Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
95 commits
Select commit Hold shift + click to select a range
576bb0e
ci: move root install paths off yarn to bun
BridgeAR May 9, 2026
7012e25
ci: replace yarn services chain with bun isolated install
BridgeAR May 9, 2026
ff78048
ci: drop yarn run from workflows and the license check
BridgeAR May 9, 2026
19590cc
ci(docs): build TypeDoc docs with bun
BridgeAR May 9, 2026
e210e3b
chore: remove dead yarn machinery and guard the migration
BridgeAR May 9, 2026
cc9d4ef
fix(ci): skip lifecycle scripts in package-size-report bun install
BridgeAR May 9, 2026
58177e4
fix(test): switch versions/ workspace to bun's hoisted linker
BridgeAR May 9, 2026
2105e17
fix(test): restore moleculer bluebird transitive
BridgeAR May 9, 2026
c7b4031
fix(test): revert versions/ workspace to bun's isolated linker
BridgeAR May 9, 2026
ab11322
fix(test): inject @grpc/grpc-js into pubsub sandboxes
BridgeAR May 9, 2026
1d1472a
fix(langchain): pin @langchain/openai at the versions/ workspace root
BridgeAR May 9, 2026
31d77c1
fix(test): drop yarn references from new plugin-fix comments
BridgeAR May 9, 2026
1808849
fix(test): adapt versions/ sandboxes to bun isolated linker
BridgeAR May 10, 2026
c50d558
ci(licenses): skip dd-license-attribution regen on bun.lock
BridgeAR May 10, 2026
f48a206
fix(test): rebuild versions/ native bindings on Node ABI change
BridgeAR May 10, 2026
3e07ce0
ci(licenses): drop yarn references from skip-comment
BridgeAR May 10, 2026
935d02f
fix(test): drop yarn from Node-ABI cache-bust comment
BridgeAR May 10, 2026
d6e3464
fix(test): match yarn classic resolution under bun isolated linker
BridgeAR May 10, 2026
834ed1e
ci(bench): install bun for the GitLab microbenchmarks
BridgeAR May 10, 2026
77c53e7
chore(codeowners): own the install-smoke workflow
BridgeAR May 10, 2026
a212248
ci(licenses): regenerate the CSV from bun.lock and auto-commit via oc…
BridgeAR May 10, 2026
71f14b6
ci(install-smoke): push results to Test Optimization via dd-sts
BridgeAR May 10, 2026
11129ee
fix(test): only prune ambiguous bun central symlinks
BridgeAR May 10, 2026
eb5093a
fix(test): override collections to 5.x for q@2.0.0
BridgeAR May 10, 2026
59106b1
fix(licenses): strip name fields without regex on untrusted input
BridgeAR May 10, 2026
51ec958
fix(test): inject google-auth-library into vertex-ai sandboxes
BridgeAR May 10, 2026
750a511
ci(bench): install unzip before bun-curl on the GitLab runner
BridgeAR May 10, 2026
0ab8a44
chore(codeowners): own the docs/ TypeDoc workspace
BridgeAR May 10, 2026
6b41f41
fix(test): pin the langchain-openai floor for its core transitive
BridgeAR May 10, 2026
c859c2d
fix(test): inject zod into the ai sandbox
BridgeAR May 24, 2026
e721e77
ci: fix workflow regressions surfaced by the yarn-to-bun rebase
BridgeAR May 25, 2026
36abfd5
build(deps): regenerate bun.lock after the devDependency bumps
BridgeAR May 25, 2026
47a7038
fix(test): scope sandbox dependencies for bun's isolated linker
BridgeAR May 25, 2026
3432aee
test(scripts): resolve bun via PATH lookup in the sandbox-install guard
BridgeAR May 25, 2026
120467b
fix(test): pass --ignore-engines to yarn in sandbox specs
BridgeAR May 25, 2026
2e71a0a
ci(platform): bound the consumer-install step with a retry
BridgeAR May 25, 2026
32a4e8f
test(iast): drop vestigial yarn re-install in sourcemap sandbox
BridgeAR May 25, 2026
7ddc613
ci(install): commit versions/bunfig.toml so the isolated linker is st…
BridgeAR May 25, 2026
7c017c6
ci(datadog-ci): pin the action's npm install with a lockfile
BridgeAR May 25, 2026
41bde84
chore(security): cool down npm installs and freeze the dev lockfile
BridgeAR May 25, 2026
e2998aa
ci: finish yarn-to-bun rebase conflict cleanup
BridgeAR Jul 13, 2026
85bae08
ci(install): fix remaining bun migration failures
BridgeAR Jul 13, 2026
139dd9a
ci(install): handle legacy locks and incomplete registry metadata
BridgeAR Jul 13, 2026
41d8907
ci(install): normalize legacy GitHub shorthand
BridgeAR Jul 13, 2026
15cd7bd
bench: preserve baseline package manager in comparisons
BridgeAR Jul 13, 2026
81101ee
build(deps): sync bun lock with master
BridgeAR Jul 14, 2026
7c2428f
chore(codeowners): own versions bun config
BridgeAR Jul 14, 2026
14f92a9
build(docs): sync bun lock with master
BridgeAR Jul 15, 2026
29c3f9a
ci(install): cache plugin sandbox metadata
BridgeAR Jul 15, 2026
44640da
ci(install): close bun migration hardening gaps
BridgeAR Jul 15, 2026
e9acb5f
chore(licenses): merge attribution across locked versions
BridgeAR Jul 15, 2026
42aa8e1
ci(install): tighten migration metadata checks
BridgeAR Jul 15, 2026
fb6c050
ci(install): handle release-age races in sandboxes
BridgeAR Jul 15, 2026
c96bcc2
test(install): cover plugin workspace failure paths
BridgeAR Jul 15, 2026
d211829
ci(lint): stabilize Actions import classification
BridgeAR Jul 16, 2026
a2e9dc6
test(install): scope sandbox policy to each plugin
BridgeAR Jul 16, 2026
aaa2bb9
test(install): preserve highest bun workspace versions
BridgeAR Jul 16, 2026
405ba98
test(knex): make sqlite build dependency direct
BridgeAR Jul 16, 2026
9f86000
ci(install): freeze all Bun-managed dependency trees
BridgeAR Jul 17, 2026
f1dfd3f
fix(install): silence Bun prepare output
BridgeAR Jul 17, 2026
5f13e3e
ci(install): harden Bun artifact packaging
BridgeAR Jul 20, 2026
8bd25f5
test(install): allow Yarn validation fixtures
BridgeAR Jul 20, 2026
56f3379
ci(install): bootstrap Bun inside source archives
BridgeAR Jul 20, 2026
81440d4
ci(coverage): isolate patched Bun dependencies
BridgeAR Jul 20, 2026
6c6610c
test(install): cover Bun bootstrap branches
BridgeAR Jul 20, 2026
56d1523
test(install): isolate Bun bootstrap PATH fixtures
BridgeAR Jul 21, 2026
6e2140c
ci(dependencies): refresh vulnerable Bun lock entries
BridgeAR Jul 21, 2026
9224c7a
ci: assign vendor lockfile ownership
BridgeAR Jul 21, 2026
a07c760
ci(dependencies): align Bun lock after rebase
BridgeAR Jul 21, 2026
8219451
ci: fix Bun rebase integration gaps
BridgeAR Jul 29, 2026
764f37a
ci(dependencies): patch brace-expansion and ignore its cross-major ad…
BridgeAR Jul 29, 2026
29571b4
test(install): declare the peer transitives the sandbox specs resolve
BridgeAR Jul 29, 2026
84958a0
test(llmobs): resolve the agents openai client from the loaded package
BridgeAR Jul 30, 2026
d7bb136
ci(licenses): quote the GitHub output writes
BridgeAR Jul 30, 2026
0ff7ea6
ci(install): close Bun migration validation gaps
BridgeAR Jul 30, 2026
53f2373
ci(install): resolve forced transitives from the consuming package's …
BridgeAR Jul 31, 2026
62454af
fix(scripts): reject a non-JavaScript npm_execpath in the Bun bootstrap
BridgeAR Jul 31, 2026
6a2e835
fix(vendor): attribute every bundled package's license
BridgeAR Jul 31, 2026
145a942
fix(licenses): attribute the peers of production dependencies
BridgeAR Jul 31, 2026
865f210
ci(audit): fail on an accepted advisory that is no longer reported
BridgeAR Jul 31, 2026
ad778e3
docs(llmobs): name the services script the repo actually has
BridgeAR Jul 31, 2026
b8f1d11
fix(licenses): keep copied-source attributions out of the dependency …
BridgeAR Jul 31, 2026
01c1845
fix(audit): fail on a severity the wrapper cannot rank
BridgeAR Jul 31, 2026
c5324e3
ci(audit): run the audit when its own policy changes
BridgeAR Jul 31, 2026
39e6055
ci(install): derive the CI Bun install from the pinned version
BridgeAR Jul 31, 2026
1837c29
test(langchain): drop an override Bun silently ignores
BridgeAR Jul 31, 2026
8b2eb5a
ci(codeowners): own the whole .github tree and lint it
BridgeAR Jul 31, 2026
535b14e
ci(bun): fix rebased migration regressions
BridgeAR Aug 8, 2026
c641283
ci(bun): fix latest master integration
BridgeAR Aug 10, 2026
73ac49a
ci(bun): fix license and dependency audits
BridgeAR Aug 10, 2026
5961dd4
ci(bun): simplify migration follow-ups
BridgeAR Aug 11, 2026
661d1d2
ci(audit): restore scheduled Bun checks
BridgeAR Aug 11, 2026
64e83ee
test(plugins): remove obsolete Bun dependency workarounds (#9769)
BridgeAR Aug 11, 2026
e109dd9
ci(bun): prevent partial-state success
BridgeAR Aug 11, 2026
a88fe65
ci(audit): restore strict Bun advisory policy
BridgeAR Aug 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .agents/skills/apm-integrations/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -170,7 +170,7 @@ Follow these steps when creating or modifying an integration:
6. **Run tests** — Validate with:

```bash
# Run plugin tests (preferred CI command — handles yarn services automatically)
# Run plugin tests (preferred CI command — handles `npm run services` automatically)
PLUGINS="<name>" npm run test:plugins:ci

# If the plugin needs external services (databases, message brokers, etc.),
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -285,7 +285,7 @@ See [Testing](testing.md) for complete templates.
**ESM integration tests** — `packages/datadog-plugin-<name>/test/integration-test/`

```bash
# CI command (preferred) — handles dependency installation via yarn services
# CI command (preferred) — handles dependency installation via `npm run services`
PLUGINS="<name>" npm run test:plugins:ci
```

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ source hooks, ESM support, and avoiding runtime monkey-patching.
Engine: `@apm-js-collab/code-transformer` (mirror of
[nodejs/orchestrion-js](https://github.com/nodejs/orchestrion-js)), vendored at
`vendor/dist/@apm-js-collab/code-transformer/`. Installed version is in
`vendor/package-lock.json`.
`vendor/bun.lock`.

> **Verify before relying on a field/transform.** The engine is actively
> developed and the config surface changes between releases. This doc tracks
Expand Down
6 changes: 3 additions & 3 deletions .agents/skills/apm-integrations/references/testing.md
Original file line number Diff line number Diff line change
Expand Up @@ -191,13 +191,13 @@ describe('esm', () => {

## Running Tests

dd-trace uses a non-standard dependency installation for plugin tests. Libraries under test are installed per-version via `yarn services`, not through the normal `node_modules`. The `:ci` script handles this automatically.
dd-trace uses a non-standard dependency installation for plugin tests. Libraries under test are installed per-version via `npm run services` (which drives `scripts/install_plugin_modules.js` and a bun isolated install per sandbox), not through the normal `node_modules`. The `:ci` script handles this automatically.

