Skip to content

Fix weak hash false positive in oracle.security.o5logon.O5Logon - #8608

Merged
jandro996 merged 8 commits into
masterfrom
alejandro.gonzalez/APPSEC-57044
Mar 25, 2025
Merged

Fix weak hash false positive in oracle.security.o5logon.O5Logon#8608
jandro996 merged 8 commits into
masterfrom
alejandro.gonzalez/APPSEC-57044

Conversation

@jandro996

@jandro996jandro996 commented Mar 24, 2025

Copy link
Copy Markdown
Member

What Does This Do

Exclude oracle.security.o5logon.O5Logon in IAST

Motivation

Additional Notes

Contributor Checklist

Jira ticket: APPSEC-57044

@jandro996jandro996 added type: feature Enhancements and improvements comp: asm iast Application Security Management (IAST) labels Mar 24, 2025
@jandro996
jandro996 marked this pull request as ready for review March 24, 2025 08:18
@jandro996
jandro996 requested a review from a team as a code ownerMarch 24, 2025 08:18
@pr-commenter

pr-commenterBot commented Mar 24, 2025

Copy link
Copy Markdown

Benchmarks

Startup

Parameters

BaselineCandidate
baseline_or_candidatebaselinecandidate
git_branchmasteralejandro.gonzalez/APPSEC-57044
git_commit_date17428257491742890817
git_commit_sha51813bdab7b08c
release_version1.48.0-SNAPSHOT~51813bdfcb1.48.0-SNAPSHOT~ab7b08c058
See matching parameters
BaselineCandidate
applicationinsecure-bankinsecure-bank
ci_job_date17428936551742893655
ci_job_id862832235862832235
ci_pipeline_id5986010659860106
cpu_modelIntel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHzIntel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_versionLinux runner-kj59svlh-project-304-concurrent-0-y1d6cxxz 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/LinuxLinux runner-kj59svlh-project-304-concurrent-0-y1d6cxxz 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux
moduleAgentAgent
parentNoneNone
variantiastiast

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 65 metrics, 6 unstable metrics.

Startup time reports for insecure-bank
gantt
title insecure-bank - global startup overhead: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.046 s) : 0, 1046427
Total [baseline] (8.698 s) : 0, 8698078
Agent [candidate] (1.05 s) : 0, 1050396
Total [candidate] (8.662 s) : 0, 8661992
section iast
Agent [baseline] (1.177 s) : 0, 1176529
Total [baseline] (9.222 s) : 0, 9221947
Agent [candidate] (1.176 s) : 0, 1176106
Total [candidate] (9.235 s) : 0, 9235197
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.186 s) : 0, 1185965
Total [baseline] (9.241 s) : 0, 9241174
Agent [candidate] (1.186 s) : 0, 1186213
Total [candidate] (9.253 s) : 0, 9253018
section iast_TELEMETRY_OFF
Agent [baseline] (1.178 s) : 0, 1178467
Total [baseline] (9.271 s) : 0, 9270706
Agent [candidate] (1.179 s) : 0, 1179020
Total [candidate] (9.24 s) : 0, 9239679
Loading
  • baseline results
ModuleVariantDurationΔ tracing
Agenttracing1.046 s-
Agentiast1.177 s130.102 ms (12.4%)
Agentiast_HARDCODED_SECRET_DISABLED1.186 s139.538 ms (13.3%)
Agentiast_TELEMETRY_OFF1.178 s132.04 ms (12.6%)
Totaltracing8.698 s-
Totaliast9.222 s523.868 ms (6.0%)
Totaliast_HARDCODED_SECRET_DISABLED9.241 s543.095 ms (6.2%)
Totaliast_TELEMETRY_OFF9.271 s572.628 ms (6.6%)
  • candidate results
ModuleVariantDurationΔ tracing
Agenttracing1.05 s-
Agentiast1.176 s125.71 ms (12.0%)
Agentiast_HARDCODED_SECRET_DISABLED1.186 s135.817 ms (12.9%)
Agentiast_TELEMETRY_OFF1.179 s128.624 ms (12.2%)
Totaltracing8.662 s-
Totaliast9.235 s573.206 ms (6.6%)
Totaliast_HARDCODED_SECRET_DISABLED9.253 s591.027 ms (6.8%)
Totaliast_TELEMETRY_OFF9.24 s577.687 ms (6.7%)
gantt
title insecure-bank - break down per module: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (718.017 ms) : 0, 718017
BytebuddyAgent [candidate] (719.31 ms) : 0, 719310
GlobalTracer [baseline] (239.959 ms) : 0, 239959
GlobalTracer [candidate] (240.001 ms) : 0, 240001
AppSec [baseline] (54.611 ms) : 0, 54611
AppSec [candidate] (55.028 ms) : 0, 55028
Debugger [baseline] (4.398 ms) : 0, 4398
Debugger [candidate] (4.432 ms) : 0, 4432
Remote Config [baseline] (701.713 µs) : 0, 702
Remote Config [candidate] (721.376 µs) : 0, 721
Telemetry [baseline] (12.733 ms) : 0, 12733
Telemetry [candidate] (14.889 ms) : 0, 14889
section iast
BytebuddyAgent [baseline] (838.522 ms) : 0, 838522
BytebuddyAgent [candidate] (837.885 ms) : 0, 837885
GlobalTracer [baseline] (229.916 ms) : 0, 229916
GlobalTracer [candidate] (229.985 ms) : 0, 229985
IAST [baseline] (22.696 ms) : 0, 22696
IAST [candidate] (22.835 ms) : 0, 22835
AppSec [baseline] (55.991 ms) : 0, 55991
AppSec [candidate] (55.802 ms) : 0, 55802
Debugger [baseline] (4.141 ms) : 0, 4141
Debugger [candidate] (4.175 ms) : 0, 4175
Remote Config [baseline] (595.984 µs) : 0, 596
Remote Config [candidate] (598.238 µs) : 0, 598
Telemetry [baseline] (8.736 ms) : 0, 8736
Telemetry [candidate] (8.746 ms) : 0, 8746
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (844.816 ms) : 0, 844816
BytebuddyAgent [candidate] (845.497 ms) : 0, 845497
GlobalTracer [baseline] (231.493 ms) : 0, 231493
GlobalTracer [candidate] (231.568 ms) : 0, 231568
IAST [baseline] (23.09 ms) : 0, 23090
IAST [candidate] (23.12 ms) : 0, 23120
AppSec [baseline] (56.741 ms) : 0, 56741
AppSec [candidate] (56.284 ms) : 0, 56284
Debugger [baseline] (4.214 ms) : 0, 4214
Debugger [candidate] (4.18 ms) : 0, 4180
Remote Config [baseline] (615.35 µs) : 0, 615
Remote Config [candidate] (602.351 µs) : 0, 602
Telemetry [baseline] (8.883 ms) : 0, 8883
Telemetry [candidate] (8.878 ms) : 0, 8878
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (840.463 ms) : 0, 840463
BytebuddyAgent [candidate] (839.645 ms) : 0, 839645
GlobalTracer [baseline] (230.224 ms) : 0, 230224
GlobalTracer [candidate] (231.5 ms) : 0, 231500
IAST [baseline] (22.398 ms) : 0, 22398
IAST [candidate] (23.272 ms) : 0, 23272
AppSec [baseline] (55.971 ms) : 0, 55971
AppSec [candidate] (55.272 ms) : 0, 55272
Debugger [baseline] (4.141 ms) : 0, 4141
Debugger [candidate] (4.141 ms) : 0, 4141
Remote Config [baseline] (605.883 µs) : 0, 606
Remote Config [candidate] (590.636 µs) : 0, 591
Telemetry [baseline] (8.578 ms) : 0, 8578
Telemetry [candidate] (8.588 ms) : 0, 8588
Loading
Startup time reports for petclinic
gantt
title petclinic - global startup overhead: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.048 s) : 0, 1048214
Total [baseline] (10.463 s) : 0, 10462912
Agent [candidate] (1.047 s) : 0, 1046732
Total [candidate] (10.478 s) : 0, 10477706
section appsec
Agent [baseline] (1.188 s) : 0, 1188123
Total [baseline] (10.796 s) : 0, 10795792
Agent [candidate] (1.196 s) : 0, 1195689
Total [candidate] (10.793 s) : 0, 10793059
section iast
Agent [baseline] (1.177 s) : 0, 1176611
Total [baseline] (11.012 s) : 0, 11012027
Agent [candidate] (1.189 s) : 0, 1189390
Total [candidate] (11.032 s) : 0, 11032147
section profiling
Agent [baseline] (1.282 s) : 0, 1282410
Total [baseline] (10.928 s) : 0, 10927500
Agent [candidate] (1.27 s) : 0, 1270343
Total [candidate] (10.816 s) : 0, 10815893
Loading
  • baseline results
ModuleVariantDurationΔ tracing
Agenttracing1.048 s-
Agentappsec1.188 s139.91 ms (13.3%)
Agentiast1.177 s128.397 ms (12.2%)
Agentprofiling1.282 s234.196 ms (22.3%)
Totaltracing10.463 s-
Totalappsec10.796 s332.881 ms (3.2%)
Totaliast11.012 s549.116 ms (5.2%)
Totalprofiling10.928 s464.588 ms (4.4%)
  • candidate results
ModuleVariantDurationΔ tracing
Agenttracing1.047 s-
Agentappsec1.196 s148.957 ms (14.2%)
Agentiast1.189 s142.658 ms (13.6%)
Agentprofiling1.27 s223.612 ms (21.4%)
Totaltracing10.478 s-
Totalappsec10.793 s315.353 ms (3.0%)
Totaliast11.032 s554.441 ms (5.3%)
Totalprofiling10.816 s338.187 ms (3.2%)
gantt
title petclinic - break down per module: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (718.222 ms) : 0, 718222
BytebuddyAgent [candidate] (718.238 ms) : 0, 718238
GlobalTracer [baseline] (239.693 ms) : 0, 239693
GlobalTracer [candidate] (239.623 ms) : 0, 239623
AppSec [baseline] (54.863 ms) : 0, 54863
AppSec [candidate] (54.689 ms) : 0, 54689
Debugger [baseline] (5.859 ms) : 0, 5859
Debugger [candidate] (5.155 ms) : 0, 5155
Remote Config [baseline] (712.222 µs) : 0, 712
Remote Config [candidate] (708.45 µs) : 0, 708
Telemetry [baseline] (12.841 ms) : 0, 12841
Telemetry [candidate] (12.314 ms) : 0, 12314
section appsec
BytebuddyAgent [baseline] (736.019 ms) : 0, 736019
BytebuddyAgent [candidate] (741.219 ms) : 0, 741219
GlobalTracer [baseline] (236.094 ms) : 0, 236094
GlobalTracer [candidate] (237.728 ms) : 0, 237728
IAST [baseline] (21.537 ms) : 0, 21537
IAST [candidate] (21.459 ms) : 0, 21459
AppSec [baseline] (175.725 ms) : 0, 175725
AppSec [candidate] (176.279 ms) : 0, 176279
Debugger [baseline] (4.298 ms) : 0, 4298
Debugger [candidate] (4.328 ms) : 0, 4328
Remote Config [baseline] (652.95 µs) : 0, 653
Remote Config [candidate] (651.781 µs) : 0, 652
Telemetry [baseline] (8.532 ms) : 0, 8532
Telemetry [candidate] (8.649 ms) : 0, 8649
section iast
BytebuddyAgent [baseline] (838.133 ms) : 0, 838133
BytebuddyAgent [candidate] (846.985 ms) : 0, 846985
GlobalTracer [baseline] (230.172 ms) : 0, 230172
GlobalTracer [candidate] (232.853 ms) : 0, 232853
IAST [baseline] (22.764 ms) : 0, 22764
IAST [candidate] (23.418 ms) : 0, 23418
AppSec [baseline] (56.182 ms) : 0, 56182
AppSec [candidate] (56.372 ms) : 0, 56372
Debugger [baseline] (4.123 ms) : 0, 4123
Debugger [candidate] (4.179 ms) : 0, 4179
Remote Config [baseline] (588.482 µs) : 0, 588
Remote Config [candidate] (607.725 µs) : 0, 608
Telemetry [baseline] (8.684 ms) : 0, 8684
Telemetry [candidate] (8.797 ms) : 0, 8797
section profiling
BytebuddyAgent [baseline] (714.074 ms) : 0, 714074
BytebuddyAgent [candidate] (708.957 ms) : 0, 708957
GlobalTracer [baseline] (353.625 ms) : 0, 353625
GlobalTracer [candidate] (349.97 ms) : 0, 349970
AppSec [baseline] (54.898 ms) : 0, 54898
AppSec [candidate] (53.451 ms) : 0, 53451
Debugger [baseline] (4.368 ms) : 0, 4368
Debugger [candidate] (4.254 ms) : 0, 4254
Remote Config [baseline] (713.936 µs) : 0, 714
Remote Config [candidate] (703.543 µs) : 0, 704
Telemetry [baseline] (9.172 ms) : 0, 9172
Telemetry [candidate] (8.926 ms) : 0, 8926
ProfilingAgent [baseline] (103.473 ms) : 0, 103473
ProfilingAgent [candidate] (102.503 ms) : 0, 102503
Profiling [baseline] (103.631 ms) : 0, 103631
Profiling [candidate] (102.53 ms) : 0, 102530
Loading

Load

Parameters

BaselineCandidate
baseline_or_candidatebaselinecandidate
end_time2025-03-25T08:35:492025-03-25T08:43:36
git_branchmasteralejandro.gonzalez/APPSEC-57044
git_commit_date17428257491742890817
git_commit_sha51813bdab7b08c
release_version1.48.0-SNAPSHOT~51813bdfcb1.48.0-SNAPSHOT~ab7b08c058
start_time2025-03-25T08:35:352025-03-25T08:43:22
See matching parameters
BaselineCandidate
applicationinsecure-bankinsecure-bank
ci_job_date17428926151742892615
ci_job_id862832236862832236
ci_pipeline_id5986010659860106
cpu_modelIntel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHzIntel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_versionLinux runner-vapngg-f-project-304-concurrent-0-dugngi4u 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/LinuxLinux runner-vapngg-f-project-304-concurrent-0-dugngi4u 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux
variantiastiast

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 13 metrics, 17 unstable metrics.

Request duration reports for insecure-bank
gantt
title insecure-bank - request duration [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section baseline
no_agent (387.414 µs) : 367, 408
. : milestone, 387,
iast (523.618 µs) : 502, 545
. : milestone, 524,
iast_FULL (737.228 µs) : 715, 759
. : milestone, 737,
iast_GLOBAL (569.741 µs) : 548, 592
. : milestone, 570,
iast_HARDCODED_SECRET_DISABLED (513.573 µs) : 492, 535
. : milestone, 514,
iast_INACTIVE (466.618 µs) : 445, 488
. : milestone, 467,
iast_TELEMETRY_OFF (508.999 µs) : 487, 531
. : milestone, 509,
tracing (461.4 µs) : 440, 483
. : milestone, 461,
section candidate
no_agent (394.125 µs) : 374, 414
. : milestone, 394,
iast (521.509 µs) : 500, 543
. : milestone, 522,
iast_FULL (732.422 µs) : 710, 754
. : milestone, 732,
iast_GLOBAL (564.385 µs) : 542, 587
. : milestone, 564,
iast_HARDCODED_SECRET_DISABLED (519.527 µs) : 498, 541
. : milestone, 520,
iast_INACTIVE (471.714 µs) : 449, 494
. : milestone, 472,
iast_TELEMETRY_OFF (504.235 µs) : 482, 526
. : milestone, 504,
tracing (462.592 µs) : 442, 483
. : milestone, 463,
Loading
  • baseline results
VariantRequest duration [CI 0.99]Δ no_agent
no_agent387.414 µs [367.231 µs, 407.596 µs]-
iast523.618 µs [501.827 µs, 545.408 µs]136.204 µs (35.2%)
iast_FULL737.228 µs [715.211 µs, 759.246 µs]349.815 µs (90.3%)
iast_GLOBAL569.741 µs [547.535 µs, 591.946 µs]182.327 µs (47.1%)
iast_HARDCODED_SECRET_DISABLED513.573 µs [492.083 µs, 535.063 µs]126.159 µs (32.6%)
iast_INACTIVE466.618 µs [445.191 µs, 488.046 µs]79.205 µs (20.4%)
iast_TELEMETRY_OFF508.999 µs [487.047 µs, 530.951 µs]121.586 µs (31.4%)
tracing461.4 µs [440.245 µs, 482.554 µs]73.986 µs (19.1%)
  • candidate results
VariantRequest duration [CI 0.99]Δ no_agent
no_agent394.125 µs [374.095 µs, 414.156 µs]-
iast521.509 µs [499.599 µs, 543.42 µs]127.384 µs (32.3%)
iast_FULL732.422 µs [710.403 µs, 754.442 µs]338.297 µs (85.8%)
iast_GLOBAL564.385 µs [542.193 µs, 586.578 µs]170.26 µs (43.2%)
iast_HARDCODED_SECRET_DISABLED519.527 µs [497.774 µs, 541.28 µs]125.401 µs (31.8%)
iast_INACTIVE471.714 µs [449.37 µs, 494.058 µs]77.588 µs (19.7%)
iast_TELEMETRY_OFF504.235 µs [482.151 µs, 526.318 µs]110.109 µs (27.9%)
tracing462.592 µs [442.016 µs, 483.167 µs]68.466 µs (17.4%)
Request duration reports for petclinic
gantt
title petclinic - request duration [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section baseline
no_agent (1.373 ms) : 1352, 1393
. : milestone, 1373,
appsec (1.734 ms) : 1710, 1758
. : milestone, 1734,
appsec_no_iast (1.739 ms) : 1715, 1762
. : milestone, 1739,
code_origins (1.688 ms) : 1661, 1716
. : milestone, 1688,
iast (1.518 ms) : 1493, 1542
. : milestone, 1518,
profiling (1.577 ms) : 1552, 1602
. : milestone, 1577,
tracing (1.496 ms) : 1471, 1521
. : milestone, 1496,
section candidate
no_agent (1.37 ms) : 1351, 1390
. : milestone, 1370,
appsec (1.747 ms) : 1723, 1770
. : milestone, 1747,
appsec_no_iast (1.742 ms) : 1719, 1765
. : milestone, 1742,
code_origins (1.67 ms) : 1642, 1697
. : milestone, 1670,
iast (1.516 ms) : 1491, 1541
. : milestone, 1516,
profiling (1.529 ms) : 1504, 1555
. : milestone, 1529,
tracing (1.511 ms) : 1486, 1535
. : milestone, 1511,
Loading
  • baseline results
VariantRequest duration [CI 0.99]Δ no_agent
no_agent1.373 ms [1.352 ms, 1.393 ms]-
appsec1.734 ms [1.71 ms, 1.758 ms]361.507 µs (26.3%)
appsec_no_iast1.739 ms [1.715 ms, 1.762 ms]365.914 µs (26.7%)
code_origins1.688 ms [1.661 ms, 1.716 ms]315.889 µs (23.0%)
iast1.518 ms [1.493 ms, 1.542 ms]145.305 µs (10.6%)
profiling1.577 ms [1.552 ms, 1.602 ms]204.724 µs (14.9%)
tracing1.496 ms [1.471 ms, 1.521 ms]123.77 µs (9.0%)
  • candidate results
VariantRequest duration [CI 0.99]Δ no_agent
no_agent1.37 ms [1.351 ms, 1.39 ms]-
appsec1.747 ms [1.723 ms, 1.77 ms]376.322 µs (27.5%)
appsec_no_iast1.742 ms [1.719 ms, 1.765 ms]371.872 µs (27.1%)
code_origins1.67 ms [1.642 ms, 1.697 ms]299.548 µs (21.9%)
iast1.516 ms [1.491 ms, 1.541 ms]145.847 µs (10.6%)
profiling1.529 ms [1.504 ms, 1.555 ms]159.282 µs (11.6%)
tracing1.511 ms [1.486 ms, 1.535 ms]140.479 µs (10.3%)

Dacapo

Parameters

BaselineCandidate
baseline_or_candidatebaselinecandidate
git_branchmasteralejandro.gonzalez/APPSEC-57044
git_commit_date17428257491742890817
git_commit_sha51813bdab7b08c
release_version1.48.0-SNAPSHOT~51813bdfcb1.48.0-SNAPSHOT~ab7b08c058
See matching parameters
BaselineCandidate
applicationbiojavabiojava
ci_job_date17428931831742893183
ci_job_id862832237862832237
ci_pipeline_id5986010659860106
cpu_modelIntel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHzIntel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_versionLinux runner-kj59svlh-project-304-concurrent-1-t7nevrbc 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/LinuxLinux runner-kj59svlh-project-304-concurrent-1-t7nevrbc 6.8.0-1024-aws #26~22.04.1-Ubuntu SMP Wed Feb 19 06:54:57 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux
variantappsecappsec

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 1 unstable metrics.

Execution time for tomcat
gantt
title tomcat - execution time [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section baseline
no_agent (1.475 ms) : 1463, 1486
. : milestone, 1475,
appsec (2.331 ms) : 2288, 2375
. : milestone, 2331,
iast (2.12 ms) : 2065, 2175
. : milestone, 2120,
iast_GLOBAL (2.172 ms) : 2116, 2228
. : milestone, 2172,
profiling (2.439 ms) : 2258, 2621
. : milestone, 2439,
tracing (1.956 ms) : 1913, 1999
. : milestone, 1956,
section candidate
no_agent (1.473 ms) : 1461, 1484
. : milestone, 1473,
appsec (2.351 ms) : 2307, 2395
. : milestone, 2351,
iast (2.123 ms) : 2068, 2179
. : milestone, 2123,
iast_GLOBAL (2.163 ms) : 2107, 2219
. : milestone, 2163,
profiling (1.968 ms) : 1924, 2012
. : milestone, 1968,
tracing (1.952 ms) : 1910, 1995
. : milestone, 1952,
Loading
  • baseline results
VariantExecution Time [CI 0.99]Δ no_agent
no_agent1.475 ms [1.463 ms, 1.486 ms]-
appsec2.331 ms [2.288 ms, 2.375 ms]856.53 µs (58.1%)
iast2.12 ms [2.065 ms, 2.175 ms]645.233 µs (43.8%)
iast_GLOBAL2.172 ms [2.116 ms, 2.228 ms]697.05 µs (47.3%)
profiling2.439 ms [2.258 ms, 2.621 ms]964.699 µs (65.4%)
tracing1.956 ms [1.913 ms, 1.999 ms]481.151 µs (32.6%)
  • candidate results
VariantExecution Time [CI 0.99]Δ no_agent
no_agent1.473 ms [1.461 ms, 1.484 ms]-
appsec2.351 ms [2.307 ms, 2.395 ms]878.539 µs (59.6%)
iast2.123 ms [2.068 ms, 2.179 ms]650.611 µs (44.2%)
iast_GLOBAL2.163 ms [2.107 ms, 2.219 ms]690.102 µs (46.9%)
profiling1.968 ms [1.924 ms, 2.012 ms]494.801 µs (33.6%)
tracing1.952 ms [1.91 ms, 1.995 ms]479.423 µs (32.6%)
Execution time for biojava
gantt
title biojava - execution time [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section baseline
no_agent (14.835 s) : 14835000, 14835000
. : milestone, 14835000,
appsec (15.096 s) : 15096000, 15096000
. : milestone, 15096000,
iast (19.106 s) : 19106000, 19106000
. : milestone, 19106000,
iast_GLOBAL (18.107 s) : 18107000, 18107000
. : milestone, 18107000,
profiling (15.145 s) : 15145000, 15145000
. : milestone, 15145000,
tracing (15.086 s) : 15086000, 15086000
. : milestone, 15086000,
section candidate
no_agent (15.597 s) : 15597000, 15597000
. : milestone, 15597000,
appsec (15.379 s) : 15379000, 15379000
. : milestone, 15379000,
iast (19.126 s) : 19126000, 19126000
. : milestone, 19126000,
iast_GLOBAL (17.671 s) : 17671000, 17671000
. : milestone, 17671000,
profiling (15.038 s) : 15038000, 15038000
. : milestone, 15038000,
tracing (15.136 s) : 15136000, 15136000
. : milestone, 15136000,
Loading
  • baseline results
VariantExecution Time [CI 0.99]Δ no_agent
no_agent14.835 s [14.835 s, 14.835 s]-
appsec15.096 s [15.096 s, 15.096 s]261.0 ms (1.8%)
iast19.106 s [19.106 s, 19.106 s]4.271 s (28.8%)
iast_GLOBAL18.107 s [18.107 s, 18.107 s]3.272 s (22.1%)
profiling15.145 s [15.145 s, 15.145 s]310.0 ms (2.1%)
tracing15.086 s [15.086 s, 15.086 s]251.0 ms (1.7%)
  • candidate results
VariantExecution Time [CI 0.99]Δ no_agent
no_agent15.597 s [15.597 s, 15.597 s]-
appsec15.379 s [15.379 s, 15.379 s]-218.0 ms (-1.4%)
iast19.126 s [19.126 s, 19.126 s]3.529 s (22.6%)
iast_GLOBAL17.671 s [17.671 s, 17.671 s]2.074 s (13.3%)
profiling15.038 s [15.038 s, 15.038 s]-559.0 ms (-3.6%)
tracing15.136 s [15.136 s, 15.136 s]-461.0 ms (-3.0%)

@jandro996jandro996 added this to the 1.48.0 milestone Mar 25, 2025
@jandro996
jandro996 merged commit eb44168 into masterMar 25, 2025
@jandro996
jandro996 deleted the alejandro.gonzalez/APPSEC-57044 branch March 25, 2025 11:41
svc-squareup-copybara pushed a commit to cashapp/misk that referenced this pull request Apr 11, 2025
| Package | Type | Package file | Manager | Update | Change |
|---|---|---|---|---|---|
| org.flywaydb.flyway | plugin | misk/gradle/libs.versions.toml | gradle
| minor | `11.6.0` -> `11.7.0` |
|
[com.squareup.okio:okio-fakefilesystem](https://github.com/square/okio)
| dependencies | misk/gradle/libs.versions.toml | gradle | minor |
`3.10.2` -> `3.11.0` |
| [com.squareup.okio:okio](https://github.com/square/okio) |
dependencies | misk/gradle/libs.versions.toml | gradle | minor |
`3.10.2` -> `3.11.0` |
|
[com.autonomousapps.dependency-analysis](https://github.com/autonomousapps/dependency-analysis-android-gradle-plugin)
| plugin | misk/gradle/libs.versions.toml | gradle | minor | `2.15.0` ->
`2.16.0` |
| [com.datadoghq:dd-trace-api](https://github.com/datadog/dd-trace-java)
| dependencies | misk/gradle/libs.versions.toml | gradle | minor |
`1.47.3` -> `1.48.1` |
| [com.datadoghq:dd-trace-ot](https://github.com/datadog/dd-trace-java)
| dependencies | misk/gradle/libs.versions.toml | gradle | minor |
`1.47.3` -> `1.48.1` |
| [software.amazon.awssdk:sdk-core](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:sqs](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
|
[software.amazon.awssdk:dynamodb-enhanced](https://aws.amazon.com/sdkforjava)
| dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:dynamodb](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:aws-core](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:bom](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:auth](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
---
### Release Notes
<details>
<summary>square/okio (com.squareup.okio:okio-fakefilesystem)</summary>
###
[`v3.11.0`](https://github.com/square/okio/blob/HEAD/CHANGELOG.md#Version-3110)
*2025-04-09*
- Fix: Clear the deflater's byte array reference
- New: Faster implementation of `String.decodeHex()` on Kotlin/JS.
- New: Declare `EXACTLY_ONCE` execution for blocks like `Closeable.use
{}` and `FileSystem.read {}`.
- Upgrade: \[Kotlin 2.1.20]\[kotlin\_2\_1\_20].
</details>
<details>
<summary>autonomousapps/dependency-analysis-android-gradle-plugin
(com.autonomousapps.dependency-analysis)</summary>
###
[`v2.16.0`](https://github.com/autonomousapps/dependency-analysis-android-gradle-plugin/blob/HEAD/CHANGELOG.md#Version-2160)
- \[Feat]: support `com.android.test` projects.
- \[Feat]: support typesafe project accessors with opt-in.
```kotlin
dependencyAnalysis {
useTypesafeProjectAccessors(true) // false by default
}
```
</details>
<details>
<summary>datadog/dd-trace-java (com.datadoghq:dd-trace-api)</summary>
###
[`v1.48.1`](https://github.com/DataDog/dd-trace-java/releases/tag/v1.48.1):
1.48.1
### Components
#### Tracer internal logging
- 🐛 Remove print line causing unnecessary logs
([#&#8203;8687](DataDog/dd-trace-java#8687) -
[@&#8203;sarahchen6](https://github.com/sarahchen6))
###
[`v1.48.0`](https://github.com/DataDog/dd-trace-java/releases/tag/v1.48.0):
1.48.0
### Known Bugs
> \[!NOTE]
> If you are experiencing issues with spamming timeout logs, please
update to the [latest
version](https://github.com/DataDog/dd-trace-java/releases/latest) or
set
[JDK_SOCKET_ENABLED](https://github.com/DataDog/dd-trace-java/blob/33fc3c9a9b7cda3beda88b8b3e5224ae2b10764a/dd-trace-api/src/main/java/datadog/trace/api/config/GeneralConfig.java#L98)
to false.
### Components
#### Application Security Management (IAST)
- ✨ Fix vulnerability location org.jose4j.lang.HashUtil
([#&#8203;8610](DataDog/dd-trace-java#8610) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Fix weak randomness in oracle.ucp.util.OpaqueString
([#&#8203;8609](DataDog/dd-trace-java#8609) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Fix weak hash false positive in
oracle.security.o5logon.O5Logon
([#&#8203;8608](DataDog/dd-trace-java#8608) -
[@&#8203;jandro996](https://github.com/jandro996))
- 🐛 Prevent before callsites targeting constructors in super calls
([#&#8203;8549](DataDog/dd-trace-java#8549) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
#### Application Security Management (WAF)
- ✨ Update login events public SDK to V2
([#&#8203;8620](DataDog/dd-trace-java#8620) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- 🐛 Send RASP LFI capability only when AppSec is statically enabled
([#&#8203;8573](DataDog/dd-trace-java#8573) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Improve detection of missing request end events
([#&#8203;8510](DataDog/dd-trace-java#8510) -
[@&#8203;smola](https://github.com/smola))
- 🧹 Remove remote configuration for API Security sampling rate
([#&#8203;8486](DataDog/dd-trace-java#8486) -
[@&#8203;smola](https://github.com/smola))
- ✨ Add setUser to user monitoring SDK
([#&#8203;8482](DataDog/dd-trace-java#8482) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- ✨ Add missing address for signup event
([#&#8203;8469](DataDog/dd-trace-java#8469) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- ✨ Allow login events SDK to be used with appsec disabled
([#&#8203;8464](DataDog/dd-trace-java#8464) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- ✨ Add support for endpoint discovery in spring mvc
([#&#8203;8352](DataDog/dd-trace-java#8352) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- ✨ New API Security sampling algorithm
([#&#8203;8178](DataDog/dd-trace-java#8178) -
[@&#8203;ValentinZakharov](https://github.com/ValentinZakharov))
#### Build & Tooling
- ✨ Add buffer size customizability to JDK UDS support
([#&#8203;8629](DataDog/dd-trace-java#8629) -
[@&#8203;sarahchen6](https://github.com/sarahchen6))
- ✨ Add JDK built-in support for UDS on Java 16+
([#&#8203;8314](DataDog/dd-trace-java#8314) -
[@&#8203;sarahchen6](https://github.com/sarahchen6))
#### Configuration at Runtime
- 🐛 Send RASP LFI capability only when AppSec is statically enabled
([#&#8203;8573](DataDog/dd-trace-java#8573) -
[@&#8203;jandro996](https://github.com/jandro996))
#### Continuous Integration Visibility
- 🐛 Prevent double reporting of Scalatest events when using SBT with
test forking
([#&#8203;8682](DataDog/dd-trace-java#8682) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- 🐛 Shutdown CI Visibility test event handlers before tracer
([#&#8203;8677](DataDog/dd-trace-java#8677) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- 🐛 Do not apply JUnit 4 instrumentation to MUnit runners
([#&#8203;8675](DataDog/dd-trace-java#8675),
[#&#8203;8683](DataDog/dd-trace-java#8683) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- ✨ Remove error log when source path resolution fails on
isModified check
([#&#8203;8663](DataDog/dd-trace-java#8663) -
[@&#8203;daniel-mohedano](https://github.com/daniel-mohedano))
- ✨ Implement tests reordering for JUnit 4
([#&#8203;8650](DataDog/dd-trace-java#8650) -
[@&#8203;daniel-mohedano](https://github.com/daniel-mohedano))
- 🐛 Set default Attempt to Fix retries if none provided from the
backend
([#&#8203;8615](DataDog/dd-trace-java#8615) -
[@&#8203;daniel-mohedano](https://github.com/daniel-mohedano))
- ✨ Allow to manually set PR info
([#&#8203;8566](DataDog/dd-trace-java#8566) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- 🐛 Fix Test Optimization init when repo root cannot be determined
([#&#8203;8533](DataDog/dd-trace-java#8533) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- ✨ Add capabilities tagging
([#&#8203;8499](DataDog/dd-trace-java#8499),
[#&#8203;8540](DataDog/dd-trace-java#8540) -
[@&#8203;daniel-mohedano](https://github.com/daniel-mohedano))
#### Crash tracking
- 🐛 Remove dependency on bash from crash/oome uploder scripts
([#&#8203;8652](DataDog/dd-trace-java#8652) -
[@&#8203;jbachorik](https://github.com/jbachorik))
#### Data Streams Monitoring
- ✨ e2e pipeline configuration when data jobs is enabled
([#&#8203;8553](DataDog/dd-trace-java#8553) -
[@&#8203;kr-igor](https://github.com/kr-igor))
#### Dynamic Instrumentation
- 🐛 Fix In-Product when config is empty
([#&#8203;8679](DataDog/dd-trace-java#8679) -
[@&#8203;jpbempel](https://github.com/jpbempel))
- ✨ Add support for filtering shaded third-party libs
([#&#8203;8612](DataDog/dd-trace-java#8612) -
[@&#8203;jpbempel](https://github.com/jpbempel))
- ✨ Add In-Product Enablement
([#&#8203;8587](DataDog/dd-trace-java#8587) -
[@&#8203;jpbempel](https://github.com/jpbempel))
- ✨⚡ Reduce footprint of SourceFile tracking
([#&#8203;8524](DataDog/dd-trace-java#8524) -
[@&#8203;jpbempel](https://github.com/jpbempel))
- ✨⚡ Optimize the SourceFile tracking
([#&#8203;8520](DataDog/dd-trace-java#8520) -
[@&#8203;jpbempel](https://github.com/jpbempel))
#### OpenTracing
- 🧹 Remove activeScope() use in OpenTracing shim
([#&#8203;8478](DataDog/dd-trace-java#8478) -
[@&#8203;mcculls](https://github.com/mcculls))
#### Profiling
- ✨ Add profiler env check command to AgentCLI
([#&#8203;8671](DataDog/dd-trace-java#8671) -
[@&#8203;jbachorik](https://github.com/jbachorik))
- ✨ Bump ddprof to 1.23.0
([#&#8203;8668](DataDog/dd-trace-java#8668) -
[@&#8203;jbachorik](https://github.com/jbachorik))
- Fix a crash related to ElfParser::loadSymbolTable
([#&#8203;191](DataDog/dd-trace-java#191)) by
[@&#8203;yanglong1010](https://github.com/yanglong1010) in
DataDog/java-profiler#192
- Unwind String.indexOf intrinsic on AArch64 by
[@&#8203;MattAlp](https://github.com/MattAlp) in
DataDog/java-profiler#193
- Fix Java 24 support by
[@&#8203;jbachorik](https://github.com/jbachorik) in
DataDog/java-profiler#194
- A set of fixes related to clang, aarch64 and musl pecularities of
vmstructs stack unwinder by
[@&#8203;jbachorik](https://github.com/jbachorik) in
DataDog/java-profiler#199
- 🐛 Remove process information from JFR recording
([#&#8203;8661](DataDog/dd-trace-java#8661) -
[@&#8203;r1viollet](https://github.com/r1viollet))
- 🐛 Make TempLocationManager USER aware
([#&#8203;8605](DataDog/dd-trace-java#8605) -
[@&#8203;jbachorik](https://github.com/jbachorik))
- ✨ Extract git tags from embedded git.properties and
datadog_git.properties
([#&#8203;8561](DataDog/dd-trace-java#8561) -
[@&#8203;wmouchere](https://github.com/wmouchere))
#### Telemetry
- 🐛 Fix appsec.rasp.error and appsec.waf.error telemetry metrics
([#&#8203;8624](DataDog/dd-trace-java#8624) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Create metric: appsec.rasp.rule.skipped
([#&#8203;8618](DataDog/dd-trace-java#8618) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Extract git tags from embedded git.properties and
datadog_git.properties
([#&#8203;8561](DataDog/dd-trace-java#8561) -
[@&#8203;wmouchere](https://github.com/wmouchere))
#### Testing
- 🧹 Simplify ssi tests one-pipeline
([#&#8203;8558](DataDog/dd-trace-java#8558) -
[@&#8203;robertomonteromiguel](https://github.com/robertomonteromiguel))
- ✨ Add smoke tests for java's concurrent API
([#&#8203;8438](DataDog/dd-trace-java#8438) -
[@&#8203;sarahchen6](https://github.com/sarahchen6))
#### Trace context propagation
- ✨ Adding Support for `TRACE_PROPAGATION_BEHAVIOR_EXTRACT`
([#&#8203;8535](DataDog/dd-trace-java#8535) -
[@&#8203;mhlidd](https://github.com/mhlidd))
#### Tracer core
- 🐛 Ensure shaded helpers have unique names
([#&#8203;8559](DataDog/dd-trace-java#8559) -
[@&#8203;amarziali](https://github.com/amarziali))
- ✨ Support common config sources for user-provided git info
([#&#8203;8547](DataDog/dd-trace-java#8547) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- ✨ Make the default config sources more robust when a security
manager is installed
([#&#8203;8544](DataDog/dd-trace-java#8544) -
[@&#8203;mcculls](https://github.com/mcculls))
- ✨ Support targeting services with configurations in stable
configuration file
([#&#8203;8526](DataDog/dd-trace-java#8526) -
[@&#8203;mtoffl01](https://github.com/mtoffl01))
- ✨ Add new parser for `DD_TAGS` and prioritizing `DD_SERVICE`
([#&#8203;8296](DataDog/dd-trace-java#8296) -
[@&#8203;mhlidd](https://github.com/mhlidd))
#### Tracer internal logging
- 🐛 Add missing debug log for the cloudPayloadTaggingServices config
([#&#8203;8600](DataDog/dd-trace-java#8600) -
[@&#8203;ygree](https://github.com/ygree))
- ✨ Add the possibility to output the logs of the Java tracer
in JSON
([#&#8203;8083](DataDog/dd-trace-java#8083) -
[@&#8203;cecile75](https://github.com/cecile75))
#### Tracer public API
- ✨ Introducing `DD_TRACE_EXPERIMENTAL_FEATURES_ENABLED` Config
([#&#8203;8536](DataDog/dd-trace-java#8536) -
[@&#8203;mhlidd](https://github.com/mhlidd))
- ✨ Config Consistency Round 2
([#&#8203;8489](DataDog/dd-trace-java#8489) -
[@&#8203;mhlidd](https://github.com/mhlidd))
### Instrumentations
####
- 🐛 Fix NPE in getMdcCopy of LoggingEventInstrumentation
([#&#8203;8599](DataDog/dd-trace-java#8599) -
[@&#8203;ygree](https://github.com/ygree))
#### Apache Spark instrumentation
- ✨ Instrument Runtime.exit() to finish spark application spans
([#&#8203;8572](DataDog/dd-trace-java#8572) -
[@&#8203;paul-laffon-dd](https://github.com/paul-laffon-dd))
- ✨ Configure OpenLineage if present in Spark instrumentation
([#&#8203;8541](DataDog/dd-trace-java#8541) -
[@&#8203;mobuchowski](https://github.com/mobuchowski))
#### Armeria Instrumentation
- ✨ Support armeria grpc 1.32.3
([#&#8203;8606](DataDog/dd-trace-java#8606) -
[@&#8203;github-actions](https://github.com/github-actions)\[bot])
#### AWS DynamoDB Instrumentation
- ✨ Create DynamoDB instrumentation + add span pointers for
`updateItem` and `deleteItem`
([#&#8203;8490](DataDog/dd-trace-java#8490) -
[@&#8203;nhulston](https://github.com/nhulston))
#### AWS SDK instrumentation
- ✨ Add DynamoDB in
DEFAULT_TRACE_CLOUD_PAYLOAD_TAGGING_SERVICES
([#&#8203;8595](DataDog/dd-trace-java#8595) -
[@&#8203;joeyzhao2018](https://github.com/joeyzhao2018))
#### Azure Functions instrumentation
- ✨ Enable tracer computed trace metrics by default for Azure
Functions
([#&#8203;8518](DataDog/dd-trace-java#8518) -
[@&#8203;duncanpharvey](https://github.com/duncanpharvey))
- 💡 Add azure-functions instrumentation
([#&#8203;8432](DataDog/dd-trace-java#8432) -
[@&#8203;duncanpharvey](https://github.com/duncanpharvey))
#### Core Java language instrumentation
- 🐛 Fix ForkJoinPool.execute() instrumentation on Java 21+
([#&#8203;8560](DataDog/dd-trace-java#8560) -
[@&#8203;PerfectSlayer](https://github.com/PerfectSlayer))
#### Eclipse Vert.x instrumentation
- ✨ Add vertx postgresql client instrumentation
([#&#8203;8471](DataDog/dd-trace-java#8471) -
[@&#8203;vandonr](https://github.com/vandonr) - thanks for the
contribution!)
#### Kafka instrumentation
- ✨ Support and test kafka-clients 4
([#&#8203;8581](DataDog/dd-trace-java#8581) -
[@&#8203;amarziali](https://github.com/amarziali))
#### Kotlin instrumentation
- ✨ Avoid disconnected traces when using Kotlin flowOn
([#&#8203;8651](DataDog/dd-trace-java#8651) -
[@&#8203;mcculls](https://github.com/mcculls))
#### OpenTelemetry instrumentation
- 🧹 Migrate OtelContext wrapper to new internal Context API
([#&#8203;8645](DataDog/dd-trace-java#8645) -
[@&#8203;mcculls](https://github.com/mcculls))
#### Spring instrumentation
- 🐛 Support CompletableFuture on spring webmvc controllers
([#&#8203;8659](DataDog/dd-trace-java#8659) -
[@&#8203;amarziali](https://github.com/amarziali))
- ✨ Add support for endpoint discovery in spring mvc
([#&#8203;8352](DataDog/dd-trace-java#8352) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
#### WebSocket Instrumentation
- ✨ Instrument Jetty websocket pojo
([#&#8203;8562](DataDog/dd-trace-java#8562) -
[@&#8203;amarziali](https://github.com/amarziali))
- 💡 Instrument Java Websocket API (JSR356)
([#&#8203;8440](DataDog/dd-trace-java#8440) -
[@&#8203;amarziali](https://github.com/amarziali))
#### All other instrumentations
- ✨ Introduce cache for peer.hostname lookup
([#&#8203;8601](DataDog/dd-trace-java#8601) -
[@&#8203;mcculls](https://github.com/mcculls))
- ✨ Support pekko http 1.1
([#&#8203;8532](DataDog/dd-trace-java#8532) -
[@&#8203;amarziali](https://github.com/amarziali))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "after 6pm every weekday,before 2am
every weekday" in timezone Australia/Melbourne, Automerge - At any time
(no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config help](https://github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://github.com/renovatebot/renovate).
GitOrigin-RevId: 331314f71acaced3adc75ea5d7e855c248d593fc
eizus pushed a commit to cdrxyz/misk that referenced this pull request Jul 18, 2026
| Package | Type | Package file | Manager | Update | Change |
|---|---|---|---|---|---|
| org.flywaydb.flyway | plugin | misk/gradle/libs.versions.toml | gradle
| minor | `11.6.0` -> `11.7.0` |
|
[com.squareup.okio:okio-fakefilesystem](https://github.com/square/okio)
| dependencies | misk/gradle/libs.versions.toml | gradle | minor |
`3.10.2` -> `3.11.0` |
| [com.squareup.okio:okio](https://github.com/square/okio) |
dependencies | misk/gradle/libs.versions.toml | gradle | minor |
`3.10.2` -> `3.11.0` |
|
[com.autonomousapps.dependency-analysis](https://github.com/autonomousapps/dependency-analysis-android-gradle-plugin)
| plugin | misk/gradle/libs.versions.toml | gradle | minor | `2.15.0` ->
`2.16.0` |
| [com.datadoghq:dd-trace-api](https://github.com/datadog/dd-trace-java)
| dependencies | misk/gradle/libs.versions.toml | gradle | minor |
`1.47.3` -> `1.48.1` |
| [com.datadoghq:dd-trace-ot](https://github.com/datadog/dd-trace-java)
| dependencies | misk/gradle/libs.versions.toml | gradle | minor |
`1.47.3` -> `1.48.1` |
| [software.amazon.awssdk:sdk-core](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:sqs](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
|
[software.amazon.awssdk:dynamodb-enhanced](https://aws.amazon.com/sdkforjava)
| dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:dynamodb](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:aws-core](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:bom](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
| [software.amazon.awssdk:auth](https://aws.amazon.com/sdkforjava) |
dependencies | misk/gradle/libs.versions.toml | gradle | patch |
`2.31.18` -> `2.31.20` |
---
### Release Notes
<details>
<summary>square/okio (com.squareup.okio:okio-fakefilesystem)</summary>
###
[`v3.11.0`](https://github.com/square/okio/blob/HEAD/CHANGELOG.md#Version-3110)
*2025-04-09*
- Fix: Clear the deflater's byte array reference
- New: Faster implementation of `String.decodeHex()` on Kotlin/JS.
- New: Declare `EXACTLY_ONCE` execution for blocks like `Closeable.use
{}` and `FileSystem.read {}`.
- Upgrade: \[Kotlin 2.1.20]\[kotlin\_2\_1\_20].
</details>
<details>
<summary>autonomousapps/dependency-analysis-android-gradle-plugin
(com.autonomousapps.dependency-analysis)</summary>
###
[`v2.16.0`](https://github.com/autonomousapps/dependency-analysis-android-gradle-plugin/blob/HEAD/CHANGELOG.md#Version-2160)
- \[Feat]: support `com.android.test` projects.
- \[Feat]: support typesafe project accessors with opt-in.
```kotlin
dependencyAnalysis {
useTypesafeProjectAccessors(true) // false by default
}
```
</details>
<details>
<summary>datadog/dd-trace-java (com.datadoghq:dd-trace-api)</summary>
###
[`v1.48.1`](https://github.com/DataDog/dd-trace-java/releases/tag/v1.48.1):
1.48.1
### Components
#### Tracer internal logging
- 🐛 Remove print line causing unnecessary logs
([#&#8203;8687](DataDog/dd-trace-java#8687) -
[@&#8203;sarahchen6](https://github.com/sarahchen6))
###
[`v1.48.0`](https://github.com/DataDog/dd-trace-java/releases/tag/v1.48.0):
1.48.0
### Known Bugs
> \[!NOTE]
> If you are experiencing issues with spamming timeout logs, please
update to the [latest
version](https://github.com/DataDog/dd-trace-java/releases/latest) or
set
[JDK_SOCKET_ENABLED](https://github.com/DataDog/dd-trace-java/blob/33fc3c9a9b7cda3beda88b8b3e5224ae2b10764a/dd-trace-api/src/main/java/datadog/trace/api/config/GeneralConfig.java#L98)
to false.
### Components
#### Application Security Management (IAST)
- ✨ Fix vulnerability location org.jose4j.lang.HashUtil
([#&#8203;8610](DataDog/dd-trace-java#8610) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Fix weak randomness in oracle.ucp.util.OpaqueString
([#&#8203;8609](DataDog/dd-trace-java#8609) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Fix weak hash false positive in
oracle.security.o5logon.O5Logon
([#&#8203;8608](DataDog/dd-trace-java#8608) -
[@&#8203;jandro996](https://github.com/jandro996))
- 🐛 Prevent before callsites targeting constructors in super calls
([#&#8203;8549](DataDog/dd-trace-java#8549) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
#### Application Security Management (WAF)
- ✨ Update login events public SDK to V2
([#&#8203;8620](DataDog/dd-trace-java#8620) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- 🐛 Send RASP LFI capability only when AppSec is statically enabled
([#&#8203;8573](DataDog/dd-trace-java#8573) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Improve detection of missing request end events
([#&#8203;8510](DataDog/dd-trace-java#8510) -
[@&#8203;smola](https://github.com/smola))
- 🧹 Remove remote configuration for API Security sampling rate
([#&#8203;8486](DataDog/dd-trace-java#8486) -
[@&#8203;smola](https://github.com/smola))
- ✨ Add setUser to user monitoring SDK
([#&#8203;8482](DataDog/dd-trace-java#8482) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- ✨ Add missing address for signup event
([#&#8203;8469](DataDog/dd-trace-java#8469) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- ✨ Allow login events SDK to be used with appsec disabled
([#&#8203;8464](DataDog/dd-trace-java#8464) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- ✨ Add support for endpoint discovery in spring mvc
([#&#8203;8352](DataDog/dd-trace-java#8352) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
- ✨ New API Security sampling algorithm
([#&#8203;8178](DataDog/dd-trace-java#8178) -
[@&#8203;ValentinZakharov](https://github.com/ValentinZakharov))
#### Build & Tooling
- ✨ Add buffer size customizability to JDK UDS support
([#&#8203;8629](DataDog/dd-trace-java#8629) -
[@&#8203;sarahchen6](https://github.com/sarahchen6))
- ✨ Add JDK built-in support for UDS on Java 16+
([#&#8203;8314](DataDog/dd-trace-java#8314) -
[@&#8203;sarahchen6](https://github.com/sarahchen6))
#### Configuration at Runtime
- 🐛 Send RASP LFI capability only when AppSec is statically enabled
([#&#8203;8573](DataDog/dd-trace-java#8573) -
[@&#8203;jandro996](https://github.com/jandro996))
#### Continuous Integration Visibility
- 🐛 Prevent double reporting of Scalatest events when using SBT with
test forking
([#&#8203;8682](DataDog/dd-trace-java#8682) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- 🐛 Shutdown CI Visibility test event handlers before tracer
([#&#8203;8677](DataDog/dd-trace-java#8677) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- 🐛 Do not apply JUnit 4 instrumentation to MUnit runners
([#&#8203;8675](DataDog/dd-trace-java#8675),
[#&#8203;8683](DataDog/dd-trace-java#8683) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- ✨ Remove error log when source path resolution fails on
isModified check
([#&#8203;8663](DataDog/dd-trace-java#8663) -
[@&#8203;daniel-mohedano](https://github.com/daniel-mohedano))
- ✨ Implement tests reordering for JUnit 4
([#&#8203;8650](DataDog/dd-trace-java#8650) -
[@&#8203;daniel-mohedano](https://github.com/daniel-mohedano))
- 🐛 Set default Attempt to Fix retries if none provided from the
backend
([#&#8203;8615](DataDog/dd-trace-java#8615) -
[@&#8203;daniel-mohedano](https://github.com/daniel-mohedano))
- ✨ Allow to manually set PR info
([#&#8203;8566](DataDog/dd-trace-java#8566) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- 🐛 Fix Test Optimization init when repo root cannot be determined
([#&#8203;8533](DataDog/dd-trace-java#8533) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- ✨ Add capabilities tagging
([#&#8203;8499](DataDog/dd-trace-java#8499),
[#&#8203;8540](DataDog/dd-trace-java#8540) -
[@&#8203;daniel-mohedano](https://github.com/daniel-mohedano))
#### Crash tracking
- 🐛 Remove dependency on bash from crash/oome uploder scripts
([#&#8203;8652](DataDog/dd-trace-java#8652) -
[@&#8203;jbachorik](https://github.com/jbachorik))
#### Data Streams Monitoring
- ✨ e2e pipeline configuration when data jobs is enabled
([#&#8203;8553](DataDog/dd-trace-java#8553) -
[@&#8203;kr-igor](https://github.com/kr-igor))
#### Dynamic Instrumentation
- 🐛 Fix In-Product when config is empty
([#&#8203;8679](DataDog/dd-trace-java#8679) -
[@&#8203;jpbempel](https://github.com/jpbempel))
- ✨ Add support for filtering shaded third-party libs
([#&#8203;8612](DataDog/dd-trace-java#8612) -
[@&#8203;jpbempel](https://github.com/jpbempel))
- ✨ Add In-Product Enablement
([#&#8203;8587](DataDog/dd-trace-java#8587) -
[@&#8203;jpbempel](https://github.com/jpbempel))
- ✨⚡ Reduce footprint of SourceFile tracking
([#&#8203;8524](DataDog/dd-trace-java#8524) -
[@&#8203;jpbempel](https://github.com/jpbempel))
- ✨⚡ Optimize the SourceFile tracking
([#&#8203;8520](DataDog/dd-trace-java#8520) -
[@&#8203;jpbempel](https://github.com/jpbempel))
#### OpenTracing
- 🧹 Remove activeScope() use in OpenTracing shim
([#&#8203;8478](DataDog/dd-trace-java#8478) -
[@&#8203;mcculls](https://github.com/mcculls))
#### Profiling
- ✨ Add profiler env check command to AgentCLI
([#&#8203;8671](DataDog/dd-trace-java#8671) -
[@&#8203;jbachorik](https://github.com/jbachorik))
- ✨ Bump ddprof to 1.23.0
([#&#8203;8668](DataDog/dd-trace-java#8668) -
[@&#8203;jbachorik](https://github.com/jbachorik))
- Fix a crash related to ElfParser::loadSymbolTable
([#&#8203;191](DataDog/dd-trace-java#191)) by
[@&#8203;yanglong1010](https://github.com/yanglong1010) in
DataDog/java-profiler#192
- Unwind String.indexOf intrinsic on AArch64 by
[@&#8203;MattAlp](https://github.com/MattAlp) in
DataDog/java-profiler#193
- Fix Java 24 support by
[@&#8203;jbachorik](https://github.com/jbachorik) in
DataDog/java-profiler#194
- A set of fixes related to clang, aarch64 and musl pecularities of
vmstructs stack unwinder by
[@&#8203;jbachorik](https://github.com/jbachorik) in
DataDog/java-profiler#199
- 🐛 Remove process information from JFR recording
([#&#8203;8661](DataDog/dd-trace-java#8661) -
[@&#8203;r1viollet](https://github.com/r1viollet))
- 🐛 Make TempLocationManager USER aware
([#&#8203;8605](DataDog/dd-trace-java#8605) -
[@&#8203;jbachorik](https://github.com/jbachorik))
- ✨ Extract git tags from embedded git.properties and
datadog_git.properties
([#&#8203;8561](DataDog/dd-trace-java#8561) -
[@&#8203;wmouchere](https://github.com/wmouchere))
#### Telemetry
- 🐛 Fix appsec.rasp.error and appsec.waf.error telemetry metrics
([#&#8203;8624](DataDog/dd-trace-java#8624) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Create metric: appsec.rasp.rule.skipped
([#&#8203;8618](DataDog/dd-trace-java#8618) -
[@&#8203;jandro996](https://github.com/jandro996))
- ✨ Extract git tags from embedded git.properties and
datadog_git.properties
([#&#8203;8561](DataDog/dd-trace-java#8561) -
[@&#8203;wmouchere](https://github.com/wmouchere))
#### Testing
- 🧹 Simplify ssi tests one-pipeline
([#&#8203;8558](DataDog/dd-trace-java#8558) -
[@&#8203;robertomonteromiguel](https://github.com/robertomonteromiguel))
- ✨ Add smoke tests for java's concurrent API
([#&#8203;8438](DataDog/dd-trace-java#8438) -
[@&#8203;sarahchen6](https://github.com/sarahchen6))
#### Trace context propagation
- ✨ Adding Support for `TRACE_PROPAGATION_BEHAVIOR_EXTRACT`
([#&#8203;8535](DataDog/dd-trace-java#8535) -
[@&#8203;mhlidd](https://github.com/mhlidd))
#### Tracer core
- 🐛 Ensure shaded helpers have unique names
([#&#8203;8559](DataDog/dd-trace-java#8559) -
[@&#8203;amarziali](https://github.com/amarziali))
- ✨ Support common config sources for user-provided git info
([#&#8203;8547](DataDog/dd-trace-java#8547) -
[@&#8203;nikita-tkachenko-datadog](https://github.com/nikita-tkachenko-datadog))
- ✨ Make the default config sources more robust when a security
manager is installed
([#&#8203;8544](DataDog/dd-trace-java#8544) -
[@&#8203;mcculls](https://github.com/mcculls))
- ✨ Support targeting services with configurations in stable
configuration file
([#&#8203;8526](DataDog/dd-trace-java#8526) -
[@&#8203;mtoffl01](https://github.com/mtoffl01))
- ✨ Add new parser for `DD_TAGS` and prioritizing `DD_SERVICE`
([#&#8203;8296](DataDog/dd-trace-java#8296) -
[@&#8203;mhlidd](https://github.com/mhlidd))
#### Tracer internal logging
- 🐛 Add missing debug log for the cloudPayloadTaggingServices config
([#&#8203;8600](DataDog/dd-trace-java#8600) -
[@&#8203;ygree](https://github.com/ygree))
- ✨ Add the possibility to output the logs of the Java tracer
in JSON
([#&#8203;8083](DataDog/dd-trace-java#8083) -
[@&#8203;cecile75](https://github.com/cecile75))
#### Tracer public API
- ✨ Introducing `DD_TRACE_EXPERIMENTAL_FEATURES_ENABLED` Config
([#&#8203;8536](DataDog/dd-trace-java#8536) -
[@&#8203;mhlidd](https://github.com/mhlidd))
- ✨ Config Consistency Round 2
([#&#8203;8489](DataDog/dd-trace-java#8489) -
[@&#8203;mhlidd](https://github.com/mhlidd))
### Instrumentations
####
- 🐛 Fix NPE in getMdcCopy of LoggingEventInstrumentation
([#&#8203;8599](DataDog/dd-trace-java#8599) -
[@&#8203;ygree](https://github.com/ygree))
#### Apache Spark instrumentation
- ✨ Instrument Runtime.exit() to finish spark application spans
([#&#8203;8572](DataDog/dd-trace-java#8572) -
[@&#8203;paul-laffon-dd](https://github.com/paul-laffon-dd))
- ✨ Configure OpenLineage if present in Spark instrumentation
([#&#8203;8541](DataDog/dd-trace-java#8541) -
[@&#8203;mobuchowski](https://github.com/mobuchowski))
#### Armeria Instrumentation
- ✨ Support armeria grpc 1.32.3
([#&#8203;8606](DataDog/dd-trace-java#8606) -
[@&#8203;github-actions](https://github.com/github-actions)\[bot])
#### AWS DynamoDB Instrumentation
- ✨ Create DynamoDB instrumentation + add span pointers for
`updateItem` and `deleteItem`
([#&#8203;8490](DataDog/dd-trace-java#8490) -
[@&#8203;nhulston](https://github.com/nhulston))
#### AWS SDK instrumentation
- ✨ Add DynamoDB in
DEFAULT_TRACE_CLOUD_PAYLOAD_TAGGING_SERVICES
([#&#8203;8595](DataDog/dd-trace-java#8595) -
[@&#8203;joeyzhao2018](https://github.com/joeyzhao2018))
#### Azure Functions instrumentation
- ✨ Enable tracer computed trace metrics by default for Azure
Functions
([#&#8203;8518](DataDog/dd-trace-java#8518) -
[@&#8203;duncanpharvey](https://github.com/duncanpharvey))
- 💡 Add azure-functions instrumentation
([#&#8203;8432](DataDog/dd-trace-java#8432) -
[@&#8203;duncanpharvey](https://github.com/duncanpharvey))
#### Core Java language instrumentation
- 🐛 Fix ForkJoinPool.execute() instrumentation on Java 21+
([#&#8203;8560](DataDog/dd-trace-java#8560) -
[@&#8203;PerfectSlayer](https://github.com/PerfectSlayer))
#### Eclipse Vert.x instrumentation
- ✨ Add vertx postgresql client instrumentation
([#&#8203;8471](DataDog/dd-trace-java#8471) -
[@&#8203;vandonr](https://github.com/vandonr) - thanks for the
contribution!)
#### Kafka instrumentation
- ✨ Support and test kafka-clients 4
([#&#8203;8581](DataDog/dd-trace-java#8581) -
[@&#8203;amarziali](https://github.com/amarziali))
#### Kotlin instrumentation
- ✨ Avoid disconnected traces when using Kotlin flowOn
([#&#8203;8651](DataDog/dd-trace-java#8651) -
[@&#8203;mcculls](https://github.com/mcculls))
#### OpenTelemetry instrumentation
- 🧹 Migrate OtelContext wrapper to new internal Context API
([#&#8203;8645](DataDog/dd-trace-java#8645) -
[@&#8203;mcculls](https://github.com/mcculls))
#### Spring instrumentation
- 🐛 Support CompletableFuture on spring webmvc controllers
([#&#8203;8659](DataDog/dd-trace-java#8659) -
[@&#8203;amarziali](https://github.com/amarziali))
- ✨ Add support for endpoint discovery in spring mvc
([#&#8203;8352](DataDog/dd-trace-java#8352) -
[@&#8203;manuel-alvarez-alvarez](https://github.com/manuel-alvarez-alvarez))
#### WebSocket Instrumentation
- ✨ Instrument Jetty websocket pojo
([#&#8203;8562](DataDog/dd-trace-java#8562) -
[@&#8203;amarziali](https://github.com/amarziali))
- 💡 Instrument Java Websocket API (JSR356)
([#&#8203;8440](DataDog/dd-trace-java#8440) -
[@&#8203;amarziali](https://github.com/amarziali))
#### All other instrumentations
- ✨ Introduce cache for peer.hostname lookup
([#&#8203;8601](DataDog/dd-trace-java#8601) -
[@&#8203;mcculls](https://github.com/mcculls))
- ✨ Support pekko http 1.1
([#&#8203;8532](DataDog/dd-trace-java#8532) -
[@&#8203;amarziali](https://github.com/amarziali))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "after 6pm every weekday,before 2am
every weekday" in timezone Australia/Melbourne, Automerge - At any time
(no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config help](https://github.com/renovatebot/renovate/discussions) if
that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR has been generated by [Renovate
Bot](https://github.com/renovatebot/renovate).
GitOrigin-RevId: 331314f71acaced3adc75ea5d7e855c248d593fc
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp: asm iastApplication Security Management (IAST)type: featureEnhancements and improvements

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jandro996@smola@manuel-alvarez-alvarez