NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #610 most downloaded on PyPI
Datadog APM client library
Last release today
01 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
5 versions withdrawn
withdrawn after publishing
10 years old
853 releases · first in 2017
Ensure IAST SSRF vulnerability redacts the url query parameters correctly.
SCA:
Celery:
Code Security:
Profiling:
One column per quarter.
Ensures that common patches for exploit prevention and SCA are only loaded if required, and only loaded once.
ASM
LLM Observability
Tracing
botocore: Resolves an issue in the Bedrock integration where not consuming the full response stream would prevent spans from finishing.celery: Changes celery out.host span tag to point towards broker host url instead of local celery process hostname. Fixes inferred service representation issues when using celery.grpcaio: Resolves a concurrency bug where distributed tracing headers were overwritten resulting in spans being assigned to the wrong trace.Resolves an issue where some root spans were not appropriately tagged for ASM standalone.
click and jinja2 installed on 3.8 were outside of the allowed minimum versions for autoinstrumentation.Support added for session fingerprints.
ASM
LLM Observability
llm span.chat_model.with_structured_output(..., method="json_mode") is used, or response_format={"type": "json_object"} is passed into a langchain chat model invocation, the LLM Observability span will be an llm span instead of a workflow span.SSI
requirements.json to SSI artifact for bailing out on unsupported systems.Tracing
DD_SERVICE is not set, replacing instances of 'unnamed-python-service'. Ensures that a more meaningful service name is used whenever possible, enhancing clarity in service identification.ASM
DD_DJANGO_INCLUDE_EMAIL (false by default), will tag user events with user email as before.Code Security/IAST
umap, numba and pynndescent to the Code Security denylist.googlecloudsdk and google auth to the Code Security deny list.google.cloud.storage.batch module would fail raising an ImportErrorCrashtracking
Lib-Injection
ddtrace if it is present.sys.argv is not available.LLM Observability
Profiling
DD_PROFILING_STACK_V2_ENABLED was set.DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_TIMELINE_ENABLED or DD_PROFILING_STACK_V2_ENABLED turned off live heap profiling.ensure_binary_or_empty() function, on Python versions before 3.12, with DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.fork() by clearing it in the child process.Span. The mapping is populated and used when DD_PROFILING_ENDPOINT_COLLECTION_ENABLED and DD_PROFILING_STACK_V2_ENABLED were set to enable grouping of profiles for endpoints.Tracing
--ddtrace are no longer skipped when executing tests with pytest. Previously, the algorithm misinterpreted these arguments as standard flags, overlooking possible test paths that may contribute to the inferred service name.botocore: Resolves the issue where the span pointer for deserialized DynamoDB requests (through the resource-based API) were not being generated.botocore: Resolves an issue where our span pointer calculation code added recently logged unactionable messages.pymongo: add type checking to solve an issue where NoneType instead of expected Pin object would throw an error in TracedTopology method.Adds umap, numba and pynndescent to the Code Security denylist.
Code Security
umap, numba and pynndescent to the Code Security denylist.Lib-Injection
Tracing
--ddtrace are no longer skipped when executing tests with pytest. Previously, the algorithm misinterpreted these arguments as standard flags, overlooking possible test paths that may contribute to the inferred service name.Adds support for session fingerprints.
ASM
LLM Observability
llm span.chat_model.with_structured_output(..., method="json_mode") is used, or response_format={"type": "json_object"} is passed into a langchain chat model invocation, the LLM Observability span will be an llm span instead of a workflow span.Single Step Instrumentation
requirements.json to SSI artifact for bailing out on unsupported systems.Tracing
DD_SERVICE is not set, replacing instances of unnamed-python-service. Ensures that a more meaningful service name is used whenever possible, enhancing clarity in service identification.ASM/Threats
DD_DJANGO_INCLUDE_EMAIL (false by default), will tag user events with user email as before.Code Security/IAST
google.cloud.storage.batch module would fail raising an ImportError.Crashtracking
Lib-Injection
ddtrace if it is present.sys.argv is not available.LLM Observability
Profiling
DD_PROFILING_STACK_V2_ENABLED was set.DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_TIMELINE_ENABLED or DD_PROFILING_STACK_V2_ENABLED turned off live heap profiling.ensure_binary_or_empty() function, on Python versions before 3.12, with DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.fork() by clearing it in the child process.Span. The mapping is populated and used when DD_PROFILING_ENDPOINT_COLLECTION_ENABLED and DD_PROFILING_STACK_V2_ENABLED were set to enable grouping of profiles for endpoints.Tracing
NoneType instead of expected Pin object would throw an error in TracedTopology method.Ensure IAST SSRF vulnerability redacts the url query parameters correctly.
SCA:
Code Security:
Lib-Injection:
Profiling
Ensures that common patches for exploit prevention and sca are only loaded if required, and only loaded once.
ASM
Auto-Instrumentation
click and jinja2 installed on python3.8 were outside of the allowed minimum versions for auto-instrumentation.Code Security
LLM Observability
Tracing
botocore: Resolves an issue in the Bedrock integration where not consuming the full response stream would prevent spans from finishing.botocore: Resolves the issue where the span pointer for deserialized DynamoDB requests (through the resource-based API) were not being generated.
Code Security: add umap, numba and pynndescent to the Code Security denylist.
The lock profiler would log a warning if it couldn't determine a name for a lock, and it would try determining a name multiple times for the same lock
Profiling
Tracing
NoneType instead of expected Pin object would throw an error in TracedTopology method.The new user events policy is preventing users PII to be added by default as span tags. To allow customers using the Django auto instrumentation to st
Threats
DD_DJANGO_INCLUDE_EMAIL (false by default), will tag user events with user email as before.Code Security
Crashtracking
Lib-Injection
ddtrace if it is present.LLM Observability
Profiling
DD_PROFILING_STACK_V2_ENABLED was set.ensure_binary_or_empty() function, on Python versions before 3.12, with DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.fork() by clearing it in the child process.When starting LLM and embedding spans, the model_name argument is now optional and will default to custom. This applies to both inline methods (e.g. L
LLM Observability
model_name argument is now optional and will default to custom. This applies to both inline methods (e.g. LLMObs.llm()) and function decorators (e.g. @llm).submit_evaluation method. For more information, see submitting evaluations with the SDK.Tracing
BatchWriteItem spans. Table Primary Keys will need to be provided with the ddtrace.config.botocore.dynamodb_primary_key_names_for_tables option or the DD_BOTOCORE_DYNAMODB_TABLE_PRIMARY_KEYS environment variable to correctly handle the PutRequest items.TransactWriteItems spans. Table Primary Keys will need to be provided with the ddtrace.config.botocore.dynamodb_primary_key_names_for_tables option or the DD_BOTOCORE_DYNAMODB_TABLE_PRIMARY_KEYS environment variable to correctly handle the Put items.ddtrace.config.botocore.add_span_pointers option or the DD_BOTOCORE_ADD_SPAN_POINTERS environment variable to control adding span pointers to some successful AWS API requests. This option is enabled by default.CI Visibility
CODEOWNERS would incorrectly fail to discard line-level trailing comments (eg: @code/owner # my comment would result in codeowners being parsed as @code/owner, #, my, and comment)git binary or .git directory)Code Security
google.cloud.storage.batch module would fail raising an ImportErrorDynamic Instrumentation
LLM Observability
LLMObs.annotate.Profiling
DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_TIMELINE_ENABLED or DD_PROFILING_STACK_V2_ENABLED turned off live heap profiling.Span. The mapping is populated and used when DD_PROFILING_ENDPOINT_COLLECTION_ENABLED and DD_PROFILING_STACK_V2_ENABLED were set to enable grouping of profiles for endpoints.DD_PROFILING_STACK_V2_ENABLED is set.TypeError exception when it is given a Span with None span_type.Tracing
AGENT_CONFIG remote configuration product.LLMObs.annotate is called multiple times on the same span so that the latest value for a tag key overrides the previous value.Nothing published for this version
Nothing published for this version
Ensures that common patches for exploit prevention and sca are only loaded if required, and only loaded once.
ASM
Auto-Instrumentation
click and jinja2 installed on python3.8 were outside of the allowed minimum versions for auto-instrumentation.Code Security
LLM Observability
Tracing
botocore: Resolves an issue in the Bedrock integration where not consuming the full response stream would prevent spans from finishing.The new user events policy is preventing users PII to be added by default as span tags. To allow customers using the Django auto instrumentation to st
ASM:
LLM Observability:
Code Security:
Profiling:
Fixes an issue where cpu-time was not profiled for services using gunicorn, when <span class="title-ref">`DD_PROFILING_STACK_V2_ENABLED</span> was set.
The lock profiler would log a warning if it couldn't determine a
name for a lock, and it would try determining a name multiple times for the same lock. This lead to excessive log spam. Downgrade this to a debug log and only try to determine the name once.
Fixes an issue where the sample pool could deadlock after fork()
by clearing it in the child process.
Fixes an issue where enabling native exporter via DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_TIMELINE_ENABLED or DD_PROFILING_STACK_V2_ENABLED tu
DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_TIMELINE_ENABLED or DD_PROFILING_STACK_V2_ENABLED turned off live heap profiling.ensure_binary_or_empty() function, on Python versions before 3.12, with DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.Span. The mapping is populated and used when DD_PROFILING_ENDPOINT_COLLECTION_ENABLED and DD_PROFILING_STACK_V2_ENABLED were set to enable grouping of profiles for endpoints.DD_PROFILING_STACK_V2_ENABLED is set.NoneType instead of expected Pin object would throw an error in TracedTopology method.Fixes a bug where CODEOWNERS would incorrectly fail to discard line-level trailing comments (eg: @code/owner # my comment would result in codeowners b
CODEOWNERS would incorrectly fail to discard line-level trailing comments (eg: @code/owner # my comment would result in codeowners being parsed as @code/owner, #, my, and comment)git binary or .git directory)google.cloud.storage.batch module would fail raising an ImportError.TypeError exception when it is given a Span with None span_type.Additionally, it improves validations in both the Processor and Vulnerability Reporter, depending on whether IAST is active or not.
LLM Observability
prompt and name arguments to LLMObs.annotation_context to support setting an integration generated span's name and prompt field. For more information on annotation contexts, see the docs here.stream calls on LCEL chains, chat completion models, or completion models. Note that due to an upstream issue with the langchain library itself, streamed responses will not be tagged correctly based on the choice index when the underlying model is configured to return n>1 choices. Please refer to this GitHub issue for more details.llm.stream, chat_model.stream, and chain.stream) submit to LLM Observability.CI Visibility
test_session.name tag to test events. The test session name can be set via the DD_TEST_SESSION_NAME environment variable. If DD_TEST_SESSION_NAME is not specified, the test session name is set from the CI job id and the test command.Tracing
DD_CODE_ORIGIN_FOR_SPANS_ENABLED environment variable to true.DeleteItem spans.PutItem spans. Table Primary Keys need to be provided with the ddtrace.config.botocore.dynamodb_primary_key_names_for_tables option or the DD_BOTOCORE_DYNAMODB_TABLE_PRIMARY_KEYS environment variable.UpdateItem spans.CompleteMultipartUpload spans.DD_TRACE_HTTP_CLIENT_ERROR_STATUSES environment variable to configure the list of HTTP status codes that should be considered errors when instrumenting HTTP servers.DD_TRACE_HTTP_CLIENT_TAG_QUERY_STRING instead of ddtrace.config.http_tag_query_stringDD_TRACE_HEADER_TAGS instead of ddtrace.config.trace_http_header_tagsDD_TRACE_REPORT_HOSTNAME instead of ddtrace.config.report_hostnameDD_TRACE_HEALTH_METRICS_ENABLED instead of ddtrace.config.health_metrics_enabledDD_TRACE_ANALYTICS_ENABLED instead of ddtrace.config.analytics_enabledDD_TRACE_CLIENT_IP_HEADER instead of ddtrace.config.client_ip_headerDD_TRACE_CLIENT_IP_ENABLED instead of ddtrace.config.retrieve_client_ipDD_TRACE_PROPAGATION_HTTP_BAGGAGE_ENABLED instead of ddtrace.config.propagation_http_baggage_enabledDD_TRACE_OBFUSCATION_QUERY_STRING_REGEXP to an empty string instead of setting ddtrace.config.global_query_string_obfuscation_disabled to True (default value is False)DD_TRACE_METHODS instead of ddtrace.config.trace_methodsDD_CIVISIBILITY_LOG_LEVEL instead of ddtrace.config.ci_visibility_log_levelDD_TRACE_SAMPLE_RATE environment variable. It will be removed in 3.0.0. Use DD_TRACE_SAMPLING_RULES to configure sampling rates instead.DD_TRACE_API_VERSION=v0.3 is deprecated. Use v0.4 or v0.5 instead.Code security
_DD_IAST_DEBUG environment variable is enabled or not.re.finditer.LLM Observability
LLMObs.enable() did not patch google_generativeai library.modelId when using cross-region inference.Profiling
DD_PROFILING_STACK_V2_ENABLED is set.DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_STACK_V2_ENABLED, or DD_PROFILING_TIMELINE_ENABLED.DD_PROFILING_STACK_V2_ENABLED.Tracing
resource_name.AGENT_CONFIG remote configuration product.celery.apply spans didn't close if the after_task_publish or task_postrun signals didn't get sent when using apply_async, which can happen if there is an internal exception during the handling of the task. This update also marks the span as an error if an exception occurs.celery.apply spans using task_protocol 1 didn't close by improving the check for the task id in the body.http.url span tag contains the full query string when DD_TRACE_OBFUSCATION_QUERY_STRING_REGEXP is set to an empty string.DD_TRACE_RATE_LIMIT environment variable is only applied to spans for which tracer sampling is configured. For spans not matching sampling rules default rate limits should be applied by the Datadog Agent.Other
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add googlecloudsdk and google auth to the Code Security deny list.
Code Security:
Profiling:
Fixes an issue where cpu-time was not profiled for services using gunicorn, when DD_PROFILING_STACK_V2_ENABLED was set.
Fixes an issue where the sample pool could deadlock after fork() by clearing it in the child process.
Fixes an issue where enabling native exporter via DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_TIMELINE_ENABLED or DD_PROFILING_STACK_V2_ENABLED tu
Profiling
DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_TIMELINE_ENABLED or DD_PROFILING_STACK_V2_ENABLED turned off live heap profiling.ensure_binary_or_empty() function, on Python versions before 3.12, with DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.Span. The mapping is populated and used when DD_PROFILING_ENDPOINT_COLLECTION_ENABLED and DD_PROFILING_STACK_V2_ENABLED were set to enable grouping of profiles for endpoints.DD_PROFILING_STACK_V2_ENABLED is set.Tracing
NoneType instead of expected Pin object would throw an error in TracedTopology method.LLM Observability: This fix resolves an issue where LLMObs.enable() did not patch google\_generativeai library.
CODEOWNERS would incorrectly fail to discard line-level trailing comments (eg: @code/owner # my comment would result in codeowners being parsed as @code/owner, #, my, and comment)git binary or .git directory)google.cloud.storage.batch module would fail raising an ImportErrorTypeError exception when it is given a Span with None span_type.Ensures IAST propagation does not raise side effects related to re.finditer.
re.finditer.modelId when using cross-region inference.AGENT_CONFIG remote configuration product.celery: Fixes an issue where celery.apply spans didn't close if the after_task_publish or task_postrun signals didn't get sent when using apply_async,
Tracing
celery.apply spans didn't close if the after_task_publish or task_postrun signals didn't get sent when using apply_async, which can happen if there is an internal exception during the handling of the task. This update also marks the span as an error if an exception occurs.celery.apply spans using task_protocol 1 didn't close by improving the check for the task id in the body.Profiling
DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_STACK_V2_ENABLED, or DD_PROFILING_TIMELINE_ENABLED.DD_PROFILING_STACK_V2_ENABLED.Code Security (IAST): Always report a telemetry log error when an IAST propagation error raises, regardless of whether the _DD_IAST_DEBUG environment
_DD_IAST_DEBUG environment variable is enabled or not.DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.Deprecates the DD_TRACE_SPAN_AGGREGATOR_RLOCK environment variable. It will be removed in v3.0.0.
DD_TRACE_SPAN_AGGREGATOR_RLOCK environment variable. It will be removed in v3.0.0.DD_HTTP_CLIENT_TAG_QUERY_STRING configuration is deprecated and will be removed in v3.0.0. Use DD_TRACE_HTTP_CLIENT_TAG_QUERY_STRING instead.DSM
LLM Observability
model_provider values. Span names are now prefixed with the OpenAI client name (possible values: OpenAI/AzureOpenAI) instead of the default openai prefix to better differentiate whether the request was made to Azure OpenAI or OpenAI. The model_provider field also now corresponds to openai or azure_openai based on the OpenAI client.stream_options={"include_usage": True} option is set on the completion or chat completion call.LLMObs.annotation_context() context manager method, which allows modifying the tags of integration generated LLM Observability spans created while the context manager is active.LLMObs.annotate(prompt={...}) for LLM span kinds. For more information on prompt annotations, see the docs.generate_content calls.openai.request.client tag with the possible values OpenAI/AzureOpenAI to help differentiate whether the request was made to Azure OpenAI or OpenAI.stream_options={"include_usage": True} option is set on the completion or chat completion call.Profiling
asyncio.Lock usages with with context managers.Other
Code Security (ASM)
AttributeError exceptions were being caught, interfering with the proper application cycle.LLM Observability
LLMObs.enable(agentless_enabled=True) or setting DD_LLMOBS_AGENTLESS_ENABLED=1.LLMObs.annotate() method where non-JSON serializable arguments were discarded entirely. Now, the LLMObs.annotate() method safely handles non-JSON-serializable arguments by defaulting to a placeholder text.TypeError in the OpenAI, LangChain, Bedrock, and Anthropic integrations.TypeError. The Anthropic integration now safely tags non-JSON serializable arguments with a default placeholder text.TypeError. The LangChain integration now safely tags non-JSON serializable arguments with a default placeholder text.Other
pymongo.MongoClient can be patch after pymongo is importedNothing published for this version
Fixes a bug where CODEOWNERS would incorrectly fail to discard line-level trailing comments (eg: @code/owner # my comment would result in codeowners b
CI Visibility
CODEOWNERS would incorrectly fail to discard line-level trailing comments (eg: @code/owner # my comment would result in codeowners being parsed as @code/owner, #, my, and comment)git binary or .git directory)Code security
google.cloud.storage.batch module would fail raising an ImportErrorLLM Observability
LLMObs.annotate.Profiling
TypeError exception when it is given a Span with None span_type.Tracing
elasticsearch: Resolves an issue where span tags were not fully populated on "sampled" spans, causing metric dimensions to be incorrect when spans were prematurely marked as sampled, including resource_name.Ensures IAST propagation does not raise side effects related to re.finditer.
re.finditer.modelId when using cross-region inference.AGENT_CONFIG remote configuration product.Always report a telemetry log error when an IAST propagation error raises, regardless of whether the _DD_IAST_DEBUG environment variable is enabled or
Code Security (IAST)
_DD_IAST_DEBUG environment variable is enabled or not.Profiling:
DD_PROFILING_STACK_V2_ENABLED is set.DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_STACK_V2_ENABLED, or DD_PROFILING_TIMELINE_ENABLED.DD_PROFILING_STACK_V2_ENABLED.Tracing
celery.apply spans didn't close if the after_task_publish or task_postrun signals didn't get sent when using apply_async, which can happen if there is an internal exception during the handling of the task. This update also marks the span as an error if an exception occurs.celery.apply spans using task_protocol 1 didn't close by improving the check for the task id in the body.tracing: All public patch modules are deprecated. The non-deprecated methods are included in the __all__ attribute.
set_exc_info.similarity_search spans to LLM Observability as retrieval spans.ml_app and timestamp_ms fields in LLMObs.submit_evaluationmodel tag for openai integration metrics for consistency with the OpenAI SaaS Integration. It has the same value as openai.request.model.__all__ attribute.priority_sampling argument in ddtrace.tracer.Tracer.configure(...).attrs installed by default on some Ubuntu installations was treated as incompatible with library injectionTypeError. The Anthropic integration now safely tags non-JSON serializable arguments with a default placeholder text..git was incorrectly being stripped from repository URLs when extracting service names, resulting in g, i, or t being removed (eg: test-environment.git incorrectly becoming test-environmen)start_execution commands. This re-enables distributed tracing when a Python service invokes a properly instrumented Step Function.celery or gunicorn workers. The LLM Observability writer thread now automatically restarts when a forked process is detected.TypeError exception at runtime.X-Datadog-Trace-Count payload header.ddtrace package files were published with incorrect file attributes.session_id was being defaulted to trace_id, which was causing unexpected UI behavior.asyncio.TimeoutErrors were not being propagated correctly from canceled OpenAI API requests.DD_PROFILING_TAGS and DD_TAGS to the libdatadog exporter, a new exporter codepath which is enabled when either one of the following is set, DD_PROFILING_STACK_V2_ENABLED, DD_PROFILING_EXPORT_LIBDD_ENABLED, or DD_PROFILING_TIMELINE_ENABLED or dd-trace-py is running in an injected environment.DD_PRIORITY_SAMPLING configuration option. This option is not used in any ddtrace>=2.0 releases.Nothing published for this version
Fixes an issue where stack v2 couldn't be enabled as pthread was not properly linked on some debian based images for aarch64 architecture.
AGENT_CONFIG remote configuration product.This fix resolves an issue where exploit prevention was not properly blocking requests with custom redirection actions.
Code Security
Initializer object is always reset and freed before the Python runtime.LLM Observability
LLMObs.enable(agentless_enabled=True) or setting DD_LLMOBS_AGENTLESS_ENABLED=1.LLMObs.annotate() method where non-JSON serializable arguments were discarded entirely. Now, the LLMObs.annotate() method safely handles non-JSON-serializable arguments by defaulting to a placeholder text.TypeError in the OpenAI, LangChain, Bedrock, and Anthropic integrations.TypeError. The Anthropic integration now safely tags non-JSON serializable arguments with a default placeholder text.TypeError. The LangChain integration now safely tags non-JSON serializable arguments with a default placeholder text.Profiling
DD_PROFILING_STACK_V2_ENABLED is set.DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.DD_PROFILING_EXPORT_LIBDD_ENABLED, DD_PROFILING_STACK_V2_ENABLED, or DD_PROFILING_TIMELINE_ENABLED.DD_PROFILING_STACK_V2_ENABLED.Tracing
celery.apply spans didn't close if the after_task_publish or task_postrun signals didn't get sent when using apply_async, which can happen if there is an internal exception during the handling of the task. This update also marks the span as an error if an exception occurs.celery.apply spans using task_protocol 1 didn't close by improving the check for the task id in the body.TypeError exception would be raised if the first message's topic() returned None during consumption.library injection: Resolves an issue where the version of attrs installed by default on some Ubuntu installations was treated as incompatible with lib
attrs installed by default on some Ubuntu installations was treated as incompatible with library injectionAttributeError exceptions were being caught, interfering with the proper application cycle.SSI: This fix ensures injection denylist is included in published OCI package.
config: DD_TRACE_128_BIT_TRACEID_LOGGING_ENABLED is deprecated. Trace id logging format is now configured automatically.
model tag for openai integration metrics for consistency with the OpenAI SaaS Integration. It has the same value as openai.request.model.server.address tag to all <database>.query spans (ex: postgres.query). This tag stores the name of the database host.ddtrace.trace.Context to the public api. This class can now be used to propagate context across execution boundaries (ex: threads).DD_TRACE_128_BIT_TRACEID_LOGGING_ENABLED is deprecated. Trace id logging format is now configured automatically.ddtrace.contrib.[integration_name] package. Use attributes exposed in ddtrace.contrib.[integration_name].__all__ instead. The following are impacted:
aioredis, algoliasearch. anthropic, aredis, asgi, asyncpg, aws_lambda, boto, botocore, bottle, cassandra, celery, cherrypy, consul, coverage, django, dogpile_cache, dramatiq, elasticsearch, falcon, fastapi, flask, flask_cache, futures, gevent, graphql, grpc, httplib, httpx, jinja2, kafka, kombu, langchain, logbook, logging, loguru, mako, mariadb, molten, mongoengine, mysql, mysqldb, openai, psycopg, pylibmc, pymemcache, pymongo, pymysql, pynamodb, pyodbc, pyramid, redis, rediscluster, requests, sanic, snowflake, sqlalchemy, sqlite3, starlette, structlog, subprocess, tornado, urllib, urllib3, vertica, webbrowser, wsgi, yaaredisCI Visibility: Resolves an issue where exceptions other than timeouts and connection errors raised while fetching the list of skippable tests for ITR were not being handled correctly and caused the tracer to crash.
