Security
- tracing: Fixes a security vulnerability, as described in GHSA-3633-r77q-h3v3.
Application performance monitoring and tracing SDKs
npx @buildinternet/releases get apmFixed a macOS deadlock that could occur when starting a subprocess during a hostname lookup, and a native memory leak on Linux when DD_TRACE_OTEL_CTX_ENABLED=true and a thread exits with an OpenTelemetry context still attached.
Allocation profiling and the auto OOM heap limit are now enabled by default, and remote-config can activate or deactivate profiling. Added Postgres.js and Supabase tracing, Postgres DBM propagation, LLM Observability prompt management and gen_ai.* span attributes, and dynamic ATR support across Jest, Mocha, Vitest, Cypress, Playwright, Cucumber, and WebdriverIO.
Resolves an issue where gen_ai.* attributes were added to APM spans when LLM Observability was disabled; they are now emitted only when LLM Observability is enabled.
Adds DD_AGENTLESS_ENABLED (default false), a single switch that submits telemetry, traces, Remote Configuration, Dynamic Instrumentation, crash reports, Test Optimization, and LLM Observability data directly to the Datadog intake instead of through a local Agent, requiring DD_API_KEY and becoming the default for per-product agentless settings. Also adds consistent probability sampling support for distributed traces in mixed Datadog-OpenTelemetry environments, a discard field on DD_TRACE_SAMPLING_RULES, Span.remove_tag/remove_metric, and CPython GC collection and stop-the-world pause metrics.