages as direct dependencies, as `@sentry/… - #355
Merged
Merged
Conversation
…node-core` declares them only as optional peer dependencies and npm does not necessarily install them
Apollon77
approved these changes
Sep 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Users report this error in the log, typically right after an adapter update:
The adapter itself keeps running — only the error reporting is dead — but the message looks alarming and gets reported as an adapter bug.
Root cause
@sentry/node-coreimports several OpenTelemetry packages at runtime, but declares all of them as optional peer dependencies:Because they are optional, npm never installs them on behalf of
node-core. They only end up in the tree at all because@sentry/nodehappens to list three of them as direct dependencies.All ioBroker adapters share one flat
/opt/iobroker/node_modules.@sentry/node-coreis hoisted to the top level there, so it can only resolve@opentelemetry/instrumentationfrom that same top level. As soon as npm nests the OpenTelemetry packages undernode_modules/@sentry/node/node_modules/— which happens when something else in the flat tree claims a conflicting@opentelemetry/instrumentationversion — the hoisted@sentry/node-corecan no longer see them, and the dynamicimport('@sentry/node')fails with the error above.Changes
1. OpenTelemetry packages added as direct dependencies
So that npm is required to keep a satisfying copy next to the hoisted
@sentry/node-core:The ranges are deliberately the wide ones that
@sentry/node-coreitself declares in its peer dependencies, rather than the narrower ones from@sentry/node. This way the plugin never narrows the resolution, and future@sentry/nodebumps (e.g.@opentelemetry/instrumentation0.220 → 0.230) still dedupe to a single top-level copy instead of forcing a second, nested one — which would reintroduce exactly the bug being fixed here.@opentelemetry/exporter-trace-otlp-httpand@opentelemetry/context-async-hooksare intentionally left out: they are only referenced from lazily loaded OTLP exporter code paths thatinit()never reaches.2. An incomplete installation no longer produces a cryptic resolution error
import('@sentry/node')moved into a new_loadSentry(), which catchesERR_MODULE_NOT_FOUND/MODULE_NOT_FOUND, extracts the name of the missing package and logs a readable, actionable warning. Every other error is re-thrown unchanged.Before:
After:
The plugin still throws so that
PluginBasedeactivates it — but with a message that tells the user what actually happened.3. Two related bugs fixed along the way
this.reallyEnabled = truewas set before the import. If the import failed, the flag stayedtruewhilethis.Sentryremainedundefined, sogetSentryObject()would hand outundefinedto adapters. It is now set only after the module has successfully loaded.require('source-map-support')was unguarded and can fail with the same class of error. It is now wrapped in try/catch — without it, only the original source locations in stack traces are lost.4. Dependency updates
@sentry/node→^10.74.0,baseline-browser-mapping(dev) →^2.11.24, lockfile regenerated.Testing
Verified on this branch with a clean
npm cion Node.js 22.23.2:npm run buildandnpm run lintpass, and the committedbuild/output matches a fresh compile.npm ci, all four OpenTelemetry packages resolve at the top level ofnode_modules; there are no nested duplicates of@opentelemetry/*or@sentry/*._registerSentry()behaviour in three different trees:reallyEnabled = true@opentelemetry/instrumentationremovedreallyEnabled = false,Sentrystaysundefined@sentry/noderemoved@sentry/node, same clean deactivation