```bash
# CI command (preferred) — runs yarn services for dependency installation, then tests
# CI command (preferred) — runs `npm run services` for dependency installation, then tests
PLUGINS="<name>" npm run test:plugins:ci

# Unit tests only (assumes yarn services already ran)
# Unit tests only (assumes `npm run services` already ran)
PLUGINS="<name>" npm run test:plugins

# With external services (e.g., databases, message brokers)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -79,7 +79,7 @@ npm run test:llmobs:sdk # everything except the plugin spec
`packages/dd-trace/test/llmobs/plugins/@(${PLUGINS})/*.spec.js`.

`Cannot find module '…/versions/<package>@<version>'` is a missing version fixture, not a broken spec:
`PLUGINS=<integration> yarn services` installs it. The error names the npm package while `PLUGINS` takes
`PLUGINS=<integration> npm run services` installs it. The error names the npm package while `PLUGINS` takes
the integration key, which is the file name under `packages/datadog-instrumentations/src/` — so
`@anthropic-ai/sdk` is `anthropic` and `@google/genai` is `google-genai`. The fixtures live in a gitignored
`versions/` directory at the repo root, so a fresh worktree has none of them.
2 changes: 1 addition & 1 deletion .cursor/worktrees.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"scripts": {
"postCreate": "yarn install"
"postCreate": "bun install"
}
}
6 changes: 6 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@
/.agents/ @DataDog/lang-platform-js
/.claude/ @DataDog/lang-platform-js
/.github/actions/ @DataDog/lang-platform-js
/.github/audit-allowlist.json @DataDog/lang-platform-js
/.github/ISSUE_TEMPLATE/ @DataDog/lang-platform-js
/.gitlab/ @DataDog/lang-platform-js
/.husky/ @DataDog/lang-platform-js
Expand Down Expand Up @@ -110,6 +111,7 @@
/packages/dd-trace/src/propagation-hash/ @DataDog/apm-idm-js
/packages/dd-trace/test/plugins/ @DataDog/apm-idm-js
/packages/dd-trace/test/process-tags.spec.js @DataDog/apm-idm-js
/versions/bunfig.toml @DataDog/lang-platform-js
/packages/dd-trace/src/service-naming/ @DataDog/apm-idm-js
/packages/dd-trace/test/service-naming/ @DataDog/apm-idm-js
/packages/dd-trace/test/payload_tagging.spec.js @DataDog/apm-idm-js
Expand Down Expand Up @@ -327,6 +329,7 @@
# CI
/.github/actions/upload-coverage-artifact/ @DataDog/ci-app-libraries
/.github/actions/upload-junit-artifacts/ @DataDog/ci-app-libraries
/.github/all-green/ @DataDog/lang-platform-js
/.github/editorconfig-checker/ @Datadog/lang-platform-js
/.github/playwright/ @DataDog/ci-app-libraries
/.github/selenium/ @DataDog/ci-app-libraries
Expand Down Expand Up @@ -382,6 +385,9 @@
/.github/pull_request_template.md @DataDog/lang-platform-js
/.github/vendored-dependencies.csv @DataDog/lang-platform-js

/docs/bun.lock @DataDog/lang-platform-js
/vendor/bun.lock @DataDog/lang-platform-js

/benchmark/* @DataDog/lang-platform-js
/benchmark/openfeature.js @DataDog/lang-platform-js @DataDog/feature-flagging-and-experimentation-sdk
/benchmark/sirun/* @DataDog/lang-platform-js
Expand Down
1 change: 0 additions & 1 deletion .github/actions/datadog-ci/.yarnrc

This file was deleted.

4 changes: 3 additions & 1 deletion .github/actions/datadog-ci/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,14 +8,16 @@ runs:
with:
node-version: '20'

# The repository's Node setup installs Bun through npm, so this also works in
# container jobs without `unzip`.
- uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
max_attempts: 3
timeout_minutes: 5
retry_wait_seconds: 30
command: |
cd ${{ github.workspace }}/.github/actions/datadog-ci
yarn install --frozen-lockfile
bun --config="${{ github.workspace }}/bunfig.toml" install --frozen-lockfile --ignore-scripts

- shell: bash
run: echo "${{ github.workspace }}/.github/actions/datadog-ci/node_modules/.bin" >> $GITHUB_PATH
15 changes: 15 additions & 0 deletions .github/actions/datadog-ci/bun.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

8 changes: 0 additions & 8 deletions .github/actions/datadog-ci/yarn.lock

This file was deleted.

8 changes: 6 additions & 2 deletions .github/actions/install/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,11 @@ runs:
steps:
- uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
max_attempts: 3
max_attempts: 2
timeout_minutes: 5
retry_wait_seconds: 30
command: bun install --linker=hoisted --trust --network-concurrency 8
shell: bash
# A retry against Bun's partial install state can skip lifecycle scripts. Start every attempt clean.
command: >-
node -e "require('node:fs').rmSync('node_modules', { recursive: true, force: true })" &&
bun install --frozen-lockfile --linker=hoisted --network-concurrency 8
7 changes: 6 additions & 1 deletion .github/actions/node/setup/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,12 @@ runs:
run: |
MAJOR=$(node -e "process.stdout.write(String(parseInt(process.versions.node)))")
echo "supported=$([ "$MAJOR" -ge 12 ] && echo true || echo false)" >> "$GITHUB_OUTPUT"
# `scripts/bun.js` bootstraps the pinned version locally whenever the global one differs, so a
# hard-coded version here would not run the wrong Bun — it would just make every job pay for that
# bootstrap once Dependabot bumps the devDependency. Read the pin instead of restating it.
- name: Install Bun
if: steps.bun-check.outputs.supported == 'true'
shell: bash
run: npm install -g bun@1.3.1 --prefer-offline --no-audit --no-fund
run: |
VERSION=$(node -p "require('./package.json').devDependencies.bun")
npm install -g "bun@$VERSION" --prefer-offline --no-audit --no-fund
99 changes: 99 additions & 0 deletions .github/all-green/bun.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

9 changes: 9 additions & 0 deletions .github/all-green/package.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
"name": "dd-trace-js-all-green",
"private": true,
"dependencies": {
"@actions/core": "^3.0.1",
"@actions/github": "^9.1.1",
"octokit": "^5.0.3"
}
}
21 changes: 21 additions & 0 deletions .github/audit-allowlist.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
{
".": {
"allow": [
{
"id": "GHSA-5c6j-r48x-rmvq",
"package": "serialize-javascript",
"reason": "Patched in 7.0.3, but mocha declares serialize-javascript@^6.0.2. The vulnerable path is limited to mocha's dev-only parallel test metadata until mocha widens its range."
}
]
},
"vendor": {
"level": "moderate",
"allow": [
{
"id": "GHSA-8988-4f7v-96qf",
"package": "@opentelemetry/core",
"reason": "Patched in 2.8.0, outside the OpenTelemetry 1.x compatibility range bundled for customers. Clearing it requires a deliberate vendored OpenTelemetry major upgrade."
}
]
}
}
Loading
Loading