Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix circular dependencies in waf calls #4125

Merged
merged 2 commits into from
Mar 4, 2024

Conversation

uurien
Copy link
Collaborator

@uurien uurien commented Mar 1, 2024

What does this PR do?

Updates @datadog/native-appsec library to version v7.1.0. This version updates the libddwaf to 1.16.0 and fixes errors with circular dependencies.

Adds test with sequelize to be sure that the error is fixed, and prevent the same error in the future.

Plugin Checklist

  • Unit tests.

Additional Notes

Test failure with @datadog/native-appsec v7.0.0: https://github.com/DataDog/dd-trace-js/actions/runs/8109230968/job/22163995098

Security

Datadog employees:

  • If this PR touches code that signs or publishes builds or packages, or handles credentials of any kind, I've requested a review from @DataDog/security-design-and-guidance.
  • This PR doesn't touch any of that.

Unsure? Have a question? Request a review!

@uurien uurien added bug Something isn't working asm-waf labels Mar 1, 2024
Copy link

github-actions bot commented Mar 1, 2024

Overall package size

Self size: 6.15 MB
Deduped: 61.89 MB
No deduping: 62.65 MB

Dependency sizes

name version self size total size
@datadog/native-iast-taint-tracking 1.7.0 16.71 MB 16.72 MB
@datadog/native-appsec 7.1.0 14.37 MB 14.38 MB
@datadog/pprof 5.0.0 9.59 MB 10.44 MB
protobufjs 7.2.5 2.77 MB 6.56 MB
@datadog/native-iast-rewriter 2.2.3 2.19 MB 2.28 MB
@opentelemetry/core 1.14.0 872.87 kB 1.47 MB
@datadog/native-metrics 2.0.0 898.77 kB 1.3 MB
@opentelemetry/api 1.4.1 780.32 kB 780.32 kB
import-in-the-middle 1.7.3 67.62 kB 731.01 kB
pprof-format 2.0.7 588.12 kB 588.12 kB
msgpack-lite 0.1.26 201.16 kB 281.59 kB
opentracing 0.14.7 194.81 kB 194.81 kB
semver 7.5.4 93.4 kB 123.8 kB
@datadog/sketches-js 2.1.0 109.9 kB 109.9 kB
lodash.sortby 4.7.0 75.76 kB 75.76 kB
lru-cache 7.14.0 74.95 kB 74.95 kB
ipaddr.js 2.1.0 60.23 kB 60.23 kB
ignore 5.2.4 51.22 kB 51.22 kB
int64-buffer 0.1.10 49.18 kB 49.18 kB
shell-quote 1.8.1 44.96 kB 44.96 kB
istanbul-lib-coverage 3.2.0 29.34 kB 29.34 kB
tlhunter-sorted-set 0.1.0 24.94 kB 24.94 kB
limiter 1.1.5 23.17 kB 23.17 kB
dc-polyfill 0.1.4 23.1 kB 23.1 kB
retry 0.13.1 18.85 kB 18.85 kB
node-abort-controller 3.1.1 16.89 kB 16.89 kB
jest-docblock 29.7.0 8.99 kB 12.76 kB
crypto-randomuuid 1.0.0 11.18 kB 11.18 kB
path-to-regexp 0.1.7 6.78 kB 6.78 kB
koalas 1.0.2 6.47 kB 6.47 kB
methods 1.1.2 5.29 kB 5.29 kB
module-details-from-path 1.0.3 4.47 kB 4.47 kB

🤖 This report was automatically generated by heaviest-objects-in-the-universe

Copy link

codecov bot commented Mar 1, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 85.25%. Comparing base (b6fe67e) to head (dfa1bb2).

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #4125   +/-   ##
=======================================
  Coverage   85.25%   85.25%           
=======================================
  Files         247      247           
  Lines       10848    10848           
  Branches       33       33           
=======================================
  Hits         9248     9248           
  Misses       1600     1600           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@pr-commenter
Copy link

pr-commenter bot commented Mar 1, 2024

Benchmarks

Benchmark execution time: 2024-03-01 16:22:04

Comparing candidate commit dfa1bb2 in PR branch ugaitz/fix-waf-circular-dependency with baseline commit b6fe67e in branch master.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 261 metrics, 5 unstable metrics.

@uurien uurien marked this pull request as ready for review March 1, 2024 16:35
@uurien uurien requested review from a team as code owners March 1, 2024 16:35
@uurien uurien merged commit b496eae into master Mar 4, 2024
109 of 111 checks passed
@uurien uurien deleted the ugaitz/fix-waf-circular-dependency branch March 4, 2024 08:19
uurien added a commit that referenced this pull request Mar 4, 2024
uurien added a commit that referenced this pull request Mar 5, 2024
uurien added a commit that referenced this pull request Mar 5, 2024
This was referenced Mar 5, 2024
uurien added a commit that referenced this pull request Mar 6, 2024
uurien added a commit that referenced this pull request Mar 6, 2024
uurien added a commit that referenced this pull request Mar 7, 2024
uurien added a commit that referenced this pull request Mar 7, 2024
uurien added a commit that referenced this pull request Mar 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
asm-waf bug Something isn't working semver-patch
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants