NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3273 most downloaded on npm
Datadog APM tracing client for JavaScript
Last release today
06 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
337 versions withdrawn
withdrawn after publishing
9 years old
742 releases · first in 2018
iast: No HttpOnly vulnerability detection
_dd.iast.enabled=1 metric out of request vulnerabilities tags (#3231)store has value before use it (#3257)One column per quarter.
iast: Add exclusions for weak hash vulnerabilities
pg: do not throw when query contains getter
iast: Detect SSRF vulnerabilities
iast: redact potentially sensitive data from vulnerability evidence
More information about the breaking changes from this release can be found in the migration guide.
jest-jasmine2 (#3046)orphanable options (#3077, #3133)next <10.2 (#3107)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
iast: use variable name as evidence in hardcoded password vulnerability
Do not require appsec modules when disabling appsec if they have not been required before
> This release contains a known issue with Next.js (see #4259 for details). Please upgrade to v3.57.0 or greater if you're using it with a Next.js app
[!WARNING] This release contains a known issue with Next.js (see #4259 for details). Please upgrade to v3.57.0 or greater if you're using it with a Next.js application.
apm: add support for oracledb 6
asm-iast: Reduce object iterations in NoSQL vulnerabilities
> This version of the library contains a memory leak when IAST is enabled. Please upgrade to a newer version.
[!WARNING] This version of the library contains a memory leak when IAST is enabled. Please upgrade to a newer version.
> This version of the library contains a memory leak when IAST is enabled. Please upgrade to a newer version.
[!WARNING] This version of the library contains a memory leak when IAST is enabled. Please upgrade to a newer version.
core: Update DSM encoding / decoding to work with other languages and use base64
profiling: Use new intake format for profiles
cypress open when passing experimentalInteractiveRunEvents: true (#4083)jest with a custom test sequencer (#4088)after:run directly in cypress (#4090)asm: Avoid Max call stack size exceeded on vulnerability format
asm: Fix location in mysql vulnerability
evp_proxy/v4 (gzip compatible) (#3998)--forceExit (#4049)lodash: Remove reliance on vulnerable lodash.pick dependency (#3999), thanks @Nico385412 for the original PR and for notifying us
lodash: Remove reliance on vulnerable lodash.pick dependency (#3999), thanks @Nico385412 for the original PR and for notifying us
asm: fix mquery vulnerability location (#3797)
dsm: add support for sqs/sns/kinesis in aws-sdk (#3864)
iast: Added support for weak randomness vulnerability
requestOptions object (#3959)profiling: Add experimental CPU profiler
core: Add remote config support for custom tags
pino: ignore pino error tests when node version is 21
appsec: use existing response header instrumentation to detect Header Injection vulnerability when a unsafe string is written in a header
[!WARNING] This version of the library contains a memory leak with outbound HTTP requests. Please upgrade to a newer version.
require_git field is true (#3790)http service configuration option enablePropagationWithAmazonHeaders (#3836)core: always propagate tracestate when tracecontext is configured
core: modified telemetry.enabled to comply with instrumentation telemetry specs
@datadog/native-appsec (#3778)dc-polyfill instead of diagnostics_channel directly (#3722)core: fix next.js build errors by refactoring config
DD_GIT_REPOSITORY_URL (#3744)Fixed a problem with release scripts (#3697, #3723)
appsec: Fix SQLi location when using knex
HTTP_REQUEST_PATH to HTTP_REQUEST_URI (#3644)core: fix errors from object shape of pg query being altered
_dd.base_service tag (#3557)appsec: Fix LDAPi vulnerability location
asm-iast: Modify vulnerability location using js file sourcemap
appsec: Add vulnerabilities loaded before starting recollect
core: add webpack5 for nextjs v9.5
iast: fix vulnerability location with pg.Pool
update import-in-the-middle to 1.4.2
core: fix flush interval in serverless environments other than aws lambda
Your coding agent can read these notes before it upgrades. Set up the MCP server →