Releases: DataDog/dd-trace-py
2.16.5
Bug Fixes
-
ASM
- Ensures that common patches for exploit prevention and sca are only loaded if required, and only loaded once.
- Resolves an issue where some root span where not appropriately tagged for ASM standalone.
-
Auto-Instrumentation
- Resolves an issue where the default versions of
click
andjinja2
installed on python3.8 were outside of the allowed minimum versions for auto-instrumentation.
- Resolves an issue where the default versions of
-
Code Security
- Patches the module dir function so original pre-patch results are not changed.
-
LLM Observability
- Ensures bedrock spans are finished even when streamed responses are not fully consumed.
-
Tracing
botocore
: Resolves an issue in the Bedrock integration where not consuming the full response stream would prevent spans from finishing.
2.15.4
Bug Fixes
-
ASM
- Ensures that common patches for exploit prevention and sca are only loaded if required, and only loaded once.
- Resolves an issue where some root span where not appropriately tagged for ASM standalone.
-
Auto-Instrumentation
- Resolves an issue where the default versions of
click
andjinja2
installed on python3.8 were outside of the allowed minimum versions for auto-instrumentation.
- Resolves an issue where the default versions of
-
Code Security
- Patches the module dir function so original pre-patch results are not changed.
-
LLM Observability
- Ensures bedrock spans are finished even when streamed responses are not fully consumed.
-
Tracing
botocore
: Resolves an issue in the Bedrock integration where not consuming the full response stream would prevent spans from finishing.
2.17.1
Bug Fixes
- ASM
- Resolves an issue where some root spans were not appropriately tagged for ASM standalone.
- Code Security
- Patches the module dir function so original pre-patch results are not changed.
- Tracing
- Resolves an issue where the default versions of
click
andjinja2
installed on 3.8 were outside of the allowed minimum versions for autoinstrumentation.
- Resolves an issue where the default versions of
2.17.0
New Features
-
ASM
- Support added for session fingerprints.
-
LLM Observability
- When not using a provider integration (OpenAI, Anthropic, or Bedrock) with the LangChain integration, token metrics will be appended to the LLM Observability
llm
span. - LLM Observability: When langchain's
chat_model.with_structured_output(..., method="json_mode")
is used, orresponse_format={"type": "json_object"}
is passed into a langchain chat model invocation, the LLM Observability span will be anllm
span instead of aworkflow
span.
- When not using a provider integration (OpenAI, Anthropic, or Bedrock) with the LangChain integration, token metrics will be appended to the LLM Observability
-
SSI
- Adds
requirements.json
to SSI artifact for bailing out on unsupported systems.
- Adds
-
Tracing
- Adds support for expanding AWS request/response Payloads into flattened span tags.
- Updates the service naming algorithm to infer the base service name when
DD_SERVICE
is not set, replacing instances of'unnamed-python-service'
. Ensures that a more meaningful service name is used whenever possible, enhancing clarity in service identification.
Bug Fixes
-
ASM
- The new user events policy is preventing users PII to be added by default as span tags. To allow customers using the Django auto instrumentation to still have those information, new environment variables have been added. In particular
DD_DJANGO_INCLUDE_EMAIL
(false by default), will tag user events with user email as before.
- The new user events policy is preventing users PII to be added by default as span tags. To allow customers using the Django auto instrumentation to still have those information, new environment variables have been added. In particular
-
Code Security/IAST
- Adds
umap
,numba
andpynndescent
to the Code Security denylist. - Adds
googlecloudsdk
andgoogle auth
to the Code Security deny list. - Resolves an issue where importing the
google.cloud.storage.batch
module would fail raising an ImportError
- Adds
-
Crashtracking
- Fixes an issue where the use of the Crashtracking component could result in zombie processes.
-
Lib-Injection
- Supports Python 2.7+ for injection compatibility check.
- Adds more commands to the auto-injection denylist.
- Ensures we do not import the user installed
ddtrace
if it is present. - Fixes injection guardrail check when
sys.argv
is not available.
-
LLM Observability
- Resolves an issue where annotating spans with non-ASCII language input/output values resulted in encoded unicode being submitted.
-
Profiling
- Fixes a data race where span information associated with a thread was read and updated concurrently, leading to segfaults
- Fixes an issue where cpu-time was not profiled for services using gunicorn, when
DD_PROFILING_STACK_V2_ENABLED
was set. - Fixes an issue where enabling native exporter via
DD_PROFILING_EXPORT_LIBDD_ENABLED
,DD_PROFILING_TIMELINE_ENABLED
orDD_PROFILING_STACK_V2_ENABLED
turned off live heap profiling. - The lock profiler would log a warning if it couldn't determine a name for a lock, and it would try determining a name multiple times for the same lock. This lead to excessive log spam. Downgrade this to a debug log and only try to determine the name once.
- Fixes an issue where the profiler was allocating too much memory from
ensure_binary_or_empty()
function, on Python versions before 3.12, withDD_PROFILING_EXPORT_LIBDD_ENABLED
orDD_PROFILING_TIMELINE_ENABLED
. - Fixes an issue where the sample pool could deadlock after
fork()
by clearing it in the child process. - When a Python thread finishes, this change frees memory used for mapping its thread id to
Span
. The mapping is populated and used whenDD_PROFILING_ENDPOINT_COLLECTION_ENABLED
andDD_PROFILING_STACK_V2_ENABLED
were set to enable grouping of profiles for endpoints.
-
Tracing
- Updates the inferred base service name algorithm to ensure that arguments following
--ddtrace
are no longer skipped when executing tests with pytest. Previously, the algorithm misinterpreted these arguments as standard flags, overlooking possible test paths that may contribute to the inferred service name. botocore
: Resolves the issue where the span pointer for deserialized DynamoDB requests (through the resource-based API) were not being generated.botocore
: Resolves an issue where our span pointer calculation code added recently logged unactionable messages.pymongo
: add type checking to solve an issue whereNoneType
instead of expectedPin
object would throw an error inTracedTopology
method.
- Updates the inferred base service name algorithm to ensure that arguments following
2.17.0rc2
Bug Fixes
-
Code Security
- Adds
umap
,numba
andpynndescent
to the Code Security denylist.
- Adds
-
Lib-Injection
- Supports Python 2.7+ for injection compatibility check.
-
Tracing
- Updates the inferred base service name algorithm to ensure that arguments following
--ddtrace
are no longer skipped when executing tests with pytest. Previously, the algorithm misinterpreted these arguments as standard flags, overlooking possible test paths that may contribute to the inferred service name. - botocore: Resolves an issue where our span pointer calculation code added recently logged unactionable messages.
- Updates the inferred base service name algorithm to ensure that arguments following
2.16.4
Bug Fixes
- Tracing
- botocore: Resolves the issue where the span pointer for deserialized DynamoDB requests (through the resource-based API) were not being generated.
- botocore: Resolves an issue where our span pointer calculation code added recently logged unactionable messages.
2.16.3
2.15.3
Bug Fixes
-
ASM:
- The new user events policy is preventing users PII to be added by default as span tags. To allow customers using the Django auto instrumentation to still have those information, new environment variables have been added. In particular DD_DJANGO_INCLUDE_EMAIL (false by default), will tag user events with user email as before.
-
LLM Observability:
- Resolves an issue where annotating spans with non-ASCII language input/output values resulted in encoded unicode being submitted.
-
Code Security:
- Add googlecloudsdk,google auth, umap, numba and pynndescent to the Code Security deny list.
-
Profiling:
-
Fixes an issue where cpu-time was not profiled for services using gunicorn, when `DD_PROFILING_STACK_V2_ENABLED was set.
-
The lock profiler would log a warning if it couldn't determine a
name for a lock, and it would try determining a name multiple times for the same lock. This lead to excessive log spam. Downgrade this to a debug log and only try to determine the name once. -
Fixes an issue where the sample pool could deadlock after
fork()
by clearing it in the child process.
-
2.17.0rc1
New Features
-
ASM
- Adds support for session fingerprints.
-
LLM Observability
- When not using a provider integration (OpenAI, Anthropic, or Bedrock) with the LangChain integration, token metrics will be appended to the LLM Observability
llm
span. - When langchain's
chat_model.with_structured_output(..., method="json_mode")
is used, orresponse_format={"type": "json_object"}
is passed into a langchain chat model invocation, the LLM Observability span will be anllm
span instead of aworkflow
span.
- When not using a provider integration (OpenAI, Anthropic, or Bedrock) with the LangChain integration, token metrics will be appended to the LLM Observability
-
Single Step Instrumentation
- Adds
requirements.json
to SSI artifact for bailing out on unsupported systems.
- Adds
-
Tracing
- Adds support for expanding AWS request/response payloads into flattened span tags.
- Updates the service naming algorithm to infer the base service name when
DD_SERVICE
is not set, replacing instances ofunnamed-python-service
. Ensures that a more meaningful service name is used whenever possible, enhancing clarity in service identification.
Bug Fixes
-
ASM/Threats
- The new user events policy is preventing users PII to be added by default as span tags. To allow customers using the Django auto instrumentation to still have those information, new environment variables have been added. In particular
DD_DJANGO_INCLUDE_EMAIL
(false by default), will tag user events with user email as before.
- The new user events policy is preventing users PII to be added by default as span tags. To allow customers using the Django auto instrumentation to still have those information, new environment variables have been added. In particular
-
Code Security/IAST
- Adds googlecloudsdk and google auth to the Code Security deny list.
- Resolves an issue where importing the
google.cloud.storage.batch
module would fail raising anImportError
.
-
Crashtracking
- Fixes an issue where the use of the crashtracking component could result in zombie processes.
-
Lib-Injection
- Adds more commands to the auto-injection denylist.
- Ensures we do not import the user installed
ddtrace
if it is present. - Fixes injection guardrail check when
sys.argv
is not available.
-
LLM Observability
- Resolves an issue where annotating spans with non-ASCII language input/output values resulted in encoded unicode being submitted.
-
Profiling
- Fixes a data race where span information associated with a thread was read and updated concurrently, leading to segfaults
- Fixes an issue where cpu-time was not profiled for services using gunicorn, when
DD_PROFILING_STACK_V2_ENABLED
was set. - Fixes an issue where enabling native exporter via
DD_PROFILING_EXPORT_LIBDD_ENABLED
,DD_PROFILING_TIMELINE_ENABLED
orDD_PROFILING_STACK_V2_ENABLED
turned off live heap profiling. - The lock profiler would log a warning if it couldn't determine a name for a lock, and it would try determining a name multiple times for the same lock. This lead to excessive log spam. Downgrade this to a debug log and only try to determine the name once.
- Fixes an issue where the profiler was allocating too much memory from
ensure_binary_or_empty()
function, on Python versions before 3.12, withDD_PROFILING_EXPORT_LIBDD_ENABLED
orDD_PROFILING_TIMELINE_ENABLED
. - Fixes an issue where the sample pool could deadlock after
fork()
by clearing it in the child process. - When a Python thread finishes, this change frees memory used for mapping its thread id to
Span
. The mapping is populated and used whenDD_PROFILING_ENDPOINT_COLLECTION_ENABLED
andDD_PROFILING_STACK_V2_ENABLED
were set to enable grouping of profiles for endpoints.
-
Tracing
- pymongo: Adds type checking to solve an issue where
NoneType
instead of expectedPin
object would throw an error inTracedTopology
method.
- pymongo: Adds type checking to solve an issue where
2.16.2
Bug Fixes
-
Profiling
- The lock profiler would log a warning if it couldn't determine a name for a lock, and it would try determining a name multiple times for the same lock. This lead to excessive log spam. Downgrade this to a debug log and only try to determine the name once.
-
Tracing
- pymongo: Adds type checking to solve an issue where
NoneType
instead of expectedPin
object would throw an error inTracedTopology
method.
- pymongo: Adds type checking to solve an issue where