[serverless] Adding env variables to support .net and java instruments#65
Conversation
| @@ -0,0 +1,48 @@ | |||
| #!/bin/bash | |||
There was a problem hiding this comment.
Can we remove the .sh extension from the wrapper? the examples from AWS are all without the .sh extension, i think one benefit is that we could potentially change it to a python or non-sh script down the road without asking users to update their configurations.
There was a problem hiding this comment.
I agree it Should Be Fine to remove .sh as long as we have the shebang at the beginning of the file
There was a problem hiding this comment.
I will create a new revision for it.
maxday
left a comment
There was a problem hiding this comment.
Looks good! I left some minor comments
| fi | ||
|
|
||
| # if it is .Net | ||
| echo "The runtime is $AWS_EXECUTION_ENV" |
There was a problem hiding this comment.
I think this should be protected by a if DD_LOG_LEVEL = debug ?
There was a problem hiding this comment.
Will fix it in the next revision
| echo "The runtime is $AWS_EXECUTION_ENV" | ||
| if [[ "$AWS_EXECUTION_ENV" == *"dotnet"* ]]; | ||
| then | ||
| echo "Configuring for the .NET runtime!" |
There was a problem hiding this comment.
Will fix it in the next revision
| # if it is java | ||
| if [[ "$AWS_EXECUTION_ENV" == *"java"* ]]; | ||
| then | ||
| echo "Configuring for the Java runtime!" |
There was a problem hiding this comment.
Will fix it in the next revision
|
A new revision of the PR has just been created. |
## Summary Resolves all **24 open Dependabot security alerts** (2 critical, 6 high, 14 medium, 2 low) across three ecosystems by updating vulnerable dependencies in test infrastructure. **Note:** All affected dependencies are in test infrastructure (`integration-tests/`, `local_tests/`), not the production Rust extension (`bottlecap/`). ## Changes ### npm (`integration-tests/`) - **axios** `^1.6.7` → `^1.15.0` — fixes SSRF bypass via NO_PROXY hostname normalization (CVE-2025-62718, critical) ### Go (`local_tests/golang/`) - **golang.org/x/net** `v0.2.0` → `v0.52.0` — fixes 8 alerts: HTTP/2 rapid reset, uncontrolled resource consumption, XSS, IPv6 zone ID proxy bypass, excessive memory growth, stream cancellation, improper text rendering - **google.golang.org/grpc** `v1.50.1` → `v1.80.0` — fixes 2 alerts: authorization bypass via missing leading slash (CVE-2026-33186, critical), HTTP/2 rapid reset - **google.golang.org/protobuf** `v1.28.1` → `v1.36.11` — fixes infinite loop in protojson.Unmarshal - **github.com/golang/glog** `v1.0.0` → `v1.2.5` — fixes insecure temporary file usage ### Python (`local_tests/serverless-init/`) - **Flask** `2.1.2` → `3.1.3` — fixes session cookie disclosure, missing Vary:Cookie header - **Werkzeug** `2.2.2` → `3.1.8` — fixes 9 alerts: debugger RCE, safe_join Windows device name bypasses, multipart form DoS, resource exhaustion, nameless cookie bypass ## Reviewer Notes⚠️ **Go minimum version**: The `go` directive in `local_tests/golang/go.mod` was auto-upgraded from `go 1.22` to `go 1.25.0` (required by `golang.org/x/net v0.52.0`). This only affects the test Lambda function, not CI build toolchains for the main extension.⚠️ **Flask/Werkzeug major version jump**: Flask 2.x → 3.x and Werkzeug 2.x → 3.x are major version bumps. The test app (`app.py`) uses minimal Flask APIs and was reviewed for compatibility. However, `ddtrace==1.4.1` compatibility with Flask 3.x should be verified in CI. ## Alert Breakdown | Severity | Count | Alerts | |----------|-------|--------| | Critical | 2 | #128 (axios SSRF), #104 (gRPC auth bypass) | | High | 6 | #52, #43, #40, #38, #37, #20 | | Medium | 14 | #88, #74, #73, #70, #68, #65, #60, #59, #53, #51, #49, #45, #41, #36 | | Low | 2 | #89, #39 | Co-authored-by: Claude Opus 4.6 (1M context) <[email protected]>
What does this PR do?
Setting env variables in the dd_wrapper file to support .net and java instruments.
This is the step 1.
Step 2 is to update the corresponding datadog-ci and serverless plugin.
Motivation:
https://datadoghq.atlassian.net/browse/SLS-2190
Describe how to test/QA your changes
Manual e2e test