Skip to content

chore(deps): bump the vendor-minor-and-patch-dependencies group across 1 directory with 3 updates - #9571

Merged
BridgeAR merged 1 commit into
masterfrom
dependabot/npm_and_yarn/vendor/vendor-minor-and-patch-dependencies-37d7e6823c
Jul 29, 2026
Merged

chore(deps): bump the vendor-minor-and-patch-dependencies group across 1 directory with 3 updates#9571
BridgeAR merged 1 commit into
masterfrom
dependabot/npm_and_yarn/vendor/vendor-minor-and-patch-dependencies-37d7e6823c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the vendor-minor-and-patch-dependencies group with 3 updates in the /vendor directory: @apm-js-collab/code-transformer, pprof-format and source-map.

Updates @apm-js-collab/code-transformer from 0.18.0 to 0.18.1

Release notes

Sourced from @​apm-js-collab/code-transformer's releases.

code-transformer: v0.18.1

0.18.1 (2026-07-21)

Bug Fixes

  • Allow custom transforms to call default transforms (#99) (76b085b)
  • handle nameless blocks in class bodies (#94) (4e787e9)
  • make internally-invoked built-in transforms overridable (#97) (deec36a)
  • make the code transform idempotent per channel (#98) (7cdb9ca)
Changelog

Sourced from @​apm-js-collab/code-transformer's changelog.

0.18.1 (2026-07-21)

Bug Fixes

  • Allow custom transforms to call default transforms (#99) (76b085b)
  • handle nameless blocks in class bodies (#94) (4e787e9)
  • make internally-invoked built-in transforms overridable (#97) (deec36a)
  • make the code transform idempotent per channel (#98) (7cdb9ca)
Commits
  • f27f88a chore: release v0.18.1 (#96)
  • 7cdb9ca fix: make the code transform idempotent per channel (#98)
  • 76b085b fix: Allow custom transforms to call default transforms (#99)
  • deec36a fix: make internally-invoked built-in transforms overridable (#97)
  • 4e787e9 fix: handle nameless blocks in class bodies (#94)
  • See full diff in compare view

Updates pprof-format from 2.2.2 to 2.2.3

Commits
  • 4ff7513 v2.2.3
  • 47322f1 Bump the minor-updates group with 6 updates (#75)
  • 463f194 Bump @​eslint/eslintrc from 3.3.5 to 3.3.6 in the patch-updates group (#74)
  • 436fd0b perf: remove accidentally quadratic work (#77)
  • f8b2eb1 fix(deps): vuln js-yaml (minor → 4.3.0) (#72)
  • 1a195c9 Bump @​types/node from 25.9.3 to 26.0.0 (#70)
  • 7266a8d Bump the patch-updates group across 1 directory with 2 updates (#71)
  • ac58e1a Bump the minor-updates group with 3 updates (#67)
  • ffe09ba Bump the patch-updates group with 4 updates (#66)
  • See full diff in compare view

Updates source-map from 0.7.6 to 0.8.0

Changelog

Sourced from source-map's changelog.

0.8.0

Commits
Maintainer changes

This version was pushed to npm by hmanilla, a new releaser for source-map since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…s 1 directory with 3 updates

Bumps the vendor-minor-and-patch-dependencies group with 3 updates in the /vendor directory: [@apm-js-collab/code-transformer](https://github.com/nodejs/orchestrion-js), [pprof-format](https://github.com/DataDog/pprof-format) and [source-map](https://github.com/mozilla/source-map).


Updates `@apm-js-collab/code-transformer` from 0.18.0 to 0.18.1
- [Release notes](https://github.com/nodejs/orchestrion-js/releases)
- [Changelog](https://github.com/nodejs/orchestrion-js/blob/main/CHANGELOG.md)
- [Commits](nodejs/orchestrion-js@code-transformer-v0.18.0...code-transformer-v0.18.1)

Updates `pprof-format` from 2.2.2 to 2.2.3
- [Commits](DataDog/pprof-format@v2.2.2...v2.2.3)

Updates `source-map` from 0.7.6 to 0.8.0
- [Release notes](https://github.com/mozilla/source-map/releases)
- [Changelog](https://github.com/mozilla/source-map/blob/master/CHANGELOG.md)
- [Commits](mozilla/source-map@0.7.6...v0.8.0)

---
updated-dependencies:
- dependency-name: "@apm-js-collab/code-transformer"
  dependency-version: 0.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: pprof-format
  dependency-version: 2.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: source-map
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: vendor-minor-and-patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependabot dependencies javascript Pull requests that update javascript code semver-patch labels Jul 29, 2026
@dd-octo-sts

dd-octo-sts Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Overall package size

Self size: 7.52 MB
Deduped: 8.18 MB
No deduping: 8.18 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | import-in-the-middle | 3.3.2 | 124.41 kB | 440.65 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | dc-polyfill | 0.1.11 | 25.74 kB | 25.74 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Jul 29, 2026

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🔄 Datadog retried 1 test - 1 passed on retry View in Datadog

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: a2fcd8f | Docs | Datadog PR Page | Give us feedback!

@pr-commenter

pr-commenter Bot commented Jul 29, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-07-29 01:08:51

Comparing candidate commit a2fcd8f in PR branch dependabot/npm_and_yarn/vendor/vendor-minor-and-patch-dependencies-37d7e6823c with baseline commit a57a59d in branch master.

📊 Benchmarking dashboard

Found 0 performance improvements and 0 performance regressions! Performance is the same for 2321 metrics, 37 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:appsec-appsec-enabled-24

  • unstable execution_time [-214.600ms; +207.853ms] or [-8.061%; +7.808%]

scenario:appsec-appsec-enabled-26

  • unstable execution_time [-249.674ms; +251.970ms] or [-9.740%; +9.830%]

scenario:appsec-appsec-enabled-with-attacks-24

  • unstable execution_time [-164.759ms; +149.663ms] or [-5.334%; +4.846%]

scenario:appsec-appsec-enabled-with-attacks-26

  • unstable execution_time [-190.339ms; +200.647ms] or [-6.531%; +6.885%]

scenario:appsec-control-20

  • unstable execution_time [-137.400ms; +123.113ms] or [-8.318%; +7.453%]

scenario:appsec-control-24

  • unstable execution_time [-112754.568µs; +114682.434µs] or [-9.074%; +9.229%]

scenario:appsec-control-26

  • unstable execution_time [-128.756ms; +121.313ms] or [-10.355%; +9.757%]

scenario:appsec-iast-no-vulnerability-iast-enabled-always-active-20

  • unstable execution_time [-18.734ms; +22.888ms] or [-7.162%; +8.750%]

scenario:appsec-iast-no-vulnerability-iast-enabled-default-config-20

  • unstable execution_time [-12.053ms; +23.149ms] or [-4.659%; +8.948%]

scenario:appsec-iast-with-vulnerability-control-20

  • unstable execution_time [-29.956ms; +37.456ms] or [-5.411%; +6.765%]

scenario:debugger-line-probe-with-snapshot-default-24

  • unstable cpu_user_time [-3.564s; +0.012s] or [-37.649%; +0.122%]
  • unstable execution_time [-3.616s; +0.010s] or [-35.502%; +0.101%]
  • unstable instructions [-30.4G instructions; -0.1G instructions] or [-39.066%; -0.082%]
  • unstable throughput [-5.736op/s; +957.270op/s] or [-0.171%; +28.554%]

scenario:debugger-line-probe-with-snapshot-default-26

  • unstable cpu_user_time [-3696.359ms; +3691.051ms] or [-35.748%; +35.696%]
  • unstable execution_time [-3713.300ms; +3709.323ms] or [-33.606%; +33.570%]
  • unstable instructions [-32688.9M instructions; +32480.0M instructions] or [-37.736%; +37.495%]
  • unstable max_rss_usage [-11843.490KB; +11452.290KB] or [-7.318%; +7.076%]
  • unstable throughput [-728.987op/s; +719.981op/s] or [-23.648%; +23.356%]

scenario:debugger-line-probe-with-snapshot-minimal-26

  • unstable cpu_user_time [-3701.499ms; +3728.417ms] or [-35.940%; +36.202%]
  • unstable execution_time [-3724.509ms; +3733.727ms] or [-33.797%; +33.881%]
  • unstable instructions [-32744.5M instructions; +32627.6M instructions] or [-37.837%; +37.702%]
  • unstable max_rss_usage [-12925.127KB; +11375.527KB] or [-8.004%; +7.044%]
  • unstable throughput [-731.237op/s; +731.707op/s] or [-23.670%; +23.685%]

scenario:dogstatsd-with-tags-20

  • unstable cpu_user_time [-357.408ms; +151.061ms] or [-7.726%; +3.265%]
  • unstable execution_time [-360.917ms; +146.967ms] or [-7.673%; +3.125%]
  • unstable throughput [-53581.992op/s; +125423.162op/s] or [-3.009%; +7.042%]

scenario:plugin-claude-agent-sdk-compact-stream-scan-26

  • unstable cpu_usage_percentage [-4.680%; +5.829%]
  • unstable cpu_user_time [-2143.997µs; +4052.130µs] or [-3.554%; +6.716%]

scenario:plugin-couchbase-upsert-20

  • unstable cpu_user_time [-186.077ms; +301.810ms] or [-4.257%; +6.904%]
  • unstable execution_time [-190.656ms; +295.571ms] or [-4.351%; +6.745%]

scenario:plugin-graphql-long-with-depth-off-26

  • unstable max_rss_usage [-37.268MB; +18.869MB] or [-17.105%; +8.661%]

scenario:plugin-graphql-long-with-depth-on-max-20

  • unstable cpu_user_time [-609.125ms; +613.018ms] or [-5.266%; +5.300%]
  • unstable execution_time [-617.635ms; +627.376ms] or [-5.234%; +5.316%]
  • unstable throughput [-3.625op/s; +3.627op/s] or [-5.317%; +5.319%]

scenario:plugin-memcached-hashring-24

  • unstable execution_time [-193.761ms; +242.937ms] or [-7.538%; +9.451%]
  • unstable throughput [-1042406.059op/s; +780579.746op/s] or [-7.016%; +5.253%]

@BridgeAR
BridgeAR merged commit 397a758 into master Jul 29, 2026
666 checks passed
@BridgeAR
BridgeAR deleted the dependabot/npm_and_yarn/vendor/vendor-minor-and-patch-dependencies-37d7e6823c branch July 29, 2026 11:02
dd-octo-sts Bot pushed a commit that referenced this pull request Jul 30, 2026
…s 1 directory with 3 updates (#9571)

Bumps the vendor-minor-and-patch-dependencies group with 3 updates in the /vendor directory: [@apm-js-collab/code-transformer](https://github.com/nodejs/orchestrion-js), [pprof-format](https://github.com/DataDog/pprof-format) and [source-map](https://github.com/mozilla/source-map).


Updates `@apm-js-collab/code-transformer` from 0.18.0 to 0.18.1
- [Release notes](https://github.com/nodejs/orchestrion-js/releases)
- [Changelog](https://github.com/nodejs/orchestrion-js/blob/main/CHANGELOG.md)
- [Commits](nodejs/orchestrion-js@code-transformer-v0.18.0...code-transformer-v0.18.1)

Updates `pprof-format` from 2.2.2 to 2.2.3
- [Commits](DataDog/pprof-format@v2.2.2...v2.2.3)

Updates `source-map` from 0.7.6 to 0.8.0
- [Release notes](https://github.com/mozilla/source-map/releases)
- [Changelog](https://github.com/mozilla/source-map/blob/master/CHANGELOG.md)
- [Commits](mozilla/source-map@0.7.6...v0.8.0)

---
updated-dependencies:
- dependency-name: "@apm-js-collab/code-transformer"
  dependency-version: 0.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: pprof-format
  dependency-version: 2.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: source-map
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: vendor-minor-and-patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Jul 30, 2026
dd-octo-sts Bot pushed a commit that referenced this pull request Jul 30, 2026
…s 1 directory with 3 updates (#9571)

Bumps the vendor-minor-and-patch-dependencies group with 3 updates in the /vendor directory: [@apm-js-collab/code-transformer](https://github.com/nodejs/orchestrion-js), [pprof-format](https://github.com/DataDog/pprof-format) and [source-map](https://github.com/mozilla/source-map).


Updates `@apm-js-collab/code-transformer` from 0.18.0 to 0.18.1
- [Release notes](https://github.com/nodejs/orchestrion-js/releases)
- [Changelog](https://github.com/nodejs/orchestrion-js/blob/main/CHANGELOG.md)
- [Commits](nodejs/orchestrion-js@code-transformer-v0.18.0...code-transformer-v0.18.1)

Updates `pprof-format` from 2.2.2 to 2.2.3
- [Commits](DataDog/pprof-format@v2.2.2...v2.2.3)

Updates `source-map` from 0.7.6 to 0.8.0
- [Release notes](https://github.com/mozilla/source-map/releases)
- [Changelog](https://github.com/mozilla/source-map/blob/master/CHANGELOG.md)
- [Commits](mozilla/source-map@0.7.6...v0.8.0)

---
updated-dependencies:
- dependency-name: "@apm-js-collab/code-transformer"
  dependency-version: 0.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: pprof-format
  dependency-version: 2.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: source-map
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: vendor-minor-and-patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Jul 30, 2026
sabrenner pushed a commit that referenced this pull request Jul 30, 2026
…s 1 directory with 3 updates (#9571)

Bumps the vendor-minor-and-patch-dependencies group with 3 updates in the /vendor directory: [@apm-js-collab/code-transformer](https://github.com/nodejs/orchestrion-js), [pprof-format](https://github.com/DataDog/pprof-format) and [source-map](https://github.com/mozilla/source-map).


Updates `@apm-js-collab/code-transformer` from 0.18.0 to 0.18.1
- [Release notes](https://github.com/nodejs/orchestrion-js/releases)
- [Changelog](https://github.com/nodejs/orchestrion-js/blob/main/CHANGELOG.md)
- [Commits](nodejs/orchestrion-js@code-transformer-v0.18.0...code-transformer-v0.18.1)

Updates `pprof-format` from 2.2.2 to 2.2.3
- [Commits](DataDog/pprof-format@v2.2.2...v2.2.3)

Updates `source-map` from 0.7.6 to 0.8.0
- [Release notes](https://github.com/mozilla/source-map/releases)
- [Changelog](https://github.com/mozilla/source-map/blob/master/CHANGELOG.md)
- [Commits](mozilla/source-map@0.7.6...v0.8.0)

---
updated-dependencies:
- dependency-name: "@apm-js-collab/code-transformer"
  dependency-version: 0.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: pprof-format
  dependency-version: 2.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: source-map
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: vendor-minor-and-patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
sabrenner pushed a commit that referenced this pull request Jul 30, 2026
…s 1 directory with 3 updates (#9571)

Bumps the vendor-minor-and-patch-dependencies group with 3 updates in the /vendor directory: [@apm-js-collab/code-transformer](https://github.com/nodejs/orchestrion-js), [pprof-format](https://github.com/DataDog/pprof-format) and [source-map](https://github.com/mozilla/source-map).


Updates `@apm-js-collab/code-transformer` from 0.18.0 to 0.18.1
- [Release notes](https://github.com/nodejs/orchestrion-js/releases)
- [Changelog](https://github.com/nodejs/orchestrion-js/blob/main/CHANGELOG.md)
- [Commits](nodejs/orchestrion-js@code-transformer-v0.18.0...code-transformer-v0.18.1)

Updates `pprof-format` from 2.2.2 to 2.2.3
- [Commits](DataDog/pprof-format@v2.2.2...v2.2.3)

Updates `source-map` from 0.7.6 to 0.8.0
- [Release notes](https://github.com/mozilla/source-map/releases)
- [Changelog](https://github.com/mozilla/source-map/blob/master/CHANGELOG.md)
- [Commits](mozilla/source-map@0.7.6...v0.8.0)

---
updated-dependencies:
- dependency-name: "@apm-js-collab/code-transformer"
  dependency-version: 0.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: pprof-format
  dependency-version: 2.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vendor-minor-and-patch-dependencies
- dependency-name: source-map
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: vendor-minor-and-patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependabot dependencies javascript Pull requests that update javascript code semver-patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant