Skip to content

Conversation

@avara1986
Copy link
Member

Checklist

  • PR author has checked that all the criteria below are met
  • The PR description includes an overview of the change
  • The PR description articulates the motivation for the change
  • The change includes tests OR the PR description describes a testing strategy
  • The PR description notes risks associated with the change, if any
  • Newly-added code is easy to change
  • The change follows the library release note guidelines
  • The change includes or references documentation updates if necessary
  • Backport labels are set (if applicable)

Reviewer Checklist

  • Reviewer has checked that all the criteria below are met
  • Title is accurate
  • All changes are related to the pull request's stated goal
  • Avoids breaking API changes
  • Testing strategy adequately addresses listed risks
  • Newly-added code is easy to change
  • Release note makes sense to a user of the library
  • If necessary, author has acknowledged and discussed the performance implications of this PR as reported in the benchmarks PR comment
  • Backport labels are set in a manner that is consistent with the release branch maintenance policy

@avara1986 avara1986 added changelog/no-changelog A changelog entry is not required for this PR. ASM Application Security Monitoring labels Apr 21, 2025
@github-actions
Copy link
Contributor

github-actions bot commented Apr 21, 2025

CODEOWNERS have been resolved as:

tests/appsec/integrations/fixtures/patch_file_paths.py                  @DataDog/asm-python
tests/appsec/integrations/flask_tests/test_sanitizers.py                @DataDog/asm-python
ddtrace/appsec/_iast/_patch_modules.py                                  @DataDog/asm-python
tests/appsec/iast/test_iast_dbs.py                                      @DataDog/asm-python

@github-actions
Copy link
Contributor

github-actions bot commented Apr 21, 2025

Bootstrap import analysis

Comparison of import times between this PR and base.

Summary

The average import time from this PR is: 233 ± 3 ms.

The average import time from base is: 237 ± 2 ms.

The import time difference between this PR and base is: -3.9 ± 0.1 ms.

Import time breakdown

The following import paths have shrunk:

ddtrace.auto 2.088 ms (0.90%)
ddtrace.bootstrap.sitecustomize 1.413 ms (0.61%)
ddtrace.bootstrap.preload 1.413 ms (0.61%)
ddtrace.internal.products 1.413 ms (0.61%)
ddtrace.internal.remoteconfig.client 0.648 ms (0.28%)
ddtrace 0.675 ms (0.29%)

@pr-commenter
Copy link

pr-commenter bot commented Apr 21, 2025

Benchmarks

Benchmark execution time: 2025-04-23 14:37:59

Comparing candidate commit 2737f46 in PR branch avara1986/APPSEC-57370_path_traversal_secure_mark with baseline commit 6d33c22 in branch main.

Found 0 performance improvements and 2 performance regressions! Performance is the same for 498 metrics, 8 unstable metrics.

scenario:iast_aspects-ospathdirname_aspect

  • 🟥 execution_time [+803.470ns; +912.875ns] or [+17.496%; +19.878%]

scenario:iast_aspects-ospathnormcase_aspect

  • 🟥 execution_time [+347.129ns; +420.792ns] or [+10.053%; +12.186%]

@avara1986 avara1986 marked this pull request as ready for review April 23, 2025 08:27
@avara1986 avara1986 requested a review from a team as a code owner April 23, 2025 08:27
@avara1986 avara1986 merged commit 064f872 into main Apr 23, 2025
399 checks passed
@avara1986 avara1986 deleted the avara1986/APPSEC-57370_path_traversal_secure_mark branch April 23, 2025 15:35
brettlangdon pushed a commit that referenced this pull request May 6, 2025
## Checklist
- [x] PR author has checked that all the criteria below are met
- The PR description includes an overview of the change
- The PR description articulates the motivation for the change
- The change includes tests OR the PR description describes a testing
strategy
- The PR description notes risks associated with the change, if any
- Newly-added code is easy to change
- The change follows the [library release note
guidelines](https://ddtrace.readthedocs.io/en/stable/releasenotes.html)
- The change includes or references documentation updates if necessary
- Backport labels are set (if
[applicable](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting))

## Reviewer Checklist
- [x] Reviewer has checked that all the criteria below are met 
- Title is accurate
- All changes are related to the pull request's stated goal
- Avoids breaking
[API](https://ddtrace.readthedocs.io/en/stable/versioning.html#interfaces)
changes
- Testing strategy adequately addresses listed risks
- Newly-added code is easy to change
- Release note makes sense to a user of the library
- If necessary, author has acknowledged and discussed the performance
implications of this PR as reported in the benchmarks PR comment
- Backport labels are set in a manner that is consistent with the
[release branch maintenance
policy](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ASM Application Security Monitoring changelog/no-changelog A changelog entry is not required for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants