Skip to content

Conversation

rochdev
Copy link
Member

@rochdev rochdev commented Jul 25, 2025

What does this PR do?

Remove audit workflow in favour of Datadog SCA.

Motivation

This has several benefits:

  • Datadog SCA is a lot more powerful:
    • It collects its data from more sources than a simple npm audit and it keeps historical data.
    • It can detect non-npm vulnerabilities.
    • It can also be used for other types of security and code quality issues.
    • It supports alerting us immediately when the vulnerability is detected without waiting for our CI to run.
  • Stop blocking PRs for unrelated changes that also touch package.json or yarn.lock.
    • This is especially true for vulnerabilities that don't have a release with a fix yet.
  • Stop broadcasting vulnerabilities publicly while we work on fixing them.
  • Allow ignoring specific vulnerabilities, for example if they are known to not affect us and we cannot update because of Node version support.

I kept the workflow only for Dependabot branches, because those branches should auto-merge whenever possible, and without human interaction we need some guardrail in place to block on detection.

Copy link

Overall package size

Self size: 11.11 MB
Deduped: 110.69 MB
No deduping: 111.08 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | @datadog/libdatadog | 0.7.0 | 35.02 MB | 35.02 MB | | @datadog/native-appsec | 10.0.1 | 20.3 MB | 20.3 MB | | @datadog/native-iast-taint-tracking | 4.0.0 | 11.72 MB | 11.73 MB | | @datadog/pprof | 5.9.0 | 9.77 MB | 10.14 MB | | @opentelemetry/core | 1.30.1 | 908.66 kB | 7.16 MB | | protobufjs | 7.5.3 | 2.95 MB | 5.6 MB | | @datadog/wasm-js-rewriter | 4.0.1 | 2.85 MB | 3.58 MB | | @datadog/native-metrics | 3.1.1 | 1.02 MB | 1.43 MB | | @opentelemetry/api | 1.8.0 | 1.21 MB | 1.21 MB | | jsonpath-plus | 10.3.0 | 617.18 kB | 1.08 MB | | import-in-the-middle | 1.14.2 | 122.36 kB | 850.93 kB | | lru-cache | 10.4.3 | 804.3 kB | 804.3 kB | | source-map | 0.7.4 | 226 kB | 226 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | pprof-format | 2.1.0 | 111.69 kB | 111.69 kB | | @datadog/sketches-js | 2.1.1 | 109.9 kB | 109.9 kB | | lodash.sortby | 4.7.0 | 75.76 kB | 75.76 kB | | ignore | 7.0.5 | 63.38 kB | 63.38 kB | | istanbul-lib-coverage | 3.2.2 | 34.37 kB | 34.37 kB | | rfdc | 1.4.1 | 27.15 kB | 27.15 kB | | dc-polyfill | 0.1.10 | 26.73 kB | 26.73 kB | | @isaacs/ttlcache | 1.4.1 | 25.2 kB | 25.2 kB | | tlhunter-sorted-set | 0.1.0 | 24.94 kB | 24.94 kB | | shell-quote | 1.8.3 | 23.74 kB | 23.74 kB | | limiter | 1.1.5 | 23.17 kB | 23.17 kB | | retry | 0.13.1 | 18.85 kB | 18.85 kB | | semifies | 1.0.0 | 15.84 kB | 15.84 kB | | jest-docblock | 29.7.0 | 8.99 kB | 12.76 kB | | crypto-randomuuid | 1.0.0 | 11.18 kB | 11.18 kB | | ttl-set | 1.0.0 | 4.61 kB | 9.69 kB | | mutexify | 1.4.0 | 5.71 kB | 8.74 kB | | path-to-regexp | 0.1.12 | 6.6 kB | 6.6 kB | | koalas | 1.0.2 | 6.47 kB | 6.47 kB | | module-details-from-path | 1.0.4 | 3.96 kB | 3.96 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

Copy link

codecov bot commented Jul 25, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.80%. Comparing base (919a919) to head (4d66440).
⚠️ Report is 6 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #6176   +/-   ##
=======================================
  Coverage   82.80%   82.80%           
=======================================
  Files         476      476           
  Lines       19661    19661           
=======================================
  Hits        16281    16281           
  Misses       3380     3380           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@datadog-datadog-prod-us1
Copy link

✅ Tests

🎉 All green!

❄️ No new flaky tests detected
🧪 All tests passed

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 4d66440 | Was this helpful? Give us feedback!

@pr-commenter
Copy link

pr-commenter bot commented Jul 25, 2025

Benchmarks

Benchmark execution time: 2025-07-25 20:36:20

Comparing candidate commit 4d66440 in PR branch remove-audit-workflow with baseline commit 919a919 in branch master.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 1267 metrics, 56 unstable metrics.

@rochdev rochdev changed the title remove audit workflow in favour of datadog sca use datadog sca for vulnerability detection Jul 25, 2025
@rochdev rochdev marked this pull request as ready for review July 25, 2025 21:57
@rochdev rochdev requested a review from a team as a code owner July 25, 2025 21:57
Copy link
Member

@simon-id simon-id left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i see you're removing npm audit, but i don't see where you're adding SCA ?

@rochdev
Copy link
Member Author

rochdev commented Jul 29, 2025

@simon-id Will answer in DM

@rochdev rochdev merged commit f2bccff into master Jul 29, 2025
960 of 962 checks passed
@rochdev rochdev deleted the remove-audit-workflow branch July 29, 2025 02:03
@dd-octo-sts dd-octo-sts bot mentioned this pull request Jul 29, 2025
@dd-octo-sts dd-octo-sts bot mentioned this pull request Jul 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants