chore(deps): bump dd-trace from 4.38.0 to 5.100.0 - #4352
Conversation
PR SummaryMedium Risk Overview The lockfile reflects a major tracer stack shift: newer Datadog native modules, OpenTelemetry / OpenFeature optional integrations, oxc-parser / WASM rewriter pieces, and import-in-the-middle moving from 1.x to 3.x (relevant to how auto-instrumentation patches modules). Vitest resolution also picks up optional Deploy/runtime note: dd-trace 5.100.0 targets Node Reviewed by Cursor Bugbot for commit 6c49972. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
|
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
83ca184 to
6afd150
Compare
Bumps [dd-trace](https://github.com/DataDog/dd-trace-js) from 4.38.0 to 5.100.0. - [Release notes](https://github.com/DataDog/dd-trace-js/releases) - [Commits](DataDog/dd-trace-js@v4.38.0...v5.100.0) --- updated-dependencies: - dependency-name: dd-trace dependency-version: 5.100.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
6afd150 to
6c49972
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 6c49972. Configure here.
| needle@https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: | ||
| resolution: {tarball: https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b} | ||
| needle@git+https://git@github.com:clearbit/needle.git#84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: | ||
| resolution: {commit: 84d28b5f2c3916db1e7eb84aeaa9d976cc40054b, repo: git@github.com:clearbit/needle.git, type: git} |
There was a problem hiding this comment.
Lockfile forces SSH for needle
Medium Severity
The clearbit → needle dependency was re-resolved from a public HTTPS tarball (codeload.github.com) to a git@github.com SSH git dependency. Fresh installs in CI or other environments without GitHub SSH keys can fail with permission errors even though the repo is public.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 6c49972. Configure here.


Bumps dd-trace from 4.38.0 to 5.100.0.
Release notes
Sourced from dd-trace's releases.
... (truncated)
Commits
581910dv5.100.0b24e364perf(propagation): rewrite tracestate parser to be linear (#8256)8e59ac7chore(deps-dev): bump the dev-minor-and-patch-dependencies group across 1 dir...e909c52chore(deps): bump the gh-actions-packages group across 2 directories with 1 u...86e35a9fix(express): use the host's path-to-regexp dialect for route tagging (#8224)9f302ferefactor(otel): extract bridge helpers into span-helpers.js (#8220)200d3bdfix(otel): return a non-recording span when the inner tracer is the noop (#8218)b2df728fix(esm): expose 'tracer' as an ESM named export (#8216)741482cfix: small correctness issues in mongodb-core and bullmq (#8228)280f96efix(config): align inferred service name with agent normalization (#8217)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for dd-trace since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.