NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3273 most downloaded on npm
Datadog APM tracing client for JavaScript
Last release today
06 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
337 versions withdrawn
withdrawn after publishing
9 years old
742 releases · first in 2018
\[`fcc318497b`] - (SEMVER-PATCH) fix langchain tests trying to run on unsupported node (Roch Devost) #4926
fcc318497b] - (SEMVER-PATCH) fix langchain tests trying to run on unsupported node (Roch Devost) #4926f64f306790] - (SEMVER-PATCH) fix missing commands in denylist by allowing all (Roch Devost) #49220bd54869a5] - (SEMVER-PATCH) add package manager symlinks to denylist (Bryan English) #49210bade65244] - (SEMVER-PATCH) update crashtracker timeout to 5 seconds (Roch Devost) #49206080dfa24c] - (SEMVER-PATCH) Abstract the passing of extracted header span links to startSpan (mhlidd) #4918d0e80ea9b7] - (SEMVER-PATCH) next.js: complete v14.x compatibility (fixing >=14.2.7) (Thomas Hunter II) #4916747cd5078f] - (SEMVER-PATCH) [ASM] Discard inferred spans when resolving the root span of a trace (Igor Unanua) #488170a2c22330] - (SEMVER-PATCH) fix crashtracker not working with uds (Roch Devost) #4917c8ab3e4440] - (SEMVER-MINOR) [MLOB-1804] feat(langchain): add langchain instrumentation (Sam Brenner) #48607408b1c04d] - (SEMVER-MINOR) Add profiler API telemetry metrics (Attila Szegedi) #4832204eb3514b] - (SEMVER-PATCH) fix release notes always flagged as latest (Roch Devost) #491004ad3927cd] - (SEMVER-PATCH) fix release script hanging on applying new changes (Roch Devost) #4908One column per quarter.
\[`985cb1db96`] - (SEMVER-MINOR) Template injection vulnerability detection in handlebars and pug (ishabi) #4827
add2338291] - (SEMVER-PATCH) Increase timeout on RASP integration test for windows (Carles Capell) #4907920d2a2768] - (SEMVER-PATCH) [test optimization] Report code coverage relative to the repository root, not the project's root dir or working directory (Juan Antonio Fernández de Alba) #4903a41951c2c6] - (SEMVER-MINOR) log template messages and errors (Igor Unanua) #48569c081c81d2] - (SEMVER-PATCH) disable merge queue (Bryan English) #49056392a2e12b] - (SEMVER-MINOR) [serverless] Add S3 Span Pointers (Nicholas Hulston) #48752072a1f0e7] - (SEMVER-PATCH) improve output for release proposal script (Roch Devost) #48979de411aa0c] - (SEMVER-PATCH) automate release notes from github actions (Roch Devost) #4893f0df061a4b] - (SEMVER-MINOR) Adding Span Link support for distributed tracing header extractions with invalid traces (mhlidd) #487461c5a3218e] - (SEMVER-PATCH) Upgrade cross-spawn to v7.0.5 - patched ReDoS (Carles Capell) #4899bdbeb024b0] - (SEMVER-MINOR) add support to api security sampling (ishabi) #47551670ef921d] - (SEMVER-PATCH) Adding new ST scenarios for rasp (Ugaitz Urien) #4883170a97cc95] - (SEMVER-MINOR) Update WAF rules and bindings (Carles Capell) #489151bea5452e] - (SEMVER-PATCH) [DSM] Set checkpoints for DSM even when there is no context if the service is instrumented and fix typo (Eric Firth) #4851a8896ee676] - (SEMVER-PATCH) update release script to also create pr (Roch Devost) #488025ae8e737e] - (SEMVER-PATCH) Ignore elasticsearch 8.16.0 from esm tests (Ugaitz Urien) #4892985cb1db96] - (SEMVER-MINOR) Template injection vulnerability detection in handlebars and pug (ishabi) #482759e9a2a75f] - (SEMVER-PATCH) [test optimization] Fix active span being null in cypress (Juan Antonio Fernández de Alba) #48639146f26c93] - (SEMVER-PATCH) Remove x-forwarded from ipHeaderList (simon-id) #488283e11a3e13] - (SEMVER-PATCH) add namespace support for async storage (Roch Devost) #47751ce47d2ba0] - (SEMVER-PATCH) chore(llmobs): tracer version tagging (Sam Brenner) #48857addced607] - (SEMVER-MINOR) add crashtracking with libdatadog native binding (Roch Devost) #469236903cc982] - (SEMVER-PATCH) skip warning if propagator is baggage (Ida Liu) #48669794630aa0] - (SEMVER-PATCH) add more node version test to unsupported guardrails matrix (Roch Devost) #48791e1a2a1014] - (SEMVER-PATCH) add guardrail to completely bail out in very old versions (Roch Devost) #487829ff735a64] - (SEMVER-MINOR) feat(tracing): AWS API Gateway Inferred Span Support (William Conti) #4837b81d9d84bf] - (SEMVER-MINOR) Prevent errors in Express 5.x applications (wantsui) #48720a44e6e4dc] - (SEMVER-PATCH) Have one version tag in metrics (Attila Szegedi) #48570a411ee6e1] - (SEMVER-PATCH) add release proposal script for use locally (Roch Devost) #485370e99bd56b] - (SEMVER-MINOR) Add exclusions for header injection vulnerability (Carles Capell) #4841367bd2d65c] - (SEMVER-PATCH) Discard non-web traces when searching for a vulnerability not being present (Carles Capell) #48711ee8000111] - (SEMVER-PATCH) Revert "always enable tracing header injection for AWS requests (#4717)" (Thomas Hunter II) #4867\[`168d662c9f`] - (SEMVER-PATCH) Fix header injection vulnerability detection for access-control-allow-origin (Carles Capell) #4844
ff9b02b769] - (SEMVER-PATCH) update AWS payload extraction rules (Thomas Hunter II) #48598112f6cd4a] - (SEMVER-PATCH) simplify baggage code and add test case (Ida Liu) #48580b4dab7181] - (SEMVER-MINOR) [test visibility] Simple dynamic instrumentation - test visibility client (Juan Antonio Fernández de Alba) #4826497ff72317] - (SEMVER-MINOR) Support url.parse, url.URL.parse and new url.URL for IAST taint tracking (Ugaitz Urien) #48365028d30503] - (SEMVER-PATCH) Onboarding tests: simple installer scenario (Roberto Montero) #4855b8af762cc9] - (SEMVER-PATCH) fix incompatibilities with node 16 for 4.49.0 release (Roch Devost) #4854f58e7461bf] - (SEMVER-MINOR) Baggage support (Ida Liu) #456383fcef6806] - (SEMVER-MINOR) Profiling code to presume at least Node 16 (Attila Szegedi) #43356c1c075b17] - (SEMVER-MINOR) Exploit prevention Shell injection (Ugaitz Urien) #4792c03d608753] - (SEMVER-MINOR) Fix amqp instrumentation (Piotr WOLSKI) #483928eb9582cc] - (SEMVER-PATCH) add yarn env <plugin-name> (Bryan English) #48521188ea24df] - (SEMVER-PATCH) add some clarity in CONTRIBUTING.md (Bryan English) #485057f8a10ae8] - (SEMVER-PATCH) fix(ci): revert typescript 5.0 for docs tests (Sam Brenner) #4846b3e2077af7] - (SEMVER-PATCH) upgrade to latest @azure/functions version (Ayan Khan) #4845b1a106b58b] - (SEMVER-MINOR) [MLOB-1562] feat(llmobs): add openai integration (Sam Brenner) #48404edba95dd4] - (SEMVER-PATCH) Defend against ref being undefined (Attila Szegedi) #4831168d662c9f] - (SEMVER-PATCH) Fix header injection vulnerability detection for access-control-allow-origin (Carles Capell) #48449e65a80db0] - (SEMVER-MINOR) add dsm for google pub sub (William Conti) #385570ec90e19e] - (SEMVER-PATCH) update native metrics to 3.0.1 (Roch Devost) #483891c43717be] - (SEMVER-MINOR) Add support for exit spans in Code Origin for Spans (Thomas Watson) #4772111c14a43d] - (SEMVER-PATCH) [DI] Drop snapshot if JSON payload is too large (Thomas Watson) #48181c0958e2af] - [MLOB-1524] feat(llmobs): Introduce LLM Observability SDK (Sam Brenner) #4773e94c68220c] - (SEMVER-MINOR) [ASM] multer instrumentation (Igor Unanua) #478149d6c584f7] - (SEMVER-PATCH) [DI] Adhere to maxFieldCount limit in snapshots (Thomas Watson) #48292a4b80da47] - (SEMVER-MINOR) Update WAF recommended rules to v1.13.2 (Carles Capell) #48344a711d9a23] - (SEMVER-MINOR) Replace manual.keep tag usage with an specific method to keep the trace (Igor Unanua) #4739564795fbe9] - (SEMVER-MINOR) [test visibility] Add dynamic instrumentation logs writer for test visibility (Juan Antonio Fernández de Alba) #4821a8721751e4] - (SEMVER-MINOR) Profiler shouldn't retry some HTTP requests when sending profiles (Attila Szegedi) #482324e846e35a] - (SEMVER-PATCH) [DI] Refactor integration tests (Thomas Watson) #4817a0816597f2] - (SEMVER-MINOR) feat(kafkajs): add kafka cluster id to spans and dsm metrics (William Conti) #4808c0073549cf] - (SEMVER-MINOR) Update @datadog/native-iast-taint-tracking (Ugaitz Urien) #4824fcecd865bf] - (SEMVER-MINOR) Separating Plugin Tests to Their Own CI Run (Crystal Magloire) #4822c53c395706] - (SEMVER-PATCH) Protect some lines in text_map.js (Ugaitz Urien) #48202387d265be] - (SEMVER-MINOR) Support Node 23 in the profiler (Attila Szegedi) #4815aff335da1d] - (SEMVER-PATCH) [DI] Guard against invalid probe config and related edge-cases (Thomas Watson) #481681d6947b53] - (SEMVER-MINOR) [test visibility] Add errors in retried tests in mocha (Juan Antonio Fernández de Alba) #481331ab8e5af2] - (SEMVER-MINOR) Add support for Azure App Services tags in profiler (Attila Szegedi) #4803a16a051592] - (SEMVER-PATCH) add requirements json with native deps and denylist (Roch Devost) #475315ab272a70] - (SEMVER-MINOR) Add Support For Overriding GRPC Error Statuses (Ayan Khan) #4800c4e39793dd] - (SEMVER-MINOR) refactor system tests (William Conti) #4811e7edfcffaf] - (SEMVER-PATCH) [DI] Adhere to maxCollectionSize limit in snapshots (Thomas Watson) #47807f812e19e2] - (SEMVER-MINOR) Update native-appsec to 8.2.1 (Ugaitz Urien) #4810c8be435751] - (SEMVER-PATCH) also audit devDependencies (Bryan English) #4807145b41c79c] - (SEMVER-PATCH) Fix yarn.lock (Thomas Watson) #480931dc1ec543] - (SEMVER-PATCH) [CI] Enable Fastify suite.js (Thomas Watson) #47711522a483bd] - (SEMVER-MINOR) Implement Config Consistency (Ayan Khan) #4725597d7c5741] - (SEMVER-PATCH) Fix: esbuild plugin when requiring esm files (Crystal Magloire) #47746e21f9af90] - (SEMVER-MINOR) Identify span metrics from OpenTelemetry libraries with 'otel.library' tag (Stuart McCulloch) #47245e4900d794] - (SEMVER-PATCH) don't update waf version if it dosn't exist (simon-id) #48014f62b5ad9f] - (SEMVER-PATCH) [ASM] Ssrf handle request options (Igor Unanua) #479183468b8d82] - (SEMVER-PATCH) fix WAF update rules version (simon-id) #4798\[`e4532439c2`] - (SEMVER-PATCH) Upgrading jsonpath-plus to v10 to resolve CVE-2024-21534 (Thomas Watson) #4782
89619bdf46] - (SEMVER-PATCH) update body-parser (Bryan English) #4790d7b1dad805] - (SEMVER-PATCH) pin latest to 22 (Bryan English) #4793f8515ec28b] - (SEMVER-PATCH) Remove old debug option from docs (simon-id) #478659eb9a724a] - (SEMVER-PATCH) Don't stop the profiler if encoding a profile fails (Attila Szegedi) #47798969e05336] - (SEMVER-PATCH) vendor jsonpath-plus (Bryan English) #4785501ff2fbfb] - (SEMVER-MINOR) Suspicious request blocking - Express Path Parameters (Carles Capell) #4769e4532439c2] - (SEMVER-PATCH) Upgrading jsonpath-plus to v10 to resolve CVE-2024-21534 (Thomas Watson) #4782944f57d5d4] - (SEMVER-PATCH) [DI] Refactor unit tests (Thomas Watson) #4777f62cbfadc7] - (SEMVER-PATCH) Unsubscribe NextJS body and query channels on appsec disable (Carles Capell) #4776c085df1eae] - (SEMVER-MINOR) Add support for Fastify entry spans for Code Origin for Spans (Thomas Watson) #4449bd4aff563f] - (SEMVER-MINOR) Update waf rules to 1.13.1 (Ugaitz Urien) #47685a113b2bcd] - (SEMVER-MINOR) Add Plugin for @azure/functions (Duncan Harvey) #4716ce0bdcea6e] - (SEMVER-MINOR) Fix capability identifier (Igor Unanua) #476760529442d2] - (SEMVER-MINOR) Use static vulnerability hash source when the cookie name is too long (Ugaitz Urien) #47645eea208392] - (SEMVER-MINOR) [test visibility] Add option to automatically report logs within tests when using winston (Juan Antonio Fernández de Alba) #47622d175d30d5] - (SEMVER-MINOR) Keep a profiling context object in spans (Attila Szegedi) #4763a2b318df27] - (SEMVER-MINOR) [ASM] Add support for attacker fingerprinting (Carles Capell) #4698111a156693] - (SEMVER-PATCH) Exploit Prevention LFI (Igor Unanua) #4715a11a1fd20e] - (SEMVER-MINOR) Upgrade iast rewriter to 2.5.0 (Igor Unanua) #47617f93d36b79] - (SEMVER-PATCH) use AsyncLocalStorage instead of our home-grown solutions (Bryan English) #4201bba5f3ddb3] - (SEMVER-MINOR) feat(dsm): implement avro schemas for avsc package (William Conti) #472608525d4c3c] - (SEMVER-MINOR) feat(tracing): implement protobufjs DSM schema support (William Conti) #4701d024777515] - (SEMVER-MINOR) [DI] Add ability to take state snapshot feature (Thomas Watson) #4549a00c9c8361] - (SEMVER-MINOR) Sql injection Exploit Prevention implementation for mysql2 library (Ugaitz Urien) #4712d1abcab7a1] - (SEMVER-MINOR) [DI] Add hostname to probe result (Thomas Watson) #4756d1f29dba99] - (SEMVER-PATCH) Fix appsec rate limiter flaky test (Ugaitz Urien) #4754eef6711411] - (SEMVER-PATCH) Fix child process not maintaining previous parent span after execution (Ugaitz Urien) #4752c700341689] - (SEMVER-PATCH) prefix system-tests env var names (William Conti) #4746f988e003bf] - (SEMVER-MINOR) [DI] Add GitHub repo and SHA tags to probe results (Thomas Watson) #4751e09305d366] - (SEMVER-PATCH) [DI] Fix probe.location.lines to be string[] instead of number[] (Thomas Watson) #4750748ef616c3] - (SEMVER-PATCH) [DI] Switch unit tests to Mocha instead of Tap (Thomas Watson) #472870d5591d9b] - (SEMVER-MINOR) [test visibility] Read pull_request and pull_request_target event info from GHA (Juan Antonio Fernández de Alba) #47454d2f5b86a0] - (SEMVER-PATCH) Don't use deprecated url.parse function (Thomas Watson) #474392515a65e3] - (SEMVER-MINOR) [DI] Add stack trace to log probe results (Thomas Watson) #4727[29c42f144466bc929beedda8c9e7744195823918] Update workflows to fix release process
[f229d64e4c59e434b1138913e006f3df27e7f8ca] - aws payload tagging (Thomas Hunter II) https://github.com/DataDog/dd-trace-js/pull/4309
[ab80d703c1] - fix(lambda): gate timeout spans and add missing clear (jordan gonzález) https://github.com/DataDog/dd-trace-js/pull/4446
@datadog/native-appsec to 8.1.1 (Carles Capell) https://github.com/DataDog/dd-trace-js/pull/4630[core] Fix ALS continuation bug in body-parser
all input (#4568)iast: Add support for Code Injection vulnerability detection
[appsec] Update waf obfuscator key regex #4498
[appsec]: Update appsec rules to 1.12.0 #4398
DD_EXPERIMENTAL_APPSEC_STANDALONE_ENABLED #4291, #4416batchPropagationEnabled configuration option to inject all messages with trace context during AWS SQS, SNS, and Kinesis batch send operations #4434core: RecordException api now supports adding exceptions as span events
graphql: fix graphql.resolve span durations
Remove outdated polyfills #4009
debug warnings when init after instrumented packages
core: Add child_process plugin to typings (#4306), thanks to @ikonst for the original PR
iast: use variable name as evidence in hardcoded password vulnerability
Do not require appsec modules when disabling appsec if they have not been required before
> This release contains a known issue with Next.js (see #4259 for details). Please upgrade to v5.12.0 or greater if you're using it with a Next.js app
[!WARNING] This release contains a known issue with Next.js (see #4259 for details). Please upgrade to v5.12.0 or greater if you're using it with a Next.js application.
apm: add support for oracledb 6
asm-iast: Reduce object iterations in NoSQL vulnerabilities
> This version of the library contains a memory leak when IAST is enabled. Please upgrade to a newer version.
[!WARNING] This version of the library contains a memory leak when IAST is enabled. Please upgrade to a newer version.
> This version of the library contains a memory leak when IAST is enabled. Please upgrade to a newer version.
[!WARNING] This version of the library contains a memory leak when IAST is enabled. Please upgrade to a newer version.
core: Update DSM encoding / decoding to work with other languages and use base64
profiling: Use new intake format for profiles
cypress open when passing experimentalInteractiveRunEvents: true (#4083)jest with a custom test sequencer (#4088)after:run directly in cypress (#4090)asm: Avoid Max call stack size exceeded on vulnerability format
asm: Fix location in mysql vulnerability
evp_proxy/v4 (gzip compatible) (#3998)--forceExit (#4049)lodash: Remove reliance on vulnerable lodash.pick dependency (#3999), thanks @Nico385412 for the original PR and for notifying us
lodash: Remove reliance on vulnerable lodash.pick dependency (#3999), thanks @Nico385412 for the original PR and for notifying us
asm: fix mquery vulnerability location (#3797)
dsm: add support for sqs/sns/kinesis in aws-sdk (#3864)
iast: Added support for weak randomness vulnerability
requestOptions object (#3959)More information about the breaking changes from this release can be found in the migration guide.
More information about the breaking changes from this release can be found in the migration guide.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →