← Home

dd-trace

32
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

datadog

Keywords

datadogtracetracingprofileprofilerprofilingopentracingapm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used in a proxy for logging plugin, standard JS pattern not obfuscation. ai
dependencies unvetted-dep:@datadog/native-iast-rewriter AI (dependencies): First-party Datadog native module, expected dependency for IAST features. ai
phantom-deps phantom-dep:protobufjs AI (phantom-deps): Used via config/generated code; stable FP for this package. ai
semgrep semgrep:env-spread AI (semgrep): Spreads env to set DD_CIVISIBILITY_ENABLED in a worker; not exfil. ai
source-diff net-exec-file:vendor/dist/protobufjs/index.js AI (source-diff): Webpack-bundled protobufjs vendored dep; network+eval pattern is standard bundler output, not a dropper. ai
source-diff large-new-source-files AI (source-diff): Deps vendored into vendor/dist as bundled output; expected restructuring for this package. ai
npm-metadata bundled-binaries AI (npm-metadata): vendor source-map mappings.wasm; standard bundled dependency, stable across versions. ai
publish-pattern new-deps-added AI (publish-pattern): opentracing is the canonical OpenTracing API package; directly relevant to dd-trace's stated purpose. ai
semgrep semgrep:dynamic-require AI (semgrep): Used in pkg.js for package metadata loading; standard pattern for APM instrumentation across all versions. ai
semgrep semgrep:hex-decode AI (semgrep): GraphQL transform tooling; legitimate instrumentation use. ai
semgrep semgrep:new-function-constructor AI (semgrep): new Function used as a data object constructor for pprof profiling, not for dynamic code execution. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP appears only in a comment/example string (127.0.0.1), not an actual outbound request. ai
semgrep semgrep:child-process-import AI (semgrep): Used in guardrails/telemetry for spawning subprocesses; standard for an APM agent. ai
semgrep semgrep:env-bulk-read AI (semgrep): APM config library explicitly reads all env vars for configuration reporting — documented and expected. ai
semgrep semgrep:base64-decode AI (semgrep): Decoding AWS Kinesis payloads and similar instrumentation data; expected in an APM tracing library. ai
semgrep semgrep:dll-injection-apis AI (semgrep): LD_PRELOAD appears in an allowlist/denylist for child_process command scrubbing — defensive use, not injection. ai
install-scripts install-script:preinstall AI (install-scripts): Long-standing preinstall script for dd-trace; runs node scripts/preinstall.js, not arbitrary remote code. ai

Versions (showing 32 of 32)

Version Deps Published
6.6.0 3 / 58
6.5.0 3 / 58
6.4.0 3 / 57
6.3.0 3 / 57
6.2.0 3 / 58
6.1.0 3 / 57
6.0.0 3 / 54
5.117.0 3 / 58
5.116.0 3 / 58
5.115.0 3 / 57
5.114.0 3 / 57
5.113.0 3 / 58
5.112.0 3 / 57
5.111.0 3 / 54
5.110.0 3 / 54
5.109.0 3 / 53
5.108.0 3 / 53
5.107.0 3 / 53
5.104.0 3 / 53
5.101.0 2 / 53
5.100.0 2 / 53
5.99.1 2 / 53
5.98.0 2 / 50
5.94.0 2 / 50
5.91.0 2 / 50
5.87.0 2 / 47
5.85.0 2 / 47
5.83.0 2 / 45
5.80.0 37 / 47
5.76.0 37 / 46
5.50.0 33 / 41
5.12.0 32 / 36

v6.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.117.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.116.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.115.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.114.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.113.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.112.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • vendor/dist/source-map/mappings.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.111.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.91.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.87.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.83.0

26 findings
HIGH New obfuscated file: vendor/dist/@datadog/sketches-js/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/@datadog/source-map/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/@isaacs/ttlcache/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/@opentelemetry/core/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/@opentelemetry/resources/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/astring/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/crypto-randomuuid/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/esquery/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/ignore/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/istanbul-lib-coverage/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/jsonpath-plus/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/limiter/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/lodash.sortby/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/lru-cache/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/meriyah/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/opentracing/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/pprof-format/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/protobufjs/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: vendor/dist/protobufjs/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: vendor/dist/protobufjs/minimal/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/retry/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/rfdc/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/source-map/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/source-map/lib/util/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/tlhunter-sorted-set/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.50.0

2 findings
HIGH env-spread: packages/dd-trace/src/ci-visibility/dynamic-instrumentation/index.js:74 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/DataDog/dd-trace-js/blob/e7c986fe16e04d926ae550a2966733de16b227a2/packages/dd-trace/src/ci-visibility/dynamic-instrumentation/index.js#L74 72 | // for PnP support, hence why we deviate from the DI pattern here. 73 | // To avoid infinite initialization loops, we're disabling DI and tracing in the worker. > 74 | env: { 75 | ...process.env, 76 | DD_CIVISIBILITY_ENABLED: 0,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.