Fixes a security vulnerability described in GHSA-3633-r77q-h3v3 and adds native trace-context support for Trio tasks and worker threads on Linux, enabled by default and disableable with DD_TRACE_TRIO_ENABLED=false. New tracing stats cardinality-limit environment variables bound trace metrics aggregation keys, and LLM Observability adds tag-based head sampling via DD_LLMOBS_SAMPLING_RULES.
Datadog dd-trace-py
npx @buildinternet/releases get datadog-dd-trace-pyFixes a security vulnerability in tracing, detailed in advisory GHSA-3633-r77q-h3v3. No further technical detail is given in the release notes.
Code Security (IAST) fixed an issue where taint tracking could abort the Python process when old-style % string formatting handled tainted text containing a lone surrogate character.
Fixed a macOS deadlock that could occur when starting a subprocess during a hostname lookup, and a native memory leak on Linux when DD_TRACE_OTEL_CTX_ENABLED=true and a thread exits with an OpenTelemetry context still attached.
Fixed an issue where the Python garbage collector stops and memory grows without limit when DD_RUNTIME_METRICS_ENABLED is true, along with a profiling crash in applications that use signal handlers to recover from crashes. Cancelled or failed OpenAI and Bedrock streamed requests now produce LLM Observability spans with the input messages, partial output, and estimated token metrics instead of being dropped or left unmarked.
DD_TRACE_OTEL_CTX_ENABLED now defaults to false until a Linux-native memory leak caused by enabling it is fixed. Fixed abandoned or disconnected streamed LLM requests leaving spans unfinished and growing memory in long-running workers, plus Auto Test Retries not retrying tests that use pytest-timeout thread mode and terminate a pytest-xdist worker.
DD_TRACE_OTEL_CTX_ENABLED now defaults to false again until a Linux-native memory leak caused by enabling it is fixed. Also fixed LLM Observability discarding every trace when combined with DD_APM_TRACING_ENABLED=false, and standalone-mode traces being sent without the one-trace-per-minute sampling limit or the _dd.apm.enabled=0 billing opt-out metric.
DD_TRACE_OTEL_CTX_ENABLED now defaults to false until a Linux-native memory leak caused by setting it to true is fixed. Also fixes pytest-xdist test sessions on shallow Git checkouts spending excessive time unshallowing and failing or timing out during collection.
Resolves an issue where gen_ai.* attributes were added to APM spans when LLM Observability was disabled; they are now emitted only when LLM Observability is enabled.
Adds DD_AGENTLESS_ENABLED (default false), a single switch that submits telemetry, traces, Remote Configuration, Dynamic Instrumentation, crash reports, Test Optimization, and LLM Observability data directly to the Datadog intake instead of through a local Agent, requiring DD_API_KEY and becoming the default for per-product agentless settings. Also adds consistent probability sampling support for distributed traces in mixed Datadog-OpenTelemetry environments, a discard field on DD_TRACE_SAMPLING_RULES, Span.remove_tag/remove_metric, and CPython GC collection and stop-the-world pause metrics.
DD_TRACE_SAMPLING_RULES rules gain a discard boolean field to fully drop trace chunks rejected during sampling, and OTLP-exported spans now carry OpenTelemetry consistent probability sampling state when OTEL_TRACES_EXPORTER=otlp. Also adds CPython GC collection counts and stop-the-world pause metrics to runtime metrics, span links for Kafka consumption, and a heap profiler Mem domain that now defaults to true on Python 3.12+, alongside fixes for crashtracking intake routing and a memory leak.
Fixes a ModuleNotFoundError that silently disabled all vLLM tracing and metrics on vLLM >= 0.14.0, and an AttributeError that prevented applications with LLM Observability enabled from starting on google-adk >= 2.7.0. Also fixes dropped LLM Observability traces caused by non-JSON-serializable span data, streaming tool call spans recording no output on google-adk < 2.7.0, and MCP patching errors when a non-SDK module named mcp is importable.
Test sessions using pytest-xdist on shallow Git checkouts no longer spend excessive time unshallowing the repository, preventing collection failures and timeouts.
Adds automatic tracing for httpx2>=2.0.0, native heap profiling for C/C++ on Linux, and GC time in flame graphs. Deprecates the tracer parameter of RuntimeMetrics.enable and the DD_GOOGLE_CLOUD_PUBSUB_PROPAGATION_AS_SPAN_LINKS variable, replaced by DD_TRACE_PROPAGATION_AS_SPAN_LINKS. Also fixes a memory leak in HTTP clients and entity-tag loss on runtime metrics.
Code origin for spans no longer raises exceptions in large view or traced function sets. Profiling fast memory copy is now automatically disabled when Python runs as an embedded interpreter.
Fixed an exception in span view or traced functions when their count is large, and Fast memory copy for profiling is now automatically disabled when Python runs as an embedded interpreter.
OpenFeature provider now loads configuration directly from Datadog over HTTPS without a Datadog Agent, with remote configuration via DD_FEATURE_FLAGS_CONFIGURATION_SOURCE=remote_config. Also adds AI Guard redaction, LLM Observability experiment queries and feedback submission, and Span.remove_tag/remove_metric, plus fixes for Bedrock token metrics, Django worker memory, and distributed sampling decisions.
Code origin for spans no longer raises an exception when the number of views or traced functions is large.
Fixed an issue where code origin for spans could raise an exception when the number of view or traced functions was large.
Fixed a reentrant SpanData borrow panic in tracing.



