Skip to content

chore(licenses): read dependencies directly from lockfiles - #9540

Merged
BridgeAR merged 1 commit into
masterfrom
BridgeAR/2026-07-27-speed-license-check
Jul 27, 2026
Merged

chore(licenses): read dependencies directly from lockfiles#9540
BridgeAR merged 1 commit into
masterfrom
BridgeAR/2026-07-27-speed-license-check

Conversation

@BridgeAR

Copy link
Copy Markdown
Member

Summary

Spawning Yarn and npm made every license check build dependency trees in separate processes. This reads Yarn, npm, and Bun lockfiles directly and follows their production dependency graphs. On the repository lockfiles, mean end-to-end time dropped from 285.8 ms to 32.1 ms.

Spawning Yarn and npm makes the license check pay their startup and dependency-tree construction costs on every lint run. Reading Yarn, npm, and Bun lockfiles directly reduced the representative end-to-end check from 285.8 ms to 32.1 ms.
@dd-octo-sts

dd-octo-sts Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Overall package size

Self size: 7.46 MB
Deduped: 8.12 MB
No deduping: 8.12 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | import-in-the-middle | 3.3.2 | 124.41 kB | 440.65 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | dc-polyfill | 0.1.11 | 25.74 kB | 25.74 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Jul 27, 2026

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 98.43% (+0.00%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 0e4eee8 | Docs | Datadog PR Page | Give us feedback!

@codecov

codecov Bot commented Jul 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.43%. Comparing base (1def946) to head (0e4eee8).
⚠️ Report is 4 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff            @@
##           master    #9540    +/-   ##
========================================
  Coverage   98.43%   98.43%            
========================================
  Files         947      947            
  Lines      128152   128152            
  Branches    10912    11142   +230     
========================================
  Hits       126142   126142            
  Misses       2010     2010            
Flag Coverage Δ
aiguard 57.48% <ø> (-0.03%) ⬇️
aiguard-integration 56.30% <ø> (ø)
apm-bucket-0 57.73% <ø> (-0.03%) ⬇️
apm-bucket-1 64.01% <ø> (-0.03%) ⬇️
apm-bucket-2 62.78% <ø> (-0.03%) ⬇️
apm-bucket-3 60.23% <ø> (-0.03%) ⬇️
apm-capabilities-tracing 62.67% <ø> (ø)
apm-integrations-aerospike 56.82% <ø> (-0.03%) ⬇️
apm-integrations-confluentinc-kafka-javascript 61.66% <ø> (-0.03%) ⬇️
apm-integrations-couchbase 57.17% <ø> (-0.03%) ⬇️
apm-integrations-http 62.79% <ø> (-0.03%) ⬇️
apm-integrations-kafkajs 62.27% <ø> (-0.03%) ⬇️
apm-integrations-next 59.26% <ø> (-0.03%) ⬇️
apm-integrations-prisma 58.75% <ø> (-0.03%) ⬇️
appsec 72.95% <ø> (-0.02%) ⬇️
appsec-express_fastify_graphql 70.41% <ø> (-0.02%) ⬇️
appsec-integration 51.50% <ø> (ø)
appsec-kafka_ldapjs_lodash 64.00% <ø> (-0.02%) ⬇️
appsec-mongodb-core_mongoose_mysql 67.71% <ø> (-0.02%) ⬇️
appsec-next 57.60% <ø> (-0.02%) ⬇️
appsec-node-serialize_passport_postgres 67.39% <ø> (-0.02%) ⬇️
appsec-sourcing_stripe_template 65.73% <ø> (-0.02%) ⬇️
debugger 64.91% <ø> (-0.03%) ⬇️
instrumentations-bucket-0 51.83% <ø> (-0.03%) ⬇️
instrumentations-bucket-1 60.31% <ø> (-0.03%) ⬇️
instrumentations-bucket-10 62.12% <ø> (-0.03%) ⬇️
instrumentations-bucket-11 51.74% <ø> (-0.03%) ⬇️
instrumentations-bucket-12 52.31% <ø> (-0.03%) ⬇️
instrumentations-bucket-13 51.86% <ø> (-0.03%) ⬇️
instrumentations-bucket-2 53.74% <ø> (-0.03%) ⬇️
instrumentations-bucket-3 59.32% <ø> (-0.03%) ⬇️
instrumentations-bucket-4 52.40% <ø> (-0.03%) ⬇️
instrumentations-bucket-5 57.64% <ø> (-0.03%) ⬇️
instrumentations-bucket-6 60.84% <ø> (-0.03%) ⬇️
instrumentations-bucket-7 58.51% <ø> (-0.03%) ⬇️
instrumentations-bucket-8 59.65% <ø> (-0.03%) ⬇️
instrumentations-bucket-9 61.64% <ø> (-0.03%) ⬇️
instrumentations-instrumentation-couchbase 51.14% <ø> (-0.03%) ⬇️
instrumentations-integration-esbuild 34.27% <ø> (ø)
llmobs-ai_anthropic_bedrock 62.96% <ø> (-0.02%) ⬇️
llmobs-bucket-1 61.70% <ø> (-0.02%) ⬇️
llmobs-openai 62.43% <ø> (-0.03%) ⬇️
llmobs-openai-agents_vertex-ai 59.79% <ø> (-0.03%) ⬇️
llmobs-sdk 65.59% <ø> (-0.03%) ⬇️
master-coverage 98.43% <ø> (?)
openfeature 56.18% <ø> (ø)
openfeature-unit 53.48% <ø> (-0.03%) ⬇️
platform-core_esbuild_instrumentations-misc 40.63% <ø> (-0.02%) ⬇️
platform-integration 61.49% <ø> (ø)
platform-shimmer_unit-guardrails_webpack 39.26% <ø> (-0.02%) ⬇️
plugins-bucket-0 57.14% <ø> (-0.03%) ⬇️
plugins-bucket-1 54.44% <ø> (ø)
plugins-bucket-11 62.35% <ø> (-0.03%) ⬇️
plugins-bucket-18 62.06% <ø> (-0.03%) ⬇️
plugins-bucket-19 60.14% <ø> (-0.03%) ⬇️
plugins-bucket-20 62.15% <ø> (-0.03%) ⬇️
plugins-bucket-4 58.67% <ø> (-0.03%) ⬇️
plugins-bullmq_cassandra_cookie 61.84% <ø> (-0.03%) ⬇️
plugins-cookie-parser_crypto_dd-trace-api 56.83% <ø> (-0.03%) ⬇️
plugins-fetch_fs_generic-pool 58.87% <ø> (-0.03%) ⬇️
plugins-google-cloud-pubsub_grpc_handlebars 64.77% <ø> (-0.03%) ⬇️
plugins-hapi_hono_ioredis 60.32% <ø> (-0.03%) ⬇️
plugins-jest_knex_langgraph 55.70% <ø> (-0.03%) ⬇️
plugins-ldapjs_light-my-request_limitd-client 58.60% <ø> (-0.02%) ⬇️
plugins-lodash_mariadb_memcached 58.19% <ø> (-0.03%) ⬇️
plugins-moleculer_mongodb_mongodb-core 62.00% <ø> (-0.03%) ⬇️
plugins-mongoose_multer_mysql 59.18% <ø> (-0.03%) ⬇️
plugins-mysql2_nats_node-serialize 60.81% <ø> (-0.03%) ⬇️
plugins-opensearch_passport-http_pino 59.64% <ø> (-0.03%) ⬇️
plugins-postgres_process_pug 58.38% <ø> (-0.03%) ⬇️
plugins-redis_router_sequelize 62.19% <ø> (-0.03%) ⬇️
plugins-test-and-upstream-rhea_undici_url 61.72% <ø> (-0.03%) ⬇️
plugins-valkey_vm_winston 58.07% <ø> (-0.07%) ⬇️
plugins-ws 59.69% <ø> (-0.03%) ⬇️
profiling 62.23% <ø> (-0.03%) ⬇️
serverless-aws-sdk-aws-sdk 55.15% <ø> (-0.02%) ⬇️
serverless-aws-sdk-bedrockruntime 54.86% <ø> (-0.03%) ⬇️
serverless-aws-sdk-client 56.53% <ø> (-0.03%) ⬇️
serverless-aws-sdk-dynamodb 55.76% <ø> (-0.04%) ⬇️
serverless-aws-sdk-eventbridge 49.48% <ø> (-0.03%) ⬇️
serverless-aws-sdk-kinesis 59.43% <ø> (-0.03%) ⬇️
serverless-aws-sdk-lambda 57.51% <ø> (-0.03%) ⬇️
serverless-aws-sdk-s3 55.86% <ø> (-0.03%) ⬇️
serverless-aws-sdk-serverless-peer-service 59.84% <ø> (-0.03%) ⬇️
serverless-aws-sdk-sns 60.29% <ø> (-0.03%) ⬇️
serverless-aws-sdk-sqs 60.71% <ø> (-0.06%) ⬇️
serverless-aws-sdk-stepfunctions 55.69% <ø> (-0.03%) ⬇️
serverless-aws-sdk-util 51.59% <ø> (-0.03%) ⬇️
serverless-bucket-0 54.34% <ø> (ø)
serverless-bucket-1 59.35% <ø> (-0.03%) ⬇️
test-optimization-cucumber 71.98% <ø> (-0.05%) ⬇️
test-optimization-cypress 65.91% <ø> (+0.12%) ⬆️
test-optimization-jest 73.28% <ø> (-0.06%) ⬇️
test-optimization-mocha 73.53% <ø> (+0.03%) ⬆️
test-optimization-playwright-playwright-atr 60.46% <ø> (-0.02%) ⬇️
test-optimization-playwright-playwright-efd 60.64% <ø> (-0.02%) ⬇️
test-optimization-playwright-playwright-final-status 60.61% <ø> (-0.02%) ⬇️
test-optimization-playwright-playwright-impacted-tests 60.34% <ø> (+0.14%) ⬆️
test-optimization-playwright-playwright-reporting 61.64% <ø> (-0.13%) ⬇️
test-optimization-playwright-playwright-test-management 61.15% <ø> (-0.12%) ⬇️
test-optimization-playwright-playwright-test-span 60.56% <ø> (-0.01%) ⬇️
test-optimization-selenium 60.12% <ø> (-0.10%) ⬇️
test-optimization-testopt 58.56% <ø> (+0.08%) ⬆️
test-optimization-vitest 70.32% <ø> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pr-commenter

