Skip to content

feat(turbopack): instrument bundled dependencies - #10047

Draft
BridgeAR wants to merge 10 commits into
masterfrom
BridgeAR/2026-08-28-turbopack-instrumentation
Draft

feat(turbopack): instrument bundled dependencies#10047
BridgeAR wants to merge 10 commits into
masterfrom
BridgeAR/2026-08-28-turbopack-instrumentation

Conversation

@BridgeAR

Copy link
Copy Markdown
Member

Turbopack bundles server dependencies before runtime module hooks can observe them. This adds withDatadogTurbopack, which creates a content-addressed build plan and adds Node-only loader rules.

CommonJS targets publish replaceable exports through the existing bundler channel. ESM targets use generated live-binding proxies. The loader uses Turbopack resolution, so application aliases and conditions remain authoritative.

Source hashes prevent stale plans from instrumenting changed dependencies. Target discovery and source analysis stay outside the application request path.

@dd-octo-sts

dd-octo-sts Bot commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

Overall package size

Self size: 8.64 MB
Deduped: 9.84 MB
No deduping: 9.84 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | enhanced-resolve | 5.24.5 | 420.33 kB | 526.29 kB | | import-in-the-middle | 3.4.0 | 127.33 kB | 447.04 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | dc-polyfill | 0.1.11 | 25.74 kB | 25.74 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@datadog-datadog-us1-prod

datadog-datadog-us1-prod Bot commented Aug 28, 2026

Copy link
Copy Markdown

Tests

All CI checks and tests passed.

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 98.66% (+0.06%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 276c51f | Docs | View more details | Give us feedback!

@codecov

codecov Bot commented Aug 28, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.66%. Comparing base (6a922b4) to head (276c51f).
⚠️ Report is 3 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #10047      +/-   ##
==========================================
+ Coverage   98.60%   98.66%   +0.06%     
==========================================
  Files         992      998       +6     
  Lines      149800   151984    +2184     
  Branches    12758    12777      +19     
==========================================
+ Hits       147704   149953    +2249     
+ Misses       2096     2031      -65     
Flag Coverage Δ
aiguard 63.36% <66.80%> (-0.07%) ⬇️
aiguard-integration 59.17% <63.56%> (+0.01%) ⬆️
apm-bucket-0 62.71% <66.80%> (-0.06%) ⬇️
apm-bucket-1 68.17% <66.80%> (-0.10%) ⬇️
apm-bucket-2 67.74% <66.80%> (-0.11%) ⬇️
apm-bucket-3 64.57% <66.80%> (-0.08%) ⬇️
apm-capabilities-tracing 62.88% <66.80%> (+0.28%) ⬆️
apm-integrations-aerospike 60.71% <66.80%> (-0.04%) ⬇️
apm-integrations-confluentinc-kafka-javascript 66.87% <66.80%> (-0.10%) ⬇️
apm-integrations-couchbase 61.22% <66.80%> (-0.04%) ⬇️
apm-integrations-http 66.43% <66.80%> (-0.09%) ⬇️
apm-integrations-kafkajs 67.45% <66.80%> (-0.11%) ⬇️
apm-integrations-next 64.05% <66.80%> (-0.07%) ⬇️
apm-integrations-prisma 62.07% <66.80%> (-0.05%) ⬇️
appsec 76.99% <66.80%> (-0.16%) ⬇️
appsec-express_fastify_graphql 73.43% <66.80%> (-0.12%) ⬇️
appsec-integration 49.56% <64.65%> (+0.05%) ⬆️
appsec-kafka_ldapjs_lodash 67.65% <66.80%> (-0.09%) ⬇️
appsec-mongodb-core_mongoose_mysql 70.84% <66.80%> (-0.10%) ⬇️
appsec-next 57.24% <66.80%> (+<0.01%) ⬆️
appsec-node-serialize_passport_postgres 70.30% <66.80%> (-0.10%) ⬇️
appsec-sourcing_stripe_template 68.73% <66.80%> (-0.09%) ⬇️
debugger 69.31% <66.80%> (-0.11%) ⬇️
instrumentations-bucket-0 56.25% <66.80%> (+0.01%) ⬆️
instrumentations-bucket-1 64.38% <66.80%> (-0.07%) ⬇️
instrumentations-bucket-10 53.42% <66.80%> (+0.03%) ⬆️
instrumentations-bucket-11 65.82% <66.80%> (-0.08%) ⬇️
instrumentations-bucket-12 61.59% <66.80%> (-0.05%) ⬇️
instrumentations-bucket-13 56.44% <66.80%> (+<0.01%) ⬆️
instrumentations-bucket-14 55.88% <66.80%> (+0.01%) ⬆️
instrumentations-bucket-2 57.09% <66.80%> (+<0.01%) ⬆️
instrumentations-bucket-3 57.29% <66.80%> (+<0.01%) ⬆️
instrumentations-bucket-4 63.99% <66.80%> (-0.07%) ⬇️
instrumentations-bucket-5 56.70% <66.80%> (+<0.01%) ⬆️
instrumentations-bucket-6 58.26% <66.80%> (-0.01%) ⬇️
instrumentations-bucket-7 65.89% <66.80%> (-0.09%) ⬇️
instrumentations-bucket-8 63.13% <66.80%> (-0.06%) ⬇️
instrumentations-bucket-9 64.72% <66.80%> (-0.07%) ⬇️
instrumentations-instrumentation-couchbase 54.85% <66.80%> (+0.02%) ⬆️
instrumentations-instrumentation-zlib 55.93% <66.80%> (+0.01%) ⬆️
instrumentations-integration-esbuild 34.51% <61.04%> (+0.09%) ⬆️
llmobs-ai_anthropic_bedrock 66.86% <66.80%> (-0.08%) ⬇️
llmobs-bucket-1 64.98% <66.80%> (-0.06%) ⬇️
llmobs-openai 66.90% <66.80%> (-0.09%) ⬇️
llmobs-openai-agents_vertex-ai 64.10% <66.80%> (-0.06%) ⬇️
llmobs-sdk 76.33% <66.80%> (-0.19%) ⬇️
master-coverage 98.66% <100.00%> (?)
openfeature 59.79% <61.13%> (+0.02%) ⬆️
openfeature-unit 58.45% <66.80%> (-0.02%) ⬇️
platform-core_esbuild_instrumentations-misc 41.25% <100.00%> (+0.23%) ⬆️
platform-integration 65.04% <63.56%> (+0.04%) ⬆️
platform-shimmer_turbopack_unit-guardrails 40.06% <97.31%> (?)
platform-shimmer_unit-guardrails_webpack ?
platform-webpack 38.76% <66.26%> (?)
plugins-browser-bunyan_bullmq_cassandra 66.46% <66.80%> (-0.09%) ⬇️
plugins-bucket-0 61.09% <66.80%> (-0.04%) ⬇️
plugins-bucket-1 58.35% <61.13%> (+0.04%) ⬆️
plugins-bucket-11 66.93% <66.80%> (-0.09%) ⬇️
plugins-bucket-18 66.36% <66.80%> (-0.09%) ⬇️
plugins-bucket-19 65.16% <66.80%> (-0.08%) ⬇️
plugins-bucket-20 66.96% <66.80%> (-0.10%) ⬇️
plugins-bucket-4 61.29% <66.80%> (-0.05%) ⬇️
plugins-cookie_cookie-parser_crypto 55.84% <66.80%> (+0.01%) ⬆️
plugins-fastify_fetch_fs 65.54% <66.80%> (-0.11%) ⬇️
plugins-generic-pool_google-cloud-pubsub_grpc 69.17% <66.80%> (-0.11%) ⬇️
plugins-handlebars_hapi_hono 63.80% <66.80%> (-0.07%) ⬇️
plugins-ioredis_knex_langgraph 61.80% <66.80%> (-0.05%) ⬇️
plugins-ldapjs_light-my-request_limitd-client 63.53% <66.80%> (-0.07%) ⬇️
plugins-lodash_mariadb_memcached 64.00% <66.80%> (-0.07%) ⬇️
plugins-moleculer_mongodb_mongodb-core 66.26% <66.80%> (-0.09%) ⬇️
plugins-mongoose_multer_mysql 64.10% <66.80%> (-0.07%) ⬇️
plugins-mysql2_nats_node-serialize 66.34% <66.80%> (-0.09%) ⬇️
plugins-opensearch_passport-http_pino 64.22% <66.80%> (-0.07%) ⬇️
plugins-postgres_process_pug 63.25% <66.80%> (-0.06%) ⬇️
plugins-redis_router_sequelize 66.84% <66.80%> (-0.10%) ⬇️
plugins-test-and-upstream-rhea_undici_url 66.18% <66.80%> (-0.09%) ⬇️
plugins-valkey_vm_winston 62.57% <66.80%> (-0.06%) ⬇️
plugins-ws 64.65% <66.80%> (-0.08%) ⬇️
profiling 66.41% <66.80%> (-0.03%) ⬇️
serverless-aws-sdk-aws-sdk 55.54% <66.80%> (+0.01%) ⬆️
serverless-aws-sdk-base-inject-field 55.41% <66.80%> (+0.02%) ⬆️
serverless-aws-sdk-bedrockruntime 58.42% <66.80%> (-0.01%) ⬇️
serverless-aws-sdk-client 60.22% <66.80%> (-0.03%) ⬇️
serverless-aws-sdk-dynamodb 59.28% <66.80%> (-0.02%) ⬇️
serverless-aws-sdk-eventbridge 57.75% <66.80%> (-0.01%) ⬇️
serverless-aws-sdk-kinesis 63.29% <66.80%> (-0.06%) ⬇️
serverless-aws-sdk-lambda 61.24% <66.80%> (-0.04%) ⬇️
serverless-aws-sdk-s3 59.34% <66.80%> (-0.02%) ⬇️
serverless-aws-sdk-serverless-peer-service 63.86% <66.80%> (-0.06%) ⬇️
serverless-aws-sdk-sns 64.18% <66.80%> (-0.07%) ⬇️
serverless-aws-sdk-sqs 64.64% <66.80%> (-0.07%) ⬇️
serverless-aws-sdk-stepfunctions 59.19% <66.80%> (-0.02%) ⬇️
serverless-aws-sdk-util 56.04% <66.80%> (+0.01%) ⬆️
serverless-bucket-0 57.97% <63.56%> (+0.03%) ⬆️
serverless-bucket-1 63.88% <66.80%> (-0.07%) ⬇️
test-optimization-cucumber 70.70% <66.80%> (-0.05%) ⬇️
test-optimization-cypress 64.92% <61.13%> (+0.07%) ⬆️
test-optimization-jest 72.23% <66.80%> (-0.07%) ⬇️
test-optimization-mocha 72.14% <66.80%> (-0.02%) ⬇️
test-optimization-playwright-playwright-atr 59.97% <63.56%> (+0.01%) ⬆️
test-optimization-playwright-playwright-efd 60.56% <63.56%> (-0.04%) ⬇️
test-optimization-playwright-playwright-final-status 60.17% <63.56%> (-0.04%) ⬇️
test-optimization-playwright-playwright-impacted-tests 60.28% <63.56%> (+0.11%) ⬆️
test-optimization-playwright-playwright-reporting 61.25% <63.56%> (-0.04%) ⬇️
test-optimization-playwright-playwright-test-management 61.34% <63.56%> (-0.04%) ⬇️
test-optimization-playwright-playwright-test-span 59.97% <63.56%> (+0.01%) ⬆️
test-optimization-selenium 58.99% <61.13%> (-0.05%) ⬇️
test-optimization-testopt 61.91% <65.99%> (+0.06%) ⬆️
test-optimization-vitest 72.84% <66.80%> (+0.01%) ⬆️
test-optimization-vitest-browser 58.80% <63.56%> (-0.03%) ⬇️
test-optimization-webdriverio 65.64% <66.80%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pr-commenter

pr-commenter Bot commented Aug 31, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-08-31 15:49:24

Comparing candidate commit 276c51f in PR branch BridgeAR/2026-08-28-turbopack-instrumentation with baseline commit 6a922b4 in branch master.

📊 Benchmarking dashboard

Found 0 performance improvements and 0 performance regressions! Performance is the same for 2296 metrics, 14 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:appsec-iast-with-vulnerability-iast-enabled-default-config-20

  • unstable max_rss_usage [-30.640MB; +21.890MB] or [-8.099%; +5.786%]

scenario:dogstatsd-with-tags-20

  • unstable cpu_user_time [-443.483ms; +240.960ms] or [-8.791%; +4.776%]
  • unstable execution_time [-445.256ms; +245.795ms] or [-8.689%; +4.797%]
  • unstable throughput [-81499.151op/s; +150251.880op/s] or [-4.980%; +9.181%]

scenario:plugin-graphql-long-with-depth-and-collapse-off-20

  • unstable max_rss_usage [-27.288MB; +39.835MB] or [-7.038%; +10.273%]

scenario:plugin-graphql-long-with-depth-off-20

  • unstable max_rss_usage [-6463.420KB; +6477.135KB] or [-5.165%; +5.176%]

scenario:plugin-graphql-long-with-depth-off-26

  • unstable max_rss_usage [-51.782MB; +4.758MB] or [-25.741%; +2.365%]

scenario:plugin-graphql-long-with-depth-on-max-20

  • unstable cpu_user_time [-797.139ms; +942.078ms] or [-6.753%; +7.981%]
  • unstable execution_time [-812.081ms; +957.973ms] or [-6.744%; +7.956%]
  • unstable throughput [-5.028op/s; +4.146op/s] or [-7.493%; +6.178%]

scenario:plugin-pg-service-24

  • unstable cpu_usage_percentage [-9.316%; +6.018%]
  • unstable execution_time [-152.457ms; +235.535ms] or [-8.996%; +13.899%]
  • unstable throughput [-347494.508op/s; +228659.696op/s] or [-9.678%; +6.368%]

scenario:plugin-pino-json-log-injection-26

  • unstable execution_time [-134.236ms; +173.699ms] or [-4.451%; +5.760%]

1. Clean installs hoisted Babel 8's ESM parser into the CommonJS fake Next compiler because its Babel 7 inputs were only transitive dependencies.
2. Bun applied the root files allowlist to nested READMEs while npm included them automatically, so the package archives differed.
Backport CI widens the repository engine range to include Node 18 and 20. The test then loads ESLint 10 on unsupported runtimes, which fail while parsing its /v regular expressions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants