← Home

dd-trace

28
Versions
License
Yes
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

datadog

Keywords

datadogtracetracingprofileprofilerprofilingopentracingapm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used in a proxy for logging plugin, standard JS pattern not obfuscation. ai
dependencies unvetted-dep:@datadog/native-iast-rewriter AI (dependencies): First-party Datadog native module, expected dependency for IAST features. ai
phantom-deps phantom-dep:protobufjs AI (phantom-deps): Used via config/generated code; stable FP for this package. ai
semgrep semgrep:env-spread AI (semgrep): Spreads env to set DD_CIVISIBILITY_ENABLED in a worker; not exfil. ai
source-diff net-exec-file:vendor/dist/protobufjs/index.js AI (source-diff): Webpack-bundled protobufjs vendored dep; network+eval pattern is standard bundler output, not a dropper. ai
source-diff large-new-source-files AI (source-diff): Deps vendored into vendor/dist as bundled output; expected restructuring for this package. ai
npm-metadata bundled-binaries AI (npm-metadata): vendor source-map mappings.wasm; standard bundled dependency, stable across versions. ai
publish-pattern new-deps-added AI (publish-pattern): opentracing is the canonical OpenTracing API package; directly relevant to dd-trace's stated purpose. ai
semgrep semgrep:dynamic-require AI (semgrep): Used in pkg.js for package metadata loading; standard pattern for APM instrumentation across all versions. ai
semgrep semgrep:hex-decode AI (semgrep): GraphQL transform tooling; legitimate instrumentation use. ai
semgrep semgrep:new-function-constructor AI (semgrep): new Function used as a data object constructor for pprof profiling, not for dynamic code execution. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP appears only in a comment/example string (127.0.0.1), not an actual outbound request. ai
semgrep semgrep:child-process-import AI (semgrep): Used in guardrails/telemetry for spawning subprocesses; standard for an APM agent. ai
semgrep semgrep:env-bulk-read AI (semgrep): APM config library explicitly reads all env vars for configuration reporting — documented and expected. ai
semgrep semgrep:base64-decode AI (semgrep): Decoding AWS Kinesis payloads and similar instrumentation data; expected in an APM tracing library. ai
semgrep semgrep:dll-injection-apis AI (semgrep): LD_PRELOAD appears in an allowlist/denylist for child_process command scrubbing — defensive use, not injection. ai
install-scripts install-script:preinstall AI (install-scripts): Long-standing preinstall script for dd-trace; runs node scripts/preinstall.js, not arbitrary remote code. ai

Versions (showing 28 of 28)

Version Deps Published
6.7.0 3 / 58
6.6.0 3 / 58
6.5.0 3 / 58
6.4.0 3 / 57
6.3.0 3 / 57
6.2.0 3 / 58
6.1.0 3 / 57
6.0.0 3 / 54
5.118.0 3 / 58
5.117.0 3 / 58
5.116.0 3 / 58
5.115.0 3 / 57
5.114.0 3 / 57
5.113.0 3 / 58
5.112.0 3 / 57
5.111.0 3 / 54
5.110.0 3 / 54
5.109.0 3 / 53
5.108.0 3 / 53
5.107.0 3 / 53
5.104.0 3 / 53
5.101.0 2 / 53
5.100.0 2 / 53
5.91.0 2 / 50
5.87.0 2 / 47
5.83.0 2 / 45
5.50.0 33 / 41
5.12.0 32 / 36

v6.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.118.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.117.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.116.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.115.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.114.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.113.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.112.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • vendor/dist/source-map/mappings.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.111.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.110.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.109.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.108.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.107.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.104.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.101.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.100.0

2 findings
HIGH New obfuscated file: vendor/dist/@apm-js-collab/code-transformer/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.91.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.87.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.83.0

26 findings
HIGH New obfuscated file: vendor/dist/@datadog/sketches-js/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/@datadog/source-map/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/@isaacs/ttlcache/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/@opentelemetry/core/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/@opentelemetry/resources/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/astring/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/crypto-randomuuid/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/esquery/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/ignore/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/istanbul-lib-coverage/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/jsonpath-plus/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/limiter/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/lodash.sortby/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/lru-cache/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/meriyah/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/opentracing/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/pprof-format/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/protobufjs/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: vendor/dist/protobufjs/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: vendor/dist/protobufjs/minimal/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/retry/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/rfdc/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/source-map/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/source-map/lib/util/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: vendor/dist/tlhunter-sorted-set/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.50.0

2 findings
HIGH env-spread: packages/dd-trace/src/ci-visibility/dynamic-instrumentation/index.js:74 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/DataDog/dd-trace-js/blob/e7c986fe16e04d926ae550a2966733de16b227a2/packages/dd-trace/src/ci-visibility/dynamic-instrumentation/index.js#L74 72 | // for PnP support, hence why we deviate from the DI pattern here. 73 | // To avoid infinite initialization loops, we're disabling DI and tracing in the worker. > 74 | env: { 75 | ...process.env, 76 | DD_CIVISIBILITY_ENABLED: 0,

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.