Skip to content

test(nodejs-lambda): enable API Security schema tests for the Lambda weblogs - #7806

Open
CarlesDD wants to merge 9 commits into
mainfrom
ccapell/APPSEC-68818/nodejs-lambda-api-security
Open

CarlesDD wants to merge 9 commits into
mainfrom
ccapell/APPSEC-68818/nodejs-lambda-api-security

Conversation

@CarlesDD

@CarlesDD CarlesDD commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

Node.js API Security for AWS Lambda ships schema extraction. This turns on the corresponding test_schemas.py coverage for the two weblogs whose trigger carries a route (nodejs-apigw-rest, nodejs-apigw-http).

Changes

  • Per-test, per-weblog version gates in manifests/nodejs_lambda.yml, replacing the blanket missing_feature on tests/appsec/api_security/test_schemas.py.
  • nodejs-apigw-rest/nodejs-apigw-http/nodejs-alb/nodejs-alb-multi/nodejs-function-url Dockerfiles moved from the Node 18 to the Node 22 base image (AL2 → AL2023, yum → dnf): Node 18 pins the old dd-trace v5 line

Verified locally against a hand-built layer from the two open branches: 8 passed / 2 xfailed on both weblogs, no regressions in APPSEC_LAMBDA_DEFAULT/BLOCKING/RASP/INFERRED_SPANS.

Workflow

  1. ⚠️ Create your PR as draft ⚠️
  2. Work on you PR until the CI passes
  3. Mark it as ready for review
    • Test logic is modified? -> Get a review from RFC owner.
    • Framework is modified, or non obvious usage of it -> get a review from R&P team

🚀 Once your PR is reviewed and the CI green, you can merge it!

🛟 #apm-shared-testing 🛟

Reviewer checklist

  • Anything but tests/ or manifests/ is modified ? I have the approval from R&P team
  • A docker base image is modified?
    • the relevant build-XXX-image label is present
  • A scenario is added, removed or renamed?

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

CODEOWNERS have been resolved as:

manifests/nodejs_lambda.yml                                             @DataDog/system-tests-reviewers
mirror_images.lock.yaml                                                 @DataDog/system-tests-core
mirror_images.yaml                                                      @DataDog/system-tests-core
utils/build/docker/nodejs_lambda/nodejs-alb-multi.Dockerfile            @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-alb.Dockerfile                  @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-apigw-http.Dockerfile           @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-apigw-rest.Dockerfile           @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-function-url.Dockerfile         @DataDog/system-tests-reviewers

@datadog-datadog-us1-prod

datadog-datadog-us1-prod Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Pipelines  Tests

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 38 Pipeline jobs failed

Testing the test | System Tests (php, dev) / End-to-end #2 / apache-mod-7.0-zts 2 — ❌ 6 tests failed · 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

❌ tests.stats.test_stats.Test_Client_Stats.test_top_level_service[apache-mod-7.0-zts] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Client_Stats object at 0x7f32e4d57800>

    def test_top_level_service(self):
        """Test that the top-level Service field in the stats payload matches the configured base service"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
❌ tests.stats.test_stats.Test_Time_Bucketing.test_client_side_stats[apache-mod-7.0-zts] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Time_Bucketing object at 0x7f32e4b93b60>

    def test_client_side_stats(self):
        """Test that client-side stats are properly bucketed in 10-second intervals"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
❌ tests.stats.test_stats.Test_Time_Bucketing.test_client_side_stats_bucket_alignment[apache-mod-7.0-zts] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Time_Bucketing object at 0x7f32e4b93ce0>

    def test_client_side_stats_bucket_alignment(self):
        """Test that client-side stats are aligned on 10-second intervals"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
↳ and 3 more — View all
Testing the test | System Tests (php, dev) / End-to-end #2 / apache-mod-7.1 2 — ❌ 6 tests failed · 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

❌ tests.stats.test_stats.Test_Client_Stats.test_top_level_service[apache-mod-7.1] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Client_Stats object at 0x7ffab8353680>

    def test_top_level_service(self):
        """Test that the top-level Service field in the stats payload matches the configured base service"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
❌ tests.stats.test_stats.Test_Time_Bucketing.test_client_side_stats[apache-mod-7.1] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Time_Bucketing object at 0x7ffab8351c10>

    def test_client_side_stats(self):
        """Test that client-side stats are properly bucketed in 10-second intervals"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
❌ tests.stats.test_stats.Test_Time_Bucketing.test_client_side_stats_bucket_alignment[apache-mod-7.1] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Time_Bucketing object at 0x7ffab83513d0>

    def test_client_side_stats_bucket_alignment(self):
        """Test that client-side stats are aligned on 10-second intervals"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
↳ and 3 more — View all
Testing the test | System Tests (php, dev) / End-to-end #2 / apache-mod-7.1-zts 2 — ❌ 6 tests failed · 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

❌ tests.stats.test_stats.Test_Client_Stats.test_top_level_service[apache-mod-7.1-zts] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Client_Stats object at 0x7f6957cefd10>

    def test_top_level_service(self):
        """Test that the top-level Service field in the stats payload matches the configured base service"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
❌ tests.stats.test_stats.Test_Time_Bucketing.test_client_side_stats[apache-mod-7.1-zts] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Time_Bucketing object at 0x7f6957ceed80>

    def test_client_side_stats(self):
        """Test that client-side stats are properly bucketed in 10-second intervals"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
❌ tests.stats.test_stats.Test_Time_Bucketing.test_client_side_stats_bucket_alignment[apache-mod-7.1-zts] from system_tests_suite
AssertionError: Should have at least one stats request
assert 0 > 0
 +  where 0 = len([])

self = <tests.stats.test_stats.Test_Time_Bucketing object at 0x7f6957ceea50>

    def test_client_side_stats_bucket_alignment(self):
        """Test that client-side stats are aligned on 10-second intervals"""
        stats_requests = list(interfaces.library.get_data("/v0.6/stats"))
>       assert len(stats_requests) > 0, "Should have at least one stats request"
...
↳ and 3 more — View all

View all 38 failed jobs.

ℹ️ Info

No other issues found (see more)

❄️ No new flaky tests detected

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 76daa81 | Docs | View more details | Give us feedback!

@CarlesDD
CarlesDD force-pushed the ccapell/APPSEC-68818/nodejs-lambda-api-security branch from 2d29934 to 34dc505 Compare September 23, 2026 20:00
@CarlesDD
CarlesDD force-pushed the ccapell/APPSEC-68818/nodejs-lambda-api-security branch from 34dc505 to 4d7eea7 Compare September 23, 2026 20:00
@CarlesDD
CarlesDD marked this pull request as ready for review September 25, 2026 05:29
@CarlesDD
CarlesDD requested review from a team as code owners September 25, 2026 05:29
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-25T05:33:08.927752Z 46e2fc9 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 46e2fc9d2d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread manifests/nodejs_lambda.yml

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants