NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3273 most downloaded on npm
Datadog APM tracing client for JavaScript
Last release today
06 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
337 versions withdrawn
withdrawn after publishing
9 years old
742 releases · first in 2018
Use naming schema for http, http2, next, fetch, couchbase
http, http2, next, fetch, couchbaseiast: add exclusions for weak hash vulnerabilities
usr.id field being reported (#3442)DD_TRACE_CLIENT_IP_ENABLED option having no effect (#3442)One column per quarter.
serverless: feat: add the lib/core file which each client lib imports directly, s…
None, this is a patch release
None, this is a patch release
iast: Detect missing header vulnerabilities
profiling: Adapt to new pprof-nodejs API
core/redis: peer service extract host and port
core/kafka: add support for data stream monitoring for kafkajs
v0 (#3305)core: add instrumentation for the openai package
ServerPlugins (#3261)iast: No HttpOnly vulnerability detection
_dd.iast.enabled=1 metric out of request vulnerabilities tags (#3231)store has value before use it (#3257)iast: Add exclusions for weak hash vulnerabilities
pg: do not throw when query contains getter
iast: Detect SSRF vulnerabilities
iast: redact potentially sensitive data from vulnerability evidence
core: Revert service naming framework introduction
test_module_id (#3101)test.fixme logic in playwright (#3100)ci-visibility: correctly extract rootDir for playwright >=1.33.0
> ESM support has been temporarily disabled starting from Node 20 as significant changes are in progress.
Warning ESM support has been temporarily disabled starting from Node 20 as significant changes are in progress.
> This version of the library contains a known bug with AppSec IP and User Blocking. Please do not use this version if you want to use this feature.
Warning This version of the library contains a known bug with AppSec IP and User Blocking. Please do not use this version if you want to use this feature.
[iast] Exclude vulnerabilities coming from send module
Warning This version of the library contains a known bug with AppSec IP and User Blocking. Please do not use this version if you want to use this feature.
[appsec] Vulnerability deduplication rework
test.bundle (#2880)network.destination.port for client port tag name (#2826)test.toolchain containing the package manager name and version (#2907)[asm] Don't send blocking response if headers have already been sent
DD_APM_FLUSH_DEADLINE_MILLISECONDS is handled (#2824)[tracing] Fix traceparent version and version propagation #2810
[tracing] Remove resource name truncation with agent
aws-sdk v3 (#2754)cucumber (#2782)cypress (#2783)tracer: Check if channel has subscribers before call unsubscribe
.asyncResource (#2756)### Bugfixes - Fix require("node:fs") bug
appsec: Detect path traversal vulnerabilities
Fix a bug where Lambda plugin would look for package.json from dd-lambda-js, which wasn't needed and could break in some cases #2721
Full Changelog: https://github.com/DataDog/dd-trace-js/compare/v3.12.0...v3.12.1
Create a span for vulnerabilities outside of requests
Full Changelog: https://github.com/DataDog/dd-trace-js/compare/v3.11.0...v3.12.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
> This is the final release of the v2.x series. If you're still using this version it is advised that you upgrade to a more recent version of the libr
Important This is the final release of the v2.x series. If you're still using this version it is advised that you upgrade to a more recent version of the library.
update import-in-the-middle to 1.4.2
core: fix flush interval in serverless environments other than aws lambda
Use naming schema for http, http2, next, fetch, couchbase
http, http2, next, fetch, couchbaseiast: add exclusions for weak hash vulnerabilities
usr.id field being reported (#3442)DD_TRACE_CLIENT_IP_ENABLED option having no effect (#3442)serverless: feat: add the lib/core file which each client lib imports directly, s…
None, this is a patch release
None, this is a patch release
iast: Detect missing header vulnerabilities
profiling: Adapt to new pprof-nodejs API
core/redis: peer service extract host and port
core/kafka: add support for data stream monitoring for kafkajs
v0 (#3305)core: add instrumentation for the openai package
ServerPlugins (#3261)iast: No HttpOnly vulnerability detection
_dd.iast.enabled=1 metric out of request vulnerabilities tags (#3231)store has value before use it (#3257)iast: Add exclusions for weak hash vulnerabilities
Your coding agent can read these notes before it upgrades. Set up the MCP server →