build(deps): bump the minor-and-patch group with 5 updates #24

Merged
dependabot[bot] merged 1 commit from dependabot/npm_and_yarn/minor-and-patch-62d144906b into main 2026-05-08 22:27:49 +00:00
dependabot[bot] commented 2026-05-08 18:24:37 +00:00 (Migrated from github.com)

Bumps the minor-and-patch group with 5 updates:

Package From To
aws-cdk-lib 2.252.0 2.253.1
@aws-sdk/client-dynamodb 3.1041.0 3.1045.0
@aws-sdk/lib-dynamodb 3.1041.0 3.1045.0
aws-cdk 2.1120.0 2.1121.0
esbuild 0.25.12 0.28.0

Updates aws-cdk-lib from 2.252.0 to 2.253.1

Release notes

Sourced from aws-cdk-lib's releases.

v2.253.1

Bug Fixes

  • core: "exports cannot be updated" for cross-region references (#37790) (b0c00e2)
  • s3deploy: empty sources leads to deployment error (#37786) (f61656a)

Alpha modules (2.253.1-alpha.0)

v2.253.0

Features

Bug Fixes

  • cloudfront: skip cachePolicyName length validation for unresolved tokens (#37751) (3b96e97), closes #23567 #34102
  • cloudwatch: remove false positive warning for CDK tokens in MathExpression (#36882) (c29dc17), closes #34977
  • codebuild: correct S3 log encryption boolean inversion (#37761) (4031918)
  • ecs: enabling the circuitBreaker is not recommended loudly enough (#37755) (a52af7d)
  • eks: add dependency from HelmChart custom resource to s3 chartAsset IAM policy (#37731) (99d0a5b), closes #19880

Alpha modules (2.253.0-alpha.0)

Features

  • bedrock-agentcore-alpha: add OnlineEvaluationConfig and Evaluator L2 constructs (#37615) (c13de04), closes #37614
  • glue-alpha: add extraPythonFiles support to PythonShellJob (#37130) (c9c6f9c), closes #34448

Bug Fixes

  • bedrock-agentcore-alpha: self-managed memory strategy validation throws on unresolved tokens (#37691) (7956537), closes #37197
Changelog

Sourced from aws-cdk-lib's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

2.253.1-alpha.0 (2026-05-08)

2.253.0-alpha.0 (2026-05-06)

Features

  • bedrock-agentcore-alpha: add OnlineEvaluationConfig and Evaluator L2 constructs (#37615) (c13de04), closes #37614
  • glue-alpha: add extraPythonFiles support to PythonShellJob (#37130) (c9c6f9c), closes #34448

Bug Fixes

  • bedrock-agentcore-alpha: self-managed memory strategy validation throws on unresolved tokens (#37691) (7956537), closes #37197

2.252.0-alpha.0 (2026-04-29)

2.251.0-alpha.0 (2026-04-24)

Features

  • bedrock-agentcore-alpha: add L2 constructs for policy and policy engine (#37238) (1e89e7e)
  • bedrock-agentcore-alpha: add observability configuration for Runtime (#36689) (34b43aa), closes #36596
  • bedrock-agentcore-alpha: support No Authorization for AgentCore Gateway (#36610) (f20bd8e)
  • dsql-alpha: initial L2 construct (#34599) (be1a458), closes #34593

2.250.0-alpha.0 (2026-04-14)

2.249.0-alpha.0 (2026-04-10)

2.248.0-alpha.0 (2026-04-02)

2.247.0-alpha.0 (2026-04-02)

Features

2.246.0-alpha.0 (2026-03-31)

2.245.0-alpha.0 (2026-03-27)

Features

... (truncated)

Commits
  • b0c00e2 fix(core): "exports cannot be updated" for cross-region references (#37790)
  • f61656a fix(s3deploy): empty sources leads to deployment error (#37786)
  • 55a4299 chore: update analytics metadata blueprints
  • e9c0b5a chore(release): 2.253.0
  • a52af7d fix(ecs): enabling the circuitBreaker is not recommended loudly enough (#37755)
  • a661c2d feat: update L1 CloudFormation resource definitions (#37753)
  • c29dc17 fix(cloudwatch): remove false positive warning for CDK tokens in MathExpressi...
  • dedf99b chore: replace Lazy with IBox (#37739)
  • 4031918 fix(codebuild): correct S3 log encryption boolean inversion (#37761)
  • 99d0a5b fix(eks): add dependency from HelmChart custom resource to s3 chartAsset IAM ...
  • Additional commits viewable in compare view

Updates @aws-sdk/client-dynamodb from 3.1041.0 to 3.1045.0

Release notes

Sourced from @​aws-sdk/client-dynamodb's releases.

v3.1045.0

3.1045.0(2026-05-07)

Documentation Changes
  • client-guardduty: This is a documentation update (1484574c)
New Features
  • clients: update client endpoints as of 2026-05-07 (81310767)
  • client-bcm-data-exports: With this release, customers can configure their data exports to generate additional integration artifacts for Athena and Redshift. (238da2c1)
  • client-invoicing: Updated ListInvoiceSummaries API to add new ReceiverRole filter in Request and Response (60a448cb)
  • client-bedrock-agentcore: Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). (1e1031a7)
  • client-ec2: DescribeInstanceTypes now accepts an IncludeUnsupportedInRegion parameter. When set, the response also lists instance types that are not available in the current Region. Each instance type includes a SupportedInRegion field indicating its regional availability. (70262433)
  • client-bedrock-agentcore-control: Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). (fe5861ae)
  • client-route53resolver: Adds supports for DNS64 on inbound endpoints and IPv6 forwarding through the internet gateway (IGW) on outbound endpoints, making it easier to manage hybrid DNS across IPv4 and IPv6 networks. (8e6e18c6)

For list of updated packages, view updated-packages.md in assets-3.1045.0.zip

v3.1044.0

3.1044.0(2026-05-06)

New Features
  • client-securityhub: Release GenerateRecommendedPolicyV2 and GetRecommendedPolicyV2 APIs. This supports generating and retrieving policy recommendations to remediate unused permissions findings that are now being supported on Security Hub. (772b8629)
  • client-sagemaker: Amazon SageMaker HyperPod now returns ImageVersionStatus in DescribeCluster, DescribeClusterNode, and ListClusterNodes responses, indicating whether cluster instances are running the latest available image version. (2be7e6b4)
  • client-glue: Adds support for a CustomLogGroupPrefix parameter in StartDataQualityRulesetEvaluationRun to specify custom CloudWatch log group paths, and a RulesetName filter in ListDataQualityRulesetEvaluationRuns to filter evaluation runs by ruleset name. (b95d850b)
  • client-lex-models-v2: Amazon Lex V2 introduces audio filler support for speech-to-speech bots. Configure melody or typing sounds that play during backend processing to reduce perceived latency and maintain a natural conversational experience for callers. (01426f8e)
  • client-bedrock-agentcore-control: Adds support for bring-your-own file system in AgentCore Runtime. Developers can mount Amazon S3 Files and Amazon EFS access points directly into agent sessions using filesystemConfigurations. (e20f24d9)
  • client-s3: Validate outpost access point resource name (bee88a56)
  • client-mwaa: Amazon MWAA now supports a PublicAndPrivate webserver access mode. The Airflow web server is accessible over both public and private endpoints, enabling workers in VPCs without internet access to reach the Task API privately while retaining public access to the Airflow UI. (3a6054ef)
  • client-imagebuilder: The ImportDiskImage API now enforces a maximum character limit of 128 characters on the image name field. (7fc2565c)
Tests
  • scripts: include type symbols in api snapshot test (#7985) (02f86176)

For list of updated packages, view updated-packages.md in assets-3.1044.0.zip

v3.1043.0

3.1043.0(2026-05-05)

New Features

... (truncated)

Changelog

Sourced from @​aws-sdk/client-dynamodb's changelog.

3.1045.0 (2026-05-07)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1044.0 (2026-05-06)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1043.0 (2026-05-05)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1042.0 (2026-05-04)

Note: Version bump only for package @​aws-sdk/client-dynamodb

Commits

Updates @aws-sdk/lib-dynamodb from 3.1041.0 to 3.1045.0

Release notes

Sourced from @​aws-sdk/lib-dynamodb's releases.

v3.1045.0

3.1045.0(2026-05-07)

Documentation Changes
  • client-guardduty: This is a documentation update (1484574c)
New Features
  • clients: update client endpoints as of 2026-05-07 (81310767)
  • client-bcm-data-exports: With this release, customers can configure their data exports to generate additional integration artifacts for Athena and Redshift. (238da2c1)
  • client-invoicing: Updated ListInvoiceSummaries API to add new ReceiverRole filter in Request and Response (60a448cb)
  • client-bedrock-agentcore: Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). (1e1031a7)
  • client-ec2: DescribeInstanceTypes now accepts an IncludeUnsupportedInRegion parameter. When set, the response also lists instance types that are not available in the current Region. Each instance type includes a SupportedInRegion field indicating its regional availability. (70262433)
  • client-bedrock-agentcore-control: Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). (fe5861ae)
  • client-route53resolver: Adds supports for DNS64 on inbound endpoints and IPv6 forwarding through the internet gateway (IGW) on outbound endpoints, making it easier to manage hybrid DNS across IPv4 and IPv6 networks. (8e6e18c6)

For list of updated packages, view updated-packages.md in assets-3.1045.0.zip

v3.1044.0

3.1044.0(2026-05-06)

New Features
  • client-securityhub: Release GenerateRecommendedPolicyV2 and GetRecommendedPolicyV2 APIs. This supports generating and retrieving policy recommendations to remediate unused permissions findings that are now being supported on Security Hub. (772b8629)
  • client-sagemaker: Amazon SageMaker HyperPod now returns ImageVersionStatus in DescribeCluster, DescribeClusterNode, and ListClusterNodes responses, indicating whether cluster instances are running the latest available image version. (2be7e6b4)
  • client-glue: Adds support for a CustomLogGroupPrefix parameter in StartDataQualityRulesetEvaluationRun to specify custom CloudWatch log group paths, and a RulesetName filter in ListDataQualityRulesetEvaluationRuns to filter evaluation runs by ruleset name. (b95d850b)
  • client-lex-models-v2: Amazon Lex V2 introduces audio filler support for speech-to-speech bots. Configure melody or typing sounds that play during backend processing to reduce perceived latency and maintain a natural conversational experience for callers. (01426f8e)
  • client-bedrock-agentcore-control: Adds support for bring-your-own file system in AgentCore Runtime. Developers can mount Amazon S3 Files and Amazon EFS access points directly into agent sessions using filesystemConfigurations. (e20f24d9)
  • client-s3: Validate outpost access point resource name (bee88a56)
  • client-mwaa: Amazon MWAA now supports a PublicAndPrivate webserver access mode. The Airflow web server is accessible over both public and private endpoints, enabling workers in VPCs without internet access to reach the Task API privately while retaining public access to the Airflow UI. (3a6054ef)
  • client-imagebuilder: The ImportDiskImage API now enforces a maximum character limit of 128 characters on the image name field. (7fc2565c)
Tests
  • scripts: include type symbols in api snapshot test (#7985) (02f86176)

For list of updated packages, view updated-packages.md in assets-3.1044.0.zip

v3.1043.0

3.1043.0(2026-05-05)

New Features

... (truncated)

Changelog

Sourced from @​aws-sdk/lib-dynamodb's changelog.

3.1045.0 (2026-05-07)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1044.0 (2026-05-06)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1043.0 (2026-05-05)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1042.0 (2026-05-04)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

Commits

Updates aws-cdk from 2.1120.0 to 2.1121.0

Release notes

Sourced from aws-cdk's releases.

aws-cdk@v2.1121.0

2.1121.0 (2026-05-06)

Features

Bug Fixes

  • update version includes a spurious newline (#1477) (1f09294)
Commits
  • 7abdd4e chore(deps): bump ip-address from 10.1.0 to 10.2.0 (#1479)
  • ab82d61 chore(deps): bump @​aws-sdk/client-ssm from 3.1036.0 to 3.1037.0 (#1470)
  • 1f09294 fix: update version includes a spurious newline (#1477)
  • 63db541 chore(deps): bump @​aws-sdk/client-ecr from 3.1036.0 to 3.1037.0 (#1473)
  • 04c27f2 chore(deps): bump @​aws-sdk/client-appsync from 3.1036.0 to 3.1037.0 (#1471)
  • 68540cc chore(deps): bump @​aws-sdk/client-cloudformation from 3.1036.0 to 3.1037.0 (#...
  • 158daf3 chore(deps): bump @​aws-sdk/client-kms from 3.1036.0 to 3.1037.0 (#1469)
  • 0f86332 chore(deps): upgrade dependencies (#1468)
  • 09b7f15 chore: Remove package-lock.json from template.gitignore (#1466)
  • 9f872c9 feat(deps): upgrade aws-cdk-lib (#1465)
  • See full diff in compare view

Updates esbuild from 0.25.12 to 0.28.0

Release notes

Sourced from esbuild's releases.

v0.28.0

  • Add support for with { type: 'text' } imports (#4435)

    The import text proposal has reached stage 3 in the TC39 process, which means that it's recommended for implementation. It has also already been implemented by Deno and Bun. So with this release, esbuild also adds support for it. This behaves exactly the same as esbuild's existing text loader. Here's an example:

    import string from './example.txt' with { type: 'text' }
    console.log(string)
    
  • Add integrity checks to fallback download path (#4343)

    Installing esbuild via npm is somewhat complicated with several different edge cases (see esbuild's documentation for details). If the regular installation of esbuild's platform-specific package fails, esbuild's install script attempts to download the platform-specific package itself (first with the npm command, and then with a HTTP request to registry.npmjs.org as a last resort).

    This last resort path previously didn't have any integrity checks. With this release, esbuild will now verify that the hash of the downloaded binary matches the expected hash for the current release. This means the hashes for all of esbuild's platform-specific binary packages will now be embedded in the top-level esbuild package. Hopefully this should work without any problems. But just in case, this change is being done as a breaking change release.

  • Update the Go compiler from 1.25.7 to 1.26.1

    This upgrade should not affect anything. However, there have been some significant internal changes to the Go compiler, so esbuild could potentially behave differently in certain edge cases:

    • It now uses the new garbage collector that comes with Go 1.26.
    • The Go compiler is now more aggressive with allocating memory on the stack.
    • The executable format that the Go linker uses has undergone several changes.
    • The WebAssembly build now unconditionally makes use of the sign extension and non-trapping floating-point to integer conversion instructions.

    You can read the Go 1.26 release notes for more information.

v0.27.7

  • Fix lowering of define semantics for TypeScript parameter properties (#4421)

    The previous release incorrectly generated class fields for TypeScript parameter properties even when the configured target environment does not support class fields. With this release, the generated class fields will now be correctly lowered in this case:

    // Original code
    class Foo {
      constructor(public x = 1) {}
      y = 2
    }
    

    // Old output (with --loader=ts --target=es2021)
    class Foo {
    constructor(x = 1) {
    this.x = x;
    __publicField(this, "y", 2);
    }
    x;
    }

    // New output (with --loader=ts --target=es2021)
    class Foo {

... (truncated)

Changelog

Sourced from esbuild's changelog.

Changelog: 2025

This changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).

0.27.2

  • Allow import path specifiers starting with #/ (#4361)

    Previously the specification for package.json disallowed import path specifiers starting with #/, but this restriction has recently been relaxed and support for it is being added across the JavaScript ecosystem. One use case is using it for a wildcard pattern such as mapping #/* to ./src/* (previously you had to use another character such as #_* instead, which was more confusing). There is some more context in nodejs/node#49182.

    This change was contributed by @​hybrist.

  • Automatically add the -webkit-mask prefix (#4357, #4358)

    This release automatically adds the -webkit- vendor prefix for the mask CSS shorthand property:

    /* Original code */
    main {
      mask: url(x.png) center/5rem no-repeat
    }
    

    /* Old output (with --target=chrome110) */
    main {
    mask: url(x.png) center/5rem no-repeat;
    }

    /* New output (with --target=chrome110) */
    main {
    -webkit-mask: url(x.png) center/5rem no-repeat;
    mask: url(x.png) center/5rem no-repeat;
    }

    This change was contributed by @​BPJEnnova.

  • Additional minification of switch statements (#4176, #4359)

    This release contains additional minification patterns for reducing switch statements. Here is an example:

    // Original code
    switch (x) {
      case 0:
        foo()
        break
      case 1:
      default:
        bar()
    }
    

... (truncated)

Commits
  • 6a794df publish 0.28.0 to npm
  • 64ee0ea fix #4435: support with { type: text } imports
  • ef65aee fix sort order in snapshots_packagejson.txt
  • 1a26a8e try to fix test-old-ts, also shuffle CI tasks
  • 556ce6c use '' instead of null to omit build hashes
  • 8e675a8 ci: allow missing binary hashes for tests
  • 7067763 Reapply "update go 1.25.7 => 1.26.1"
  • 39473a9 fix #4343: integrity check for binary download
  • 2025c9f publish 0.27.7 to npm
  • c6b586e fix typo in Makefile for @esbuild/win32-x64
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for esbuild since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
Bumps the minor-and-patch group with 5 updates: | Package | From | To | | --- | --- | --- | | [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) | `2.252.0` | `2.253.1` | | [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1041.0` | `3.1045.0` | | [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1041.0` | `3.1045.0` | | [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1120.0` | `2.1121.0` | | [esbuild](https://github.com/evanw/esbuild) | `0.25.12` | `0.28.0` | Updates `aws-cdk-lib` from 2.252.0 to 2.253.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-cdk/releases">aws-cdk-lib's releases</a>.</em></p> <blockquote> <h2>v2.253.1</h2> <h3>Bug Fixes</h3> <ul> <li><strong>core:</strong> &quot;exports cannot be updated&quot; for cross-region references (<a href="https://redirect.github.com/aws/aws-cdk/issues/37790">#37790</a>) (<a href="https://github.com/aws/aws-cdk/commit/b0c00e2b1fde5da462d4fd848610f59e78b482ba">b0c00e2</a>)</li> <li><strong>s3deploy:</strong> empty sources leads to deployment error (<a href="https://redirect.github.com/aws/aws-cdk/issues/37786">#37786</a>) (<a href="https://github.com/aws/aws-cdk/commit/f61656a3a408b0b50d79f43cdf18d0f5801e9a43">f61656a</a>)</li> </ul> <hr /> <h2>Alpha modules (2.253.1-alpha.0)</h2> <h2>v2.253.0</h2> <h3>Features</h3> <ul> <li>update L1 CloudFormation resource definitions (<a href="https://redirect.github.com/aws/aws-cdk/issues/37753">#37753</a>) (<a href="https://github.com/aws/aws-cdk/commit/a661c2ddee343a610b0ab312996ce34e6cacb571">a661c2d</a>)</li> <li><strong>apigatewayv2-integrations:</strong> auto-include EventBusName in HttpEventBridgeIntegration default parameter mapping (<a href="https://redirect.github.com/aws/aws-cdk/issues/36780">#36780</a>) (<a href="https://github.com/aws/aws-cdk/commit/9734bb4382db1123b3c78ffea1130d702fb5a845">9734bb4</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/36775">#36775</a></li> <li><strong>core:</strong> add Fn::GetStackOutput for cross-region references (<a href="https://redirect.github.com/aws/aws-cdk/issues/37724">#37724</a>) (<a href="https://github.com/aws/aws-cdk/commit/ffae8613d0f2dbb94ff7a2ea1e6cd53036bd9870">ffae861</a>)</li> <li><strong>core:</strong> integrate construct annotations into validation report (<a href="https://redirect.github.com/aws/aws-cdk/issues/37712">#37712</a>) (<a href="https://github.com/aws/aws-cdk/commit/438bd0b756603e60433c6bd9a080be7c234b1d56">438bd0b</a>)</li> <li><strong>synthetics:</strong> add Playwright 5.1 and 6.0 runtimes (<a href="https://redirect.github.com/aws/aws-cdk/issues/37665">#37665</a>) (<a href="https://github.com/aws/aws-cdk/commit/c1afb43b16db8d4eeaeb4dda413fc64637b7e014">c1afb43</a>)</li> <li>emr instance fleet priority allocation (<a href="https://redirect.github.com/aws/aws-cdk/issues/35731">#35731</a>) (<a href="https://github.com/aws/aws-cdk/commit/db1188a34b2ec4c37d6d9e5c44df65d784e9a5bf">db1188a</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/35710">#35710</a> <a href="https://github.com/aws//github.com/aws/aws-cdk/blob/3ec6d06c7c58e4f14b3fb114d7c35dc6d01794d9/packages/aws-cdk-lib/aws-stepfunctions-tasks/lib/emr/private/cluster-utils.ts/issues/L91">/github.com/aws/aws-cdk/blob/3ec6d06c7c58e4f14b3fb114d7c35dc6d01794d9/packages/aws-cdk-lib/aws-stepfunctions-tasks/lib/emr/private/cluster-utils.ts#L91</a></li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>cloudfront:</strong> skip cachePolicyName length validation for unresolved tokens (<a href="https://redirect.github.com/aws/aws-cdk/issues/37751">#37751</a>) (<a href="https://github.com/aws/aws-cdk/commit/3b96e97af91701fc17e8c3ad35a8564d57085a9d">3b96e97</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/23567">#23567</a> <a href="https://redirect.github.com/aws/aws-cdk/issues/34102">#34102</a></li> <li><strong>cloudwatch:</strong> remove false positive warning for CDK tokens in MathExpression (<a href="https://redirect.github.com/aws/aws-cdk/issues/36882">#36882</a>) (<a href="https://github.com/aws/aws-cdk/commit/c29dc17e770183ef1c83595bd6873b2fb3379d7f">c29dc17</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/34977">#34977</a></li> <li><strong>codebuild:</strong> correct S3 log encryption boolean inversion (<a href="https://redirect.github.com/aws/aws-cdk/issues/37761">#37761</a>) (<a href="https://github.com/aws/aws-cdk/commit/40319185dc645d2afc6acf1d25547a86250e97af">4031918</a>)</li> <li><strong>ecs:</strong> enabling the circuitBreaker is not recommended loudly enough (<a href="https://redirect.github.com/aws/aws-cdk/issues/37755">#37755</a>) (<a href="https://github.com/aws/aws-cdk/commit/a52af7dc4eb79fc145181602e13c864dd61a197a">a52af7d</a>)</li> <li><strong>eks:</strong> add dependency from HelmChart custom resource to s3 chartAsset IAM policy (<a href="https://redirect.github.com/aws/aws-cdk/issues/37731">#37731</a>) (<a href="https://github.com/aws/aws-cdk/commit/99d0a5ba83771e46aca9971d00af027f42078f4a">99d0a5b</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/19880">#19880</a></li> </ul> <hr /> <h2>Alpha modules (2.253.0-alpha.0)</h2> <h3>Features</h3> <ul> <li><strong>bedrock-agentcore-alpha:</strong> add OnlineEvaluationConfig and Evaluator L2 constructs (<a href="https://redirect.github.com/aws/aws-cdk/issues/37615">#37615</a>) (<a href="https://github.com/aws/aws-cdk/commit/c13de04223e32272b0c6c6dd4e2fca8e300fafa8">c13de04</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/37614">#37614</a></li> <li><strong>glue-alpha:</strong> add extraPythonFiles support to PythonShellJob (<a href="https://redirect.github.com/aws/aws-cdk/issues/37130">#37130</a>) (<a href="https://github.com/aws/aws-cdk/commit/c9c6f9c1b7c12722d18a45bf8a02c09672f8720d">c9c6f9c</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/34448">#34448</a></li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>bedrock-agentcore-alpha:</strong> self-managed memory strategy validation throws on unresolved tokens (<a href="https://redirect.github.com/aws/aws-cdk/issues/37691">#37691</a>) (<a href="https://github.com/aws/aws-cdk/commit/79565376cdb642d821625fe10ae5916e7d2e64fe">7956537</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/37197">#37197</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-cdk/blob/v2.253.1/CHANGELOG.v2.alpha.md">aws-cdk-lib's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <p>All notable changes to this project will be documented in this file. See <a href="https://github.com/conventional-changelog/standard-version">standard-version</a> for commit guidelines.</p> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.253.0-alpha.0...v2.253.1-alpha.0">2.253.1-alpha.0</a> (2026-05-08)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.252.0-alpha.0...v2.253.0-alpha.0">2.253.0-alpha.0</a> (2026-05-06)</h2> <h3>Features</h3> <ul> <li><strong>bedrock-agentcore-alpha:</strong> add OnlineEvaluationConfig and Evaluator L2 constructs (<a href="https://redirect.github.com/aws/aws-cdk/issues/37615">#37615</a>) (<a href="https://github.com/aws/aws-cdk/commit/c13de04223e32272b0c6c6dd4e2fca8e300fafa8">c13de04</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/37614">#37614</a></li> <li><strong>glue-alpha:</strong> add extraPythonFiles support to PythonShellJob (<a href="https://redirect.github.com/aws/aws-cdk/issues/37130">#37130</a>) (<a href="https://github.com/aws/aws-cdk/commit/c9c6f9c1b7c12722d18a45bf8a02c09672f8720d">c9c6f9c</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/34448">#34448</a></li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>bedrock-agentcore-alpha:</strong> self-managed memory strategy validation throws on unresolved tokens (<a href="https://redirect.github.com/aws/aws-cdk/issues/37691">#37691</a>) (<a href="https://github.com/aws/aws-cdk/commit/79565376cdb642d821625fe10ae5916e7d2e64fe">7956537</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/37197">#37197</a></li> </ul> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.251.0-alpha.0...v2.252.0-alpha.0">2.252.0-alpha.0</a> (2026-04-29)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.250.0-alpha.0...v2.251.0-alpha.0">2.251.0-alpha.0</a> (2026-04-24)</h2> <h3>Features</h3> <ul> <li><strong>bedrock-agentcore-alpha:</strong> add L2 constructs for policy and policy engine (<a href="https://redirect.github.com/aws/aws-cdk/issues/37238">#37238</a>) (<a href="https://github.com/aws/aws-cdk/commit/1e89e7e921a9946cb9c23f967c6b7a33a6048de4">1e89e7e</a>)</li> <li><strong>bedrock-agentcore-alpha:</strong> add observability configuration for Runtime (<a href="https://redirect.github.com/aws/aws-cdk/issues/36689">#36689</a>) (<a href="https://github.com/aws/aws-cdk/commit/34b43aabe2c3a946ba286812b402ce946222d820">34b43aa</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/36596">#36596</a></li> <li><strong>bedrock-agentcore-alpha:</strong> support No Authorization for AgentCore Gateway (<a href="https://redirect.github.com/aws/aws-cdk/issues/36610">#36610</a>) (<a href="https://github.com/aws/aws-cdk/commit/f20bd8e43700877f7166cdac3cd994876963bc67">f20bd8e</a>)</li> <li><strong>dsql-alpha:</strong> initial L2 construct (<a href="https://redirect.github.com/aws/aws-cdk/issues/34599">#34599</a>) (<a href="https://github.com/aws/aws-cdk/commit/be1a45861a5138b6e397cf076e39dfe0a18d4e99">be1a458</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/34593">#34593</a></li> </ul> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.249.0-alpha.0...v2.250.0-alpha.0">2.250.0-alpha.0</a> (2026-04-14)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.248.0-alpha.0...v2.249.0-alpha.0">2.249.0-alpha.0</a> (2026-04-10)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.247.0-alpha.0...v2.248.0-alpha.0">2.248.0-alpha.0</a> (2026-04-02)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.246.0-alpha.0...v2.247.0-alpha.0">2.247.0-alpha.0</a> (2026-04-02)</h2> <h3>Features</h3> <ul> <li><strong>mediapackagev2-alpha:</strong> new L2 construct (<a href="https://redirect.github.com/aws/aws-cdk/issues/37279">#37279</a>) (<a href="https://github.com/aws/aws-cdk/commit/7debfb9c5e807fac5df6e9e0ea3097d72325ffbc">7debfb9</a>)</li> </ul> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.245.0-alpha.0...v2.246.0-alpha.0">2.246.0-alpha.0</a> (2026-03-31)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.244.0-alpha.0...v2.245.0-alpha.0">2.245.0-alpha.0</a> (2026-03-27)</h2> <h3>Features</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-cdk/commit/b0c00e2b1fde5da462d4fd848610f59e78b482ba"><code>b0c00e2</code></a> fix(core): &quot;exports cannot be updated&quot; for cross-region references (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/37790">#37790</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/f61656a3a408b0b50d79f43cdf18d0f5801e9a43"><code>f61656a</code></a> fix(s3deploy): empty sources leads to deployment error (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/37786">#37786</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/55a42993ee9c2af4094979e2bfcc4dd0bb723cf2"><code>55a4299</code></a> chore: update analytics metadata blueprints</li> <li><a href="https://github.com/aws/aws-cdk/commit/e9c0b5ae64f1b7aefaa2f04a3fb3af534bc86891"><code>e9c0b5a</code></a> chore(release): 2.253.0</li> <li><a href="https://github.com/aws/aws-cdk/commit/a52af7dc4eb79fc145181602e13c864dd61a197a"><code>a52af7d</code></a> fix(ecs): enabling the circuitBreaker is not recommended loudly enough (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/37755">#37755</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/a661c2ddee343a610b0ab312996ce34e6cacb571"><code>a661c2d</code></a> feat: update L1 CloudFormation resource definitions (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/37753">#37753</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/c29dc17e770183ef1c83595bd6873b2fb3379d7f"><code>c29dc17</code></a> fix(cloudwatch): remove false positive warning for CDK tokens in MathExpressi...</li> <li><a href="https://github.com/aws/aws-cdk/commit/dedf99bc9c6a3bc27a8f2d37d3c8a41302a28549"><code>dedf99b</code></a> chore: replace <code>Lazy</code> with <code>IBox</code> (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/37739">#37739</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/40319185dc645d2afc6acf1d25547a86250e97af"><code>4031918</code></a> fix(codebuild): correct S3 log encryption boolean inversion (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/37761">#37761</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/99d0a5ba83771e46aca9971d00af027f42078f4a"><code>99d0a5b</code></a> fix(eks): add dependency from HelmChart custom resource to s3 chartAsset IAM ...</li> <li>Additional commits viewable in <a href="https://github.com/aws/aws-cdk/commits/v2.253.1/packages/aws-cdk-lib">compare view</a></li> </ul> </details> <br /> Updates `@aws-sdk/client-dynamodb` from 3.1041.0 to 3.1045.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@​aws-sdk/client-dynamodb's releases</a>.</em></p> <blockquote> <h2>v3.1045.0</h2> <h4>3.1045.0(2026-05-07)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-guardduty:</strong> This is a documentation update (<a href="https://github.com/aws/aws-sdk-js-v3/commit/1484574cd28136e104e4364499a02f0435d274af">1484574c</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>clients:</strong> update client endpoints as of 2026-05-07 (<a href="https://github.com/aws/aws-sdk-js-v3/commit/81310767bd884df988d524faf7d1f131f15c6197">81310767</a>)</li> <li><strong>client-bcm-data-exports:</strong> With this release, customers can configure their data exports to generate additional integration artifacts for Athena and Redshift. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/238da2c16c5885ef9051c2798c0bec4a5c10fa9f">238da2c1</a>)</li> <li><strong>client-invoicing:</strong> Updated ListInvoiceSummaries API to add new ReceiverRole filter in Request and Response (<a href="https://github.com/aws/aws-sdk-js-v3/commit/60a448cbfb17643b0b93c0bf72848b404dc31a83">60a448cb</a>)</li> <li><strong>client-bedrock-agentcore:</strong> Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). (<a href="https://github.com/aws/aws-sdk-js-v3/commit/1e1031a7c070e56c2c781df05af75baf543e65ca">1e1031a7</a>)</li> <li><strong>client-ec2:</strong> DescribeInstanceTypes now accepts an IncludeUnsupportedInRegion parameter. When set, the response also lists instance types that are not available in the current Region. Each instance type includes a SupportedInRegion field indicating its regional availability. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/7026243303994e24be2996bf169b6acd50d5b081">70262433</a>)</li> <li><strong>client-bedrock-agentcore-control:</strong> Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). (<a href="https://github.com/aws/aws-sdk-js-v3/commit/fe5861ae18b0b71616398dcbb54936a919af1d8f">fe5861ae</a>)</li> <li><strong>client-route53resolver:</strong> Adds supports for DNS64 on inbound endpoints and IPv6 forwarding through the internet gateway (IGW) on outbound endpoints, making it easier to manage hybrid DNS across IPv4 and IPv6 networks. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/8e6e18c603f2392b7b61d5f2efdfc54dab0d8126">8e6e18c6</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1045.0.zip</strong></p> <h2>v3.1044.0</h2> <h4>3.1044.0(2026-05-06)</h4> <h5>New Features</h5> <ul> <li><strong>client-securityhub:</strong> Release GenerateRecommendedPolicyV2 and GetRecommendedPolicyV2 APIs. This supports generating and retrieving policy recommendations to remediate unused permissions findings that are now being supported on Security Hub. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/772b8629c270edee6fb4bb6874bb4036102d0f60">772b8629</a>)</li> <li><strong>client-sagemaker:</strong> Amazon SageMaker HyperPod now returns ImageVersionStatus in DescribeCluster, DescribeClusterNode, and ListClusterNodes responses, indicating whether cluster instances are running the latest available image version. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2be7e6b4b07f9732823fbb6b9b6e0c78b640e44f">2be7e6b4</a>)</li> <li><strong>client-glue:</strong> Adds support for a CustomLogGroupPrefix parameter in StartDataQualityRulesetEvaluationRun to specify custom CloudWatch log group paths, and a RulesetName filter in ListDataQualityRulesetEvaluationRuns to filter evaluation runs by ruleset name. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b95d850bd64dae6c73588e9035803b9924781a4d">b95d850b</a>)</li> <li><strong>client-lex-models-v2:</strong> Amazon Lex V2 introduces audio filler support for speech-to-speech bots. Configure melody or typing sounds that play during backend processing to reduce perceived latency and maintain a natural conversational experience for callers. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/01426f8e5c9073cdf81e7bd2a6d816156bd81249">01426f8e</a>)</li> <li><strong>client-bedrock-agentcore-control:</strong> Adds support for bring-your-own file system in AgentCore Runtime. Developers can mount Amazon S3 Files and Amazon EFS access points directly into agent sessions using filesystemConfigurations. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/e20f24d92f340e25371fa4b00e1321b627211b98">e20f24d9</a>)</li> <li><strong>client-s3:</strong> Validate outpost access point resource name (<a href="https://github.com/aws/aws-sdk-js-v3/commit/bee88a56c5d1e8ffe9b2953117d81f4fc221ac68">bee88a56</a>)</li> <li><strong>client-mwaa:</strong> Amazon MWAA now supports a PublicAndPrivate webserver access mode. The Airflow web server is accessible over both public and private endpoints, enabling workers in VPCs without internet access to reach the Task API privately while retaining public access to the Airflow UI. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/3a6054ef54e1f8afbc167fa27761c1cd36dffa5e">3a6054ef</a>)</li> <li><strong>client-imagebuilder:</strong> The ImportDiskImage API now enforces a maximum character limit of 128 characters on the image name field. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/7fc2565c6b8b25d3257729b962125cffe00e5c42">7fc2565c</a>)</li> </ul> <h5>Tests</h5> <ul> <li><strong>scripts:</strong> include type symbols in api snapshot test (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7985">#7985</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/02f86176e779ecd6f7e9802b92fc15080803973b">02f86176</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1044.0.zip</strong></p> <h2>v3.1043.0</h2> <h4>3.1043.0(2026-05-05)</h4> <h5>New Features</h5> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md">@​aws-sdk/client-dynamodb's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1044.0...v3.1045.0">3.1045.0</a> (2026-05-07)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1043.0...v3.1044.0">3.1044.0</a> (2026-05-06)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1042.0...v3.1043.0">3.1043.0</a> (2026-05-05)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1041.0...v3.1042.0">3.1042.0</a> (2026-05-04)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/b329def5fdfa4fc2f311a66553d6b3782f78d4ce"><code>b329def</code></a> Publish v3.1045.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/1ccd438a189e58745a6f25f5dec7ecd83120f7a8"><code>1ccd438</code></a> Publish v3.1044.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/96baad9d69cbc4157632d8e76753d19e5a13cd04"><code>96baad9</code></a> Publish v3.1043.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/d942e31ae5787bc4f46e2fbe17b3e4116708097b"><code>d942e31</code></a> Publish v3.1042.0</li> <li>See full diff in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1045.0/clients/client-dynamodb">compare view</a></li> </ul> </details> <br /> Updates `@aws-sdk/lib-dynamodb` from 3.1041.0 to 3.1045.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@​aws-sdk/lib-dynamodb's releases</a>.</em></p> <blockquote> <h2>v3.1045.0</h2> <h4>3.1045.0(2026-05-07)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-guardduty:</strong> This is a documentation update (<a href="https://github.com/aws/aws-sdk-js-v3/commit/1484574cd28136e104e4364499a02f0435d274af">1484574c</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>clients:</strong> update client endpoints as of 2026-05-07 (<a href="https://github.com/aws/aws-sdk-js-v3/commit/81310767bd884df988d524faf7d1f131f15c6197">81310767</a>)</li> <li><strong>client-bcm-data-exports:</strong> With this release, customers can configure their data exports to generate additional integration artifacts for Athena and Redshift. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/238da2c16c5885ef9051c2798c0bec4a5c10fa9f">238da2c1</a>)</li> <li><strong>client-invoicing:</strong> Updated ListInvoiceSummaries API to add new ReceiverRole filter in Request and Response (<a href="https://github.com/aws/aws-sdk-js-v3/commit/60a448cbfb17643b0b93c0bf72848b404dc31a83">60a448cb</a>)</li> <li><strong>client-bedrock-agentcore:</strong> Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). (<a href="https://github.com/aws/aws-sdk-js-v3/commit/1e1031a7c070e56c2c781df05af75baf543e65ca">1e1031a7</a>)</li> <li><strong>client-ec2:</strong> DescribeInstanceTypes now accepts an IncludeUnsupportedInRegion parameter. When set, the response also lists instance types that are not available in the current Region. Each instance type includes a SupportedInRegion field indicating its regional availability. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/7026243303994e24be2996bf169b6acd50d5b081">70262433</a>)</li> <li><strong>client-bedrock-agentcore-control:</strong> Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). (<a href="https://github.com/aws/aws-sdk-js-v3/commit/fe5861ae18b0b71616398dcbb54936a919af1d8f">fe5861ae</a>)</li> <li><strong>client-route53resolver:</strong> Adds supports for DNS64 on inbound endpoints and IPv6 forwarding through the internet gateway (IGW) on outbound endpoints, making it easier to manage hybrid DNS across IPv4 and IPv6 networks. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/8e6e18c603f2392b7b61d5f2efdfc54dab0d8126">8e6e18c6</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1045.0.zip</strong></p> <h2>v3.1044.0</h2> <h4>3.1044.0(2026-05-06)</h4> <h5>New Features</h5> <ul> <li><strong>client-securityhub:</strong> Release GenerateRecommendedPolicyV2 and GetRecommendedPolicyV2 APIs. This supports generating and retrieving policy recommendations to remediate unused permissions findings that are now being supported on Security Hub. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/772b8629c270edee6fb4bb6874bb4036102d0f60">772b8629</a>)</li> <li><strong>client-sagemaker:</strong> Amazon SageMaker HyperPod now returns ImageVersionStatus in DescribeCluster, DescribeClusterNode, and ListClusterNodes responses, indicating whether cluster instances are running the latest available image version. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2be7e6b4b07f9732823fbb6b9b6e0c78b640e44f">2be7e6b4</a>)</li> <li><strong>client-glue:</strong> Adds support for a CustomLogGroupPrefix parameter in StartDataQualityRulesetEvaluationRun to specify custom CloudWatch log group paths, and a RulesetName filter in ListDataQualityRulesetEvaluationRuns to filter evaluation runs by ruleset name. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b95d850bd64dae6c73588e9035803b9924781a4d">b95d850b</a>)</li> <li><strong>client-lex-models-v2:</strong> Amazon Lex V2 introduces audio filler support for speech-to-speech bots. Configure melody or typing sounds that play during backend processing to reduce perceived latency and maintain a natural conversational experience for callers. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/01426f8e5c9073cdf81e7bd2a6d816156bd81249">01426f8e</a>)</li> <li><strong>client-bedrock-agentcore-control:</strong> Adds support for bring-your-own file system in AgentCore Runtime. Developers can mount Amazon S3 Files and Amazon EFS access points directly into agent sessions using filesystemConfigurations. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/e20f24d92f340e25371fa4b00e1321b627211b98">e20f24d9</a>)</li> <li><strong>client-s3:</strong> Validate outpost access point resource name (<a href="https://github.com/aws/aws-sdk-js-v3/commit/bee88a56c5d1e8ffe9b2953117d81f4fc221ac68">bee88a56</a>)</li> <li><strong>client-mwaa:</strong> Amazon MWAA now supports a PublicAndPrivate webserver access mode. The Airflow web server is accessible over both public and private endpoints, enabling workers in VPCs without internet access to reach the Task API privately while retaining public access to the Airflow UI. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/3a6054ef54e1f8afbc167fa27761c1cd36dffa5e">3a6054ef</a>)</li> <li><strong>client-imagebuilder:</strong> The ImportDiskImage API now enforces a maximum character limit of 128 characters on the image name field. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/7fc2565c6b8b25d3257729b962125cffe00e5c42">7fc2565c</a>)</li> </ul> <h5>Tests</h5> <ul> <li><strong>scripts:</strong> include type symbols in api snapshot test (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7985">#7985</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/02f86176e779ecd6f7e9802b92fc15080803973b">02f86176</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1044.0.zip</strong></p> <h2>v3.1043.0</h2> <h4>3.1043.0(2026-05-05)</h4> <h5>New Features</h5> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md">@​aws-sdk/lib-dynamodb's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1044.0...v3.1045.0">3.1045.0</a> (2026-05-07)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1043.0...v3.1044.0">3.1044.0</a> (2026-05-06)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1042.0...v3.1043.0">3.1043.0</a> (2026-05-05)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1041.0...v3.1042.0">3.1042.0</a> (2026-05-04)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/b329def5fdfa4fc2f311a66553d6b3782f78d4ce"><code>b329def</code></a> Publish v3.1045.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/1ccd438a189e58745a6f25f5dec7ecd83120f7a8"><code>1ccd438</code></a> Publish v3.1044.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/96baad9d69cbc4157632d8e76753d19e5a13cd04"><code>96baad9</code></a> Publish v3.1043.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/d942e31ae5787bc4f46e2fbe17b3e4116708097b"><code>d942e31</code></a> Publish v3.1042.0</li> <li>See full diff in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1045.0/lib/lib-dynamodb">compare view</a></li> </ul> </details> <br /> Updates `aws-cdk` from 2.1120.0 to 2.1121.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-cdk-cli/releases">aws-cdk's releases</a>.</em></p> <blockquote> <h2>aws-cdk@v2.1121.0</h2> <h2><a href="https://github.com/aws/aws-cdk-cli/compare/aws-cdk@v2.1120.0...aws-cdk@v2.1121.0">2.1121.0</a> (2026-05-06)</h2> <h3>Features</h3> <ul> <li><strong>deps:</strong> upgrade aws-cdk-lib (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1465">#1465</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/9f872c940d23e9c27a99be36a955a56f58e1bf72">9f872c9</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>update version includes a spurious newline (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1477">#1477</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/1f09294dd203c1ce6523cffb6080fffccb6af061">1f09294</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-cdk-cli/commit/7abdd4e80bd28692b01461de60e1d864c055fb19"><code>7abdd4e</code></a> chore(deps): bump ip-address from 10.1.0 to 10.2.0 (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1479">#1479</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/ab82d616ac683162f6354ac7d467bafd2c743ecb"><code>ab82d61</code></a> chore(deps): bump <code>@​aws-sdk/client-ssm</code> from 3.1036.0 to 3.1037.0 (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1470">#1470</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/1f09294dd203c1ce6523cffb6080fffccb6af061"><code>1f09294</code></a> fix: update version includes a spurious newline (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1477">#1477</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/63db54159472f8cce0edf07da4d45910c7b9e809"><code>63db541</code></a> chore(deps): bump <code>@​aws-sdk/client-ecr</code> from 3.1036.0 to 3.1037.0 (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1473">#1473</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/04c27f2bca0d6492ffdd8c8657f011b10b1f58af"><code>04c27f2</code></a> chore(deps): bump <code>@​aws-sdk/client-appsync</code> from 3.1036.0 to 3.1037.0 (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1471">#1471</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/68540cc6d438c8965484520bc26937b592c0aa29"><code>68540cc</code></a> chore(deps): bump <code>@​aws-sdk/client-cloudformation</code> from 3.1036.0 to 3.1037.0 (#...</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/158daf335bc83548326fcf9049e8e46ecd94be98"><code>158daf3</code></a> chore(deps): bump <code>@​aws-sdk/client-kms</code> from 3.1036.0 to 3.1037.0 (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1469">#1469</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/0f86332fdbd9013296a5d8d3ed68c28f9af1eb75"><code>0f86332</code></a> chore(deps): upgrade dependencies (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1468">#1468</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/09b7f15b19d608c46c4970ea2990aa1297ee2481"><code>09b7f15</code></a> chore: Remove package-lock.json from template.gitignore (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1466">#1466</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/9f872c940d23e9c27a99be36a955a56f58e1bf72"><code>9f872c9</code></a> feat(deps): upgrade aws-cdk-lib (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1465">#1465</a>)</li> <li>See full diff in <a href="https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1121.0/packages/aws-cdk">compare view</a></li> </ul> </details> <br /> Updates `esbuild` from 0.25.12 to 0.28.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/evanw/esbuild/releases">esbuild's releases</a>.</em></p> <blockquote> <h2>v0.28.0</h2> <ul> <li> <p>Add support for <code>with { type: 'text' }</code> imports (<a href="https://redirect.github.com/evanw/esbuild/issues/4435">#4435</a>)</p> <p>The <a href="https://github.com/tc39/proposal-import-text">import text</a> proposal has reached stage 3 in the TC39 process, which means that it's recommended for implementation. It has also already been implemented by <a href="https://docs.deno.com/examples/importing_text/">Deno</a> and <a href="https://bun.com/docs/guides/runtime/import-html">Bun</a>. So with this release, esbuild also adds support for it. This behaves exactly the same as esbuild's existing <a href="https://esbuild.github.io/content-types/#text"><code>text</code> loader</a>. Here's an example:</p> <pre lang="js"><code>import string from './example.txt' with { type: 'text' } console.log(string) </code></pre> </li> <li> <p>Add integrity checks to fallback download path (<a href="https://redirect.github.com/evanw/esbuild/issues/4343">#4343</a>)</p> <p>Installing esbuild via npm is somewhat complicated with several different edge cases (see <a href="https://esbuild.github.io/getting-started/#additional-npm-flags">esbuild's documentation</a> for details). If the regular installation of esbuild's platform-specific package fails, esbuild's install script attempts to download the platform-specific package itself (first with the <code>npm</code> command, and then with a HTTP request to <code>registry.npmjs.org</code> as a last resort).</p> <p>This last resort path previously didn't have any integrity checks. With this release, esbuild will now verify that the hash of the downloaded binary matches the expected hash for the current release. This means the hashes for all of esbuild's platform-specific binary packages will now be embedded in the top-level <code>esbuild</code> package. Hopefully this should work without any problems. But just in case, this change is being done as a breaking change release.</p> </li> <li> <p>Update the Go compiler from 1.25.7 to 1.26.1</p> <p>This upgrade should not affect anything. However, there have been some significant internal changes to the Go compiler, so esbuild could potentially behave differently in certain edge cases:</p> <ul> <li>It now uses the <a href="https://go.dev/doc/go1.26#new-garbage-collector">new garbage collector</a> that comes with Go 1.26.</li> <li>The Go compiler is now more aggressive with allocating memory on the stack.</li> <li>The executable format that the Go linker uses has undergone several changes.</li> <li>The WebAssembly build now unconditionally makes use of the sign extension and non-trapping floating-point to integer conversion instructions.</li> </ul> <p>You can read the <a href="https://go.dev/doc/go1.26">Go 1.26 release notes</a> for more information.</p> </li> </ul> <h2>v0.27.7</h2> <ul> <li> <p>Fix lowering of define semantics for TypeScript parameter properties (<a href="https://redirect.github.com/evanw/esbuild/issues/4421">#4421</a>)</p> <p>The previous release incorrectly generated class fields for TypeScript parameter properties even when the configured target environment does not support class fields. With this release, the generated class fields will now be correctly lowered in this case:</p> <pre lang="ts"><code>// Original code class Foo { constructor(public x = 1) {} y = 2 } <p>// Old output (with --loader=ts --target=es2021)<br /> class Foo {<br /> constructor(x = 1) {<br /> this.x = x;<br /> __publicField(this, &quot;y&quot;, 2);<br /> }<br /> x;<br /> }</p> <p>// New output (with --loader=ts --target=es2021)<br /> class Foo {<br /> </code></pre></p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md">esbuild's changelog</a>.</em></p> <blockquote> <h1>Changelog: 2025</h1> <p>This changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).</p> <h2>0.27.2</h2> <ul> <li> <p>Allow import path specifiers starting with <code>#/</code> (<a href="https://redirect.github.com/evanw/esbuild/pull/4361">#4361</a>)</p> <p>Previously the specification for <code>package.json</code> disallowed import path specifiers starting with <code>#/</code>, but this restriction <a href="https://redirect.github.com/nodejs/node/pull/60864">has recently been relaxed</a> and support for it is being added across the JavaScript ecosystem. One use case is using it for a wildcard pattern such as mapping <code>#/*</code> to <code>./src/*</code> (previously you had to use another character such as <code>#_*</code> instead, which was more confusing). There is some more context in <a href="https://redirect.github.com/nodejs/node/issues/49182">nodejs/node#49182</a>.</p> <p>This change was contributed by <a href="https://github.com/hybrist"><code>@​hybrist</code></a>.</p> </li> <li> <p>Automatically add the <code>-webkit-mask</code> prefix (<a href="https://redirect.github.com/evanw/esbuild/issues/4357">#4357</a>, <a href="https://redirect.github.com/evanw/esbuild/issues/4358">#4358</a>)</p> <p>This release automatically adds the <code>-webkit-</code> vendor prefix for the <a href="https://developer.mozilla.org/en-US/docs/Web/CSS/Reference/Properties/mask"><code>mask</code></a> CSS shorthand property:</p> <pre lang="css"><code>/* Original code */ main { mask: url(x.png) center/5rem no-repeat } <p>/* Old output (with --target=chrome110) */<br /> main {<br /> mask: url(x.png) center/5rem no-repeat;<br /> }</p> <p>/* New output (with --target=chrome110) */<br /> main {<br /> -webkit-mask: url(x.png) center/5rem no-repeat;<br /> mask: url(x.png) center/5rem no-repeat;<br /> }<br /> </code></pre></p> <p>This change was contributed by <a href="https://github.com/BPJEnnova"><code>@​BPJEnnova</code></a>.</p> </li> <li> <p>Additional minification of <code>switch</code> statements (<a href="https://redirect.github.com/evanw/esbuild/issues/4176">#4176</a>, <a href="https://redirect.github.com/evanw/esbuild/issues/4359">#4359</a>)</p> <p>This release contains additional minification patterns for reducing <code>switch</code> statements. Here is an example:</p> <pre lang="js"><code>// Original code switch (x) { case 0: foo() break case 1: default: bar() } </code></pre> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/evanw/esbuild/commit/6a794dff68e6a43539f6da671e3080efdf11ca70"><code>6a794df</code></a> publish 0.28.0 to npm</li> <li><a href="https://github.com/evanw/esbuild/commit/64ee0ea63b2ff303caafc9610c388dc72c882c23"><code>64ee0ea</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4435">#4435</a>: support <code>with { type: text }</code> imports</li> <li><a href="https://github.com/evanw/esbuild/commit/ef65aeeaacdb71eade186f888975b1de89574314"><code>ef65aee</code></a> fix sort order in <code>snapshots_packagejson.txt</code></li> <li><a href="https://github.com/evanw/esbuild/commit/1a26a8ecbc39aaf1379c524a0274a08fbcbed655"><code>1a26a8e</code></a> try to fix <code>test-old-ts</code>, also shuffle CI tasks</li> <li><a href="https://github.com/evanw/esbuild/commit/556ce6c1fc00d7c0917fbfada01ed8e5251bc510"><code>556ce6c</code></a> use <code>''</code> instead of <code>null</code> to omit build hashes</li> <li><a href="https://github.com/evanw/esbuild/commit/8e675a81a473ea69a46a69792f1386bb110dd877"><code>8e675a8</code></a> ci: allow missing binary hashes for tests</li> <li><a href="https://github.com/evanw/esbuild/commit/7067763b904fe8a522fa840a4a48c5fbd4c395e0"><code>7067763</code></a> Reapply &quot;update go 1.25.7 =&gt; 1.26.1&quot;</li> <li><a href="https://github.com/evanw/esbuild/commit/39473a952ab3b450d0578b698a8b8d2a02332e0d"><code>39473a9</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4343">#4343</a>: integrity check for binary download</li> <li><a href="https://github.com/evanw/esbuild/commit/2025c9ff6ab15ba6b0f9d074fd732250cc46e4a3"><code>2025c9f</code></a> publish 0.27.7 to npm</li> <li><a href="https://github.com/evanw/esbuild/commit/c6b586e4904f47e8d5f783a2813660c13e2672e7"><code>c6b586e</code></a> fix typo in <code>Makefile</code> for <code>@esbuild/win32-x64</code></li> <li>Additional commits viewable in <a href="https://github.com/evanw/esbuild/compare/v0.25.12...v0.28.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for esbuild since your current version.</p> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details>
claude[bot] commented 2026-05-08 22:27:25 +00:00 (Migrated from github.com)

Reviewed — looks good. Lockfile-only Dependabot bump for AWS SDK/CDK patch versions and esbuild. Worth noting esbuild jumps from 0.25 → 0.28 (two minor versions on a 0.x package, where minor bumps can carry breaking changes), but it's dev-only tooling consumed via CDK NodejsFunction bundling, so any bundling regression would surface immediately at cdk synth/deploy time. No Sea Haven convention or security concerns.

Reviewed — looks good. Lockfile-only Dependabot bump for AWS SDK/CDK patch versions and esbuild. Worth noting esbuild jumps from 0.25 → 0.28 (two minor versions on a 0.x package, where minor bumps can carry breaking changes), but it's dev-only tooling consumed via CDK `NodejsFunction` bundling, so any bundling regression would surface immediately at `cdk synth`/deploy time. No Sea Haven convention or security concerns.
This repo is archived. You cannot comment on pull requests.
No description provided.