CI Visibility: Fixes a bug where .git was incorrectly being stripped from repository URLs when extracting service names, resulting in g, i, or t being removed (eg: test-environment.git incorrectly becoming test-environmen)
LLM Observability: Resolves an issue where custom trace filters were being overwritten in forked processes.
tracing: Fixes a side-effect issue with module import callbacks that could cause a runtime exception.
LLM Observability: Resolves an issue where session_id was being defaulted to trace_id, which was causing unexpected UI behavior.
LLM Observability: Resolves an issue where LLM Observability spans were not being submitted in forked processes, such as when using celery or gunicorn workers. The LLM Observability writer thread now automatically restarts when a forked process is detected.
tracing: Fixes an issue with some module imports with native specs that don't support attribute assignments, resulting in a TypeError exception at runtime.
tracing: Resolves an issue where ddtrace package files were published with incorrect file attributes.
tracing: Resolves an issue where django db instrumentation could fail.
openai: Fixes a bug where asyncio.TimeoutErrors were not being propagated correctly from canceled OpenAI API requests.
aiobotocore: Fixes an issue where the _make_api_call arguments were not captured correctly when using keyword arguments.
tracing(django): Resolves a bug where ddtrace was exhausting a Django stream response before returning it to user.
LLM Observability: Fixes an issue in the OpenAI integration where integration metrics would still be submitted even if LLMObs.enable(agentless_enabled=True) was set.
internal: Fixes the Already mutably borrowed error when rate limiter is accessed across threads.
internal: Fixes the Already mutably borrowed error by reverting back to pure-python rate limiter.
Code Security: Adds null pointer checks when creating new objects ids.
profiling: Fixes an issue where the profiler could erroneously try to load protobuf in autoinjected environments, where it is not available.
crashtracking: Fixes an issue where crashtracking environment variables for Python were inconsistent with those used by other runtimes.
profiling: Fixes endpoint profiling for stack v2 when DD_PROFILING_STACK_V2_ENABLED is set.
profiling: Turns on the new native exporter when DD_PROFILING_TIMELINE_ENABLED=True is set.
Nothing published for this version
Nothing published for this version
Resolves the issue where tracer flares would not be generated if unexpected types were received in the AGENT_CONFIG remote configuration product.
AGENT_CONFIG remote configuration product.Fixes an issue where the OpenAI and LangChain integrations would still submit integration metrics even in agentless mode. Integration metrics are now
LLMObs.enable(agentless_enabled=True) or setting DD_LLMOBS_AGENTLESS_ENABLED=1.Initializer object is always reset and freed before the Python runtime.DD_PROFILING_EXPORT_LIBDD_ENABLED or DD_PROFILING_TIMELINE_ENABLED.library injection: Resolves an issue where the version of attrs installed by default on some Ubuntu installations was treated as incompatible with lib
attrs installed by default on some Ubuntu installations was treated as incompatible with library injectionAttributeError exceptions were being caught, interfering with the proper application cycle.SSI: This fix ensures injection denylist is included in published OCI package.
CI Visibility: Resolves an issue where exceptions other than timeouts and connection errors raised while fetching the list of skippable tests for ITR
.git was incorrectly being stripped from repository URLs when extracting service names, resulting in g, i, or t being removed (eg: test-environment.git incorrectly becoming test-environmen)session_id was being defaulted to trace_id which was causing unexpected UI behavior.ASM: Improves internal stability for the new fingerprinting feature.
openai: Introduces model tag for openai integration metrics for consistency with the OpenAI SaaS Integration. It has the same value as openai.request.
model tag for openai integration metrics for consistency with the OpenAI SaaS Integration. It has the same value as openai.request.model.celery or gunicorn workers. The LLM Observability writer thread now automatically restarts when a forked process is detected.asyncio.TimeoutErrors were not being propagated correctly from canceled OpenAI API requests.tracing(django): This fix resolves a bug where ddtrace was exhausting a Django stream response before returning it to user.
TypeError exception at runtime.Already mutably borrowed error by reverting back to pure-python rate limiter.ddtrace package files were published with incorrect file attributes.DD_PROFILING_STACK_V2_ENABLED set.ASM: The environment variable DD_APPSEC_AUTOMATED_USER_EVENTS_TRACKING is deprecated and will be removed in the next major release. Instead of DD_APPS…
ASM: This update introduces new Auto User Events support.
ASM’s [Account TakeOver (ATO) detection](https://docs.datadoghq.com/security/account_takeover_protection) is now automatically monitoring [all compatible user authentication frameworks](https://docs.datadoghq.com/security/application_security/enabling/compatibility/) to detect attempted or leaked user credentials during an ATO campaign.
To do so, the monitoring of the user activity is extended to now collect all forms of user IDs, including non-numerical forms such as usernames or emails. This is configurable with 3 different working modes: <span class="title-ref">identification</span> to send the user IDs in clear text; <span class="title-ref">anonymization</span> to send anonymized user IDs; or <span class="title-ref">disabled</span> to completely turn off any type of user ID collection (which leads to the disablement of the ATO detection).
The default collection mode being used is <span class="title-ref">identification</span> and this is configurable in your remote service configuration settings in the [service catalog]( https://app.datadog.com/security/appsec/inventory/services?tab=capabilities) (clicking on a service), or with the service environment variable <span class="title-ref">DD_APPSEC_AUTO_USER_INSTRUMENTATION_MODE</span>.
You can read more [here](https://docs.datadoghq.com/security/account_takeover_protection).
New local configuration environment variables include:
Additionally, an optional argument for the public API <span class="title-ref">track_user_login_success_event</span> and `track_user_login_failure_event`: <span class="title-ref">login_events_mode="auto"</span>. This allows manual instrumentation to follow remote configuration settings, enabling or disabling manual instrumentation with a single remote action on the Datadog UI.
Also prevents non numerical user ids to be reported by default without user instrumentation in Django.
Anthropic: Adds support for tracing message calls using tools.
LLM Observability: Adds support for tracing Anthropic messages using tool calls.
botocore: Adds support for overriding the default service name in botocore by either setting the environment variable DD_BOTOCORE_SERVICE or configuring it via <span class="title-ref">ddtrace.config.botocore["service"]</span>.
azure: Removes the restrictions on the tracer to only run the mini-agent on the consumption plan. The mini-agent now runs regardless of the hosting plan
ASM: Adds Threat Monitoring support for gRPC.
Code Security: add propagation for GRPC server sources.
LLM Observability: This introduces improved support for capturing tool call responses from the OpenAI and Anthropic integrations.
LLM Observability: This introduces the agentless mode configuration for LLM Observability. To enable agentless mode, set the environment variable DD_LLMOBS_AGENTLESS_ENABLED=1, or use the enable option LLMObs.enable(agentless_enabled=True).
LLM Observability: Function decorators now support tracing asynchronous functions.
LLM Observability: This introduces automatic input/output annotation for task/tool/workflow/agent/retrieval spans traced by function decorators. Note that manual annotations for input/output values will override automatic annotations.
LLM Observability: The OpenAI integration now submits embedding spans to LLM Observability.
LLM Observability: All OpenAI model parameters specified in a completion/chat completion request are now captured.
LLM Observability: This changes OpenAI-generated LLM Observability span names from openai.request to openai.createCompletion, openai.createChatCompletion, and openai.createEmbedding for completions, chat completions, and embeddings spans, respectively.
LLM Observability: This introduces the agent proxy mode for LLM Observability. By default, LLM Observability spans will be sent to the Datadog agent and then forwarded to LLM Observability. To continue submitting data directly to LLM Observability without the Datadog agent, set DD_LLMOBS_AGENTLESS_ENABLED=1 or set programmatically using LLMObs.enable(agentless_enabled=True).
LLM Observability: The Langchain integration now submits embedding spans to LLM Observability.
LLM Observability: The LLMObs.annotate() method now replaces non-JSON serializable values with a placeholder string [Unserializable object: <string representation of object>] instead of rejecting the annotation entirely.
pylibmc: adds traces for memcached add command
ASM: This introduces fingerprinting with libddwaf 1.19.1
Database Monitoring: Adds Database Monitoring (DBM) trace propagation for postgres databases used through Django.
langchain: Tags tool calls on chat completions.
LLM Observability: Adds retry logic to the agentless span writer to mitigate potential networking issues, like timeouts or dropped connections.
ASM: This introduces Command Injection support for Exploit Prevention on os.system only.
ASM: This introduces suspicious attacker blocking with libddwaf 1.19.1
patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.patch() and unpatch() are deprecated and will be removed in version 3.0.0.DD_EXCEPTION_DEBUGGING_ENABLED environment variable has been deprecated in favor of DD_EXCEPTION_REPLAY_ENABLED. The old environment variable will be removed in a future major release.LLM Observability: Fixes an issue in the OpenAI integration where integration metrics would still be submitted even if LLMObs.enable(agentless_enabled=True) was set.
Code Security: add null pointer checks when creating new objects ids.
Code Security: add encodings.idna to the IAST patching denylist to avoid problems with gevent.
Code Security: add the boto package to the IAST patching denylist.
Code Security: fix two small memory leaks with Python 3.11 and 3.12.
CI Visibility: Fixes an issue where the pytest plugin would crash if the git binary was absent
CI Visibility: fixes incorrect URL for telemetry intake in EU that was causing missing telemetry data and SSL error log messages.
celery: changes error.message span tag to no longer include the traceback that is already included in the error.stack span tag.
CI Visibility: fixes source file information that would be incorrect in certain decorated / wrapped scenarios and forces paths to be relative to the repository root, if present.
futures: Fixes inconsistent behavior with concurrent.futures.ThreadPoolExecutor context propagation by passing the current trace context instead of the currently active span to tasks. This prevents edge cases of disconnected spans when the task executes after the parent span has finished.
kafka: Fixes ArgumentError raised when injecting span context into non-existent Kafka message headers.
botocore: Fixes Botocore Kinesis span parenting to use active trace context if a propagated child context is not found instead of empty context.
langchain: This fix resolves an issue where the wrong langchain class name was being used to check for Pinecone vectorstore instances.
LLM Observability: This resolves a typing hint error in the ddtrace.llmobs.utils.Documents helper class constructor where type hints did not accept input dictionaries with integer or float values.
LLM Observability: This fix resolves an issue where the OpenAI, Anthropic, and AWS Bedrock integrations were always setting temperature and max_tokens parameters to LLM invocations. The OpenAI integration in particular was setting the wrong temperature default values. These parameters are now only set if provided in the request.
opentelemetry: Resolves circular imports raised by the OpenTelemetry API when the ddcontextvars_context entrypoint is loaded. This resolves an incompatibility introduced in opentelemetry-api==1.25.0.
opentelemetry: Resolves an issue where the get_tracer function would raise a TypeError when called with the attribute argument. This resolves an incompatibility introduced in opentelemetry-api==1.26.0.
psycopg: Ensures traced async cursors return an asynchronous iterator object.
redis: This fix resolves an issue in the redis exception handling where an UnboundLocalError was raised instead of the expected BaseException.
ASM: This fix resolves an issue where the <span class="title-ref">requests</span> integration would not propagate when apm is opted out (i.e. in ASM Standalone).
profiling: Fixes an issue where task information coming from echion was encoded improperly, which could segfault the application.
tracing: fixes a potential crash where using partial flushes and tracer.configure() could result in an IndexError
tracer: This fix resolves an issue where the tracer was not starting properly on a read-only file system.
internal: fixes an issue where some pathlib functions return OSError on Windows.
ASM: This fix resolves an issue where the WAF could be disabled if the ASM_DD rule file was not found in Remote Config.
flask: Fix scenarios when using flask-like frameworks would cause a crash because of patching issues on startup.
Code Security: Logs warning instead of throwing an exception in the native module if IAST is not enabled by env var.
Code Security: fix potential infinite loop with path traversal when the analyze quota has been exceeded.
wsgi: Ensures the status of wsgi Spans are not set to error when a StopIteration exception is raised marked the span as an error. With this change, StopIteration exceptions in this context will be ignored.
langchain: tag non-dict inputs to LCEL chains appropriately. Non-dict inputs are stringified, and dict inputs are tagged by key-value pairs.
tracing: Updates DD_HEADER_TAGS and DD_TAGS to support the following formats: key1,key2,key3, key1:val,key2:val,key3:val3, key1:val key2:val key3:val3, and key1 key2 key3. Key value pairs that do not match an expected format will be logged and ignored by the tracer.
loguru: This fix avoids copying attributes from a log record's "extras" field to the record's top level if those attributes were not added by the Datadog integration.
opentelemetry: Resolves an edge case where distributed tracing headers could be generated before a sampling decision is made, resulting in dropped spans in downstream services.
profiling: captures lock usages with with context managers, e.g. with lock:
profiling: propagates runtime_id tag to libdatadog exporter. It is a unique string identifier for the profiled process. For example, Thread Timeline visualization uses it to distinguish different processes.
profiling: show lock init location in Lock Name and hide profiler internal frames from Stack Frame in Timeline Details tab.
ASM: This fix resolves an issue where ASM one click feature could fail to deactivate ASM.
redis: This fix resolves an issue in redis utils where a variable may not be declared within a try/catch
LLMObs.submit_evaluation() requires a Datadog API key to send custom evaluations to LLM Observability. If an API key is not set using either DD_API_KEY or LLMObs.enable(api_key="<api-key>"), this method will log a warning and return None.Nothing published for this version
Nothing published for this version
CI Visibility: Resolves an issue where exceptions other than timeouts and connection errors raised while fetching the list of skippable tests for ITR
.git was incorrectly being stripped from repository URLs when extracting service names, resulting in g, i, or t being removed (eg: test-environment.git incorrectly becoming test-environmen)asyncio.TimeoutErrors were not being propagated correctly from canceled OpenAI API requests.DD_PROFILING_STACK_V2_ENABLED is set.tracing(django): Resolves a bug where ddtrace was exhausting a Django stream response before returning it to user.
ddtrace was exhausting a Django stream response before returning it to user.Already mutably borrowed error by reverting back to pure-python rate limiter.Nothing published for this version
SSI: Fixes incorrect file permissions on lib-injection images.
ASM: This fix resolves an issue where the WAF could be disabled if the ASM_DD rule file was not found in Remote Config.
lib-injection: This fix resolves an issue with docker layer caching and the final lib-injection image size.
with context managers, e.g. with lock:runtime_id tag to libdatadog exporter. It is a unique string identifier for the profiled process. For example, Thread Timeline visualization uses it to distinguish different processes.Your coding agent can read these notes before it upgrades. Set up the MCP server →