Skip to content

Conversation

@uurien
Copy link
Collaborator

@uurien uurien commented Oct 24, 2025

What does this PR do?

Motivation

Plugin Checklist

Additional Notes

@github-actions
Copy link

github-actions bot commented Oct 24, 2025

Overall package size

Self size: 13.15 MB
Deduped: 115.95 MB
No deduping: 118.16 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | @datadog/libdatadog | 0.7.0 | 35.02 MB | 35.02 MB | | @datadog/native-appsec | 10.3.0 | 20.73 MB | 20.74 MB | | @datadog/native-iast-taint-tracking | 4.0.0 | 11.72 MB | 11.73 MB | | @datadog/pprof | 5.11.1 | 9.96 MB | 10.34 MB | | @opentelemetry/core | 1.30.1 | 908.66 kB | 7.16 MB | | protobufjs | 7.5.4 | 2.95 MB | 5.82 MB | | @datadog/wasm-js-rewriter | 4.0.1 | 2.85 MB | 3.58 MB | | @opentelemetry/resources | 1.9.1 | 306.54 kB | 1.74 MB | | @datadog/native-metrics | 3.1.1 | 1.02 MB | 1.43 MB | | @opentelemetry/api-logs | 0.207.0 | 201.39 kB | 1.42 MB | | @opentelemetry/api | 1.9.0 | 1.22 MB | 1.22 MB | | jsonpath-plus | 10.3.0 | 617.18 kB | 1.08 MB | | import-in-the-middle | 1.15.0 | 127.66 kB | 856.24 kB | | lru-cache | 10.4.3 | 804.3 kB | 804.3 kB | | @datadog/openfeature-node-server | 0.1.0-preview.12 | 95.11 kB | 401.68 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | source-map | 0.7.6 | 185.63 kB | 185.63 kB | | pprof-format | 2.2.1 | 163.06 kB | 163.06 kB | | @datadog/sketches-js | 2.1.1 | 109.9 kB | 109.9 kB | | lodash.sortby | 4.7.0 | 75.76 kB | 75.76 kB | | ignore | 7.0.5 | 63.38 kB | 63.38 kB | | istanbul-lib-coverage | 3.2.2 | 34.37 kB | 34.37 kB | | rfdc | 1.4.1 | 27.15 kB | 27.15 kB | | dc-polyfill | 0.1.10 | 26.73 kB | 26.73 kB | | @isaacs/ttlcache | 1.4.1 | 25.2 kB | 25.2 kB | | tlhunter-sorted-set | 0.1.0 | 24.94 kB | 24.94 kB | | shell-quote | 1.8.3 | 23.74 kB | 23.74 kB | | limiter | 1.1.5 | 23.17 kB | 23.17 kB | | retry | 0.13.1 | 18.85 kB | 18.85 kB | | semifies | 1.0.0 | 15.84 kB | 15.84 kB | | jest-docblock | 29.7.0 | 8.99 kB | 12.76 kB | | crypto-randomuuid | 1.0.0 | 11.18 kB | 11.18 kB | | ttl-set | 1.0.0 | 4.61 kB | 9.69 kB | | mutexify | 1.4.0 | 5.71 kB | 8.74 kB | | path-to-regexp | 0.1.12 | 6.6 kB | 6.6 kB | | module-details-from-path | 1.0.4 | 3.96 kB | 3.96 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@codecov
Copy link

codecov bot commented Oct 24, 2025

Codecov Report

❌ Patch coverage is 47.61905% with 11 lines in your changes missing coverage. Please review.
✅ Project coverage is 73.66%. Comparing base (e955673) to head (6812507).

Files with missing lines Patch % Lines
packages/datadog-instrumentations/src/express.js 0.00% 5 Missing ⚠️
...c/appsec/iast/analyzers/path-traversal-analyzer.js 25.00% 3 Missing ⚠️
packages/dd-trace/src/appsec/rasp/lfi.js 75.00% 3 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff             @@
##           master    #6739       +/-   ##
===========================================
- Coverage   84.04%   73.66%   -10.39%     
===========================================
  Files         506      301      -205     
  Lines       21240    11098    -10142     
===========================================
- Hits        17851     8175     -9676     
+ Misses       3389     2923      -466     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@datadog-datadog-prod-us1
Copy link

datadog-datadog-prod-us1 bot commented Oct 24, 2025

⚠️ Tests

⚠️ Warnings

🧪 7 Tests failed

path-traversal-analyzer Analyzer should be subscribed to proper channel from path-traversal-analyzer (Datadog)
expected [ Subscription{ …(2) }, …(1) ] to have a length of 1 but got 2

AssertionError: expected [ Subscription{ …(2) }, …(1) ] to have a length of 1 but got 2
    at Context.<anonymous> (packages\dd-trace\test\appsec\iast\analyzers\path-traversal-analyzer.spec.js:77:58)
    at process.processImmediate (node:internal/timers:505:21)

      + expected - actual

      -2
      +1
RASP - lfi with express >=4.0.0 <4.3.0 (4.0.0) with ejs 3.1.10 (3.1.10) lfi test with express render rule is eval only once and rendering file accesses are ignored should block param from the request from rule is eval only once and rendering file accesses are ignored (Datadog)
expected 2 to equal 1

AssertionError: expected 2 to equal 1
    at /home/runner/work/dd-trace-js/dd-trace-js/packages/dd-trace/test/appsec/rasp/utils.js:22:12
    at handler (packages/dd-trace/test/plugins/agent.js:349:22)
    at /home/runner/work/dd-trace-js/dd-trace-js/packages/dd-trace/test/plugins/agent.js:225:7
    at Set.forEach (<anonymous>)
    at handleTraceRequest (packages/dd-trace/test/plugins/agent.js:221:17)
    at /home/runner/work/dd-trace-js/dd-trace-js/packages/dd-trace/test/plugins/agent.js:429:7
    at Layer.handleRequest (node_modules/router/lib/layer.js:152:17)
...
RASP - lfi with express >=4.0.0 <4.3.0 (4.2.0) with ejs 3.1.10 (3.1.10) lfi test with express render rule is eval only once and rendering file accesses are ignored should block param from the request from rule is eval only once and rendering file accesses are ignored (Datadog)
expected 2 to equal 1

AssertionError: expected 2 to equal 1
    at /home/runner/work/dd-trace-js/dd-trace-js/packages/dd-trace/test/appsec/rasp/utils.js:22:12
    at handler (packages/dd-trace/test/plugins/agent.js:349:22)
    at /home/runner/work/dd-trace-js/dd-trace-js/packages/dd-trace/test/plugins/agent.js:225:7
    at Set.forEach (<anonymous>)
    at handleTraceRequest (packages/dd-trace/test/plugins/agent.js:221:17)
    at /home/runner/work/dd-trace-js/dd-trace-js/packages/dd-trace/test/plugins/agent.js:429:7
    at Layer.handleRequest (node_modules/router/lib/layer.js:152:17)
...
View all

ℹ️ Info

❄️ No new flaky tests detected

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 6812507 | Docs | Datadog PR Page | Was this helpful? Give us feedback!

@pr-commenter
Copy link

pr-commenter bot commented Oct 24, 2025

Benchmarks

Benchmark execution time: 2025-10-29 14:03:35

Comparing candidate commit 6812507 in PR branch ugaitz/evaluate-lfi-on-render with baseline commit e955673 in branch master.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 1603 metrics, 67 unstable metrics.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants