v5.116.0 proposal#9492
Conversation
A failed settings response must leave test management, EFD, and ITR disabled.
…9133) The reference tracked an older code-transformer surface and read as a tour of every field. Two capabilities the prior version did not cover are the ones that decide instrumentation strategy: 1. A library that exposes work through a runtime-decorated handle (`app.decorate('x', fn)`) is still orchestrion-matchable when the function behind it is a named source declaration — match `functionName`, not the handle, and skip shimmer entirely. 2. `objectName` + `propertyName` pin a function assigned to a property on a named receiver (or `this`), where `expressionName` alone matches the wrong object when the property name repeats. Trims the per-field walkthrough to the parts that change a decision and keeps the verify-against-installed-source caveat. * docs(orchestrion): correct skill guidance for current wrappers The vendored Orchestrion templates still allocate wrapper state before the subscriber check, so the reference should not describe the inactive path as zero-cost. Extra module prefixes also require an explicit subscription loop today; documenting that prevents forked package integrations from silently missing events. * docs(orchestrion): correct wrapper lifecycle guidance An astQuery-only async hook silently selects the synchronous wrapper unless functionQuery keeps the operator metadata. Generated channels also never emit finish, and the duplicate iterator guide used the obsolete config field and channel suffix.
The server used an IPv6 wildcard while the tracer exported to 127.0.0.1. macOS can assign that wildcard a numeric port already held by an IPv4 listener, so trace payloads reached that process instead of the mock agent.
Finished manual test spans remained active in async-local storage, so nested tests and later work inherited a completed parent.
Collapsed list resolvers built both a dotted string and a parallel object path for the same key, repeating map lookups and allocations for every resolver. A five-item list with four fields per item dropped from 4.10-4.16 us to 3.68-3.69 us per bookkeeping pass (10.1-11.2%) on Node v24.18.0 / V8 13.6.233.17-node.50.
In OTel bridge mode, Next.js renames its root request span to `${method} ${route}` before ending it. The bridge mapped that value to the Datadog operation name, producing route-bearing operation names and leaving the resource as the bare method.
Apply the correction before the DD span is finished and serialized, preserving Next's route/RSC resource name while selecting the operation name from the active service-naming schema.
Fixes: #4003
Node can hang when native coverage resolves a large ESM source-map cache during isolate teardown. Resolve maps as scripts load so the final V8 snapshot retains all execution counters and foreign coverage directories remain untouched. Refs: nodejs/node#49344 * test(coverage): disconnect source-map observer before teardown Drain the last queued URLs and disconnect the Debugger session from the JavaScript exit event before Node runs native coverage serialization. This keeps late exit-time maps while avoiding a live observer during isolate teardown. * test(coverage): avoid renderer and exit-time source-map lookups Electron renderers lack a usable Node inspector, so connecting a Session prevents renderer preload and IPC instrumentation from starting. Explicit process.exit skips the scheduled warm-up, moving the full source-map backlog into the exit event where Node's teardown can hang. Skip only renderer observers and drain pending maps before explicit exit; the exit hook now only disconnects.
Next.js standalone builds using pnpm omitted the OpenFeature provider because the shared optional-peer wrapper was invisible to nft, leaving tracer.openfeature as the no-op provider at runtime. Keep the bundler escape hatch while exposing a file-traceable fallback entrypoint for tools that cannot recognize the wrapper. Also document CommonJS and ESM entrypoints. Fixes: #8635
…9289) Hardcoded CPU bounds fail when scheduler contention shifts system time, while wide static tolerances can hide conversion errors. Bracket the collector's reads with independent process CPU and monotonic-clock samples to keep the real native and fallback paths while deriving the accepted range from the observed interval.
* Add dd-octo-sts chainguard policy files Add 5 policy files under .github/chainguard/ declaring the issuer, subject, event, and permission constraints for every workflow that will be migrated from secrets.GITHUB_TOKEN to DataDog/dd-octo-sts-action. These policies must be on the default branch before the corresponding workflow changes can use them. * ci(chainguard): rescope self.* octo-sts policies to current master master already migrated project.yml (package-size-report) and part of update-3rdparty-licenses.yml (auto-commit-licenses job) to octo-sts, under a bare policy naming convention, since this PR was opened. Drop the duplicate self.package-size-report and self.check-licenses policies added here for those now-covered workflows. Also fix self.release-validate: its claim_pattern matched a pull_request/refs/pull/.../merge trigger, but release-validate.yml triggers on push to v*.*.*-proposal branches. The policy would never have matched a real token request. * ci(chainguard): add self.check-licenses policy for license regen step The check-licenses job's 'Regenerate LICENSE-3rdparty.csv' step still uses secrets.GITHUB_TOKEN on master; only the separate auto-commit-licenses job was migrated to octo-sts (policy: update-3rdparty-licenses), which is actor-restricted to dependabot/dd-octo-sts and grants contents:write for the commit-back. check-licenses runs for any PR touching the license-relevant paths, not just bot PRs, and only needs read access to generate the SBOM CSV, so it needs its own unrestricted, read-only policy rather than reusing update-3rdparty-licenses. Isolated in its own commit: revert this alone if it turns out redundant or conflicts with follow-up work on that workflow. --------- Co-authored-by: Ruben Bridgewater <ruben@bridgewater.de>
#9316) * test(plugins): retry versions install to survive transient CDN 5xx The generated versions/ workspaces download large prebuilt binaries at postinstall time (e.g. Electron pulls one archive per major from GitHub's release CDN), which intermittently fail with 502/504 gateway errors. The previous single, immediate retry fired back-to-back, so both attempts landed in the same brief outage window and the job failed anyway. Wrap the install in a small backoff-retry helper (4 attempts, 5s/10s/20s) so a transient outage no longer fails the job. This benefits every plugin's version install, not just Electron. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ci(electron): retry apt-get in the electron job The electron job installs xvfb via apt, whose package mirrors occasionally return transient 5xx/invalid-data errors and fail the job. Retry the update+install with backoff before giving up. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * test(electron): guard IPC teardown against a closed channel The afterEach teardown sent {name:'quit'} unconditionally. If the Electron child had already exited (e.g. an app crash mid-test), sending on the closed IPC channel emits an unhandled ERR_IPC_CHANNEL_CLOSED 'error' that masks the real failure and, because it throws inside the hook, aborts the rest of the suite. Only quit a still-connected child and pass a send callback so a channel that races closed is absorbed instead of emitting 'error'. A genuine crash still fails its own test via the trace-assertion timeout. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Add dd-octo-sts chainguard policy files Add 5 policy files under .github/chainguard/ declaring the issuer, subject, event, and permission constraints for every workflow that will be migrated from secrets.GITHUB_TOKEN to DataDog/dd-octo-sts-action. These policies must be on the default branch before the corresponding workflow changes can use them. * Replace secrets.GITHUB_TOKEN with dd-octo-sts Migrate the remaining secrets.GITHUB_TOKEN references in 6 GitHub Actions workflows to OIDC tokens minted by DataDog/dd-octo-sts-action. The token exchange is auditable and governed by chainguard policy files that explicitly declare which workflow, event, and ref pattern may request which permissions. For release.yml the three publish jobs already had an octo-sts step; move the GITHUB_TOKEN env from job level (where step outputs are not yet available) to step level on the release-notes script, using GH_TOKEN which the gh CLI and the notes script both recognise. For the other 5 workflows add a new dd-octo-sts step and a matching chainguard policy file. * ci(chainguard): rescope self.* octo-sts policies to current master master already migrated project.yml (package-size-report) and part of update-3rdparty-licenses.yml (auto-commit-licenses job) to octo-sts, under a bare policy naming convention, since this PR was opened. Drop the duplicate self.package-size-report and self.check-licenses policies added here for those now-covered workflows. Also fix self.release-validate: its claim_pattern matched a pull_request/refs/pull/.../merge trigger, but release-validate.yml triggers on push to v*.*.*-proposal branches. The policy would never have matched a real token request. * ci(chainguard): add self.check-licenses policy for license regen step The check-licenses job's 'Regenerate LICENSE-3rdparty.csv' step still uses secrets.GITHUB_TOKEN on master; only the separate auto-commit-licenses job was migrated to octo-sts (policy: update-3rdparty-licenses), which is actor-restricted to dependabot/dd-octo-sts and grants contents:write for the commit-back. check-licenses runs for any PR touching the license-relevant paths, not just bot PRs, and only needs read access to generate the SBOM CSV, so it needs its own unrestricted, read-only policy rather than reusing update-3rdparty-licenses. Isolated in its own commit: revert this alone if it turns out redundant or conflicts with follow-up work on that workflow. * ci(workflows): migrate check-licenses regen step to dd-octo-sts The 'Regenerate LICENSE-3rdparty.csv' step in check-licenses still used secrets.GITHUB_TOKEN; only the separate auto-commit-licenses job was migrated to octo-sts on master. Wire it to the self.check-licenses policy added alongside this (read-only, unrestricted actor, since any PR touching license-relevant paths runs this job). Isolated in its own commit, paired with the self.check-licenses chainguard policy: revert this alone if it turns out redundant or conflicts with follow-up work on that workflow. --------- Co-authored-by: Ruben Bridgewater <ruben@bridgewater.de> Co-authored-by: Roch Devost <roch.devost@datadoghq.com>
…th 8 updates (#9411) Bumps the cloud-and-messaging group with 8 updates in the /packages/dd-trace/test/plugins/versions directory: | Package | From | To | | --- | --- | --- | | [@aws-sdk/client-bedrock-runtime](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-runtime) | `3.1085.0` | `3.1086.0` | | [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1085.0` | `3.1086.0` | | [@aws-sdk/client-kinesis](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-kinesis) | `3.1085.0` | `3.1086.0` | | [@aws-sdk/client-lambda](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-lambda) | `3.1085.0` | `3.1086.0` | | [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1085.0` | `3.1086.0` | | [@aws-sdk/client-sfn](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sfn) | `3.1085.0` | `3.1086.0` | | [@aws-sdk/client-sns](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sns) | `3.1085.0` | `3.1086.0` | | [@aws-sdk/client-sqs](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sqs) | `3.1085.0` | `3.1086.0` | Updates `@aws-sdk/client-bedrock-runtime` from 3.1085.0 to 3.1086.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-runtime/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1086.0/clients/client-bedrock-runtime) Updates `@aws-sdk/client-dynamodb` from 3.1085.0 to 3.1086.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1086.0/clients/client-dynamodb) Updates `@aws-sdk/client-kinesis` from 3.1085.0 to 3.1086.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-kinesis/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1086.0/clients/client-kinesis) Updates `@aws-sdk/client-lambda` from 3.1085.0 to 3.1086.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1086.0/clients/client-lambda) Updates `@aws-sdk/client-s3` from 3.1085.0 to 3.1086.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1086.0/clients/client-s3) Updates `@aws-sdk/client-sfn` from 3.1085.0 to 3.1086.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sfn/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1086.0/clients/client-sfn) Updates `@aws-sdk/client-sns` from 3.1085.0 to 3.1086.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sns/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1086.0/clients/client-sns) Updates `@aws-sdk/client-sqs` from 3.1085.0 to 3.1086.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sqs/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1086.0/clients/client-sqs) --- updated-dependencies: - dependency-name: "@aws-sdk/client-bedrock-runtime" dependency-version: 3.1086.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-dynamodb" dependency-version: 3.1086.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-kinesis" dependency-version: 3.1086.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-lambda" dependency-version: 3.1086.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-s3" dependency-version: 3.1086.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-sfn" dependency-version: 3.1086.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-sns" dependency-version: 3.1086.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-sqs" dependency-version: 3.1086.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tes (#9410) Bumps the ai-and-llm group with 8 updates in the /packages/dd-trace/test/plugins/versions directory: | Package | From | To | | --- | --- | --- | | [@ai-sdk/amazon-bedrock](https://github.com/vercel/ai/tree/HEAD/packages/amazon-bedrock) | `5.0.16` | `5.0.20` | | [@ai-sdk/anthropic](https://github.com/vercel/ai/tree/HEAD/packages/anthropic) | `4.0.11` | `4.0.14` | | [@ai-sdk/google](https://github.com/vercel/ai/tree/HEAD/packages/google) | `4.0.11` | `4.0.14` | | [@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai) | `4.0.11` | `4.0.13` | | [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.110.0` | `0.111.0` | | [@openai/agents](https://github.com/openai/openai-agents-js) | `0.13.1` | `0.13.3` | | [@openai/agents-core](https://github.com/openai/openai-agents-js) | `0.13.1` | `0.13.3` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `7.0.19` | `7.0.26` | Updates `@ai-sdk/amazon-bedrock` from 5.0.16 to 5.0.20 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/amazon-bedrock/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/amazon-bedrock@5.0.20/packages/amazon-bedrock) Updates `@ai-sdk/anthropic` from 4.0.11 to 4.0.14 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/anthropic/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/anthropic@4.0.14/packages/anthropic) Updates `@ai-sdk/google` from 4.0.11 to 4.0.14 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/google/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/google@4.0.14/packages/google) Updates `@ai-sdk/openai` from 4.0.11 to 4.0.13 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/openai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/openai@4.0.13/packages/openai) Updates `@anthropic-ai/sdk` from 0.110.0 to 0.111.0 - [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases) - [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md) - [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.110.0...sdk-v0.111.0) Updates `@openai/agents` from 0.13.1 to 0.13.3 - [Release notes](https://github.com/openai/openai-agents-js/releases) - [Commits](openai/openai-agents-js@v0.13.1...v0.13.3) Updates `@openai/agents-core` from 0.13.1 to 0.13.3 - [Release notes](https://github.com/openai/openai-agents-js/releases) - [Commits](openai/openai-agents-js@v0.13.1...v0.13.3) Updates `ai` from 7.0.19 to 7.0.26 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@7.0.26/packages/ai) --- updated-dependencies: - dependency-name: "@ai-sdk/amazon-bedrock" dependency-version: 5.0.20 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ai-and-llm - dependency-name: "@ai-sdk/anthropic" dependency-version: 4.0.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ai-and-llm - dependency-name: "@ai-sdk/google" dependency-version: 4.0.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ai-and-llm - dependency-name: "@ai-sdk/openai" dependency-version: 4.0.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ai-and-llm - dependency-name: "@anthropic-ai/sdk" dependency-version: 0.111.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: ai-and-llm - dependency-name: "@openai/agents" dependency-version: 0.13.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ai-and-llm - dependency-name: "@openai/agents-core" dependency-version: 0.13.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ai-and-llm - dependency-name: ai dependency-version: 7.0.26 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: ai-and-llm ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…sts (#9409) The fetch, request and utility-request tests asserted traces with the 1000ms default while the IPC tests already used 10s. A freshly-spawned Electron app's first traced operation pays cold-start cost, so the first version's fetch consistently exceeded 1000ms on loaded CI runners (both attempts of a run failed on it while the 10s IPC tests passed) — cold-start latency, not trace loss (flushInterval is 0, other versions' fetch passes, and the same cold app's IPC tests deliver within 10s). Use a shared TRACE_TIMEOUT_MS for every trace assertion. They still resolve the instant the matching trace arrives, so passing runs are unaffected. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ateway inferred spans (#9089) * adding PoC azure application gateway inferred span * fixing implementation to prevent overwriting of timestamps * refactoring gateway implementation to support azure frontdoor * fixing linting issues -- adding new test case against azure proxies with no timestamp * cleaning up logic * cleaning up spacing * Fixing variable * Fixing variables * Linting * adding a check to ensure that original code path still works * clean up * Update packages/dd-trace/src/plugins/util/inferred_proxy.js Co-authored-by: Ruben Bridgewater <ruben@bridgewater.de> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * reduce logging if no proxy header is defined * fixing lint issues * linting * Fixing issue with timestamp logic * ensuring paths have slashs if there is a path present * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * fixing test typo Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * fixing suggested commit and relinted * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Fixing tests Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Revert "Fixing tests" This reverts commit 665c9f7. * Revert "Potential fix for pull request finding" This reverts commit e58b225. * fixing complex logic * fixing stray space --------- Co-authored-by: Ruben Bridgewater <ruben@bridgewater.de> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…th 12 updates (#9428) Bumps the cloud-and-messaging group with 12 updates in the /packages/dd-trace/test/plugins/versions directory: | Package | From | To | | --- | --- | --- | | [@aws-sdk/client-bedrock-runtime](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-runtime) | `3.1086.0` | `3.1089.0` | | [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1086.0` | `3.1089.0` | | [@aws-sdk/client-kinesis](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-kinesis) | `3.1086.0` | `3.1089.0` | | [@aws-sdk/client-lambda](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-lambda) | `3.1086.0` | `3.1089.0` | | [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1086.0` | `3.1089.0` | | [@aws-sdk/client-sfn](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sfn) | `3.1086.0` | `3.1089.0` | | [@aws-sdk/client-sns](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sns) | `3.1086.0` | `3.1089.0` | | [@aws-sdk/client-sqs](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sqs) | `3.1086.0` | `3.1089.0` | | [@smithy/core](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/core) | `3.29.3` | `3.29.5` | | [@smithy/smithy-client](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/smithy-client) | `4.14.8` | `4.14.10` | | [bullmq](https://github.com/taskforcesh/bullmq) | `5.80.2` | `5.80.6` | | [durable-functions](https://github.com/Azure/azure-functions-durable-js) | `3.4.0` | `3.5.0` | Updates `@aws-sdk/client-bedrock-runtime` from 3.1086.0 to 3.1089.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-runtime/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1089.0/clients/client-bedrock-runtime) Updates `@aws-sdk/client-dynamodb` from 3.1086.0 to 3.1089.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1089.0/clients/client-dynamodb) Updates `@aws-sdk/client-kinesis` from 3.1086.0 to 3.1089.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-kinesis/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1089.0/clients/client-kinesis) Updates `@aws-sdk/client-lambda` from 3.1086.0 to 3.1089.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1089.0/clients/client-lambda) Updates `@aws-sdk/client-s3` from 3.1086.0 to 3.1089.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1089.0/clients/client-s3) Updates `@aws-sdk/client-sfn` from 3.1086.0 to 3.1089.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sfn/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1089.0/clients/client-sfn) Updates `@aws-sdk/client-sns` from 3.1086.0 to 3.1089.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sns/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1089.0/clients/client-sns) Updates `@aws-sdk/client-sqs` from 3.1086.0 to 3.1089.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sqs/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1089.0/clients/client-sqs) Updates `@smithy/core` from 3.29.3 to 3.29.5 - [Release notes](https://github.com/smithy-lang/smithy-typescript/releases) - [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/core/CHANGELOG.md) - [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/core@3.29.5/packages/core) Updates `@smithy/smithy-client` from 4.14.8 to 4.14.10 - [Release notes](https://github.com/smithy-lang/smithy-typescript/releases) - [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/smithy-client/CHANGELOG.md) - [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/smithy-client@4.14.10/packages/smithy-client) Updates `bullmq` from 5.80.2 to 5.80.6 - [Release notes](https://github.com/taskforcesh/bullmq/releases) - [Commits](taskforcesh/bullmq@v5.80.2...v5.80.6) Updates `durable-functions` from 3.4.0 to 3.5.0 - [Release notes](https://github.com/Azure/azure-functions-durable-js/releases) - [Commits](Azure/azure-functions-durable-js@v3.4.0...v3.5.0) --- updated-dependencies: - dependency-name: "@aws-sdk/client-bedrock-runtime" dependency-version: 3.1089.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-dynamodb" dependency-version: 3.1089.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-kinesis" dependency-version: 3.1089.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-lambda" dependency-version: 3.1089.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-s3" dependency-version: 3.1089.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-sfn" dependency-version: 3.1089.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-sns" dependency-version: 3.1089.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@aws-sdk/client-sqs" dependency-version: 3.1089.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging - dependency-name: "@smithy/core" dependency-version: 3.29.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cloud-and-messaging - dependency-name: "@smithy/smithy-client" dependency-version: 4.14.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cloud-and-messaging - dependency-name: bullmq dependency-version: 5.80.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cloud-and-messaging - dependency-name: durable-functions dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cloud-and-messaging ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…sts (#9417) * test(appsec): deflake RASP SSRF "should not detect threat" express tests * test(appsec): disable proxy on RASP SSRF outbound "not detect threat" requests
…#9219) * feat(aiguard): evaluating anthropic calls with AI guard automatically
Coverage upload instrumentation converted rejected NYC reports into fulfilled promises, allowing the command to succeed without a report.
* fix(graphql): preserve hook error overrides The orchestrion lifecycle applied GraphQL errors after application hooks, so hooks could no longer clear expected failures. Make hooks the final span writer for result errors, synchronous throws, and rejected executor results while retaining GraphQL error events. Fixes: #9423 * fix(graphql): release execute guards before hooks The orchestrion migration kept re-entry guards active while hooks ran, so a hook starting another operation with the same context silently skipped tracing. Release the guards before handing control to application code while still finishing the span after the hook.
* spike(llmobs): control-plane HTTP client for experiments
Initial spike toward unifying the standalone Node LLM Experiments SDK
into dd-trace under llmobs. Adds a fetch-based control-plane client
(no new dependencies, same approach as src/aiguard/client.js) that
sources DD_API_KEY / DD_APP_KEY / site from tracer config, resolves the
api.<site> host, and implements get-or-create project as the first
working call. Includes a mocha/sinon spec.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(llmobs): datasets & experiments via tracer.llmobs.experiments
Ports the standalone Node LLM Experiments SDK into dd-trace as an
llmobs submodule, exposed as tracer.llmobs.experiments. No new runtime
dependency — all backend calls go through the global fetch client from
the spike, sourcing DD_API_KEY / DD_APP_KEY / site from tracer config.
- dataset.js / experiment.js / result.js: Dataset + DatasetRecord,
Experiment.run() orchestration with inline span/metric builders,
ExperimentResult/Row.
- index.js: Experiments facade (createDataset, pullDataset with
exponential backoff, experiment()) + createExperiments gating.
- noop.js: NoopExperiments for when llmobs is disabled or keys are
missing; wired into both the LLMObs SDK and its noop.
- index.d.ts: llmobs.Experiments / Dataset / Experiment / ExperimentResult types.
- tests: mocha/sinon specs for client, dataset+experiment run, and the
facade (23 passing); plus a manual end-to-end example script.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(llmobs): cover experiments error paths and branches
Raises patch coverage on the experiments module to ~99.7% lines: adds
tests for dataset getters + DatasetRecord instances, non-array push
response padding, dataset/records/experiment create failures, the
failed-status path when posting events errors, categorical stringify
branches, experiment getters, the client `site` getter, the facade
createDataset/experiment factories, the no-op operations, and
pullDataset list-error and expected-count-not-met errors.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(llmobs): generate experiment span/trace ids with the tracer's own id module
Reuse the same root-span convention as opentracing/span.js (a single random
64-bit span id, reused as the trace id's low 64 bits with a start-time-derived
high part) instead of a bespoke 32-char hex id shared between span and trace.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* fix(llmobs): mark an experiment failed when any row or evaluation errors
A task/evaluator error is isolated per row (the run doesn't abort), but the
experiment status still reported "completed" even when rows failed. Track
whether any row hit an error and report the experiment as "failed" overall
in that case.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* fix(llmobs): don't drop records pushed mid-flight, report push status
Dataset#push() advanced #pushedCount to the live records length after
awaiting the records POST, so a record added while that POST was in
flight would be silently skipped by the next push. Advance by the
snapshotted pending count instead.
Also read created records from the append-records response's top-level
`records` field (it doesn't use the usual `data` envelope), and resolve
push()/ensureCreatedAndPushed() with { pushedCount, totalCount } so
callers can confirm a push landed fully.
* chore(llmobs): mirror the experiments type surface into index.d.v5.ts
Datasets & Experiments interfaces were added to index.d.ts (v6) but not
yet to the frozen v5 type surface, so v5 consumers had no types for
tracer.llmobs.experiments. Mirror the same interfaces (Dataset,
Experiment, Experiments, DatasetPushResult, etc.) into index.d.v5.ts.
* fix(llmobs): follow pagination when pulling dataset records
pullDataset() only fetched the first page of a dataset's records
endpoint, so a dataset with more records than fit on one page returned
a silently truncated Dataset, and polling for an expectedRecordCount
beyond the first page reread the same page until the wait budget
expired. Follow the response's meta.after cursor via page[cursor]
until the last page.
* fix(llmobs): throw an actionable error when no project name is configured
createExperiments() already falls back to config.service when
llmobs.mlApp isn't set, but if neither is set it silently sent an empty
project name to the backend and failed with a confusing "Failed to
create or get project" error. Gate on it up front and return a
NoopExperiments (consistent with the disabled/missing-keys gates) that
tells the user exactly which env var or tracer.init() option to set
before retrying.
* fix(llmobs): classify evaluator metrics to match dd-trace-py
Object-valued evaluator results were stringified into a single opaque
categorical value instead of using metric_type "json", making them
unreadable in the UI. Mirror dd-trace-py's
_generate_metric_from_evaluation classification: dicts (plain objects)
become json, everything else non-primitive (including arrays) falls
through to categorical with a lowercased string representation.
* fix(llmobs): propagate the underlying error when pulling dataset records fails
pullDataset() previously swallowed a records-fetch error into a
successful empty Dataset whenever expectedRecordCount wasn't set,
masking real API/network failures as an empty dataset.
* chore(llmobs): tighten comments in the experiments module
Drop the stale "Spike:" label, orphaned W1/W2 workaround tags, and
version-specific (v0.1) wording; keep the substance each comment was
actually conveying.
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Ruben Bridgewater <ruben@bridgewater.de>
* update openai testing version * introduce new normalization for openai custom file boundaries * test and cassette changes
* ci: update one-pipeline to 1.1.0 * Add new shared-pipeline stages --------- Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com> Co-authored-by: Laplie Anderson <randomanderson@users.noreply.github.com>
…9083) * feat(llmobs): capture audio in messages and OpenAI chat completions Add LLM Observability audio support, mirroring dd-trace-py. J0 foundation: AudioPart on messages with formatAudioPart / audioMimeTypeFromFormat helpers; the tagger validates audioParts (requires mimeType + exactly one of content/attachmentKey) and emits the snake_case wire shape audio_parts: [{mime_type, content|attachment_key}]. Public TS types added to index.d.ts and index.d.v5.ts. J1a OpenAI chat: add the multimodal chat content flattener (extractContentParts) and wire input audio + non-streamed output audio into _tagChatCompletion. Model-agnostic (gpt-audio*, gpt-4o-audio-preview). Defensive guards in the audio helpers so a malformed auto-instrumented payload soft-skips instead of throwing (which would disable the plugin). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(llmobs): cover audio parity branches; tag audio validation errors Address review findings: - Tag non-string audio content/attachmentKey failures with `invalid_io_messages` so they're categorized in annotation telemetry (was routed through #tagConditionalString, which omits the tag). - Add tests for the input-flattening behavior change (text + image_url chat input) and the output-audio no-data transcript fallback, with cassettes. - Add unit tests for audioMimeTypeFromFormat, formatAudioPart, and the extractContentParts flattener (image/audio-with-data/[audio]-fallback/ multiple/unknown-type), pinning parity with dd-trace-py. - Note formatAudioPart's supported binary input shapes (Buffer/Uint8Array). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Apply suggestions from code review Co-authored-by: Zachary Groves <32471391+ZStriker19@users.noreply.github.com> * chore(llmobs): trim formatAudioPart comment Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(llmobs): include sampling tags in audio annotate assertion Master added LLMObs span sampling (`_ml_obs.sample_rate` / `_ml_obs.sampling_decision` on every annotated span). Update the audio annotate test to expect them, matching the sibling annotate tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * refactor(llmobs): address review feedback on audio support - Drop `attachmentKey` from the public AudioPart type (backend-only concept the SDK never emits); make `content` required. - Make `audioMimeTypeFromFormat(fmt, mimeTypeLookup)` provider-agnostic in util.js; move the OpenAI mp3->audio/mpeg map into the openai plugin. - Use the raw `part.text` in extractContentParts. - Re-record the OpenAI audio/image cassettes against the real API (realistic headers); keep the hand-authored synthetic no-audio-data cassette with a note. - Fold the extractContentParts coverage into openaiv4.spec.js and remove the standalone openai utils.spec.js. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore: remove accidentally committed node_modules symlink and review artifact The node_modules symlink (local test scaffolding) and codex_review markdown were committed by mistake; the symlink was breaking CI. Neither belongs in the repo. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Sam Brenner <106700075+sabrenner@users.noreply.github.com>
Overall package sizeSelf size: 7.48 MB Dependency sizes| name | version | self size | total size | |------|---------|-----------|------------| | import-in-the-middle | 3.3.2 | 124.41 kB | 440.65 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | dc-polyfill | 0.1.11 | 25.74 kB | 25.74 kB |🤖 This report was automatically generated by heaviest-objects-in-the-universe |
There was a problem hiding this comment.
More details
No diff-only production regression was identified in the highest-risk runtime paths. Anthropic lifecycle blocking and raw-response handling, agentless Feature Flag polling and retry behavior, and both loader entry modes behaved correctly under adversarial local scenarios.
📊 Validated against 138 scenarios · Open Bits AI session
🤖 Datadog Autotest · Commit 5f3fc6b · What is Autotest? · Any feedback? Reach out in #autotest
BenchmarksBenchmark execution time: 2026-07-22 22:49:41 Comparing candidate commit 10d5625 in PR branch Found 9 performance improvements and 1 performance regressions! Performance is the same for 2306 metrics, 42 unstable metrics.
|
🎉 All green!🧪 All tests passed 🎯 Code Coverage (details) 🔗 Commit SHA: 10d5625 | Docs | Datadog PR Page | Give us feedback! |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5f3fc6b138
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| * a clear message on use. | ||
| */ | ||
| get experiments () { | ||
| this.#experiments ??= createExperiments(this._config) |
There was a problem hiding this comment.
Refresh experiments after LLMObs is toggled
This getter memoizes the experiments facade even when createExperiments() returns a NoopExperiments because LLMObs is currently disabled or missing credentials. Since the existing llmobs.enable()/disable() methods mutate this._config later without clearing #experiments, accessing tracer.llmobs.experiments before programmatic enable leaves the API permanently no-op for that process (and the reverse order can leave a real client after disable). Please avoid caching the disabled facade or reset it when LLMObs configuration changes.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Less critical for now. This is deprecated anyway
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## v5.x #9492 +/- ##
===========================================
+ Coverage 83.19% 98.47% +15.28%
===========================================
Files 476 940 +464
Lines 20153 126880 +106727
Branches 0 10935 +10935
===========================================
+ Hits 16766 124945 +108179
+ Misses 3387 1935 -1452 Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Couchbase 4.x resolves cluster connect before the bucket KV endpoint is ready, so the first collection call can hit its ambiguous timeout. The KafkaJS payload-size test finished when consumer.run started rather than when eachMessage completed. Timed-out callbacks kept group members alive and made later version cases rebalance indefinitely.
* chore: update eslint unicorn plugin to v65 * fixup! * perf(core): replace split-then-index with an allocation-free getSegment Reading `str.split(sep)[i]` allocates the full segment array, and the unicorn rule's `split(sep, i + 1)[i]` rewrite is worse for a string separator: passing a limit drops V8 off its constant-limit fast path, paying a per-call ToUint32 plus the array allocation. `getSegment` scans with `indexOf` and slices out the one segment the caller wants. Node 24.15 / V8 13.6, 5M ops x 7 trials, drop best+worst: " " [1] helper 24.6ns split 30.6ns (-20%) split+limit 86.6ns "-" [0] helper 25.4ns split 35.9ns (-29%) split+limit 74.3ns "." [0] helper 16.0ns split 36.4ns (-56%) split+limit 67.2ns * test: cover uncovered diff lines from the unicorn v65 rewrite The unicorn autofix touched branches no existing spec exercised: 1. ws: a connection carrying x-forwarded-proto now asserts the server span's http.url resolves to wss, reaching getRequestProtocol's proxy arm (and the getSegment call inside it). 2. oracledb: a callback-form pool.getConnection pins the callback path, which only the promise form covered before. The ai-sdk `messages.findLast(...)` arm is left for the PR author: covering it needs a VCR cassette recorded against a real OPENAI_API_KEY, since the test agent matches cassettes by request body and runs CI in 404-on-miss mode. Test-only, no production code changes. * test(ai): cover the messages.findLast() arm in setTextGenerationTags and setObjectGenerationTags The two methods use promptInfo.messages.findLast() when the caller passes a messages array without a top-level prompt string. Existing tests all use the prompt: '' form, which short-circuits to promptInfo.prompt and leaves lines 234 and 250 uncovered. Both new tests use an inline mock fetch (same pattern as the prompt-cache capture tests), bypassing the VCR proxy so no cassette recording is needed: - generateText with messages: array and three turns verifies that the last user message is extracted as inputValue. - generateObject with output: 'no-schema' and the same messages array verifies the same path in setObjectGenerationTags. Both tests skip ai < 5.0.0 where the mock-fetch provider wiring differs. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * perf(fastify): keep the addHook wrapper allocation-free on the fast path The wrapper declared `wrappedHook (...args)`, which materialises a fresh args array on every fastify hook invocation, including the common case where none of the wrap-fed channels has a subscriber. Forward the `arguments` object untouched on the fast path and copy or index it only in the slow path, so the default request path allocates nothing. * chore(deps): update eslint to v10, unicorn to v68, switch to eslint-plugin-import-x The eslint 9->10 and unicorn 65->68 bumps turn on a large set of new recommended rules. The newly-firing ones are deactivated in the config with per-rule counts, grouped by intent (autofixable follow-up, needs-audit, never-activate), so this bump stays free of production source churn; enabling them is left to follow-ups. Some deactivated rules may surface real bugs (unicorn/no-duplicate-logical-operands, no-duplicate-if-branches, no-loop-iterable-mutation, and the core no-unassigned-vars); their config comments flag them for a focused audit. Changes the bump requires directly: 1. Port the repo's custom eslint rules to the v10 context API; context.getSourceCode() was removed in favour of context.sourceCode. 2. eslint 10 drops Node.js 18, so .nvmrc moves to 22. 3. Rename getRunInChildContextSubtype and drop an unnecessary String.raw to satisfy the two rules kept on (consistent-compound-words, prefer-string-raw). 4. Remove stale unicorn/no-array-for-each disable directives; the rule was renamed to no-for-each, which is deactivated here. * chore: deduplicate yarn.lock * Apply suggestion from @BridgeAR * test(llmobs): use installed OpenAI fixture version The message extraction tests referenced a helper that does not exist, so lint failed before the versioned provider fixture could load. * ci(lint): update validation code for unicorn v68 The validation code landed after the branch's previous base, so Unicorn 68's new checks only surfaced once the branch was rebased. * chore(lint): use Array.at for latest Cypress screenshot handler * test(cypress): cover latest manual screenshot handler * ci(licenses): include deduplicated vendor dependencies npm list represents hoisted transitive packages without a resolved URL. Skipping those entries makes the local license gate report valid attributions as extraneous when the root dependency graph no longer supplies the same package. --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: dd-octo-sts[bot] <200755185+dd-octo-sts[bot]@users.noreply.github.com>
Anthropic raw-response lifecycle handling still has unresolved performance and transport-specific correctness trade-offs under parse/asResponse concurrency. Revert the integration before the v5 release rather than ship incomplete output blocking. Refs: #9219
10d5625
5f3fc6b to
10d5625
Compare
Features
Fixes
BedrockChatLanguageModel#9487Performance
Documentation
Internal (CI, Testing, Benchmarking)