Skip to content

v5.108.0 proposal - #8896

Merged
sabrenner merged 10 commits into
v5.xfrom
v5.108.0-proposal
Jun 12, 2026
Merged

v5.108.0 proposal#8896
sabrenner merged 10 commits into
v5.xfrom
v5.108.0-proposal

Conversation

@dd-octo-sts

@dd-octo-sts dd-octo-sts Bot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor
  • [39f12e5144] - (SEMVER-PATCH) fix(profiling): handle minor mark-sweep GC events (Attila Szegedi) #8898
  • [5db7b04d61] - (SEMVER-MINOR) feat(profiling): add allocations profiling support (Ilyas Shabi) #8764
  • [467c0d9e49] - (SEMVER-PATCH) chore(benchmark): upgrade sirun to v0.1.12 and send ready signal (Roch Devost) #8842
  • [2a196b306e] - (SEMVER-PATCH) chore(deps): bump protobufjs from 8.4.2 to 8.6.0 in /vendor in the vendor-minor-and-patch-dependencies group across 1 directory (dependabot[bot]) #8851
  • [743306892d] - (SEMVER-PATCH) chore(deps): bump @anthropic-ai/sdk from 0.101.0 to 0.102.0 in /packages/dd-trace/test/plugins/versions in the ai-and-llm group across 1 directory (dependabot[bot]) #8852
  • [18e68a2f8a] - (SEMVER-PATCH) chore(deps-dev): bump the dev-minor-and-patch-dependencies group across 1 directory with 4 updates (dependabot[bot]) #8854
  • [dc0c7f13ed] - (SEMVER-PATCH) ci: add --auto-discovery flag to datadog-ci junit upload (Roch Devost) #8866
  • [ef87455420] - (SEMVER-PATCH) fix(appsec): improve appsec perf on object length (Ilyas Shabi) #8859
  • [bf6fa2bdcf] - (SEMVER-PATCH) test(cypress): rebalance parallel suites with v5 support (Juan Antonio Fernández de Alba) #8871

juan-fernandez and others added 8 commits June 12, 2026 06:32
* fix(appsec): improve appsec perf on object length
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…ss 1 directory with 4 updates (#8854)

* chore(deps-dev): bump the dev-minor-and-patch-dependencies group across 1 directory with 4 updates

Bumps the dev-minor-and-patch-dependencies group with 4 updates in the / directory: [axios](https://github.com/axios/axios), [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc), [graphql](https://github.com/graphql/graphql-js) and [semver](https://github.com/npm/node-semver).


Updates `axios` from 1.16.1 to 1.17.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.16.1...v1.17.0)

Updates `eslint-plugin-jsdoc` from 63.0.0 to 63.0.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](gajus/eslint-plugin-jsdoc@v63.0.0...v63.0.1)

Updates `graphql` from 16.14.0 to 16.14.1
- [Release notes](https://github.com/graphql/graphql-js/releases)
- [Commits](graphql/graphql-js@v16.14.0...v16.14.1)

Updates `semver` from 7.8.1 to 7.8.2
- [Release notes](https://github.com/npm/node-semver/releases)
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md)
- [Commits](npm/node-semver@v7.8.1...v7.8.2)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.17.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor-and-patch-dependencies
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 63.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor-and-patch-dependencies
- dependency-name: graphql
  dependency-version: 16.14.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor-and-patch-dependencies
- dependency-name: semver
  dependency-version: 7.8.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor-and-patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: deduplicate yarn.lock

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts[bot] <200755185+dd-octo-sts[bot]@users.noreply.github.com>
…ges/dd-trace/test/plugins/versions in the ai-and-llm group across 1 directory (#8852)

Bumps the ai-and-llm group with 1 update in the /packages/dd-trace/test/plugins/versions directory: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript).


Updates `@anthropic-ai/sdk` from 0.101.0 to 0.102.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.101.0...sdk-v0.102.0)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.102.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ai-and-llm
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ndor-minor-and-patch-dependencies group across 1 directory (#8851)

Bumps the vendor-minor-and-patch-dependencies group with 1 update in the /vendor directory: [protobufjs](https://github.com/protobufjs/protobuf.js).


Updates `protobufjs` from 8.4.2 to 8.6.0
- [Release notes](https://github.com/protobufjs/protobuf.js/releases)
- [Changelog](https://github.com/protobufjs/protobuf.js/blob/master/CHANGELOG.md)
- [Commits](protobufjs/protobuf.js@protobufjs-v8.4.2...protobufjs-v8.6.0)

---
updated-dependencies:
- dependency-name: protobufjs
  dependency-version: 8.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: vendor-minor-and-patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upgrades sirun from v0.1.11 to v0.1.12, which introduces SIRUN_READY_FD
to exclude startup time from measurements. Updates loopStart() to write
the ready signal to that fd, so sirun resets its timing metrics at the
exact point the measured loop begins.
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Jun 12, 2026
@dd-octo-sts

dd-octo-sts Bot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor Author

Overall package size

Self size: 6.2 MB
Deduped: 7.25 MB
No deduping: 7.25 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | import-in-the-middle | 3.0.2 | 85.93 kB | 825.11 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | dc-polyfill | 0.1.11 | 25.74 kB | 25.74 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@codecov

codecov Bot commented Jun 12, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 33.33333% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 36.83%. Comparing base (6b35e7d) to head (24829c1).
⚠️ Report is 1534 commits behind head on v5.x.

Files with missing lines Patch % Lines
...ackages/dd-trace/src/appsec/downstream_requests.js 33.33% 2 Missing ⚠️
packages/dd-trace/src/appsec/rasp/ssrf.js 50.00% 1 Missing ⚠️
packages/dd-trace/src/appsec/reporter.js 0.00% 1 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff             @@
##             v5.x    #8896       +/-   ##
===========================================
- Coverage   83.19%   36.83%   -46.36%     
===========================================
  Files         476      457       -19     
  Lines       20153    30308    +10155     
  Branches        0     3657     +3657     
===========================================
- Hits        16766    11164     -5602     
- Misses       3387    19144    +15757     
Flag Coverage Δ
aiguard-macos 33.15% <0.00%> (?)
apm-integrations-next-11.1.4 35.74% <ø> (?)
apm-integrations-next-12.3.7 35.74% <ø> (?)
apm-integrations-sharedb 32.22% <0.00%> (?)
appsec-next-latest-12.3.7 27.14% <ø> (?)
instrumentations-instrumentation-couchbase-18 44.83% <ø> (?)
instrumentations-instrumentation-crypto 27.33% <0.00%> (?)
instrumentations-instrumentation-express-multi-version 40.49% <ø> (?)
instrumentations-instrumentation-fetch 43.73% <ø> (?)
instrumentations-instrumentation-fs 26.98% <0.00%> (?)
instrumentations-instrumentation-hono 28.51% <0.00%> (?)
instrumentations-instrumentation-http-client-options 37.40% <0.00%> (?)
instrumentations-instrumentation-kafkajs 47.88% <ø> (?)
instrumentations-instrumentation-multer 35.13% <0.00%> (?)
instrumentations-instrumentation-otel-sdk-trace 24.96% <ø> (?)
instrumentations-instrumentation-passport-http 38.71% <33.33%> (?)
instrumentations-instrumentation-promise 27.23% <0.00%> (?)
instrumentations-instrumentation-q 27.26% <0.00%> (?)
instrumentations-instrumentation-url 27.16% <0.00%> (?)
instrumentations-instrumentation-when 27.24% <0.00%> (?)
instrumentations-instrumentation-zlib 27.21% <0.00%> (?)
openfeature-macos 37.28% <0.00%> (?)
openfeature-unit-active 49.49% <ø> (?)
openfeature-unit-latest 49.49% <ø> (?)
openfeature-unit-maintenance 49.85% <ø> (?)
openfeature-unit-oldest 49.85% <ø> (?)
platform-core 44.95% <ø> (?)
platform-esbuild 45.64% <ø> (?)
platform-shimmer 46.17% <ø> (?)
platform-unit-guardrails 40.01% <ø> (?)
platform-webpack 17.86% <ø> (?)
plugins-dd-trace-api 33.06% <0.00%> (?)
plugins-langgraph 32.08% <0.00%> (?)
plugins-test-and-upstream-avsc 33.46% <0.00%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Jun 12, 2026

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 24829c1 | Docs | Datadog PR Page | Give us feedback!

@pr-commenter

pr-commenter Bot commented Jun 12, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-06-12 10:23:35

Comparing candidate commit 24829c1 in PR branch v5.108.0-proposal with baseline commit f7ac7ea in branch v5.x.

📊 Benchmarking dashboard

Found 0 performance improvements and 0 performance regressions! Performance is the same for 1449 metrics, 18 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:debugger-line-probe-with-snapshot-default-20

  • unstable max_rss_usage [-6.924MB; +18.666MB] or [-3.671%; +9.896%]

scenario:debugger-line-probe-with-snapshot-default-26

  • unstable max_rss_usage [-10.525MB; +16.566MB] or [-3.998%; +6.294%]

scenario:log-skip-log-24

  • unstable cpu_user_time [-2782.520µs; +2212.720µs] or [-5.896%; +4.688%]

scenario:log-without-log-24

  • unstable cpu_user_time [-3007.161µs; +2310.161µs] or [-6.570%; +5.047%]

scenario:log-without-log-26

  • unstable cpu_user_time [-3198.918µs; +2749.018µs] or [-7.119%; +6.118%]

scenario:plugin-graphql-long-with-depth-and-collapse-off-24

  • unstable cpu_user_time [-279.726ms; +358.676ms] or [-6.556%; +8.406%]
  • unstable execution_time [-297.439ms; +374.892ms] or [-6.556%; +8.264%]
  • unstable max_rss_usage [-31.736MB; +39.006MB] or [-6.165%; +7.577%]

scenario:plugin-graphql-long-with-depth-off-20

  • unstable max_rss_usage [-15.881MB; +3.429MB] or [-11.387%; +2.459%]

scenario:spans-finish-later-20

  • unstable cpu_user_time [-369.620ms; +271.877ms] or [-7.496%; +5.514%]
  • unstable execution_time [-540.224ms; +394.172ms] or [-9.722%; +7.094%]

scenario:spans-finish-later-24

  • unstable cpu_user_time [-496.160ms; +769.071ms] or [-22.310%; +34.582%]
  • unstable execution_time [-507.434ms; +785.828ms] or [-21.565%; +33.396%]
  • unstable instructions [-862.4M instructions; +1390.8M instructions] or [-5.816%; +9.380%]
  • unstable max_rss_usage [-33462.659KB; +32045.993KB] or [-10.452%; +10.009%]

scenario:spans-finish-later-26

  • unstable cpu_user_time [-243.116ms; +160.282ms] or [-12.984%; +8.560%]
  • unstable execution_time [-246.014ms; +172.644ms] or [-12.663%; +8.886%]
  • unstable max_rss_usage [-13.107MB; +26.032MB] or [-6.425%; +12.761%]

szegedi added 2 commits June 12, 2026 10:09
V8's young-generation collector emits GC performance events with kind 2,
but Node.js does not expose a matching NODE_PERFORMANCE_GC_* constant for
it. The events profiler's GCDecorator built its kind label table solely
from those constants, so kindLabels[2] was undefined and got pushed into
the pprof Sample labels, crashing the process on the first GC under
V8's --minor-ms flag with "TypeError: Cannot read properties of
undefined (reading 'key')".

Map kind 2 explicitly, mirroring runtime_metrics.js: the collector was
renamed from Minor Mark-Compact to Minor Mark-Sweep in the V8 version
that shipped with Node 22, so the label is version-dependent
(minor_mark_sweep on Node >= 22, minor_mark_compact otherwise). Also
fall back to an 'unknown_<kind>' label for any future GC kind we don't
recognize so a missing constant can never crash the application again.

Closes #8839
@dd-octo-sts
dd-octo-sts Bot force-pushed the v5.108.0-proposal branch from 600d0c4 to 24829c1 Compare June 12, 2026 10:10
@szegedi
szegedi marked this pull request as ready for review June 12, 2026 14:14
@szegedi
szegedi requested review from a team as code owners June 12, 2026 14:14
@szegedi
szegedi requested review from crysmags and khanayan123 and removed request for a team June 12, 2026 14:14
@sabrenner
sabrenner merged commit 5286e9a into v5.x Jun 12, 2026
800 checks passed
@sabrenner
sabrenner deleted the v5.108.0-proposal branch June 12, 2026 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants