
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
@opentelemetry/instrumentation-memcached
Advanced tools
OpenTelemetry instrumentation for `memcached` database client for memcached
This module provides automatic instrumentation for the memcached@>=2.2.0 module, which may be loaded using the @opentelemetry/sdk-trace-node package and is included in the @opentelemetry/auto-instrumentations-node bundle.
If total installation size is not constrained, it is recommended to use the @opentelemetry/auto-instrumentations-node bundle with @opentelemetry/sdk-node for the most seamless instrumentation experience.
Compatible with OpenTelemetry JS API and SDK 1.0+.
npm install --save @opentelemetry/instrumentation-memcached
memcached versions >=2.2.0 <3OpenTelemetry Memcached Instrumentation allows the user to automatically collect trace data and export them to the backend of choice, to give observability to distributed systems when working with memcached.
To load a specific instrumentation (memcached in this case), specify it in the registerInstrumentations' configuration
const { NodeTracerProvider } = require('@opentelemetry/sdk-trace-node');
const { MemcachedInstrumentation } = require('@opentelemetry/instrumentation-memcached');
const { registerInstrumentations } = require('@opentelemetry/instrumentation');
const provider = new NodeTracerProvider();
provider.register();
registerInstrumentations({
instrumentations: [
new MemcachedInstrumentation({
enhancedDatabaseReporting: false,
}),
],
});
| Option | Type | Example | Description |
|---|---|---|---|
enhancedDatabaseReporting | boolean | false | Include full command statement in the span - leaks potentially sensitive information to your spans. Defaults to false. |
This instrumentation implements Semantic Conventions (semconv) v1.7.0. Since then, networking (in semconv v1.23.1) and database (in semconv v1.33.0) semantic conventions were stabilized. As of @opentelemetry/instrumentation-memcached@0.51.0 support has been added for migrating to the stable semantic conventions using the OTEL_SEMCONV_STABILITY_OPT_IN environment variable as follows:
OTEL_SEMCONV_STABILITY_OPT_IN=http/dup,database/dup to emit both old and stable semantic conventions. (The http token is used to control the net.* attributes, the database token to control to db.* attributes.)OTEL_SEMCONV_STABILITY_OPT_IN=http,database to emit only the stable semantic conventions.By default, if OTEL_SEMCONV_STABILITY_OPT_IN includes neither of the above tokens, the old v1.7.0 semconv is used.
The intent is to provide an approximate 6 month time window for users of this instrumentation to migrate to the new database and networking semconv, after which a new minor version will use the new semconv by default and drop support for the old semconv.
See the HTTP migration guide and the database migration guide for details.
Attributes collected:
| Old semconv | Stable semconv | Description |
|---|---|---|
db.system | db.system.name | 'memcached' |
db.operation | db.operation.name | The name of the operation being executed. |
db.statement | db.query.text | The database statement being executed (only if enhancedDatabaseReporting is enabled). |
net.peer.name | server.address | Remote hostname or similar. |
net.peer.port | server.port | Remote port number. |
Apache 2.0 - See LICENSE for more information.
@opentelemetry/instrumentation-redis is a similar package for Redis. It provides automatic tracing and metrics collection for Redis operations. Like @opentelemetry/instrumentation-memcached, it helps in monitoring and debugging Redis usage in a distributed system.
FAQs
OpenTelemetry instrumentation for `memcached` database client for memcached
The npm package @opentelemetry/instrumentation-memcached receives a total of 2,167,320 weekly downloads. As such, @opentelemetry/instrumentation-memcached popularity was classified as popular.
We found that @opentelemetry/instrumentation-memcached demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.