chore(deps): bump dd-trace from 4.38.0 to 5.100.0 - #4352
Conversation
PR SummaryMedium Risk Overview The v5 tracer pulls in a different stack than v4: newer Reviewed by Cursor Bugbot for commit 17daf2f. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
|
|
Your PR title doesn't contain a Jira issue key. Consider adding it for better traceability. Example:
Projects:
Please add a Jira issue key to your PR title. |
83ca184 to
6afd150
Compare
6afd150 to
6c49972
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 6c49972. Configure here.
| needle@https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: | ||
| resolution: {tarball: https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b} | ||
| needle@git+https://git@github.com:clearbit/needle.git#84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: | ||
| resolution: {commit: 84d28b5f2c3916db1e7eb84aeaa9d976cc40054b, repo: git@github.com:clearbit/needle.git, type: git} |
There was a problem hiding this comment.
Lockfile forces SSH for needle
Medium Severity
The clearbit → needle dependency was re-resolved from a public HTTPS tarball (codeload.github.com) to a [email protected] SSH git dependency. Fresh installs in CI or other environments without GitHub SSH keys can fail with permission errors even though the repo is public.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 6c49972. Configure here.
Bumps [dd-trace](https://github.com/DataDog/dd-trace-js) from 4.38.0 to 5.100.0. - [Release notes](https://github.com/DataDog/dd-trace-js/releases) - [Commits](DataDog/dd-trace-js@v4.38.0...v5.100.0) --- updated-dependencies: - dependency-name: dd-trace dependency-version: 5.100.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
6c49972 to
17daf2f
Compare
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |


Bumps dd-trace from 4.38.0 to 5.100.0.
Release notes
Sourced from dd-trace's releases.
... (truncated)
Commits
581910dv5.100.0b24e364perf(propagation): rewrite tracestate parser to be linear (#8256)8e59ac7chore(deps-dev): bump the dev-minor-and-patch-dependencies group across 1 dir...e909c52chore(deps): bump the gh-actions-packages group across 2 directories with 1 u...86e35a9fix(express): use the host's path-to-regexp dialect for route tagging (#8224)9f302ferefactor(otel): extract bridge helpers into span-helpers.js (#8220)200d3bdfix(otel): return a non-recording span when the inner tracer is the noop (#8218)b2df728fix(esm): expose 'tracer' as an ESM named export (#8216)741482cfix: small correctness issues in mongodb-core and bullmq (#8228)280f96efix(config): align inferred service name with agent normalization (#8217)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for dd-trace since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.