World Congress 2023 • Oct 6, 2023

From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases

Priscila Oliveira

Tired of shipping module resolution bugs? Discover how Sentry integrates Verdaccio into their CI pipeline to safely test SDK releases in a local npm proxy before going public.

Pause
Mute Enter Fullscreen
#1 about 2 min

Overview of the Sentry error and performance monitoring platform

Sentry provides open-source tools for developers to monitor application performance and track errors seamlessly.

#2 about 4 min

Installing and configuring the Sentry JavaScript SDK for applications

Setting up Sentry requires installing the framework-specific package and initializing it with a unique data source name.

#3 about 2 min

Analyzing application bugs via the Sentry issue details page

The issue details page provides key metrics on affected users, browser types, and devices to accelerate bug resolution.

#4 about 2 min

Balancing SDK feature releases with strict backward compatibility requirements

Releasing new SDK versions requires balancing feature additions and performance improvements while avoiding regressions across multiple frameworks.

#5 about 4 min

Backward compatibility issues between CommonJS and ES6 modules

Transitioning to ES6 modules can cause application crashes if typological errors disrupt compatibility with CommonJS imports.

#6 about 4 min

Setting up Verdaccio as a private npm proxy registry

Verdaccio allows developers to create a local npm registry for securely caching and publishing packages before public release.

#7 about 5 min

Running automated end-to-end tests with Verdaccio in CI pipelines

Publishing packages to a local Verdaccio registry via Docker prevents regressions by enabling automated testing within continuous integration environments.

#8 about 5 min

Validating bug fixes through localized test registries via Docker

Running locally cached end-to-end tests ensures module configuration errors are safely caught and resolved prior to publishing.

Matching moments

6:31 min

Audience Q&A on CDK implementation and automated testing

Alexander Bubeck · WWC 2023

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · WWC 2024

3:52 min

Executing security scans and leveraging centralized observability pipelines

Romano Roth Romano Roth · WWC 2025

2:00 min

Audience Q&A on SDK spying and dynamodb

Raphael Manke Raphael Manke · WWC 2023

2:18 min

Reviewing real-world configurations and handling untested repositories

Susanne Bach Ladefoged Hou Susanne Bach Ladefoged Hou · WWC Europe 2026

4:29 min

Configuring a DevSecOps pipeline and Oversecured integration demo

Moataz Nabil Moataz Nabil · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

One Repo, One Strategy: Scalable Full-Stack Testing in a Monorepo World

Bartosz Leczycki, Paweł Matynia

Bartosz Leczycki
Paweł Matynia
Open session

World Congress 2026 North America

GitHub’s Team X-Ray: Your Repository Knows More About Your Team Than Your Team Does

Andrea Griffiths

Senior Developer Advocate

Andrea Griffiths
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Merging at Scale: From Broken Builds to Green Mainline

Manjari Akella, Preetam Dwivedi

Manjari Akella
Preetam Dwivedi