Skip to content

chore: bump github.com/DataDog/dd-trace-go/v2 from 2.0.0 to 2.8.1 - #529

Draft
stirby wants to merge 1 commit into
mainfrom
bump-dd-trace-go
Draft

stirby wants to merge 1 commit into
mainfrom
bump-dd-trace-go

Conversation

@stirby

@stirby stirby commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps DataDog/dd-trace-go/v2 2.0.0 to 2.8.1. It's pulled in transitively by codersdk through coderd/tracing. govulncheck: 75 reachable to 72, fixing 3 (W3C baggage DoS and related).

Behaviour change to review: dd-trace-go 2.8 calls os.Setenv("_DD_ROOT_GO_SESSION_ID", <uuid>) at package init so child processes inherit it. envbuilder execs the workspace init process with its own environment, so this variable leaked into the workspace. That broke TestPushImage/CompareBuiltAndCachedImageEnvironment, because the ID differs between the build and cached runs. options.UnsetEnv now also clears _DD_ROOT_GO_SESSION_ID, next to the existing KANIKO_DIR cleanup.

Part of a set of independent dependency PRs. All touch go.mod/go.sum, so rebase with go mod tidy after the first one merges. The latest-Coder-SDK draft also pulls dd-trace-go 2.8 and includes the same fix.

Generated by Coder Agents on behalf of @stirby.

@spikecurtis

Copy link
Copy Markdown

I think this would be better via the CoderSDK upgrade.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants