-
Notifications
You must be signed in to change notification settings - Fork 311
Ensure usr.exists tag is not overridden by auto instrumentation #8374
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
manuel-alvarez-alvarez
merged 1 commit into
master
from
malvarez/waf-fix-ato-usr-exists-override
Feb 12, 2025
Merged
Ensure usr.exists tag is not overridden by auto instrumentation #8374
manuel-alvarez-alvarez
merged 1 commit into
master
from
malvarez/waf-fix-ato-usr-exists-override
Feb 12, 2025
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
816a095
to
126cc4c
Compare
sezen-datadog
approved these changes
Feb 12, 2025
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 59 metrics, 4 unstable metrics. Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.47.0-SNAPSHOT~126cc4cc28, baseline=1.47.0-SNAPSHOT~429031c283
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.053 s) : 0, 1053203
Total [baseline] (8.674 s) : 0, 8673813
Agent [candidate] (1.042 s) : 0, 1041924
Total [candidate] (8.626 s) : 0, 8625725
section iast
Agent [baseline] (1.174 s) : 0, 1174416
Total [baseline] (9.251 s) : 0, 9251159
Agent [candidate] (1.171 s) : 0, 1171094
Total [candidate] (9.251 s) : 0, 9250942
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.169 s) : 0, 1168753
Total [baseline] (9.165 s) : 0, 9164742
Agent [candidate] (1.173 s) : 0, 1172812
Total [candidate] (9.182 s) : 0, 9182133
section iast_TELEMETRY_OFF
Agent [baseline] (1.169 s) : 0, 1168792
Total [baseline] (9.237 s) : 0, 9236908
Agent [candidate] (1.167 s) : 0, 1167257
Total [candidate] (9.192 s) : 0, 9192473
gantt
title insecure-bank - break down per module: candidate=1.47.0-SNAPSHOT~126cc4cc28, baseline=1.47.0-SNAPSHOT~429031c283
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (724.906 ms) : 0, 724906
BytebuddyAgent [candidate] (715.56 ms) : 0, 715560
GlobalTracer [baseline] (244.668 ms) : 0, 244668
GlobalTracer [candidate] (243.195 ms) : 0, 243195
AppSec [baseline] (55.433 ms) : 0, 55433
AppSec [candidate] (55.119 ms) : 0, 55119
Remote Config [baseline] (722.557 µs) : 0, 723
Remote Config [candidate] (715.99 µs) : 0, 716
Telemetry [baseline] (12.21 ms) : 0, 12210
Telemetry [candidate] (12.186 ms) : 0, 12186
section iast
BytebuddyAgent [baseline] (835.08 ms) : 0, 835080
BytebuddyAgent [candidate] (833.234 ms) : 0, 833234
GlobalTracer [baseline] (234.778 ms) : 0, 234778
GlobalTracer [candidate] (233.333 ms) : 0, 233333
IAST [baseline] (23.187 ms) : 0, 23187
IAST [candidate] (22.905 ms) : 0, 22905
AppSec [baseline] (56.806 ms) : 0, 56806
AppSec [candidate] (57.051 ms) : 0, 57051
Remote Config [baseline] (604.072 µs) : 0, 604
Remote Config [candidate] (617.099 µs) : 0, 617
Telemetry [baseline] (8.72 ms) : 0, 8720
Telemetry [candidate] (8.731 ms) : 0, 8731
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (831.893 ms) : 0, 831893
BytebuddyAgent [candidate] (834.618 ms) : 0, 834618
GlobalTracer [baseline] (232.511 ms) : 0, 232511
GlobalTracer [candidate] (233.993 ms) : 0, 233993
IAST [baseline] (23.014 ms) : 0, 23014
IAST [candidate] (22.789 ms) : 0, 22789
AppSec [baseline] (56.771 ms) : 0, 56771
AppSec [candidate] (56.784 ms) : 0, 56784
Remote Config [baseline] (619.243 µs) : 0, 619
Remote Config [candidate] (611.149 µs) : 0, 611
Telemetry [baseline] (8.724 ms) : 0, 8724
Telemetry [candidate] (8.717 ms) : 0, 8717
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (832.129 ms) : 0, 832129
BytebuddyAgent [candidate] (830.333 ms) : 0, 830333
GlobalTracer [baseline] (233.267 ms) : 0, 233267
GlobalTracer [candidate] (233.216 ms) : 0, 233216
IAST [baseline] (25.432 ms) : 0, 25432
IAST [candidate] (24.822 ms) : 0, 24822
AppSec [baseline] (53.545 ms) : 0, 53545
AppSec [candidate] (54.58 ms) : 0, 54580
Remote Config [baseline] (610.261 µs) : 0, 610
Remote Config [candidate] (616.211 µs) : 0, 616
Telemetry [baseline] (8.606 ms) : 0, 8606
Telemetry [candidate] (8.521 ms) : 0, 8521
Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.47.0-SNAPSHOT~126cc4cc28, baseline=1.47.0-SNAPSHOT~429031c283
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.043 s) : 0, 1043127
Total [baseline] (10.455 s) : 0, 10455176
Agent [candidate] (1.042 s) : 0, 1041632
Total [candidate] (10.441 s) : 0, 10440741
section appsec
Agent [baseline] (1.184 s) : 0, 1184390
Total [baseline] (10.723 s) : 0, 10723089
Agent [candidate] (1.187 s) : 0, 1186568
Total [candidate] (10.728 s) : 0, 10727728
section iast
Agent [baseline] (1.181 s) : 0, 1180891
Total [baseline] (11.051 s) : 0, 11051395
Agent [candidate] (1.182 s) : 0, 1181861
Total [candidate] (10.924 s) : 0, 10924346
section profiling
Agent [baseline] (1.263 s) : 0, 1263273
Total [baseline] (10.791 s) : 0, 10791190
Agent [candidate] (1.273 s) : 0, 1272601
Total [candidate] (11.081 s) : 0, 11080540
gantt
title petclinic - break down per module: candidate=1.47.0-SNAPSHOT~126cc4cc28, baseline=1.47.0-SNAPSHOT~429031c283
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (716.88 ms) : 0, 716880
BytebuddyAgent [candidate] (716.851 ms) : 0, 716851
GlobalTracer [baseline] (243.516 ms) : 0, 243516
GlobalTracer [candidate] (243.432 ms) : 0, 243432
AppSec [baseline] (55.354 ms) : 0, 55354
AppSec [candidate] (54.865 ms) : 0, 54865
Remote Config [baseline] (718.884 µs) : 0, 719
Remote Config [candidate] (714.196 µs) : 0, 714
Telemetry [baseline] (11.464 ms) : 0, 11464
Telemetry [candidate] (10.671 ms) : 0, 10671
section appsec
BytebuddyAgent [baseline] (732.879 ms) : 0, 732879
BytebuddyAgent [candidate] (734.041 ms) : 0, 734041
GlobalTracer [baseline] (240.367 ms) : 0, 240367
GlobalTracer [candidate] (240.988 ms) : 0, 240988
IAST [baseline] (21.761 ms) : 0, 21761
IAST [candidate] (21.771 ms) : 0, 21771
AppSec [baseline] (176.12 ms) : 0, 176120
AppSec [candidate] (176.523 ms) : 0, 176523
Remote Config [baseline] (655.629 µs) : 0, 656
Remote Config [candidate] (659.017 µs) : 0, 659
Telemetry [baseline] (8.255 ms) : 0, 8255
Telemetry [candidate] (8.278 ms) : 0, 8278
section iast
BytebuddyAgent [baseline] (840.993 ms) : 0, 840993
BytebuddyAgent [candidate] (841.29 ms) : 0, 841290
GlobalTracer [baseline] (234.995 ms) : 0, 234995
GlobalTracer [candidate] (235.275 ms) : 0, 235275
IAST [baseline] (22.901 ms) : 0, 22901
IAST [candidate] (23.071 ms) : 0, 23071
AppSec [baseline] (57.192 ms) : 0, 57192
AppSec [candidate] (57.509 ms) : 0, 57509
Remote Config [baseline] (626.155 µs) : 0, 626
Remote Config [candidate] (618.615 µs) : 0, 619
Telemetry [baseline] (8.818 ms) : 0, 8818
Telemetry [candidate] (8.781 ms) : 0, 8781
section profiling
BytebuddyAgent [baseline] (706.594 ms) : 0, 706594
BytebuddyAgent [candidate] (712.803 ms) : 0, 712803
GlobalTracer [baseline] (353.981 ms) : 0, 353981
GlobalTracer [candidate] (355.783 ms) : 0, 355783
AppSec [baseline] (55.169 ms) : 0, 55169
AppSec [candidate] (54.814 ms) : 0, 54814
Remote Config [baseline] (697.183 µs) : 0, 697
Remote Config [candidate] (705.084 µs) : 0, 705
Telemetry [baseline] (8.857 ms) : 0, 8857
Telemetry [candidate] (8.914 ms) : 0, 8914
ProfilingAgent [baseline] (95.711 ms) : 0, 95711
ProfilingAgent [candidate] (96.712 ms) : 0, 96712
Profiling [baseline] (95.735 ms) : 0, 95735
Profiling [candidate] (96.737 ms) : 0, 96737
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 1 performance regressions! Performance is the same for 11 metrics, 16 unstable metrics.
Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.47.0-SNAPSHOT~126cc4cc28, baseline=1.47.0-SNAPSHOT~429031c283
dateFormat X
axisFormat %s
section baseline
no_agent (1.357 ms) : 1338, 1376
. : milestone, 1357,
appsec (1.752 ms) : 1729, 1775
. : milestone, 1752,
appsec_no_iast (1.747 ms) : 1724, 1770
. : milestone, 1747,
iast (1.516 ms) : 1491, 1540
. : milestone, 1516,
profiling (1.505 ms) : 1482, 1529
. : milestone, 1505,
tracing (1.474 ms) : 1449, 1499
. : milestone, 1474,
section candidate
no_agent (1.354 ms) : 1333, 1374
. : milestone, 1354,
appsec (1.756 ms) : 1732, 1779
. : milestone, 1756,
appsec_no_iast (1.761 ms) : 1738, 1784
. : milestone, 1761,
iast (1.512 ms) : 1487, 1536
. : milestone, 1512,
profiling (1.569 ms) : 1541, 1597
. : milestone, 1569,
tracing (1.503 ms) : 1479, 1527
. : milestone, 1503,
Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.47.0-SNAPSHOT~126cc4cc28, baseline=1.47.0-SNAPSHOT~429031c283
dateFormat X
axisFormat %s
section baseline
no_agent (383.642 µs) : 364, 404
. : milestone, 384,
iast (506.768 µs) : 485, 528
. : milestone, 507,
iast_FULL (745.925 µs) : 724, 768
. : milestone, 746,
iast_GLOBAL (568.811 µs) : 546, 592
. : milestone, 569,
iast_HARDCODED_SECRET_DISABLED (506.321 µs) : 485, 528
. : milestone, 506,
iast_INACTIVE (465.474 µs) : 444, 487
. : milestone, 465,
iast_TELEMETRY_OFF (498.996 µs) : 476, 522
. : milestone, 499,
tracing (459.84 µs) : 438, 481
. : milestone, 460,
section candidate
no_agent (380.77 µs) : 361, 400
. : milestone, 381,
iast (511.826 µs) : 489, 534
. : milestone, 512,
iast_FULL (738.707 µs) : 717, 761
. : milestone, 739,
iast_GLOBAL (560.76 µs) : 539, 583
. : milestone, 561,
iast_HARDCODED_SECRET_DISABLED (512.597 µs) : 491, 534
. : milestone, 513,
iast_INACTIVE (465.057 µs) : 444, 487
. : milestone, 465,
iast_TELEMETRY_OFF (501.801 µs) : 478, 525
. : milestone, 502,
tracing (458.155 µs) : 438, 479
. : milestone, 458,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.47.0-SNAPSHOT~126cc4cc28, baseline=1.47.0-SNAPSHOT~429031c283
dateFormat X
axisFormat %s
section baseline
no_agent (14.797 s) : 14797000, 14797000
. : milestone, 14797000,
appsec (15.133 s) : 15133000, 15133000
. : milestone, 15133000,
iast (18.885 s) : 18885000, 18885000
. : milestone, 18885000,
iast_GLOBAL (18.276 s) : 18276000, 18276000
. : milestone, 18276000,
profiling (15.079 s) : 15079000, 15079000
. : milestone, 15079000,
tracing (14.782 s) : 14782000, 14782000
. : milestone, 14782000,
section candidate
no_agent (15.64 s) : 15640000, 15640000
. : milestone, 15640000,
appsec (15.083 s) : 15083000, 15083000
. : milestone, 15083000,
iast (18.713 s) : 18713000, 18713000
. : milestone, 18713000,
iast_GLOBAL (18.209 s) : 18209000, 18209000
. : milestone, 18209000,
profiling (14.96 s) : 14960000, 14960000
. : milestone, 14960000,
tracing (14.973 s) : 14973000, 14973000
. : milestone, 14973000,
Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.47.0-SNAPSHOT~126cc4cc28, baseline=1.47.0-SNAPSHOT~429031c283
dateFormat X
axisFormat %s
section baseline
no_agent (1.473 ms) : 1462, 1484
. : milestone, 1473,
appsec (2.365 ms) : 2322, 2408
. : milestone, 2365,
iast (2.116 ms) : 2061, 2171
. : milestone, 2116,
iast_GLOBAL (2.16 ms) : 2105, 2216
. : milestone, 2160,
profiling (1.983 ms) : 1939, 2026
. : milestone, 1983,
tracing (1.961 ms) : 1918, 2003
. : milestone, 1961,
section candidate
no_agent (1.478 ms) : 1467, 1490
. : milestone, 1478,
appsec (2.377 ms) : 2334, 2421
. : milestone, 2377,
iast (2.12 ms) : 2065, 2175
. : milestone, 2120,
iast_GLOBAL (2.161 ms) : 2106, 2216
. : milestone, 2161,
profiling (1.989 ms) : 1944, 2034
. : milestone, 1989,
tracing (1.953 ms) : 1911, 1996
. : milestone, 1953,
|
smola
approved these changes
Feb 12, 2025
svc-squareup-copybara
pushed a commit
to cashapp/misk
that referenced
this pull request
Mar 6, 2025
| Package | Type | Package file | Manager | Update | Change | |---|---|---|---|---|---| | [com.datadoghq:dd-trace-api](https://github.com/datadog/dd-trace-java) | dependencies | misk/gradle/libs.versions.toml | gradle | minor | `1.46.1` -> `1.47.0` | | [com.datadoghq:dd-trace-ot](https://github.com/datadog/dd-trace-java) | dependencies | misk/gradle/libs.versions.toml | gradle | minor | `1.46.1` -> `1.47.0` | | [software.amazon.awssdk:sdk-core](https://aws.amazon.com/sdkforjava) | dependencies | misk/gradle/libs.versions.toml | gradle | patch | `2.30.33` -> `2.30.34` | | [software.amazon.awssdk:sqs](https://aws.amazon.com/sdkforjava) | dependencies | misk/gradle/libs.versions.toml | gradle | patch | `2.30.33` -> `2.30.34` | | [software.amazon.awssdk:dynamodb-enhanced](https://aws.amazon.com/sdkforjava) | dependencies | misk/gradle/libs.versions.toml | gradle | patch | `2.30.33` -> `2.30.34` | | [software.amazon.awssdk:dynamodb](https://aws.amazon.com/sdkforjava) | dependencies | misk/gradle/libs.versions.toml | gradle | patch | `2.30.33` -> `2.30.34` | | [software.amazon.awssdk:aws-core](https://aws.amazon.com/sdkforjava) | dependencies | misk/gradle/libs.versions.toml | gradle | patch | `2.30.33` -> `2.30.34` | | [software.amazon.awssdk:bom](https://aws.amazon.com/sdkforjava) | dependencies | misk/gradle/libs.versions.toml | gradle | patch | `2.30.33` -> `2.30.34` | | [software.amazon.awssdk:auth](https://aws.amazon.com/sdkforjava) | dependencies | misk/gradle/libs.versions.toml | gradle | patch | `2.30.33` -> `2.30.34` | --- ### Release Notes <details> <summary>datadog/dd-trace-java (com.datadoghq:dd-trace-api)</summary> ### [`v1.47.0`](https://github.com/DataDog/dd-trace-java/releases/tag/v1.47.0): 1.47.0 ##### Components ##### Application Security Management (IAST) - 🐛 Exclude com.stripe.net.HttpURLConnectionClient to solve IAST SSRF vulnerability false positives ([#​8483](DataDog/dd-trace-java#8483) - [@​jandro996](https://github.com/jandro996)) - 🐛 Add exclusion to solve IAST weak randomness vulnerability false positives ([#​8462](DataDog/dd-trace-java#8462) - [@​jandro996](https://github.com/jandro996)) - ✨ Fix weak randomness false positive in Kafka client ([#​8408](DataDog/dd-trace-java#8408) - [@​smola](https://github.com/smola)) - ✨ Fix location for SSRF with Kong Unirest ([#​8407](DataDog/dd-trace-java#8407) - [@​smola](https://github.com/smola)) - ✨ Exclude IBM Instana from IAST ([#​8406](DataDog/dd-trace-java#8406) - [@​smola](https://github.com/smola)) - 🐛 Fix org.json iast instrumentation test for latest dependency ([#​8347](DataDog/dd-trace-java#8347) - [@​jandro996](https://github.com/jandro996)) - ✨ Configuration to Disable APM Tracing ([#​8219](DataDog/dd-trace-java#8219) - [@​jandro996](https://github.com/jandro996)) - ✨ Address cookie vulnerability cardinality issues ([#​8210](DataDog/dd-trace-java#8210) - [@​jandro996](https://github.com/jandro996)) - ✨ Email HTML Injection detection in IAST ([#​8205](DataDog/dd-trace-java#8205) - [@​sezen-datadog](https://github.com/sezen-datadog)) ##### Application Security Management (WAF) - 🐛✨ Ensure usr.exists tag is not overridden when UsernameNotFoundException is thrown ([#​8376](DataDog/dd-trace-java#8376) - [@​manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez)) - 🐛✨ Ensure usr.exists tag is not overridden by auto instrumentation ([#​8374](DataDog/dd-trace-java#8374) - [@​manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez)) - ✨ Update appsec metrics with event_rules_version tag ([#​8354](DataDog/dd-trace-java#8354) - [@​sezen-datadog](https://github.com/sezen-datadog)) - ✨ Update metrics: appsec.waf.requests ([#​8353](DataDog/dd-trace-java#8353) - [@​Mariovido](https://github.com/Mariovido)) - ✨ Improve ASM support in vert.x 5.0 ([#​8285](DataDog/dd-trace-java#8285) - [@​manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez)) - ✨ Update metrics: appsec.waf.updates and appsec.waf.init ([#​8280](DataDog/dd-trace-java#8280) - [@​Mariovido](https://github.com/Mariovido)) - ✨ Configuration to Disable APM Tracing ([#​8219](DataDog/dd-trace-java#8219) - [@​jandro996](https://github.com/jandro996)) ##### Build & Tooling - 🐛 Do not generate Muzzle references for primitive arrays in method body ([#​8361](DataDog/dd-trace-java#8361) - [@​amarziali](https://github.com/amarziali)) - 📖 Improve dev env setup documentation for Windows ([#​8180](DataDog/dd-trace-java#8180) - [@​lucaspimentel](https://github.com/lucaspimentel)) ##### Continuous Integration Visibility - ✨ Add support for skip-EFD tagging ([#​8487](DataDog/dd-trace-java#8487) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - 🐛 Fix an NPE in Gradle Android instrumentation ([#​8484](DataDog/dd-trace-java#8484) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - ✨ Consider modified tests when applying fail-fast tests ordering ([#​8474](DataDog/dd-trace-java#8474) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - ✨ Implement tests reordering for TestNG ([#​8467](DataDog/dd-trace-java#8467) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - 🐛 Fix Gradle Launcher instrumentation to not interfere with Gradle Test Kit ([#​8465](DataDog/dd-trace-java#8465) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - 🧹 Use separate TestEventHandlers per framework in CI Vis instrumentations ([#​8451](DataDog/dd-trace-java#8451) - [@​daniel-mohedano](https://github.com/daniel-mohedano)) - ✨ Remove warning log when JUnit 4 test method cannot be retrieved ([#​8445](DataDog/dd-trace-java#8445) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - 🐛 Fix Scalatest tracing for tests that are reported asynchronously ([#​8444](DataDog/dd-trace-java#8444) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - ✨ Implement attempt to fix tests ([#​8393](DataDog/dd-trace-java#8393) - [@​daniel-mohedano](https://github.com/daniel-mohedano)) - ✨ Implement test disabling ([#​8377](DataDog/dd-trace-java#8377) - [@​daniel-mohedano](https://github.com/daniel-mohedano)) - ✨ Update CODEOWNERS parser to not log errors on comments with leading whitespace ([#​8349](DataDog/dd-trace-java#8349) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - ✨ Request Test Management tests list ([#​8345](DataDog/dd-trace-java#8345) - [@​daniel-mohedano](https://github.com/daniel-mohedano)) - ✨ Receive test management settings from CIVis settings request ([#​8331](DataDog/dd-trace-java#8331) - [@​daniel-mohedano](https://github.com/daniel-mohedano)) - ✨ Implement quarantined tests tagging ([#​8326](DataDog/dd-trace-java#8326) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - ✨ Implement tests quarantining ([#​8320](DataDog/dd-trace-java#8320) - [@​nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog)) - ✨ Add tag to specify if the user is setting DD_SERVICE ([#​8318](DataDog/dd-trace-java#8318) - [@​daniel-mohedano](https://github.com/daniel-mohedano)) ##### Crash tracking - ✨ Only fork jps when required ([#​8419](DataDog/dd-trace-java#8419) - [@​mcculls](https://github.com/mcculls)) - 🐛 Use Java home of the crashed process to launch crash uploader ([#​8348](DataDog/dd-trace-java#8348) - [@​jbachorik](https://github.com/jbachorik)) ##### Data Streams Monitoring - 🐛 Fix error happening when sqs message attributes are readonly ([#​8473](DataDog/dd-trace-java#8473) - [@​vandonr](https://github.com/vandonr)) - 🐛 Fix bug on proto schema extraction ([#​8403](DataDog/dd-trace-java#8403) - [@​vandonr](https://github.com/vandonr)) - 🐛 Fix service name overrides in consumers ([#​8387](DataDog/dd-trace-java#8387) - [@​piochelepiotr](https://github.com/piochelepiotr)) ##### Database Monitoring - ✨ Add DBMTracePreparedStatements to tracer configuration log ([#​8508](DataDog/dd-trace-java#8508) - [@​cecile75](https://github.com/cecile75)) ##### Dynamic Instrumentation - ✨ Look in another location for grpc service methods ([#​8468](DataDog/dd-trace-java#8468) - [@​evanchooly](https://github.com/evanchooly)) - 🐛 Fix Exception Replay with Lambda proxy classes ([#​8452](DataDog/dd-trace-java#8452) - [@​jpbempel](https://github.com/jpbempel)) - ✨ Add code origin support for spring-webmvc ([#​8416](DataDog/dd-trace-java#8416) - [@​evanchooly](https://github.com/evanchooly)) - ✨ Add support for scanning jar from loaded class ([#​8370](DataDog/dd-trace-java#8370) - [@​jpbempel](https://github.com/jpbempel)) - 🐛 Disable capture of entry values ([#​8369](DataDog/dd-trace-java#8369) - [@​jpbempel](https://github.com/jpbempel)) - 🐛 Fix CodeOrigin for `@Trace` annotation ([#​8344](DataDog/dd-trace-java#8344) - [@​jpbempel](https://github.com/jpbempel)) - 🐛 Fix equals/hashCode for CodeOrigin probe ([#​8319](DataDog/dd-trace-java#8319) - [@​jpbempel](https://github.com/jpbempel)) - ✨ Add code origin support to kafka message listeners ([#​8301](DataDog/dd-trace-java#8301) - [@​evanchooly](https://github.com/evanchooly)) ##### Metrics - ✨ Create metric: appsec.waf.error ([#​8381](DataDog/dd-trace-java#8381) - [@​sezen-datadog](https://github.com/sezen-datadog)) - ✨ Create metric: appsec.rasp.error ([#​8364](DataDog/dd-trace-java#8364) - [@​sezen-datadog](https://github.com/sezen-datadog)) ##### Profiling - ✨ Bump ddprof library to 1.22.0 ([#​8463](DataDog/dd-trace-java#8463) - [@​jbachorik](https://github.com/jbachorik)) - IBM J9 8u361 corresponds to OpenJDK 8u362 by [@​jbachorik](https://github.com/jbachorik) in DataDog/java-profiler#187 - Fix compatibility with musl libc 1.2.4 by [@​jbachorik](https://github.com/jbachorik) in DataDog/java-profiler#189 - Modify version extraction by [@​jbachorik](https://github.com/jbachorik) in DataDog/java-profiler#179 - Do not write null values to jvminfo event by [@​jbachorik](https://github.com/jbachorik) in DataDog/java-profiler#184 - Productize VMStructs-based stack walker by [@​jbachorik](https://github.com/jbachorik) in DataDog/java-profiler#177 - A few minor downport issues by [@​jbachorik](https://github.com/jbachorik) in DataDog/java-profiler#180 - Enable ASGCT by default on fairly safe J9 JDK versions by [@​jbachorik](https://github.com/jbachorik) in DataDog/java-profiler#181 - 🐛 Exclude OrderedThreadPoolExecutor from queue-time measurements ([#​8456](DataDog/dd-trace-java#8456) - [@​jbachorik](https://github.com/jbachorik)) - ✨ Record JVM info on JVMs without JFR ([#​8431](DataDog/dd-trace-java#8431) - [@​jbachorik](https://github.com/jbachorik)) - 🐛 Actually use CleanupTask in TempLocationManager ([#​8420](DataDog/dd-trace-java#8420) - [@​mcculls](https://github.com/mcculls)) - ✨ Only fork jps when required ([#​8419](DataDog/dd-trace-java#8419) - [@​mcculls](https://github.com/mcculls)) - 🐛 Adjust JFR checks for J9 ([#​8405](DataDog/dd-trace-java#8405) - [@​jbachorik](https://github.com/jbachorik)) - 🧹 Disable smap RSS parsing by default ([#​8342](DataDog/dd-trace-java#8342) - [@​MattAlp](https://github.com/MattAlp)) ##### Telemetry - 🐛 Add support for JBoss jar:file format to DependencyResolver ([#​8428](DataDog/dd-trace-java#8428) - [@​jandro996](https://github.com/jandro996)) - ✨ Update metrics: appsec.waf.requests ([#​8353](DataDog/dd-trace-java#8353) - [@​Mariovido](https://github.com/Mariovido)) ##### Trace context propagation - ✨ Introduce tracing propagator ([#​8313](DataDog/dd-trace-java#8313) - [@​PerfectSlayer](https://github.com/PerfectSlayer)) ##### Tracer core - 🐛 Fix Stable Config telemetry source names ([#​8460](DataDog/dd-trace-java#8460) - [@​BaptisteFoy](https://github.com/BaptisteFoy)) - ✨ Probe trace endpoints with a valid payload of empty arrays ([#​8414](DataDog/dd-trace-java#8414) - [@​mcculls](https://github.com/mcculls)) - ✨ Add 1 minute fail-safe to JUL/JMX class-loading callback ([#​8399](DataDog/dd-trace-java#8399) - [@​mcculls](https://github.com/mcculls)) - ✨ Migrate DSM injection calls to context-first APIs ([#​8383](DataDog/dd-trace-java#8383) - [@​PerfectSlayer](https://github.com/PerfectSlayer)) - 🧹 Move continuation capture methods from scope to tracer ([#​8371](DataDog/dd-trace-java#8371) - [@​mcculls](https://github.com/mcculls)) - ✨ Migrate context extraction calls to context-first APIs ([#​8368](DataDog/dd-trace-java#8368) - [@​PerfectSlayer](https://github.com/PerfectSlayer)) - 🧹 Migrate context injection calls to context-first APIs ([#​8358](DataDog/dd-trace-java#8358) - [@​PerfectSlayer](https://github.com/PerfectSlayer)) - 💡 Support reading configurations from files ([#​8338](DataDog/dd-trace-java#8338) - [@​mtoffl01](https://github.com/mtoffl01)) - 💡 Implementation of BaggagePropagator and BaggageContext ([#​8330](DataDog/dd-trace-java#8330) - [@​mhlidd](https://github.com/mhlidd)) - 🧹 Combine continuation implementations into one which supports multiple activations ([#​8324](DataDog/dd-trace-java#8324) - [@​mcculls](https://github.com/mcculls)) - ✨ Introduce tracing propagator ([#​8313](DataDog/dd-trace-java#8313) - [@​PerfectSlayer](https://github.com/PerfectSlayer)) - ✨ Remove old context propagation API ([#​8271](DataDog/dd-trace-java#8271) - [@​PerfectSlayer](https://github.com/PerfectSlayer)) ##### Instrumentations ##### AWS Lambda instrumentation - 🐛 Send error message and stack to Lambda extension ([#​8417](DataDog/dd-trace-java#8417) - [@​nhulston](https://github.com/nhulston)) ##### AWS SDK instrumentation - 🐛 Fix error happening when sqs message attributes are readonly ([#​8473](DataDog/dd-trace-java#8473) - [@​vandonr](https://github.com/vandonr)) - 💡 Inject trace context into AWS Step Functions input ([#​7585](DataDog/dd-trace-java#7585) - [@​DylanLovesCoffee](https://github.com/DylanLovesCoffee)) ##### Core Java language instrumentation - ✨ Look in another location for grpc service methods ([#​8468](DataDog/dd-trace-java#8468) - [@​evanchooly](https://github.com/evanchooly)) - ✨ Add code origin support for spring-webmvc ([#​8416](DataDog/dd-trace-java#8416) - [@​evanchooly](https://github.com/evanchooly)) - 💡 Implementation of BaggagePropagator and BaggageContext ([#​8330](DataDog/dd-trace-java#8330) - [@​mhlidd](https://github.com/mhlidd)) - ✨ Add code origin support to kafka message listeners ([#​8301](DataDog/dd-trace-java#8301) - [@​evanchooly](https://github.com/evanchooly)) ##### gRPC instrumentation - ✨ Look in another location for grpc service methods ([#​8468](DataDog/dd-trace-java#8468) - [@​evanchooly](https://github.com/evanchooly)) ##### Kafka instrumentation - ✨ Add messaging.destination.name tag to kafka integrations ([#​8366](DataDog/dd-trace-java#8366) - [@​rarguelloF](https://github.com/rarguelloF)) ##### Protocol Buffer instrumentation - 🐛 Fix bug on proto schema extraction ([#​8403](DataDog/dd-trace-java#8403) - [@​vandonr](https://github.com/vandonr)) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "after 6pm every weekday,before 2am every weekday" in timezone Australia/Melbourne, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Never, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). GitOrigin-RevId: 108a0f86aa59ab4c938cbac0688dd4c19cb301fa
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
comp: asm waf
Application Security Management (WAF)
type: bug
Bug report and fix
type: enhancement
Enhancements and improvements
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Does This Do
Makes sure that the automated instrumentation does not override the span tag
appsec.events.users.login.failure.usr.exists
when already provided by a call to the SDK.Motivation
Additional Notes
Contributor Checklist
type:
and (comp:
orinst:
) labels in addition to any usefull labelsclose
,fix
or any linking keywords when referencing an issue.Use
solves
instead, and assign the PR milestone to the issueJira ticket: APPSEC-56744