Skip to content

Conversation

@BridgeAR
Copy link
Collaborator

@BridgeAR BridgeAR commented Dec 8, 2025

See commit messages for details

This increases our cooldown time for regular dependencies to three
days while we use a cooldown of one day for instrumented libraries.

Security updates should happen right away in all situations. Thus,
this adds a new section for handling these separately in all cases.
Change the update strategy to increase to guarantee our library
always uses latest dpeendencies when being installed by customers.
OTEL libraries are special handled, due to needing a wide range,
if possible.
This adds updates for docs and integration tests.
@BridgeAR BridgeAR requested a review from a team as a code owner December 8, 2025 13:08
@github-actions
Copy link

github-actions bot commented Dec 8, 2025

Overall package size

Self size: 13.62 MB
Deduped: 113.82 MB
No deduping: 128.84 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | @datadog/libdatadog | 0.7.0 | 35.02 MB | 35.02 MB | | @datadog/native-appsec | 10.3.0 | 20.73 MB | 20.74 MB | | @datadog/pprof | 5.12.0 | 11.19 MB | 11.57 MB | | @datadog/native-iast-taint-tracking | 4.1.0 | 9.01 MB | 9.02 MB | | @opentelemetry/resources | 1.30.1 | 557.67 kB | 7.71 MB | | @opentelemetry/core | 1.30.1 | 908.66 kB | 7.16 MB | | protobufjs | 7.5.4 | 2.95 MB | 5.83 MB | | @datadog/wasm-js-rewriter | 5.0.1 | 2.82 MB | 3.53 MB | | @datadog/native-metrics | 3.1.1 | 1.02 MB | 1.43 MB | | @opentelemetry/api-logs | 0.208.0 | 199.48 kB | 1.42 MB | | @opentelemetry/api | 1.9.0 | 1.22 MB | 1.22 MB | | jsonpath-plus | 10.3.0 | 617.18 kB | 1.08 MB | | import-in-the-middle | 1.15.0 | 127.66 kB | 856.24 kB | | lru-cache | 10.4.3 | 804.3 kB | 804.3 kB | | @datadog/openfeature-node-server | 0.2.0 | 118.51 kB | 437.19 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | source-map | 0.7.6 | 185.63 kB | 185.63 kB | | pprof-format | 2.2.1 | 163.06 kB | 163.06 kB | | @datadog/sketches-js | 2.1.1 | 109.9 kB | 109.9 kB | | @isaacs/ttlcache | 2.1.3 | 90.79 kB | 90.79 kB | | lodash.sortby | 4.7.0 | 75.76 kB | 75.76 kB | | ignore | 7.0.5 | 63.38 kB | 63.38 kB | | istanbul-lib-coverage | 3.2.2 | 34.37 kB | 34.37 kB | | rfdc | 1.4.1 | 27.15 kB | 27.15 kB | | dc-polyfill | 0.1.10 | 26.73 kB | 26.73 kB | | tlhunter-sorted-set | 0.1.0 | 24.94 kB | 24.94 kB | | shell-quote | 1.8.3 | 23.74 kB | 23.74 kB | | limiter | 1.1.5 | 23.17 kB | 23.17 kB | | retry | 0.13.1 | 18.85 kB | 18.85 kB | | semifies | 1.0.0 | 15.84 kB | 15.84 kB | | jest-docblock | 29.7.0 | 8.99 kB | 12.76 kB | | crypto-randomuuid | 1.0.0 | 11.18 kB | 11.18 kB | | ttl-set | 1.0.0 | 4.61 kB | 9.69 kB | | mutexify | 1.4.0 | 5.71 kB | 8.74 kB | | path-to-regexp | 0.1.12 | 6.6 kB | 6.6 kB | | module-details-from-path | 1.0.4 | 3.96 kB | 3.96 kB | | escape-string-regexp | 5.0.0 | 3.66 kB | 3.66 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@codecov
Copy link

codecov bot commented Dec 8, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.80%. Comparing base (590ba8e) to head (cd24730).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #7049   +/-   ##
=======================================
  Coverage   84.80%   84.80%           
=======================================
  Files         514      514           
  Lines       21987    21987           
=======================================
  Hits        18646    18646           
  Misses       3341     3341           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@datadog-official

This comment has been minimized.

@pr-commenter
Copy link

pr-commenter bot commented Dec 9, 2025

Benchmarks

Benchmark execution time: 2025-12-10 08:57:39

Comparing candidate commit cd24730 in PR branch BridgeAR/2025-12-04-update-cve-dependencies-faster with baseline commit 590ba8e in branch master.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 293 metrics, 27 unstable metrics.

@simon-id simon-id enabled auto-merge (squash) December 10, 2025 08:49
@simon-id simon-id merged commit 9aaadb5 into master Dec 10, 2025
787 checks passed
@simon-id simon-id deleted the BridgeAR/2025-12-04-update-cve-dependencies-faster branch December 10, 2025 09:12
dd-octo-sts bot pushed a commit that referenced this pull request Dec 11, 2025
* ci: safer dependabot updates

This increases our cooldown time for regular dependencies to three
days while we use a cooldown of one day for instrumented libraries.

Security updates should happen right away in all situations. Thus,
this adds a new section for handling these separately in all cases.

* ci: increase version by default by dependabot besides for OTEL

Change the update strategy to increase to guarantee our library
always uses latest dpeendencies when being installed by customers.
OTEL libraries are special handled, due to needing a wide range,
if possible.

* ci: add more package.json to dependabot.yml

This adds updates for docs and integration tests.

* fixup! increase cooldown further as discussed in guild

* fixup!

---------

Co-authored-by: simon-id <[email protected]>
@dd-octo-sts dd-octo-sts bot mentioned this pull request Dec 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants