build(deps): bump the minor-and-patch group with 5 updates #70

Closed
dependabot[bot] wants to merge 1 commit from dependabot/npm_and_yarn/minor-and-patch-7ee6a8d88b into main
dependabot[bot] commented 2026-06-30 07:35:04 +00:00 (Migrated from github.com)

Bumps the minor-and-patch group with 5 updates:

Package From To
aws-cdk-lib 2.258.1 2.260.0
@aws-sdk/client-dynamodb 3.1066.0 3.1076.0
@aws-sdk/lib-dynamodb 3.1066.0 3.1076.0
aws-cdk 2.1126.0 2.1128.1
esbuild 0.28.0 0.28.1

Updates aws-cdk-lib from 2.258.1 to 2.260.0

Release notes

Sourced from aws-cdk-lib's releases.

v2.260.0

Features

Bug Fixes

  • bundling: docker build can be skipped if already performed (#38134) (2f9ae95)
  • core: stack traces contain decorator paths (#38130) (318f645)
  • core: weak cross-stack references fail for list attributes (#37948) (6bb9d75), closes #37910
  • lambda-nodejs: reuse posixShellEscape for Docker bundling file operations (#38133) (baa9e1d)

Alpha modules (2.260.0-alpha.0)

v2.259.0

⚠ BREAKING CHANGES

  • lambda: Runtime.NODEJS_LATEST now resolves to nodejs24.x in every region. Customers who pin to a concrete runtime (Runtime.NODEJS_22_X, useLatestRuntimeVersion: false in aws-lambda-nodejs.NodejsFunction) are unaffected. Existing AWS::Lambda::Function resources synthesized with NODEJS_LATEST will see Runtime: nodejs22.x → Runtime: nodejs24.x on next deploy. Lambda accepts runtime updates in place.

    Customer-code compatibility — IMPORTANT: Node.js 24 removes support for callback-style asynchronous handlers ((event, context, callback) => {...}) per the launch blog. Customers whose Lambda code still uses callback-based handlers will see runtime errors after the bump. Customers should migrate to async (event, context) => {...} or pin to Runtime.NODEJS_22_X explicitly.

Features

  • core: recommend the use of weak references if no choice has been made (#38070) (6e74e5e)
  • ecs: add forceNewDeployment option for Fargate and EC2 services (#36797) (3d9c4df), closes #27762
  • eks: use the recommended AL2023 instead of AL2 AMI type (under feature flag) (#37850) (6a2dcb7), closes #32211
  • lambda: upgrade lambda and custom resource default runtime to nodejs24.x (#38031) (36c84c6)

Bug Fixes

Reverts


Alpha modules (2.259.0-alpha.0)

Changelog

Sourced from aws-cdk-lib's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

2.260.0-alpha.0 (2026-06-16)

2.259.0-alpha.0 (2026-06-11)

2.258.1-alpha.0 (2026-06-08)

2.258.0-alpha.0 (2026-06-04)

Features

  • integ-tests-alpha: add option to set the provider log level (#38005) (c634a79)

Bug Fixes

  • custom-resource-handlers: deterministic asset hashes for generated lambdas (#37634) (6c3d5bc), closes #34307
  • glue-alpha: deprecate Ray Jobs (#38055) (3fa428b)
  • glue-alpha: restore notifyDelayAfter to PySpark and Scala Spark ETL jobs (#37815) (05be88a), closes #33839
  • integ-tests-alpha: assertion failures print too much unnecessary information (#37974) (bc0de1d)
  • mediapackagev2-alpha: cdnAuth on OriginEndpoint now generates the required policy (#38013) (1d56b46)

2.257.0-alpha.0 (2026-05-21)

2.256.1-alpha.0 (2026-05-20)

2.256.0-alpha.0 (2026-05-19)

2.255.0-alpha.0 (2026-05-18)

Features

  • bedrock-agentcore-alpha: Graduation of the library to stable. The Policy submodule is the only submodule that remains in alpha. All other constructs have graduated to stable in aws-cdk-lib/aws-bedrockagentcore and we recommend migrating to the stable versions (#37876) (00cf601)

2.254.0-alpha.0 (2026-05-13)

Features

  • bedrock-agentcore-alpha: add tags support to Evaluator and OnlineEvaluationConfig (#37804) (adbf88f)
  • bedrock-agentcore-alpha: add identity L2 constructs (#37610) (67c3af2)
  • mediapackagev2-alpha: add OAC integration between CloudFront and MediaPackageV2 (#37701) (654f59c)

Bug Fixes

... (truncated)

Commits
  • f266a47 feat: update L1 CloudFormation resource definitions (#38151)
  • 318f645 fix(core): stack traces contain decorator paths (#38130)
  • 2f9ae95 fix(bundling): docker build can be skipped if already performed (#38134)
  • aeafa63 docs(pipelines): clarify format of DockerHub creds (#38132)
  • baa9e1d fix(lambda-nodejs): reuse posixShellEscape for Docker bundling file operation...
  • e360dd9 feat(core): add external traces to ConstructError (#38131)
  • 5619d43 Merge branch 'main' into merge-back/2.259.0
  • 6bb9d75 fix(core): weak cross-stack references fail for list attributes (#37948)
  • c77a08c feat(core): append external stack traces to metadata if available (#38124)
  • 772eeba chore: update analytics metadata blueprints
  • Additional commits viewable in compare view

Updates @aws-sdk/client-dynamodb from 3.1066.0 to 3.1076.0

Release notes

Sourced from @​aws-sdk/client-dynamodb's releases.

v3.1076.0

3.1076.0(2026-06-29)

Chores
  • codegen:
    • sync for checksum impls, hostLabel validation (#8127) (aa94fa04)
    • sync for CBOR serde performance and retry fixes (#8125) (b6d6a759)
  • scripts: drop bundler support in dist-cjs (use dist-es instead) (#8124) (775bc034)
Documentation Changes
  • client-elasticache: Updated documentation for the ApplyImmediately parameter in ModifyCacheCluster and ModifyReplicationGroup to clarify modification behavior. (e9e0072f)
  • client-rds-data: Updated documentation to remove Aurora Serverless V1 references. (c5f50784)
New Features
  • client-glue: Added the UpdateAsset operation to set the business name and description for an existing AWS Glue Data Catalog asset. (fe604af0)
  • client-appconfig: AWS AppConfig introduces Experimentation tools - enhanced capabilities within AWS AppConfig that enable you to run AB tests, multivariate tests, and gradual feature rollouts across your application stack. (2b8591de)
  • client-resource-explorer-2: Added CFN resource type fields for Search and ListSupportedResourceTypes responses. Added SLRec field for ServiceView (a3773832)
  • client-vpc-lattice: Amazon VPC Lattice now supports mutable idle timeout configuration on VPC Lattice Services (217aaea5)
  • client-sagemaker-featurestore-runtime: Add support for ListRecords and BatchWriteRecord APIs to Feature Store. (7a6ffe5e)
  • client-connecthealth: Expand input validation to support Unicode characters and markdown table syntax. (a20832a3)
  • client-cloudwatch: This release adds the API (PutLogAlarm) to manage a new CloudWatch resource, Log Based Alarms. Log Based Alarms allows customers to alarm directly on CloudWatch Logs query results. (14f023ba)
  • client-imagebuilder: Adds support for AMI watermarks in Image Builder. (17e643a9)
  • client-evs: Amazon EVS introduces a VMware Cloud Foundation (VCF) self-deployed mode, along with new connectors to VCF components such as the Operations and SDDC managers to monitor coverage and usage. (2ae38fea)
  • client-pcs: Add support for in-place Slurm version upgrades on existing clusters by accepting scheduler.version in UpdateCluster. (16469f6b)
  • client-lambda: Lambda now supports self-managed S3 buckets for Lambda code storage giving you the option for Lambda to reference a copy of your source code from your own S3 buckets. This allows you to maintain a single copy of your source code and manage your own code storage limits. (0268f939)
  • client-connectcampaignsv2: Adding new attributes to PutProfileOutboundRequest API that will create an outbound request call for the customer's Web Notification outbound campaign. (05f467f7)
  • client-wafv2: AWS WAF added support for associating AWS WAF web ACLs with Amazon Bedrock AgentCore Gateway resources. You can now use AssociateWebACL, DisassociateWebACL, GetWebACLForResource, and ListResourcesForWebACL to protect your AgentCore Gateways with AWS WAF. (54ea3212)
  • client-ecs: Amazon ECS now supports customizable deployment circuit breaker configurations. Customers can now define the failure threshold or control the failure counting mechanism. (ff85bd33)
  • client-ec2: Adds support for the precision time strategy and a parentGroupId parameter on CreatePlacementGroup and DescribePlacementGroups. Precision time placement groups and cluster placement groups with a parent precision time placement group ensure instances launch on precision time capable hardware. (3482937a)
  • client-pinpoint-sms-voice-v2: This launch is an expansion of our Q1 RCS for business launch where we will release an API that supports rich media and interactive messaging elements. (46b16440)
Tests
  • client-dynamodb: skip endpoint string comparison tests (#8123) (8e577e08)
  • add tsup/dts and metro bundler compatibility tests (#8122) (88ae83fc)

For list of updated packages, view updated-packages.md in assets-3.1076.0.zip

v3.1075.0

3.1075.0(2026-06-23)

New Features
  • client-kafka: Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers. (005f9529)

... (truncated)

Changelog

Sourced from @​aws-sdk/client-dynamodb's changelog.

3.1076.0 (2026-06-29)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1075.0 (2026-06-23)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1074.0 (2026-06-22)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1073.0 (2026-06-19)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1072.0 (2026-06-18)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1071.0 (2026-06-17)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1070.0 (2026-06-16)

... (truncated)

Commits

Updates @aws-sdk/lib-dynamodb from 3.1066.0 to 3.1076.0

Release notes

Sourced from @​aws-sdk/lib-dynamodb's releases.

v3.1076.0

3.1076.0(2026-06-29)

Chores
  • codegen:
    • sync for checksum impls, hostLabel validation (#8127) (aa94fa04)
    • sync for CBOR serde performance and retry fixes (#8125) (b6d6a759)
  • scripts: drop bundler support in dist-cjs (use dist-es instead) (#8124) (775bc034)
Documentation Changes
  • client-elasticache: Updated documentation for the ApplyImmediately parameter in ModifyCacheCluster and ModifyReplicationGroup to clarify modification behavior. (e9e0072f)
  • client-rds-data: Updated documentation to remove Aurora Serverless V1 references. (c5f50784)
New Features
  • client-glue: Added the UpdateAsset operation to set the business name and description for an existing AWS Glue Data Catalog asset. (fe604af0)
  • client-appconfig: AWS AppConfig introduces Experimentation tools - enhanced capabilities within AWS AppConfig that enable you to run AB tests, multivariate tests, and gradual feature rollouts across your application stack. (2b8591de)
  • client-resource-explorer-2: Added CFN resource type fields for Search and ListSupportedResourceTypes responses. Added SLRec field for ServiceView (a3773832)
  • client-vpc-lattice: Amazon VPC Lattice now supports mutable idle timeout configuration on VPC Lattice Services (217aaea5)
  • client-sagemaker-featurestore-runtime: Add support for ListRecords and BatchWriteRecord APIs to Feature Store. (7a6ffe5e)
  • client-connecthealth: Expand input validation to support Unicode characters and markdown table syntax. (a20832a3)
  • client-cloudwatch: This release adds the API (PutLogAlarm) to manage a new CloudWatch resource, Log Based Alarms. Log Based Alarms allows customers to alarm directly on CloudWatch Logs query results. (14f023ba)
  • client-imagebuilder: Adds support for AMI watermarks in Image Builder. (17e643a9)
  • client-evs: Amazon EVS introduces a VMware Cloud Foundation (VCF) self-deployed mode, along with new connectors to VCF components such as the Operations and SDDC managers to monitor coverage and usage. (2ae38fea)
  • client-pcs: Add support for in-place Slurm version upgrades on existing clusters by accepting scheduler.version in UpdateCluster. (16469f6b)
  • client-lambda: Lambda now supports self-managed S3 buckets for Lambda code storage giving you the option for Lambda to reference a copy of your source code from your own S3 buckets. This allows you to maintain a single copy of your source code and manage your own code storage limits. (0268f939)
  • client-connectcampaignsv2: Adding new attributes to PutProfileOutboundRequest API that will create an outbound request call for the customer's Web Notification outbound campaign. (05f467f7)
  • client-wafv2: AWS WAF added support for associating AWS WAF web ACLs with Amazon Bedrock AgentCore Gateway resources. You can now use AssociateWebACL, DisassociateWebACL, GetWebACLForResource, and ListResourcesForWebACL to protect your AgentCore Gateways with AWS WAF. (54ea3212)
  • client-ecs: Amazon ECS now supports customizable deployment circuit breaker configurations. Customers can now define the failure threshold or control the failure counting mechanism. (ff85bd33)
  • client-ec2: Adds support for the precision time strategy and a parentGroupId parameter on CreatePlacementGroup and DescribePlacementGroups. Precision time placement groups and cluster placement groups with a parent precision time placement group ensure instances launch on precision time capable hardware. (3482937a)
  • client-pinpoint-sms-voice-v2: This launch is an expansion of our Q1 RCS for business launch where we will release an API that supports rich media and interactive messaging elements. (46b16440)
Tests
  • client-dynamodb: skip endpoint string comparison tests (#8123) (8e577e08)
  • add tsup/dts and metro bundler compatibility tests (#8122) (88ae83fc)

For list of updated packages, view updated-packages.md in assets-3.1076.0.zip

v3.1075.0

3.1075.0(2026-06-23)

New Features
  • client-kafka: Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers. (005f9529)

... (truncated)

Changelog

Sourced from @​aws-sdk/lib-dynamodb's changelog.

3.1076.0 (2026-06-29)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1075.0 (2026-06-23)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1074.0 (2026-06-22)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1073.0 (2026-06-19)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1072.0 (2026-06-18)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1071.0 (2026-06-17)

Note: Version bump only for package @​aws-sdk/lib-dynamodb

3.1070.0 (2026-06-16)

... (truncated)

Commits

Updates aws-cdk from 2.1126.0 to 2.1128.1

Release notes

Sourced from aws-cdk's releases.

aws-cdk@v2.1128.1

2.1128.1 (2026-06-22)

Bug Fixes

aws-cdk@v2.1128.0

2.1128.0 (2026-06-17)

Features

Bug Fixes

aws-cdk@v2.1127.0

2.1127.0 (2026-06-15)

Features

Bug Fixes

  • not enough information to count sequential failures (#1614) (eb1882c)
  • total deploy time is not well-accounted for (#1596) (c5db51a)
Commits
  • ee34e8c chore(cli): snapshot the destroy command's IoHost message stream (#1659)
  • 3ff0bdf fix(aws-cdk): correct project-name argument mapping in cdk init (#1644)
  • f979da7 fix: remove ~48 transitive dependencies from asset packaging (#1654)
  • 078ce70 fix(toolkit-lib): user-supplied glob include patterns silently ignored (#1652)
  • ab0f8e3 fix: validation report handling is inconsistent (#1650)
  • 7daa104 fix(cli): cdk list pollutes stdout with synthesis time (#1637)
  • 6b49a20 chore: better hotswap fallback surfacing in telemetry (#1635)
  • 9c73eaf feat(deps): upgrade aws-cdk-lib (#1639)
  • 3041560 feat(deps): upgrade aws-cdk-lib (#1627)
  • 995a457 chore(deps): upgrade dependencies (#1626)
  • Additional commits viewable in compare view

Updates esbuild from 0.28.0 to 0.28.1

Release notes

Sourced from esbuild's releases.

v0.28.1

  • Disallow \ in local development server HTTP requests (GHSA-g7r4-m6w7-qqqr)

    This release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a \ backslash character. It happened due to the use of Go's path.Clean() function, which only handles Unix-style / characters. HTTP requests with paths containing \ are no longer allowed.

    Thanks to @​dellalibera for reporting this issue.

  • Add integrity checks to the Deno API (GHSA-gv7w-rqvm-qjhr)

    The previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.

    Note that esbuild's Deno API installs from registry.npmjs.org by default, but allows the NPM_CONFIG_REGISTRY environment variable to override this with a custom package registry. This change means that the esbuild executable served by NPM_CONFIG_REGISTRY must now match the expected content.

    Thanks to @​sondt99 for reporting this issue.

  • Avoid inlining using and await using declarations (#4482)

    Previously esbuild's minifier sometimes incorrectly inlined using and await using declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for let and const declarations by avoiding doing it for var declarations, which no longer worked when more declaration types were added. Here's an example:

    // Original code
    {
      using x = new Resource()
      x.activate()
    }
    

    // Old output (with --minify)
    new Resource().activate();

    // New output (with --minify)
    {using e=new Resource;e.activate()}

  • Fix module evaluation when an error is thrown (#4461, #4467)

    If an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if import() or require() is used to import a module multiple times. The thrown error is supposed to be thrown by every call to import() or require(), not just the first. With this release, esbuild will now throw the same error every time you call import() or require() on a module that throws during its evaluation.

  • Fix some edge cases around the new operator (#4477)

    Previously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a new expression (specifically an optional chain and/or a tagged template literal). The generated code for the new target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the new target in parentheses. Here is an example of some affected code:

    // Original code
    new (foo()`bar`)()
    new (foo()?.bar)()
    

    // Old output
    new foo()bar();
    new (foo())?.bar();

... (truncated)

Changelog

Sourced from esbuild's changelog.

0.28.1

  • Disallow \ in local development server HTTP requests (GHSA-g7r4-m6w7-qqqr)

    This release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a \ backslash character. It happened due to the use of Go's path.Clean() function, which only handles Unix-style / characters. HTTP requests with paths containing \ are no longer allowed.

    Thanks to @​dellalibera for reporting this issue.

  • Add integrity checks to the Deno API (GHSA-gv7w-rqvm-qjhr)

    The previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.

    Note that esbuild's Deno API installs from registry.npmjs.org by default, but allows the NPM_CONFIG_REGISTRY environment variable to override this with a custom package registry. This change means that the esbuild executable served by NPM_CONFIG_REGISTRY must now match the expected content.

    Thanks to @​sondt99 for reporting this issue.

  • Avoid inlining using and await using declarations (#4482)

    Previously esbuild's minifier sometimes incorrectly inlined using and await using declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for let and const declarations by avoiding doing it for var declarations, which no longer worked when more declaration types were added. Here's an example:

    // Original code
    {
      using x = new Resource()
      x.activate()
    }
    

    // Old output (with --minify)
    new Resource().activate();

    // New output (with --minify)
    {using e=new Resource;e.activate()}

  • Fix module evaluation when an error is thrown (#4461, #4467)

    If an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if import() or require() is used to import a module multiple times. The thrown error is supposed to be thrown by every call to import() or require(), not just the first. With this release, esbuild will now throw the same error every time you call import() or require() on a module that throws during its evaluation.

  • Fix some edge cases around the new operator (#4477)

    Previously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a new expression (specifically an optional chain and/or a tagged template literal). The generated code for the new target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the new target in parentheses. Here is an example of some affected code:

    // Original code
    new (foo()`bar`)()
    new (foo()?.bar)()
    

    // Old output
    new foo()bar();
    new (foo())?.bar();

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
Bumps the minor-and-patch group with 5 updates: | Package | From | To | | --- | --- | --- | | [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) | `2.258.1` | `2.260.0` | | [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1066.0` | `3.1076.0` | | [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1066.0` | `3.1076.0` | | [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1126.0` | `2.1128.1` | | [esbuild](https://github.com/evanw/esbuild) | `0.28.0` | `0.28.1` | Updates `aws-cdk-lib` from 2.258.1 to 2.260.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-cdk/releases">aws-cdk-lib's releases</a>.</em></p> <blockquote> <h2>v2.260.0</h2> <h3>Features</h3> <ul> <li>update L1 CloudFormation resource definitions (<a href="https://redirect.github.com/aws/aws-cdk/issues/38151">#38151</a>) (<a href="https://github.com/aws/aws-cdk/commit/f266a47595832d6018b8a0d43dcae6afde511de6">f266a47</a>), closes <a href="https://github.com/aws//docs.aws.amazon.com/AmazonS3/latest/userguide/s3-files-prereq-policies.html/issues/s3">/docs.aws.amazon.com/AmazonS3/latest/userguide/s3-files-prereq-policies.html#s3</a></li> <li><strong>core:</strong> add external traces to ConstructError (<a href="https://redirect.github.com/aws/aws-cdk/issues/38131">#38131</a>) (<a href="https://github.com/aws/aws-cdk/commit/e360dd9b44d2111e28cd16ac683a813f33ed5793">e360dd9</a>)</li> <li><strong>core:</strong> append external stack traces to metadata if available (<a href="https://redirect.github.com/aws/aws-cdk/issues/38124">#38124</a>) (<a href="https://github.com/aws/aws-cdk/commit/c77a08c19eb16a3734183f079e598b90383d28a3">c77a08c</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>bundling:</strong> docker build can be skipped if already performed (<a href="https://redirect.github.com/aws/aws-cdk/issues/38134">#38134</a>) (<a href="https://github.com/aws/aws-cdk/commit/2f9ae95d55cda7dc5011c8a04b66af7fca0c4f9d">2f9ae95</a>)</li> <li><strong>core:</strong> stack traces contain decorator paths (<a href="https://redirect.github.com/aws/aws-cdk/issues/38130">#38130</a>) (<a href="https://github.com/aws/aws-cdk/commit/318f645df3f0c903f64126975fb4a4a65c0a18d0">318f645</a>)</li> <li><strong>core:</strong> weak cross-stack references fail for list attributes (<a href="https://redirect.github.com/aws/aws-cdk/issues/37948">#37948</a>) (<a href="https://github.com/aws/aws-cdk/commit/6bb9d75f71c229d246e39942cdf37e7406dfd5cb">6bb9d75</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/37910">#37910</a></li> <li><strong>lambda-nodejs:</strong> reuse posixShellEscape for Docker bundling file operations (<a href="https://redirect.github.com/aws/aws-cdk/issues/38133">#38133</a>) (<a href="https://github.com/aws/aws-cdk/commit/baa9e1dff469306cc23b8f4bd232d703f98bf68a">baa9e1d</a>)</li> </ul> <hr /> <h2>Alpha modules (2.260.0-alpha.0)</h2> <h2>v2.259.0</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li> <p><strong>lambda:</strong> <code>Runtime.NODEJS_LATEST</code> now resolves to <code>nodejs24.x</code> in every region. Customers who pin to a concrete runtime (<code>Runtime.NODEJS_22_X</code>, <code>useLatestRuntimeVersion: false</code> in <code>aws-lambda-nodejs.NodejsFunction</code>) are unaffected. Existing <code>AWS::Lambda::Function</code> resources synthesized with <code>NODEJS_LATEST</code> will see <code>Runtime: nodejs22.x</code> → <code>Runtime: nodejs24.x</code> on next deploy. Lambda accepts runtime updates <strong>in place</strong>.</p> <p><strong>Customer-code compatibility — IMPORTANT</strong>: Node.js 24 removes support for callback-style asynchronous handlers (<code>(event, context, callback) =&gt; {...}</code>) per the <a href="https://aws.amazon.com/blogs/compute/node-js-24-runtime-now-available-in-aws-lambda/">launch blog</a>. Customers whose Lambda code still uses callback-based handlers will see runtime errors after the bump. Customers should migrate to <code>async (event, context) =&gt; {...}</code> or pin to <code>Runtime.NODEJS_22_X</code> explicitly.</p> </li> </ul> <h3>Features</h3> <ul> <li><strong>core:</strong> recommend the use of weak references if no choice has been made (<a href="https://redirect.github.com/aws/aws-cdk/issues/38070">#38070</a>) (<a href="https://github.com/aws/aws-cdk/commit/6e74e5ebbea3959a86af3aea038df0ab87aa27b6">6e74e5e</a>)</li> <li><strong>ecs:</strong> add forceNewDeployment option for Fargate and EC2 services (<a href="https://redirect.github.com/aws/aws-cdk/issues/36797">#36797</a>) (<a href="https://github.com/aws/aws-cdk/commit/3d9c4df185026440f5668b82dd2adb47e0c366de">3d9c4df</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/27762">#27762</a></li> <li><strong>eks:</strong> use the recommended AL2023 instead of AL2 AMI type (under feature flag) (<a href="https://redirect.github.com/aws/aws-cdk/issues/37850">#37850</a>) (<a href="https://github.com/aws/aws-cdk/commit/6a2dcb7ab6e2d4a69999625947ab6a152b82bc19">6a2dcb7</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/32211">#32211</a></li> <li><strong>lambda:</strong> upgrade lambda and custom resource default runtime to nodejs24.x (<a href="https://redirect.github.com/aws/aws-cdk/issues/38031">#38031</a>) (<a href="https://github.com/aws/aws-cdk/commit/36c84c6d6ef8a4772249afadec78c2d25c44cd90">36c84c6</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>spec2cdk:</strong> sanitize hyphens in EventBridge event namespace names (<a href="https://redirect.github.com/aws/aws-cdk/issues/38088">#38088</a>) (<a href="https://github.com/aws/aws-cdk/commit/b8f41bf4f2a8ef3556f3279c7fdd8259f3b6086b">b8f41bf</a>), closes <a href="https://github.com/40aws-cdk/spec2cdk/lib/naming/conventions.ts/issues/L195">40aws-cdk/spec2cdk/lib/naming/conventions.ts#L195</a></li> </ul> <h3>Reverts</h3> <ul> <li>&quot;chore(bundling): check if docker image is cached before building&quot; (<a href="https://redirect.github.com/aws/aws-cdk/issues/38116">#38116</a>) (<a href="https://github.com/aws/aws-cdk/commit/359f2fbbebb58da0e911b0550b49033fcc84f371">359f2fb</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/37951">aws/aws-cdk#37951</a></li> </ul> <hr /> <h2>Alpha modules (2.259.0-alpha.0)</h2> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md">aws-cdk-lib's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <p>All notable changes to this project will be documented in this file. See <a href="https://github.com/conventional-changelog/standard-version">standard-version</a> for commit guidelines.</p> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.259.0-alpha.0...v2.260.0-alpha.0">2.260.0-alpha.0</a> (2026-06-16)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.258.1-alpha.0...v2.259.0-alpha.0">2.259.0-alpha.0</a> (2026-06-11)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.258.0-alpha.0...v2.258.1-alpha.0">2.258.1-alpha.0</a> (2026-06-08)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.257.0-alpha.0...v2.258.0-alpha.0">2.258.0-alpha.0</a> (2026-06-04)</h2> <h3>Features</h3> <ul> <li><strong>integ-tests-alpha:</strong> add option to set the provider log level (<a href="https://redirect.github.com/aws/aws-cdk/issues/38005">#38005</a>) (<a href="https://github.com/aws/aws-cdk/commit/c634a795de080df21b86fad191d05dfde884eb4e">c634a79</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>custom-resource-handlers:</strong> deterministic asset hashes for generated lambdas (<a href="https://redirect.github.com/aws/aws-cdk/issues/37634">#37634</a>) (<a href="https://github.com/aws/aws-cdk/commit/6c3d5bc36e19b8834319578fbd8525615a47a4b9">6c3d5bc</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/34307">#34307</a></li> <li><strong>glue-alpha:</strong> deprecate Ray Jobs (<a href="https://redirect.github.com/aws/aws-cdk/issues/38055">#38055</a>) (<a href="https://github.com/aws/aws-cdk/commit/3fa428b9b24d286841940cfff5200d16817196bf">3fa428b</a>)</li> <li><strong>glue-alpha:</strong> restore notifyDelayAfter to PySpark and Scala Spark ETL jobs (<a href="https://redirect.github.com/aws/aws-cdk/issues/37815">#37815</a>) (<a href="https://github.com/aws/aws-cdk/commit/05be88aa324635108076bdc648a4ee940d22a386">05be88a</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/33839">#33839</a></li> <li><strong>integ-tests-alpha:</strong> assertion failures print too much unnecessary information (<a href="https://redirect.github.com/aws/aws-cdk/issues/37974">#37974</a>) (<a href="https://github.com/aws/aws-cdk/commit/bc0de1dacc59b95a2e89f9c3ec96589e98b35ed2">bc0de1d</a>)</li> <li><strong>mediapackagev2-alpha:</strong> cdnAuth on OriginEndpoint now generates the required policy (<a href="https://redirect.github.com/aws/aws-cdk/issues/38013">#38013</a>) (<a href="https://github.com/aws/aws-cdk/commit/1d56b46abd477f188021d32d77551be1377765d0">1d56b46</a>)</li> </ul> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.256.1-alpha.0...v2.257.0-alpha.0">2.257.0-alpha.0</a> (2026-05-21)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.256.0-alpha.0...v2.256.1-alpha.0">2.256.1-alpha.0</a> (2026-05-20)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.255.0-alpha.0...v2.256.0-alpha.0">2.256.0-alpha.0</a> (2026-05-19)</h2> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.254.0-alpha.0...v2.255.0-alpha.0">2.255.0-alpha.0</a> (2026-05-18)</h2> <h3>Features</h3> <ul> <li><strong>bedrock-agentcore-alpha:</strong> Graduation of the library to stable. The <strong>Policy</strong> submodule is the only submodule that remains in alpha. All other constructs have graduated to stable in <code>aws-cdk-lib/aws-bedrockagentcore</code> and we recommend migrating to the stable versions (<a href="https://redirect.github.com/aws/aws-cdk/issues/37876">#37876</a>) (<a href="https://github.com/aws/aws-cdk/commit/00cf6015f30755653de7a541f79c944d4a68f423">00cf601</a>)</li> </ul> <h2><a href="https://github.com/aws/aws-cdk/compare/v2.253.1-alpha.0...v2.254.0-alpha.0">2.254.0-alpha.0</a> (2026-05-13)</h2> <h3>Features</h3> <ul> <li><strong>bedrock-agentcore-alpha:</strong> add tags support to Evaluator and OnlineEvaluationConfig (<a href="https://redirect.github.com/aws/aws-cdk/issues/37804">#37804</a>) (<a href="https://github.com/aws/aws-cdk/commit/adbf88faeb4d2b762563389aea160cfda496f200">adbf88f</a>)</li> <li><strong>bedrock-agentcore-alpha:</strong> add identity L2 constructs (<a href="https://redirect.github.com/aws/aws-cdk/issues/37610">#37610</a>) (<a href="https://github.com/aws/aws-cdk/commit/67c3af260cedb8e610dff36f829afb36114dd93a">67c3af2</a>)</li> <li><strong>mediapackagev2-alpha:</strong> add OAC integration between CloudFront and MediaPackageV2 (<a href="https://redirect.github.com/aws/aws-cdk/issues/37701">#37701</a>) (<a href="https://github.com/aws/aws-cdk/commit/654f59c559f6eb2b5240e7885372ac82ea05a996">654f59c</a>)</li> </ul> <h3>Bug Fixes</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-cdk/commit/f266a47595832d6018b8a0d43dcae6afde511de6"><code>f266a47</code></a> feat: update L1 CloudFormation resource definitions (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/38151">#38151</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/318f645df3f0c903f64126975fb4a4a65c0a18d0"><code>318f645</code></a> fix(core): stack traces contain decorator paths (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/38130">#38130</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/2f9ae95d55cda7dc5011c8a04b66af7fca0c4f9d"><code>2f9ae95</code></a> fix(bundling): docker build can be skipped if already performed (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/38134">#38134</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/aeafa634f3315995eafc0e5b3241312562219ebb"><code>aeafa63</code></a> docs(pipelines): clarify format of DockerHub creds (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/38132">#38132</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/baa9e1dff469306cc23b8f4bd232d703f98bf68a"><code>baa9e1d</code></a> fix(lambda-nodejs): reuse posixShellEscape for Docker bundling file operation...</li> <li><a href="https://github.com/aws/aws-cdk/commit/e360dd9b44d2111e28cd16ac683a813f33ed5793"><code>e360dd9</code></a> feat(core): add external traces to ConstructError (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/38131">#38131</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/5619d4304c2d681bc5033be4883b35460e5b04dc"><code>5619d43</code></a> Merge branch 'main' into merge-back/2.259.0</li> <li><a href="https://github.com/aws/aws-cdk/commit/6bb9d75f71c229d246e39942cdf37e7406dfd5cb"><code>6bb9d75</code></a> fix(core): weak cross-stack references fail for list attributes (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/37948">#37948</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/c77a08c19eb16a3734183f079e598b90383d28a3"><code>c77a08c</code></a> feat(core): append external stack traces to metadata if available (<a href="https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib/issues/38124">#38124</a>)</li> <li><a href="https://github.com/aws/aws-cdk/commit/772eeba2564af8c6dff6b678dab6150d78c20e14"><code>772eeba</code></a> chore: update analytics metadata blueprints</li> <li>Additional commits viewable in <a href="https://github.com/aws/aws-cdk/commits/v2.260.0/packages/aws-cdk-lib">compare view</a></li> </ul> </details> <br /> Updates `@aws-sdk/client-dynamodb` from 3.1066.0 to 3.1076.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@​aws-sdk/client-dynamodb's releases</a>.</em></p> <blockquote> <h2>v3.1076.0</h2> <h4>3.1076.0(2026-06-29)</h4> <h5>Chores</h5> <ul> <li><strong>codegen:</strong> <ul> <li>sync for checksum impls, hostLabel validation (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8127">#8127</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/aa94fa0469fa7e0933a4b36b4e6329fa88ee33ab">aa94fa04</a>)</li> <li>sync for CBOR serde performance and retry fixes (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8125">#8125</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b6d6a759f15f2c36745fb85905a90533998cae0e">b6d6a759</a>)</li> </ul> </li> <li><strong>scripts:</strong> drop bundler support in dist-cjs (use dist-es instead) (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8124">#8124</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/775bc034fad8cb5587434718133ce592da4e1b3e">775bc034</a>)</li> </ul> <h5>Documentation Changes</h5> <ul> <li><strong>client-elasticache:</strong> Updated documentation for the ApplyImmediately parameter in ModifyCacheCluster and ModifyReplicationGroup to clarify modification behavior. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/e9e0072fe489b26abedfc7b9aad82987de80967b">e9e0072f</a>)</li> <li><strong>client-rds-data:</strong> Updated documentation to remove Aurora Serverless V1 references. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/c5f50784baf85f4f906b4437d92ab3d2dde0b8cb">c5f50784</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-glue:</strong> Added the UpdateAsset operation to set the business name and description for an existing AWS Glue Data Catalog asset. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/fe604af0d8fb13aba0bd2829458e5d0476f47970">fe604af0</a>)</li> <li><strong>client-appconfig:</strong> AWS AppConfig introduces Experimentation tools - enhanced capabilities within AWS AppConfig that enable you to run AB tests, multivariate tests, and gradual feature rollouts across your application stack. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2b8591de5c93c50901b5ae1e7abe0f8c3e557fdb">2b8591de</a>)</li> <li><strong>client-resource-explorer-2:</strong> Added CFN resource type fields for Search and ListSupportedResourceTypes responses. Added SLRec field for ServiceView (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a3773832d2f12cd7376faab68ae92f90edde2313">a3773832</a>)</li> <li><strong>client-vpc-lattice:</strong> Amazon VPC Lattice now supports mutable idle timeout configuration on VPC Lattice Services (<a href="https://github.com/aws/aws-sdk-js-v3/commit/217aaea51e06d66991ddaecd204f0eb9b515838d">217aaea5</a>)</li> <li><strong>client-sagemaker-featurestore-runtime:</strong> Add support for ListRecords and BatchWriteRecord APIs to Feature Store. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/7a6ffe5ed4120d6637fc176a27efcaccc0752c95">7a6ffe5e</a>)</li> <li><strong>client-connecthealth:</strong> Expand input validation to support Unicode characters and markdown table syntax. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a20832a34042dc7a64fe27207d26e32950f04c92">a20832a3</a>)</li> <li><strong>client-cloudwatch:</strong> This release adds the API (PutLogAlarm) to manage a new CloudWatch resource, Log Based Alarms. Log Based Alarms allows customers to alarm directly on CloudWatch Logs query results. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/14f023badd34a78632b4792a4039c6f6faa7486b">14f023ba</a>)</li> <li><strong>client-imagebuilder:</strong> Adds support for AMI watermarks in Image Builder. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/17e643a9fd646c648fece0738a2af282ac1edf23">17e643a9</a>)</li> <li><strong>client-evs:</strong> Amazon EVS introduces a VMware Cloud Foundation (VCF) self-deployed mode, along with new connectors to VCF components such as the Operations and SDDC managers to monitor coverage and usage. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2ae38fea02b0248faaacee4fcd090d40865a8942">2ae38fea</a>)</li> <li><strong>client-pcs:</strong> Add support for in-place Slurm version upgrades on existing clusters by accepting scheduler.version in UpdateCluster. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/16469f6b6af8a6f2968d2342213b8020529ec926">16469f6b</a>)</li> <li><strong>client-lambda:</strong> Lambda now supports self-managed S3 buckets for Lambda code storage giving you the option for Lambda to reference a copy of your source code from your own S3 buckets. This allows you to maintain a single copy of your source code and manage your own code storage limits. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/0268f939a68bc042e376ab192a1bd9790750fa28">0268f939</a>)</li> <li><strong>client-connectcampaignsv2:</strong> Adding new attributes to PutProfileOutboundRequest API that will create an outbound request call for the customer's Web Notification outbound campaign. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/05f467f78815884db3d8dcb4a99e1ab95679efe5">05f467f7</a>)</li> <li><strong>client-wafv2:</strong> AWS WAF added support for associating AWS WAF web ACLs with Amazon Bedrock AgentCore Gateway resources. You can now use AssociateWebACL, DisassociateWebACL, GetWebACLForResource, and ListResourcesForWebACL to protect your AgentCore Gateways with AWS WAF. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/54ea3212eb9c71f378ac801e94fa689efde0e2df">54ea3212</a>)</li> <li><strong>client-ecs:</strong> Amazon ECS now supports customizable deployment circuit breaker configurations. Customers can now define the failure threshold or control the failure counting mechanism. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/ff85bd339bd4e5023feaef0559766015e3da9b40">ff85bd33</a>)</li> <li><strong>client-ec2:</strong> Adds support for the precision time strategy and a parentGroupId parameter on CreatePlacementGroup and DescribePlacementGroups. Precision time placement groups and cluster placement groups with a parent precision time placement group ensure instances launch on precision time capable hardware. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/3482937a47912a63508f7673372812c109e61578">3482937a</a>)</li> <li><strong>client-pinpoint-sms-voice-v2:</strong> This launch is an expansion of our Q1 RCS for business launch where we will release an API that supports rich media and interactive messaging elements. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/46b16440ad40f8ab26d01ff7c09a94c2c9521cfc">46b16440</a>)</li> </ul> <h5>Tests</h5> <ul> <li><strong>client-dynamodb:</strong> skip endpoint string comparison tests (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8123">#8123</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/8e577e08cddcd76724ac8625fea81fc52415dd92">8e577e08</a>)</li> <li>add tsup/dts and metro bundler compatibility tests (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8122">#8122</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/88ae83fcff33d1554e5393d5ed4320f59896bb68">88ae83fc</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1076.0.zip</strong></p> <h2>v3.1075.0</h2> <h4>3.1075.0(2026-06-23)</h4> <h5>New Features</h5> <ul> <li><strong>client-kafka:</strong> Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/005f9529d4d3cd0c98b002a3584773b253a702dc">005f9529</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md">@​aws-sdk/client-dynamodb's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1075.0...v3.1076.0">3.1076.0</a> (2026-06-29)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1074.0...v3.1075.0">3.1075.0</a> (2026-06-23)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1073.0...v3.1074.0">3.1074.0</a> (2026-06-22)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1072.0...v3.1073.0">3.1073.0</a> (2026-06-19)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1071.0...v3.1072.0">3.1072.0</a> (2026-06-18)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1070.0...v3.1071.0">3.1071.0</a> (2026-06-17)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/client-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1069.0...v3.1070.0">3.1070.0</a> (2026-06-16)</h1> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/dfd62f6239dc417233e3cc4dd953c6e6de1415aa"><code>dfd62f6</code></a> Publish v3.1076.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/aa94fa0469fa7e0933a4b36b4e6329fa88ee33ab"><code>aa94fa0</code></a> chore(codegen): sync for checksum impls, hostLabel validation (<a href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb/issues/8127">#8127</a>)</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/b6d6a759f15f2c36745fb85905a90533998cae0e"><code>b6d6a75</code></a> chore(codegen): sync for CBOR serde performance and retry fixes (<a href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb/issues/8125">#8125</a>)</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/29ee1999340b8d8288184076df6557541974b13f"><code>29ee199</code></a> Publish v3.1075.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/c48dfa08aa057f100c69ccb571d35004eddec207"><code>c48dfa0</code></a> Publish v3.1074.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/ee71adc9663fc2ebaabae455981fd169fd6e97b2"><code>ee71adc</code></a> Publish v3.1073.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/501cd332619533ae96f154d7c226dc2f7bf8d615"><code>501cd33</code></a> Publish v3.1072.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/3ce820aa54c953459eb58abe4f06e28ba4ceb87d"><code>3ce820a</code></a> Publish v3.1071.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/4f2cfe1cfc420d0b5bfa226ae6619dd67de73ccc"><code>4f2cfe1</code></a> Publish v3.1070.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/7058d13814795c6ff06a960077269458520bf161"><code>7058d13</code></a> Publish v3.1069.0</li> <li>Additional commits viewable in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1076.0/clients/client-dynamodb">compare view</a></li> </ul> </details> <br /> Updates `@aws-sdk/lib-dynamodb` from 3.1066.0 to 3.1076.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@​aws-sdk/lib-dynamodb's releases</a>.</em></p> <blockquote> <h2>v3.1076.0</h2> <h4>3.1076.0(2026-06-29)</h4> <h5>Chores</h5> <ul> <li><strong>codegen:</strong> <ul> <li>sync for checksum impls, hostLabel validation (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8127">#8127</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/aa94fa0469fa7e0933a4b36b4e6329fa88ee33ab">aa94fa04</a>)</li> <li>sync for CBOR serde performance and retry fixes (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8125">#8125</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b6d6a759f15f2c36745fb85905a90533998cae0e">b6d6a759</a>)</li> </ul> </li> <li><strong>scripts:</strong> drop bundler support in dist-cjs (use dist-es instead) (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8124">#8124</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/775bc034fad8cb5587434718133ce592da4e1b3e">775bc034</a>)</li> </ul> <h5>Documentation Changes</h5> <ul> <li><strong>client-elasticache:</strong> Updated documentation for the ApplyImmediately parameter in ModifyCacheCluster and ModifyReplicationGroup to clarify modification behavior. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/e9e0072fe489b26abedfc7b9aad82987de80967b">e9e0072f</a>)</li> <li><strong>client-rds-data:</strong> Updated documentation to remove Aurora Serverless V1 references. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/c5f50784baf85f4f906b4437d92ab3d2dde0b8cb">c5f50784</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-glue:</strong> Added the UpdateAsset operation to set the business name and description for an existing AWS Glue Data Catalog asset. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/fe604af0d8fb13aba0bd2829458e5d0476f47970">fe604af0</a>)</li> <li><strong>client-appconfig:</strong> AWS AppConfig introduces Experimentation tools - enhanced capabilities within AWS AppConfig that enable you to run AB tests, multivariate tests, and gradual feature rollouts across your application stack. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2b8591de5c93c50901b5ae1e7abe0f8c3e557fdb">2b8591de</a>)</li> <li><strong>client-resource-explorer-2:</strong> Added CFN resource type fields for Search and ListSupportedResourceTypes responses. Added SLRec field for ServiceView (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a3773832d2f12cd7376faab68ae92f90edde2313">a3773832</a>)</li> <li><strong>client-vpc-lattice:</strong> Amazon VPC Lattice now supports mutable idle timeout configuration on VPC Lattice Services (<a href="https://github.com/aws/aws-sdk-js-v3/commit/217aaea51e06d66991ddaecd204f0eb9b515838d">217aaea5</a>)</li> <li><strong>client-sagemaker-featurestore-runtime:</strong> Add support for ListRecords and BatchWriteRecord APIs to Feature Store. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/7a6ffe5ed4120d6637fc176a27efcaccc0752c95">7a6ffe5e</a>)</li> <li><strong>client-connecthealth:</strong> Expand input validation to support Unicode characters and markdown table syntax. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a20832a34042dc7a64fe27207d26e32950f04c92">a20832a3</a>)</li> <li><strong>client-cloudwatch:</strong> This release adds the API (PutLogAlarm) to manage a new CloudWatch resource, Log Based Alarms. Log Based Alarms allows customers to alarm directly on CloudWatch Logs query results. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/14f023badd34a78632b4792a4039c6f6faa7486b">14f023ba</a>)</li> <li><strong>client-imagebuilder:</strong> Adds support for AMI watermarks in Image Builder. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/17e643a9fd646c648fece0738a2af282ac1edf23">17e643a9</a>)</li> <li><strong>client-evs:</strong> Amazon EVS introduces a VMware Cloud Foundation (VCF) self-deployed mode, along with new connectors to VCF components such as the Operations and SDDC managers to monitor coverage and usage. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2ae38fea02b0248faaacee4fcd090d40865a8942">2ae38fea</a>)</li> <li><strong>client-pcs:</strong> Add support for in-place Slurm version upgrades on existing clusters by accepting scheduler.version in UpdateCluster. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/16469f6b6af8a6f2968d2342213b8020529ec926">16469f6b</a>)</li> <li><strong>client-lambda:</strong> Lambda now supports self-managed S3 buckets for Lambda code storage giving you the option for Lambda to reference a copy of your source code from your own S3 buckets. This allows you to maintain a single copy of your source code and manage your own code storage limits. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/0268f939a68bc042e376ab192a1bd9790750fa28">0268f939</a>)</li> <li><strong>client-connectcampaignsv2:</strong> Adding new attributes to PutProfileOutboundRequest API that will create an outbound request call for the customer's Web Notification outbound campaign. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/05f467f78815884db3d8dcb4a99e1ab95679efe5">05f467f7</a>)</li> <li><strong>client-wafv2:</strong> AWS WAF added support for associating AWS WAF web ACLs with Amazon Bedrock AgentCore Gateway resources. You can now use AssociateWebACL, DisassociateWebACL, GetWebACLForResource, and ListResourcesForWebACL to protect your AgentCore Gateways with AWS WAF. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/54ea3212eb9c71f378ac801e94fa689efde0e2df">54ea3212</a>)</li> <li><strong>client-ecs:</strong> Amazon ECS now supports customizable deployment circuit breaker configurations. Customers can now define the failure threshold or control the failure counting mechanism. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/ff85bd339bd4e5023feaef0559766015e3da9b40">ff85bd33</a>)</li> <li><strong>client-ec2:</strong> Adds support for the precision time strategy and a parentGroupId parameter on CreatePlacementGroup and DescribePlacementGroups. Precision time placement groups and cluster placement groups with a parent precision time placement group ensure instances launch on precision time capable hardware. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/3482937a47912a63508f7673372812c109e61578">3482937a</a>)</li> <li><strong>client-pinpoint-sms-voice-v2:</strong> This launch is an expansion of our Q1 RCS for business launch where we will release an API that supports rich media and interactive messaging elements. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/46b16440ad40f8ab26d01ff7c09a94c2c9521cfc">46b16440</a>)</li> </ul> <h5>Tests</h5> <ul> <li><strong>client-dynamodb:</strong> skip endpoint string comparison tests (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8123">#8123</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/8e577e08cddcd76724ac8625fea81fc52415dd92">8e577e08</a>)</li> <li>add tsup/dts and metro bundler compatibility tests (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8122">#8122</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/88ae83fcff33d1554e5393d5ed4320f59896bb68">88ae83fc</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1076.0.zip</strong></p> <h2>v3.1075.0</h2> <h4>3.1075.0(2026-06-23)</h4> <h5>New Features</h5> <ul> <li><strong>client-kafka:</strong> Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/005f9529d4d3cd0c98b002a3584773b253a702dc">005f9529</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md">@​aws-sdk/lib-dynamodb's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1075.0...v3.1076.0">3.1076.0</a> (2026-06-29)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1074.0...v3.1075.0">3.1075.0</a> (2026-06-23)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1073.0...v3.1074.0">3.1074.0</a> (2026-06-22)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1072.0...v3.1073.0">3.1073.0</a> (2026-06-19)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1071.0...v3.1072.0">3.1072.0</a> (2026-06-18)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1070.0...v3.1071.0">3.1071.0</a> (2026-06-17)</h1> <p><strong>Note:</strong> Version bump only for package <code>@​aws-sdk/lib-dynamodb</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1069.0...v3.1070.0">3.1070.0</a> (2026-06-16)</h1> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/dfd62f6239dc417233e3cc4dd953c6e6de1415aa"><code>dfd62f6</code></a> Publish v3.1076.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/aa94fa0469fa7e0933a4b36b4e6329fa88ee33ab"><code>aa94fa0</code></a> chore(codegen): sync for checksum impls, hostLabel validation (<a href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb/issues/8127">#8127</a>)</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/b6d6a759f15f2c36745fb85905a90533998cae0e"><code>b6d6a75</code></a> chore(codegen): sync for CBOR serde performance and retry fixes (<a href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb/issues/8125">#8125</a>)</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/29ee1999340b8d8288184076df6557541974b13f"><code>29ee199</code></a> Publish v3.1075.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/c48dfa08aa057f100c69ccb571d35004eddec207"><code>c48dfa0</code></a> Publish v3.1074.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/ee71adc9663fc2ebaabae455981fd169fd6e97b2"><code>ee71adc</code></a> Publish v3.1073.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/501cd332619533ae96f154d7c226dc2f7bf8d615"><code>501cd33</code></a> Publish v3.1072.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/3ce820aa54c953459eb58abe4f06e28ba4ceb87d"><code>3ce820a</code></a> Publish v3.1071.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/4f2cfe1cfc420d0b5bfa226ae6619dd67de73ccc"><code>4f2cfe1</code></a> Publish v3.1070.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/7058d13814795c6ff06a960077269458520bf161"><code>7058d13</code></a> Publish v3.1069.0</li> <li>Additional commits viewable in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1076.0/lib/lib-dynamodb">compare view</a></li> </ul> </details> <br /> Updates `aws-cdk` from 2.1126.0 to 2.1128.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-cdk-cli/releases">aws-cdk's releases</a>.</em></p> <blockquote> <h2>aws-cdk@v2.1128.1</h2> <h2><a href="https://github.com/aws/aws-cdk-cli/compare/aws-cdk@v2.1128.0...aws-cdk@v2.1128.1">2.1128.1</a> (2026-06-22)</h2> <h3>Bug Fixes</h3> <ul> <li><strong>aws-cdk:</strong> correct project-name argument mapping in cdk init (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1644">#1644</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/3ff0bdfc8b006f6e131f7b58722f6b6c63381e07">3ff0bdf</a>), closes <a href="https://redirect.github.com/aws/aws-cdk/issues/31992">aws/aws-cdk#31992</a></li> <li>remove ~48 transitive dependencies from asset packaging (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1654">#1654</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/f979da7bf2656b500a1dc0a40b087b4185b509f4">f979da7</a>)</li> <li><strong>toolkit-lib:</strong> user-supplied glob include patterns silently ignored (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1652">#1652</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/078ce70c373dca6852e95d939a27359a4f836afc">078ce70</a>), closes <a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1647">#1647</a> <a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1146">#1146</a></li> <li>validation report handling is inconsistent (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1650">#1650</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/ab0f8e3a550ad5acfe70945a8bac820e48416364">ab0f8e3</a>)</li> </ul> <h2>aws-cdk@v2.1128.0</h2> <h2><a href="https://github.com/aws/aws-cdk-cli/compare/aws-cdk@v2.1127.0...aws-cdk@v2.1128.0">2.1128.0</a> (2026-06-17)</h2> <h3>Features</h3> <ul> <li><strong>deps:</strong> upgrade aws-cdk-lib (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1639">#1639</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/9c73eaf9df441bc82436358124992f30dee5312c">9c73eaf</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>cli:</strong> cdk list pollutes stdout with synthesis time (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1637">#1637</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/7daa10461aee67d2be3bb2cc490f3c0284c33ef4">7daa104</a>), closes <a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1632">#1632</a> <a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1603">#1603</a></li> </ul> <h2>aws-cdk@v2.1127.0</h2> <h2><a href="https://github.com/aws/aws-cdk-cli/compare/aws-cdk@v2.1126.0...aws-cdk@v2.1127.0">2.1127.0</a> (2026-06-15)</h2> <h3>Features</h3> <ul> <li><strong>cli:</strong> <code>cdk validate</code> command (behind <code>--unstable</code> flag) (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1527">#1527</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/c03ef3eac256b023bd78d0055e4a112b41e3d600">c03ef3e</a>)</li> <li><strong>cli:</strong> add --debug-app and --debug-cli flags (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1604">#1604</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/a0e68fb1a0cc3d22f503597164ba8d3059c2b5ea">a0e68fb</a>)</li> <li><strong>cli:</strong> cdk validate --online (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1539">#1539</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/a731ce83f0b7743adf23a77021c231d75e759bdf">a731ce8</a>), closes <a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1527">#1527</a></li> <li><strong>deps:</strong> upgrade aws-cdk-lib (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1600">#1600</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/3e1f708578f055092c51eb84534b51f09265c034">3e1f708</a>)</li> <li><strong>deps:</strong> upgrade aws-cdk-lib (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1615">#1615</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/8d3083c002baab881512afc9266ccdbfc8245377">8d3083c</a>)</li> <li><strong>deps:</strong> upgrade aws-cdk-lib (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1627">#1627</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/304156071581edf0d3350162c9318f9bb9880ba3">3041560</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>not enough information to count sequential failures (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1614">#1614</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/eb1882c731ba6994045487929789257b02f793ed">eb1882c</a>)</li> <li>total deploy time is not well-accounted for (<a href="https://redirect.github.com/aws/aws-cdk-cli/issues/1596">#1596</a>) (<a href="https://github.com/aws/aws-cdk-cli/commit/c5db51a6a17c866fd658c6025595e86044702f2e">c5db51a</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-cdk-cli/commit/ee34e8cbed9bb7b1dfd37076e91e28298db1703a"><code>ee34e8c</code></a> chore(cli): snapshot the destroy command's IoHost message stream (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1659">#1659</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/3ff0bdfc8b006f6e131f7b58722f6b6c63381e07"><code>3ff0bdf</code></a> fix(aws-cdk): correct project-name argument mapping in cdk init (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1644">#1644</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/f979da7bf2656b500a1dc0a40b087b4185b509f4"><code>f979da7</code></a> fix: remove ~48 transitive dependencies from asset packaging (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1654">#1654</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/078ce70c373dca6852e95d939a27359a4f836afc"><code>078ce70</code></a> fix(toolkit-lib): user-supplied glob include patterns silently ignored (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1652">#1652</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/ab0f8e3a550ad5acfe70945a8bac820e48416364"><code>ab0f8e3</code></a> fix: validation report handling is inconsistent (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1650">#1650</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/7daa10461aee67d2be3bb2cc490f3c0284c33ef4"><code>7daa104</code></a> fix(cli): cdk list pollutes stdout with synthesis time (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1637">#1637</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/6b49a209216c2ab92366cd05c8a00de3c4943100"><code>6b49a20</code></a> chore: better hotswap fallback surfacing in telemetry (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1635">#1635</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/9c73eaf9df441bc82436358124992f30dee5312c"><code>9c73eaf</code></a> feat(deps): upgrade aws-cdk-lib (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1639">#1639</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/304156071581edf0d3350162c9318f9bb9880ba3"><code>3041560</code></a> feat(deps): upgrade aws-cdk-lib (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1627">#1627</a>)</li> <li><a href="https://github.com/aws/aws-cdk-cli/commit/995a45718515ae94824813eb59bfa2b07e03d6f1"><code>995a457</code></a> chore(deps): upgrade dependencies (<a href="https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk/issues/1626">#1626</a>)</li> <li>Additional commits viewable in <a href="https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.1/packages/aws-cdk">compare view</a></li> </ul> </details> <br /> Updates `esbuild` from 0.28.0 to 0.28.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/evanw/esbuild/releases">esbuild's releases</a>.</em></p> <blockquote> <h2>v0.28.1</h2> <ul> <li> <p>Disallow <code>\</code> in local development server HTTP requests (<a href="https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr">GHSA-g7r4-m6w7-qqqr</a>)</p> <p>This release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a <code>\</code> backslash character. It happened due to the use of Go's <code>path.Clean()</code> function, which only handles Unix-style <code>/</code> characters. HTTP requests with paths containing <code>\</code> are no longer allowed.</p> <p>Thanks to <a href="https://github.com/dellalibera"><code>@​dellalibera</code></a> for reporting this issue.</p> </li> <li> <p>Add integrity checks to the Deno API (<a href="https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr">GHSA-gv7w-rqvm-qjhr</a>)</p> <p>The previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.</p> <p>Note that esbuild's Deno API installs from <code>registry.npmjs.org</code> by default, but allows the <code>NPM_CONFIG_REGISTRY</code> environment variable to override this with a custom package registry. This change means that the esbuild executable served by <code>NPM_CONFIG_REGISTRY</code> must now match the expected content.</p> <p>Thanks to <a href="https://github.com/sondt99"><code>@​sondt99</code></a> for reporting this issue.</p> </li> <li> <p>Avoid inlining <code>using</code> and <code>await using</code> declarations (<a href="https://redirect.github.com/evanw/esbuild/issues/4482">#4482</a>)</p> <p>Previously esbuild's minifier sometimes incorrectly inlined <code>using</code> and <code>await using</code> declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for <code>let</code> and <code>const</code> declarations by avoiding doing it for <code>var</code> declarations, which no longer worked when more declaration types were added. Here's an example:</p> <pre lang="js"><code>// Original code { using x = new Resource() x.activate() } <p>// Old output (with --minify)<br /> new Resource().activate();</p> <p>// New output (with --minify)<br /> {using e=new Resource;e.activate()}<br /> </code></pre></p> </li> <li> <p>Fix module evaluation when an error is thrown (<a href="https://redirect.github.com/evanw/esbuild/issues/4461">#4461</a>, <a href="https://redirect.github.com/evanw/esbuild/pull/4467">#4467</a>)</p> <p>If an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if <code>import()</code> or <code>require()</code> is used to import a module multiple times. The thrown error is supposed to be thrown by every call to <code>import()</code> or <code>require()</code>, not just the first. With this release, esbuild will now throw the same error every time you call <code>import()</code> or <code>require()</code> on a module that throws during its evaluation.</p> </li> <li> <p>Fix some edge cases around the <code>new</code> operator (<a href="https://redirect.github.com/evanw/esbuild/issues/4477">#4477</a>)</p> <p>Previously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a <code>new</code> expression (specifically an optional chain and/or a tagged template literal). The generated code for the <code>new</code> target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the <code>new</code> target in parentheses. Here is an example of some affected code:</p> <pre lang="js"><code>// Original code new (foo()`bar`)() new (foo()?.bar)() <p>// Old output<br /> new foo()<code>bar</code>();<br /> new (foo())?.bar();</p> <p></code></pre></p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/evanw/esbuild/blob/main/CHANGELOG.md">esbuild's changelog</a>.</em></p> <blockquote> <h2>0.28.1</h2> <ul> <li> <p>Disallow <code>\</code> in local development server HTTP requests (<a href="https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr">GHSA-g7r4-m6w7-qqqr</a>)</p> <p>This release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a <code>\</code> backslash character. It happened due to the use of Go's <code>path.Clean()</code> function, which only handles Unix-style <code>/</code> characters. HTTP requests with paths containing <code>\</code> are no longer allowed.</p> <p>Thanks to <a href="https://github.com/dellalibera"><code>@​dellalibera</code></a> for reporting this issue.</p> </li> <li> <p>Add integrity checks to the Deno API (<a href="https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr">GHSA-gv7w-rqvm-qjhr</a>)</p> <p>The previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.</p> <p>Note that esbuild's Deno API installs from <code>registry.npmjs.org</code> by default, but allows the <code>NPM_CONFIG_REGISTRY</code> environment variable to override this with a custom package registry. This change means that the esbuild executable served by <code>NPM_CONFIG_REGISTRY</code> must now match the expected content.</p> <p>Thanks to <a href="https://github.com/sondt99"><code>@​sondt99</code></a> for reporting this issue.</p> </li> <li> <p>Avoid inlining <code>using</code> and <code>await using</code> declarations (<a href="https://redirect.github.com/evanw/esbuild/issues/4482">#4482</a>)</p> <p>Previously esbuild's minifier sometimes incorrectly inlined <code>using</code> and <code>await using</code> declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for <code>let</code> and <code>const</code> declarations by avoiding doing it for <code>var</code> declarations, which no longer worked when more declaration types were added. Here's an example:</p> <pre lang="js"><code>// Original code { using x = new Resource() x.activate() } <p>// Old output (with --minify)<br /> new Resource().activate();</p> <p>// New output (with --minify)<br /> {using e=new Resource;e.activate()}<br /> </code></pre></p> </li> <li> <p>Fix module evaluation when an error is thrown (<a href="https://redirect.github.com/evanw/esbuild/issues/4461">#4461</a>, <a href="https://redirect.github.com/evanw/esbuild/pull/4467">#4467</a>)</p> <p>If an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if <code>import()</code> or <code>require()</code> is used to import a module multiple times. The thrown error is supposed to be thrown by every call to <code>import()</code> or <code>require()</code>, not just the first. With this release, esbuild will now throw the same error every time you call <code>import()</code> or <code>require()</code> on a module that throws during its evaluation.</p> </li> <li> <p>Fix some edge cases around the <code>new</code> operator (<a href="https://redirect.github.com/evanw/esbuild/issues/4477">#4477</a>)</p> <p>Previously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a <code>new</code> expression (specifically an optional chain and/or a tagged template literal). The generated code for the <code>new</code> target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the <code>new</code> target in parentheses. Here is an example of some affected code:</p> <pre lang="js"><code>// Original code new (foo()`bar`)() new (foo()?.bar)() <p>// Old output<br /> new foo()<code>bar</code>();<br /> new (foo())?.bar();<br /> </code></pre></p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/evanw/esbuild/commit/bb9db84c02433fbe37b3509f53f9f3e3cc48725e"><code>bb9db84</code></a> publish 0.28.1 to npm</li> <li><a href="https://github.com/evanw/esbuild/commit/9ff053e53b8eeb990f59355dbea365277ac45ee2"><code>9ff053e</code></a> security: add integrity checks to the Deno API</li> <li><a href="https://github.com/evanw/esbuild/commit/0a9bf2135b67c7e28989a5ba19f0f000805a5ab5"><code>0a9bf21</code></a> enforce non-negative size in gzip parser</li> <li><a href="https://github.com/evanw/esbuild/commit/e2a1a7132058ee067fe736eac15f695861b8654e"><code>e2a1a71</code></a> security: forbid <code>\\</code> in local dev server requests</li> <li><a href="https://github.com/evanw/esbuild/commit/83a2cbfc35809f4fd5152da59572d7bed7739d78"><code>83a2cbf</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4482">#4482</a>: don't inline <code>using</code> declarations</li> <li><a href="https://github.com/evanw/esbuild/commit/308ad745d824c77bc607603451b257d0f2fd9a38"><code>308ad74</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4471">#4471</a>: renaming of nested <code>var</code> declarations</li> <li><a href="https://github.com/evanw/esbuild/commit/f013f5f99a015bce92ec48d49181d4ad3177b29b"><code>f013f5f</code></a> fix some typos</li> <li><a href="https://github.com/evanw/esbuild/commit/aafd6e48b1088336a5f5a17e930be7e840d43d8c"><code>aafd6e4</code></a> chore: fix some minor issues in comments (<a href="https://redirect.github.com/evanw/esbuild/issues/4462">#4462</a>)</li> <li><a href="https://github.com/evanw/esbuild/commit/15300c30b5e22f7cfcbed850c246d35095658386"><code>15300c3</code></a> follow up: cjs evaluation fixes</li> <li><a href="https://github.com/evanw/esbuild/commit/1bda0c31d7697c0af44b3ab39b81e599e559a395"><code>1bda0c3</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4461">#4461</a>, fix <a href="https://redirect.github.com/evanw/esbuild/issues/4467">#4467</a>: esm evaluation fixes</li> <li>Additional commits viewable in <a href="https://github.com/evanw/esbuild/compare/v0.28.0...v0.28.1">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details>
amoussa1229 commented 2026-07-02 19:29:20 +00:00 (Migrated from github.com)

Closing due to deprecation in the near future

Closing due to deprecation in the near future
dependabot[bot] commented 2026-07-02 19:29:23 +00:00 (Migrated from github.com)

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure [ignore rules](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#ignore) in dependabot.yml
This repo is archived. You cannot comment on pull requests.
No description provided.