Skip to content

feat(appsec): report DD_APPSEC_AGENTIC_ONBOARDING in config telemetry#9486

Merged
christophe-papazian merged 2 commits into
masterfrom
christophe-papazian/APPSEC-69230
Jul 22, 2026
Merged

feat(appsec): report DD_APPSEC_AGENTIC_ONBOARDING in config telemetry#9486
christophe-papazian merged 2 commits into
masterfrom
christophe-papazian/APPSEC-69230

Conversation

@christophe-papazian

Copy link
Copy Markdown
Contributor

APPSEC-69230

Implements [RFC-1113]: register DD_APPSEC_AGENTIC_ONBOARDING as a string configuration reported verbatim in configuration telemetry. Always emitted — empty value with origin=default when unset. No derived boolean and no AppSec-state logic; activation analysis is done downstream in Metabase.

Same change on other tracers: java, dotnet, go, rb.

🤖 Generated with Claude Code

Register DD_APPSEC_AGENTIC_ONBOARDING as a string configuration reported
verbatim in configuration telemetry (RFC-1113). Always emitted: empty value
with origin=default when unset. No derived boolean, no AppSec-state logic.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@dd-octo-sts

dd-octo-sts Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Overall package size

Self size: 7.51 MB
Deduped: 8.17 MB
No deduping: 8.17 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | import-in-the-middle | 3.3.2 | 124.41 kB | 440.65 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | dc-polyfill | 0.1.11 | 25.74 kB | 25.74 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Jul 22, 2026

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🔄 Datadog auto-retried 1 job - 1 passed on retry View in Datadog

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 98.44% (+0.00%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 92a0255 | Docs | Datadog PR Page | Give us feedback!

@pr-commenter

pr-commenter Bot commented Jul 22, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-07-22 13:36:53

Comparing candidate commit 92a0255 in PR branch christophe-papazian/APPSEC-69230 with baseline commit 293cf61 in branch master.

📊 Benchmarking dashboard

Found 0 performance improvements and 0 performance regressions! Performance is the same for 2328 metrics, 30 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:appsec-appsec-enabled-24

  • unstable execution_time [-215.478ms; +217.569ms] or [-8.104%; +8.182%]

scenario:appsec-appsec-enabled-26

  • unstable execution_time [-229.942ms; +225.574ms] or [-9.015%; +8.844%]

scenario:appsec-appsec-enabled-with-attacks-24

  • unstable execution_time [-156.824ms; +160.529ms] or [-5.074%; +5.194%]

scenario:appsec-appsec-enabled-with-attacks-26

  • unstable execution_time [-192.449ms; +188.313ms] or [-6.630%; +6.487%]

scenario:appsec-control-20

  • unstable execution_time [-95.299ms; +135.673ms] or [-5.850%; +8.329%]

scenario:appsec-control-24

  • unstable execution_time [-110043.757µs; +108874.724µs] or [-8.881%; +8.787%]

scenario:appsec-control-26

  • unstable execution_time [-125260.136µs; +123524.936µs] or [-10.121%; +9.981%]

scenario:appsec-iast-no-vulnerability-iast-enabled-default-config-20

  • unstable execution_time [-15664.199µs; +16340.065µs] or [-6.049%; +6.310%]

scenario:appsec-iast-with-vulnerability-control-20

  • unstable execution_time [-30.731ms; +36.742ms] or [-5.588%; +6.681%]

scenario:child_process-shell-string-24

  • unstable execution_time [-13.752ms; +22.470ms] or [-4.256%; +6.954%]

scenario:debugger-line-probe-with-snapshot-default-24

  • unstable cpu_user_time [-1765.377ms; +581.770ms] or [-21.290%; +7.016%]
  • unstable execution_time [-1778.750ms; +602.553ms] or [-19.773%; +6.698%]
  • unstable instructions [-15.0G instructions; +4.8G instructions] or [-22.232%; +7.145%]
  • unstable throughput [-166.920op/s; +473.402op/s] or [-4.555%; +12.919%]

scenario:debugger-line-probe-with-snapshot-default-26

  • unstable cpu_user_time [-2672.914ms; +4225.231ms] or [-27.988%; +44.242%]
  • unstable execution_time [-2827.500ms; +4376.262ms] or [-27.456%; +42.495%]
  • unstable instructions [-23.2G instructions; +37.0G instructions] or [-29.096%; +46.441%]
  • unstable max_rss_usage [-7.991MB; +13.053MB] or [-5.020%; +8.201%]
  • unstable throughput [-834.865op/s; +551.459op/s] or [-25.866%; +17.085%]

scenario:debugger-line-probe-without-snapshot-26

  • unstable cpu_user_time [-3.877s; +0.165s] or [-36.475%; +1.552%]
  • unstable execution_time [-3.934s; +0.205s] or [-34.643%; +1.808%]
  • unstable instructions [-34.5G instructions; +1.3G instructions] or [-38.627%; +1.474%]
  • unstable throughput [-34.967op/s; +794.067op/s] or [-1.165%; +26.461%]

scenario:dogstatsd-with-tags-20

  • unstable cpu_user_time [-428.862ms; +208.693ms] or [-8.868%; +4.315%]
  • unstable execution_time [-419.374ms; +212.612ms] or [-8.538%; +4.329%]
  • unstable throughput [-75585.953op/s; +147555.204op/s] or [-4.427%; +8.643%]

scenario:plugin-claude-agent-sdk-compact-stream-scan-26

  • unstable cpu_usage_percentage [-5.555%; +5.555%]

scenario:plugin-graphql-long-with-depth-and-collapse-off-20

  • unstable max_rss_usage [-23.220MB; +16.438MB] or [-5.878%; +4.161%]

scenario:plugin-graphql-long-with-depth-off-26

  • unstable max_rss_usage [-4.333MB; +21.522MB] or [-1.996%; +9.914%]

scenario:plugin-graphql-long-with-depth-on-max-20

  • unstable throughput [-3.471op/s; +3.392op/s] or [-5.069%; +4.953%]

Use the `appsec` namespace instead of `configurationNames` so
DD_APPSEC_AGENTIC_ONBOARDING stays a telemetry-only config (like
DD_APPSEC_SCA_ENABLED) and is not required in index.d.ts, fixing the
eslint-config-names-sync lint failure.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@christophe-papazian
christophe-papazian marked this pull request as ready for review July 22, 2026 13:40
@christophe-papazian
christophe-papazian requested a review from a team as a code owner July 22, 2026 13:40
@christophe-papazian
christophe-papazian requested review from khanayan123 and removed request for a team July 22, 2026 13:40
@christophe-papazian
christophe-papazian merged commit 43a409c into master Jul 22, 2026
771 of 772 checks passed
@christophe-papazian
christophe-papazian deleted the christophe-papazian/APPSEC-69230 branch July 22, 2026 13:47
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Jul 22, 2026
dd-octo-sts Bot pushed a commit that referenced this pull request Jul 22, 2026
…#9486)

* feat(appsec): report DD_APPSEC_AGENTIC_ONBOARDING in config telemetry

Register DD_APPSEC_AGENTIC_ONBOARDING as a string configuration reported
verbatim in configuration telemetry (RFC-1113). Always emitted: empty value
with origin=default when unset. No derived boolean, no AppSec-state logic.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(appsec): keep agentic-onboarding config out of public options

Use the `appsec` namespace instead of `configurationNames` so
DD_APPSEC_AGENTIC_ONBOARDING stays a telemetry-only config (like
DD_APPSEC_SCA_ENABLED) and is not required in index.d.ts, fixing the
eslint-config-names-sync lint failure.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Jul 22, 2026
BridgeAR pushed a commit that referenced this pull request Jul 22, 2026
…#9489)

The v5-only "should give priority to non-experimental options" test does a
strict deepStrictEqual on config.appsec. PR #9486 added
DD_APPSEC_AGENTIC_ONBOARDING as a namespace:"appsec" entry (default ""),
which populates config.appsec for all majors, but that test was gated on
DD_MAJOR < 6 and therefore skipped in master (v6/v7) CI. It only runs in
the v5 release pipeline, where the missing key broke the assertion.

Add the always-present key to the expected object.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Jul 22, 2026
dd-octo-sts Bot pushed a commit that referenced this pull request Jul 22, 2026
…#9489)

The v5-only "should give priority to non-experimental options" test does a
strict deepStrictEqual on config.appsec. PR #9486 added
DD_APPSEC_AGENTIC_ONBOARDING as a namespace:"appsec" entry (default ""),
which populates config.appsec for all majors, but that test was gated on
DD_MAJOR < 6 and therefore skipped in master (v6/v7) CI. It only runs in
the v5 release pipeline, where the missing key broke the assertion.

Add the always-present key to the expected object.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Jul 22, 2026
leoromanovsky pushed a commit that referenced this pull request Jul 22, 2026
…#9486)

* feat(appsec): report DD_APPSEC_AGENTIC_ONBOARDING in config telemetry

Register DD_APPSEC_AGENTIC_ONBOARDING as a string configuration reported
verbatim in configuration telemetry (RFC-1113). Always emitted: empty value
with origin=default when unset. No derived boolean, no AppSec-state logic.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(appsec): keep agentic-onboarding config out of public options

Use the `appsec` namespace instead of `configurationNames` so
DD_APPSEC_AGENTIC_ONBOARDING stays a telemetry-only config (like
DD_APPSEC_SCA_ENABLED) and is not required in index.d.ts, fixing the
eslint-config-names-sync lint failure.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
leoromanovsky pushed a commit that referenced this pull request Jul 22, 2026
…#9489)

The v5-only "should give priority to non-experimental options" test does a
strict deepStrictEqual on config.appsec. PR #9486 added
DD_APPSEC_AGENTIC_ONBOARDING as a namespace:"appsec" entry (default ""),
which populates config.appsec for all majors, but that test was gated on
DD_MAJOR < 6 and therefore skipped in master (v6/v7) CI. It only runs in
the v5 release pipeline, where the missing key broke the assertion.

Add the always-present key to the expected object.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
leoromanovsky pushed a commit that referenced this pull request Jul 22, 2026
…#9486)

* feat(appsec): report DD_APPSEC_AGENTIC_ONBOARDING in config telemetry

Register DD_APPSEC_AGENTIC_ONBOARDING as a string configuration reported
verbatim in configuration telemetry (RFC-1113). Always emitted: empty value
with origin=default when unset. No derived boolean, no AppSec-state logic.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(appsec): keep agentic-onboarding config out of public options

Use the `appsec` namespace instead of `configurationNames` so
DD_APPSEC_AGENTIC_ONBOARDING stays a telemetry-only config (like
DD_APPSEC_SCA_ENABLED) and is not required in index.d.ts, fixing the
eslint-config-names-sync lint failure.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
leoromanovsky pushed a commit that referenced this pull request Jul 22, 2026
…#9489)

The v5-only "should give priority to non-experimental options" test does a
strict deepStrictEqual on config.appsec. PR #9486 added
DD_APPSEC_AGENTIC_ONBOARDING as a namespace:"appsec" entry (default ""),
which populates config.appsec for all majors, but that test was gated on
DD_MAJOR < 6 and therefore skipped in master (v6/v7) CI. It only runs in
the v5 release pipeline, where the missing key broke the assertion.

Add the always-present key to the expected object.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants