---
updatedAt: 2026-10-06T15:45:15.000Z
agentTools:
  projectIndex: https://developers.heap.io/llms.txt
---

# heap.js 5 Changelog

# Changelog

All notable changes to the Heap.js 5 library will be documented in this file.

To check which version you are using, [follow these instructions](web#identifying-your-heap-version).

The format is based on [Keep a Changelog][cl] and this project adheres to\
[Semantic Versioning][sv].

[cl]: http://keepachangelog.com/

[sv]: http://semver.org/

## \[5.3.17] - 2026-10-06

### Fixed

* Checks `form.isConnected` on submit handler

## \[5.3.16] - 2026-09-15

### Fixed

* Fixed `nextPageOnly` `cvars` in Contentsquare sideloads Heap

## \[5.3.15] - 2026-08-31

### Changed

* Skipped metadata handshake when the Contentsquare tag does not boot for sideloading

### Added

* Added plugin framework telemetry

## \[5.3.14] - 2026-06-22

### Changed

* Removed Shadow DOM logging that retained references to detached DOM trees
* Replaced legacy URL parsing to prevent detached DOM node leaks

## \[5.3.13] - 2026-05-26

### Added

* Added `restrictCookiesToSubdomain` client side configuration option

### Changed

* Refactored event history tracking to use weak references, reducing the risk of long-lived memory retention

## \[5.3.12] - 2026-04-21

### Fixed

* Prevents buffered event loss by removing destructive localStorage rewrites
* Adds optional chaining to UXAnalytics

## \[5.3.11] - 2026-04-20

### Fixed

* Fixed bug for `heap.trackPageview()` being called before adapters are initialized

## \[5.3.10] - 2026-03-12

### Added

* Handled hash based routing in cross domain link decoration

## \[5.3.9] - 2026-03-04

### Changed

* Skipped compression on hp\_ved cookie if compressCookies is enabled

## \[5.3.8] - 2026-02-10

### Fixed

* Fixed bug where UTM parameters were ignoring `heap.setPath`

## \[5.3.7] - 2026-01-22

### Changed

* Updated CDT to consider hash-based routing when pulling query params

## \[5.3.6] - 2026-01-12

## Added

* Added client side support for `shopify` in track calls

## \[5.3.5] - 2025-12-10

### Fixed

* Added check if `referrer` is a string to prevent error downstream
* Added error handling on pageview snapshots

## \[5.3.4] - 2025-10-21

### Fixed

* Updated `prototype.attachShadow` patch to `Element` instead of `HTMLElement`

## \[5.3.3] - 2025-09-30

### Added

* Updated pageview autocapture to capture from `bfcache`

### Fixed

* Fixed bug with pageview snapshots

## \[5.3.2] - 2025-08-28

### Changed

* Added `sendHeapContext` call for both Contentsquare sideloading directions

### Fixed

* Fixed bug in device info

## \[5.3.1] - 2025-08-20

### Fixed

* Removed initial pageview props from cookie
* Fixed cookie decoding when there is a `%` in the value

## \[5.3.0] - 2025-08-06

### Changed

* Moved metadata creation upstream

## \[5.2.13] - 2025-06-25

### Added

* Added `heap.getPageviewMetadata()` api
* Added support for Visual Labeler in EU data storage
* Added `href` capture in SVGs

## \[5.2.12] - 2025-06-03

### Added

* Added support for array event properties in `track` and `addEventProperties` apis

### Fixed

* Fixed bug where snapshot pageview properties were not being inherited by events on the page
* Fixed bug with referrer persisting across sessions

## \[5.2.11] - 2025-05-19

### Changed

* Updated metadata timestamps to page open rather than request processed time

### Fixed

* Removed persistent `let` value from storage when switching storage methods

## \[5.2.10] - 2025-04-23

### Changed

* Updated `heap.setPath()` to allow domain
* Fixed bug in blocking transformers

## \[5.2.9] - 2025-03-18

### Fixed

* Fixed session creation bug when `compressCookies` was true and `let` cookie was inaccessible

### Changed

* Allowed calls to be enqueued onto the `onReady` queue while it’s processing
* Leaving the CSS selector empty on defined click, change and submit events will now apply to all corresponding events to align with pageview behavior

## \[5.2.8] - 2025-02-12

### Added

* Added telemetry
* Added support for `disableTextCapture` param to `trackPageview` API
* Added support for case-insensitive client-side config
* Added support for server-side `salesforceAura` setting

### Changed

* Applied Contentsquare PII settings to heap\_sideloads\_cs
* Changed `onReady` queue to drop duplicate calls

## \[5.2.7] - 2025-01-27

### Added

* Added support for static text snapshot
* Added “hashed\_user\_id” to identity blocklist
* Added call to transfer metadata to Contentsquare

### Changed

* Updateed logic in `supportedDomains` to not match a substring
  * matches subdomain (i.e. example.com will match iam.example.com)
  * matches exact
  * does not match substring (i.e. example.com will not match iamexample.com)
* Improved snapshot error logging
* Improved config telemetry
* Moved `lastEventTime` to its own cookie
  * `_hp5_let.<ENV_ID>`  - 13m expiration

### Fixed

* Fixed regression in v4 → v5 migration
* Prevents enqueuing on onReady queue while onReady queue is processing
* Added temporary AUP queue to ensure it gets executed after user is created

## \[5.2.6] - 2025-01-02

### Added

* Aborts Heap initialization if storage is not accessible (Likely due to browser settings)
* Support for enabling cookie compression via server side config

### Changed

* Updated telemetry endpoint to <https://heapanalytics.com> so no CSP update is required
* Updated timing of request triggers in Contentsquare integration
* Prevents requests from being sent in hidden tabs

### Fixed

* Creates new user and session if necessary when `heap.trackPageview()` is called

## \[5.2.5] - 2024-12-16

### Changed

* Updated retry logic to not automatically retry a 5xx
* Removed check for a blank Contentsquare tag and avoid waiting for metadata/initiating if necessary

### Added

* Implemented telemetry

### Fixed

* Fixed bug fix in 5.2.4

## \[5.2.4] - 2024-11-21

### Added

* Added fallback session time in v4 → v5 migration
* Added check for a blank Contentsquare tag and avoid waiting for metadata/initiating if necessary
* Added session info validation in track messages and remove from retry buffer if invalid

### Changed

* Skipped blocking transformer if Contentsquare has already been initialized
* Cleaned `info` level logs
* Added new session creation if session time is invalid

## \[5.2.3] - 2024-11-11

### Added

* Additional logging
* Error handling on shadowdom autocapture implementation

### Changed

* Blocked identify calls until metadata has been sent to network
* Update method to wait for metadata from Contentsquare in Contentsquare integration

### Fixed

* Execution time of `onReady` queue in Contentsquare integration
* Block event processing queue until metadata is queued in Contentsquare integration
* Bug fix in version reporting on `heap.getConfig().sdk` when self-hosting

## \[5.2.2] - 2024-10-30

### Added

* New config option `compressCookies` to enable cookie compression (disabled by default)

### Fixed

* Bug fix on `heap.identify` where identify request was not being sent if current identity matched passed identity

## \[5.2.1] - 2024-10-23

### Added

* `heap.identifyHashed`

### Fixed

* Bug fix on internal `setReferrer`
* Integration mismatch

### Changed

* Improved random ID generator

## \[5.2.0] - 2024-09-23

### Added

* User/session sync between mobile and webviews
* `queueCustomEvent` dependency for use in adapters

## \[5.1.4] - 2024-09-09

### Added

* Validation to network requests

### Fixed

* Bug fix on cross domain iFrames causing session spike

### Changed

* Move execution of `onReady` queue after metadata is stored

## \[5.1.3] - 2024-08-28

### Added

* `cs_crosswrites_heap` to `HeapTagStatus`
* Verify `userId` is available on `addUserProperties` calls

### Changed

* Lower time to flush buffer for INP
* Replace deprecated mutation events

### Fixed

* Bug fix on `heap.setLogLevel()`

## \[5.1.2] - 2024-08-12

### Fixed

* Lodash conflict
* Update rage click PointerEvent vs MouseEvent

### Added

* Capture `library_version` and `library_domain` on requests

## \[5.1.1] - 2024-07-29

### Fixed

* Missing `envId` when Heap is loaded twice

### Added

* Support Contentsquare as a client side source

## \[5.1.0] - 2024-07-12

### Added

* Handle session + pageview behavior when `identify` is called in Contentsquare tag
* Blocked heap driving logic on heap env on Contentsquare domain
* Set `content-type=application/javascript; charset=utf-8` in heap.js headers
* Added Contentsquare project id to hjs config

## \[5.0.0] - 2024-06-25

### Fixed

* Updated release version to `5.0.0`

## \[1.0.0] - 2024-06-18

### Fixed

* `cmd+click` not working as expected

### Added

* Increased retry logic to 7 days
* Updated integrations to use public `addPageviewProperties` API instead of internal