pr-commenter Bot commented Jul 27, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-07-27 14:41:47

Comparing candidate commit 0e4eee8 in PR branch BridgeAR/2026-07-27-speed-license-check with baseline commit 1def946 in branch master.

📊 Benchmarking dashboard

Found 0 performance improvements and 0 performance regressions! Performance is the same for 2325 metrics, 33 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:appsec-appsec-enabled-24

  • unstable execution_time [-209325.337µs; +208978.171µs] or [-7.887%; +7.873%]

scenario:appsec-appsec-enabled-26

  • unstable execution_time [-240.462ms; +178.512ms] or [-9.527%; +7.073%]

scenario:appsec-appsec-enabled-with-attacks-24

  • unstable execution_time [-168.292ms; +163.908ms] or [-5.363%; +5.223%]

scenario:appsec-appsec-enabled-with-attacks-26

  • unstable execution_time [-189.246ms; +195.699ms] or [-6.412%; +6.631%]

scenario:appsec-control-20

  • unstable execution_time [-126.406ms; +133.434ms] or [-7.728%; +8.158%]

scenario:appsec-control-24

  • unstable execution_time [-112825.414µs; +113913.447µs] or [-9.059%; +9.146%]

scenario:appsec-control-26

  • unstable execution_time [-122.959ms; +126.411ms] or [-9.915%; +10.193%]

scenario:appsec-iast-no-vulnerability-control-20

  • unstable execution_time [-14.054ms; +19.027ms] or [-5.468%; +7.403%]

scenario:appsec-iast-no-vulnerability-iast-enabled-default-config-20

  • unstable execution_time [-17.913ms; +13.187ms] or [-6.966%; +5.128%]

scenario:child_process-shell-string-24

  • unstable execution_time [-15.295ms; +22.524ms] or [-4.665%; +6.869%]
  • unstable throughput [-212763.826op/s; +146895.100op/s] or [-5.924%; +4.090%]

scenario:debugger-line-probe-with-snapshot-minimal-24

  • unstable cpu_user_time [-1980.641ms; +3181.706ms] or [-23.912%; +38.412%]
  • unstable execution_time [-1979.257ms; +3214.295ms] or [-21.992%; +35.714%]
  • unstable instructions [-17.1G instructions; +27.3G instructions] or [-25.233%; +40.320%]
  • unstable max_rss_usage [-8.243MB; +13.318MB] or [-5.241%; +8.467%]
  • unstable throughput [-857.225op/s; +520.397op/s] or [-23.419%; +14.217%]

scenario:dogstatsd-aggregated-20

  • unstable cpu_usage_percentage [-6.973%; +4.952%]
  • unstable execution_time [-86.952ms; +136.709ms] or [-6.728%; +10.578%]
  • unstable throughput [-866366.285op/s; +548245.756op/s] or [-7.378%; +4.669%]

scenario:dogstatsd-with-tags-20

  • unstable cpu_user_time [-188.287ms; +427.332ms] or [-3.893%; +8.836%]
  • unstable execution_time [-197.845ms; +420.315ms] or [-4.028%; +8.558%]
  • unstable throughput [-148452.079op/s; +68234.433op/s] or [-8.693%; +3.996%]

scenario:plugin-graphql-long-with-depth-and-collapse-off-20

  • unstable max_rss_usage [-22702.361KB; +21524.361KB] or [-5.779%; +5.479%]

scenario:plugin-graphql-long-with-depth-off-20

  • unstable max_rss_usage [-6569.954KB; +7051.669KB] or [-5.124%; +5.500%]

scenario:plugin-graphql-long-with-depth-off-26

  • unstable max_rss_usage [-25.688MB; +34.794MB] or [-12.646%; +17.128%]

scenario:plugin-graphql-long-with-depth-on-max-20

  • unstable cpu_user_time [-582.559ms; +607.744ms] or [-5.007%; +5.224%]
  • unstable execution_time [-596.501ms; +624.762ms] or [-5.016%; +5.254%]
  • unstable throughput [-3.566op/s; +3.396op/s] or [-5.269%; +5.018%]

scenario:plugin-pg-service-20

  • unstable cpu_usage_percentage [-6.305%; +3.898%]
  • unstable execution_time [-87.759ms; +132.945ms] or [-5.407%; +8.191%]
  • unstable throughput [-234256.880op/s; +158770.253op/s] or [-6.285%; +4.260%]

scenario:plugin-pino-json-log-injection-24

  • unstable execution_time [-113.634ms; +186.339ms] or [-3.947%; +6.472%]

scenario:test-optimization-large-suite-20

  • unstable max_rss_usage [-5.480MB; +3.176MB] or [-6.835%; +3.962%]

@BridgeAR
BridgeAR marked this pull request as ready for review July 27, 2026 15:16
@BridgeAR
BridgeAR requested a review from a team as a code owner July 27, 2026 15:16

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0e4eee8c6f

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread scripts/check_licenses.js
deps.add(name)

collectDependencies(deps, dependency)
dependencies.add(dependency.name ?? getNameFromPackagePath(packagePath))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Handle valid unnamed npm link targets

When vendor/package.json contains a file: or workspace dependency, npm generates a valid v3 lockfile with a linked node_modules/dep entry and a separate target entry such as dep that may have no name. The link entry is skipped above, but this target reaches getNameFromPackagePath('dep') and crashes the license check instead of processing the dependency tree. This shape is expected because npm includes link targets separately in the lockfile, as documented in the npm package-lock packages specification, so target entries need to be recognized rather than rejected.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can keep this risk for now. It is not something we need to support until we want to include such dependency

@BridgeAR
BridgeAR requested a review from rochdev July 27, 2026 23:15
@BridgeAR
BridgeAR merged commit 1751a8e into master Jul 27, 2026
836 of 839 checks passed
@BridgeAR
BridgeAR deleted the BridgeAR/2026-07-27-speed-license-check branch July 27, 2026 23:21
This was referenced Jul 28, 2026
sabrenner pushed a commit that referenced this pull request Jul 30, 2026
Spawning Yarn and npm makes the license check pay their startup and dependency-tree construction costs on every lint run. Reading Yarn, npm, and Bun lockfiles directly reduced the representative end-to-end check from 285.8 ms to 32.1 ms.
sabrenner pushed a commit that referenced this pull request Jul 30, 2026
Spawning Yarn and npm makes the license check pay their startup and dependency-tree construction costs on every lint run. Reading Yarn, npm, and Bun lockfiles directly reduced the representative end-to-end check from 285.8 ms to 32.1 ms.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants