dd-trace
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used in a proxy for logging plugin, standard JS pattern not obfuscation. | ai | |
| dependencies | unvetted-dep:@datadog/native-iast-rewriter | AI (dependencies): First-party Datadog native module, expected dependency for IAST features. | ai | |
| phantom-deps | phantom-dep:protobufjs | AI (phantom-deps): Used via config/generated code; stable FP for this package. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreads env to set DD_CIVISIBILITY_ENABLED in a worker; not exfil. | ai | |
| source-diff | net-exec-file:vendor/dist/protobufjs/index.js | AI (source-diff): Webpack-bundled protobufjs vendored dep; network+eval pattern is standard bundler output, not a dropper. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Deps vendored into vendor/dist as bundled output; expected restructuring for this package. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): vendor source-map mappings.wasm; standard bundled dependency, stable across versions. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): opentracing is the canonical OpenTracing API package; directly relevant to dd-trace's stated purpose. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Used in pkg.js for package metadata loading; standard pattern for APM instrumentation across all versions. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): GraphQL transform tooling; legitimate instrumentation use. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function used as a data object constructor for pprof profiling, not for dynamic code execution. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP appears only in a comment/example string (127.0.0.1), not an actual outbound request. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Used in guardrails/telemetry for spawning subprocesses; standard for an APM agent. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): APM config library explicitly reads all env vars for configuration reporting — documented and expected. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decoding AWS Kinesis payloads and similar instrumentation data; expected in an APM tracing library. | ai | |
| semgrep | semgrep:dll-injection-apis | AI (semgrep): LD_PRELOAD appears in an allowlist/denylist for child_process command scrubbing — defensive use, not injection. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Long-standing preinstall script for dd-trace; runs node scripts/preinstall.js, not arbitrary remote code. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 6.7.0 | 3 / 58 | |
| 6.6.0 | 3 / 58 | |
| 6.5.0 | 3 / 58 | |
| 6.4.0 | 3 / 57 | |
| 6.3.0 | 3 / 57 | |
| 6.2.0 | 3 / 58 | |
| 6.1.0 | 3 / 57 | |
| 6.0.0 | 3 / 54 | |
| 5.118.0 | 3 / 58 | |
| 5.117.0 | 3 / 58 | |
| 5.116.0 | 3 / 58 | |
| 5.115.0 | 3 / 57 | |
| 5.114.0 | 3 / 57 | |
| 5.113.0 | 3 / 58 | |
| 5.112.0 | 3 / 57 | |
| 5.111.0 | 3 / 54 | |
| 5.110.0 | 3 / 54 | |
| 5.109.0 | 3 / 53 | |
| 5.108.0 | 3 / 53 | |
| 5.107.0 | 3 / 53 | |
| 5.104.0 | 3 / 53 | |
| 5.101.0 | 2 / 53 | |
| 5.100.0 | 2 / 53 | |
| 5.91.0 | 2 / 50 | |
| 5.87.0 | 2 / 47 | |
| 5.83.0 | 2 / 45 | |
| 5.50.0 | 33 / 41 | |
| 5.12.0 | 32 / 36 |
v6.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.118.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.117.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.116.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.115.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.114.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.113.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.112.0
2 findingsPackage contains compiled binaries that could be backdoors: • vendor/dist/source-map/mappings.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.111.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.110.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.109.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.108.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.107.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.104.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.101.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.100.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.91.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.87.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.83.0
26 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.50.0
2 findingsSpreading entire process.env into an object — may capture all secrets Source: https://github.com/DataDog/dd-trace-js/blob/e7c986fe16e04d926ae550a2966733de16b227a2/packages/dd-trace/src/ci-visibility/dynamic-instrumentation/index.js#L74 72 | // for PnP support, hence why we deviate from the DI pattern here. 73 | // To avoid infinite initialization loops, we're disabling DI and tracing in the worker. > 74 | env: { 75 | ...process.env, 76 | DD_CIVISIBILITY_ENABLED: 0,
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.