chore(release): 2.258.0 - #38086
Merged
Merged
Conversation
… npm_and_yarn group across 1 directory (#37966) Bumps the npm_and_yarn group with 1 update in the / directory: [@smithy/config-resolver](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/config-resolver). Updates `@smithy/config-resolver` from 3.0.13 to 4.5.4 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/smithy-lang/smithy-typescript/releases">@smithy/config-resolver's releases</a>.</em></p> <blockquote> <h2><code>@smithy/config-resolver</code><a href="https://github.com/4"><code>@4</code></a>.5.4</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [9eaa5c6] <ul> <li><code>@smithy/core</code><a href="https://github.com/3"><code>@3</code></a>.24.4</li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/smithy-lang/smithy-typescript/blob/main/packages/config-resolver/CHANGELOG.md">@smithy/config-resolver's changelog</a>.</em></p> <blockquote> <h2>4.5.4</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [9eaa5c6] <ul> <li><code>@smithy/core</code><a href="https://github.com/3"><code>@3</code></a>.24.4</li> </ul> </li> </ul> <h2>4.5.3</h2> <h3>Patch Changes</h3> <ul> <li><code>@smithy/core</code><a href="https://github.com/3"><code>@3</code></a>.24.3</li> </ul> <h2>4.5.2</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [6d4eb8a] <ul> <li><code>@smithy/core</code><a href="https://github.com/3"><code>@3</code></a>.24.2</li> </ul> </li> </ul> <h2>4.5.1</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [2dc5cf6]</li> <li>Updated dependencies [1d0ff86] <ul> <li><code>@smithy/core</code><a href="https://github.com/3"><code>@3</code></a>.24.1</li> </ul> </li> </ul> <h2>4.5.0</h2> <h3>Minor Changes</h3> <ul> <li>540aeb4: consolidate core/retry and related cleanup</li> <li>4f30af1: consolidation for core/protocols</li> <li>62fed78: package consolidation for core/config</li> <li>f21bf6b: consolidate packages into core/client</li> </ul> <h3>Patch Changes</h3> <ul> <li>0be0b36: clean up exported API surface</li> <li>Updated dependencies [ee92b6b]</li> <li>Updated dependencies [540aeb4]</li> <li>Updated dependencies [0be0b36]</li> <li>Updated dependencies [4f30af1]</li> <li>Updated dependencies [8963b91]</li> <li>Updated dependencies [fb323fb]</li> <li>Updated dependencies [9194e9f]</li> <li>Updated dependencies [7ec62a0]</li> <li>Updated dependencies [62fed78]</li> <li>Updated dependencies [cad44fc]</li> </ul> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/c60fc62b31fd714a228aa80cc2ce672f389913cc"><code>c60fc62</code></a> Version NPM packages</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/396de9c6de6020bdc353e338d60afdbe196e6bc1"><code>396de9c</code></a> Version NPM packages</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/0a078e1d7a6af4901aab2c6c4eb964f4d0f91b40"><code>0a078e1</code></a> Version NPM packages</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/6b733627f88522b81d2f264a25967752d516b872"><code>6b73362</code></a> Version NPM packages</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/bf13524f10a780d7404e16686d439caf9ee871f0"><code>bf13524</code></a> chore(packages): add build:types standalone script to stub packages (<a href="https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/config-resolver/issues/2019">#2019</a>)</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/e1bede0f47296cdd8d93a715304979a63b51ec8c"><code>e1bede0</code></a> Version NPM packages</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/0be0b361fa588240e7c8998046385963d391030a"><code>0be0b36</code></a> chore(scripts): add type symbols to api snapshot (<a href="https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/config-resolver/issues/2004">#2004</a>)</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/540aeb4a66e9a7cfe14dde87a14c6557580a6974"><code>540aeb4</code></a> chore(core/retry): consolidate packages (<a href="https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/config-resolver/issues/2002">#2002</a>)</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/62fed781fa0fdfca43b02b7ab5031be52545e3e0"><code>62fed78</code></a> chore(core/config): consolidate packages (<a href="https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/config-resolver/issues/1992">#1992</a>)</li> <li><a href="https://github.com/smithy-lang/smithy-typescript/commit/f21bf6b04e98711aae56aa497e956a4f7c579a12"><code>f21bf6b</code></a> chore(core/client): package consolidation (<a href="https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/config-resolver/issues/1991">#1991</a>)</li> <li>Additional commits viewable in <a href="https://github.com/smithy-lang/smithy-typescript/commits/@smithy/config-resolver@4.5.4/packages/config-resolver">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/aws/aws-cdk/network/alerts). </details>
…ed lambdas (#37634) ### Issue # (if applicable) Closes #34307 ### Reason for this change Custom-resource handler Lambdas generated by the handler framework (e.g., `aws-ses` drop-spam, `aws-logs` log-retention, many others) stage their code via: ```ts code: lambda.Code.fromAsset(path.join(__dirname, 'handler')) ``` Because no explicit `assetHash` is provided, `AssetStaging` fingerprints the bundled directory at synth time and the fingerprint includes filesystem metadata (mtime, mode). Two synths of identical source on different machines therefore produce different S3 object keys, so `cdk diff` shows spurious Lambda asset updates against the cloud — even when the bundled bytes are byte-for-byte identical. ### Description of changes - Added `calculateDirectoryHash` to `packages/@aws-cdk/custom-resource-handlers/scripts/generate.ts`. It walks the bundled handler directory deterministically (sorted entries, SHA-256 over relative paths + file content bytes) and computes a content-only hash. - Plumbed the hash through `HandlerFrameworkModule.build → HandlerFrameworkClass` via a new optional `sourceHash` field on `HandlerFrameworkClassProps`. - When `sourceHash` is supplied, the code generator emits `Code.fromAsset(path, { assetHash: '<hash>' })` — `AssetStaging` then uses it as the `CUSTOM` fingerprint so the S3 object key depends only on the bundled bytes. - Applied only to `FUNCTION` and `SINGLETON_FUNCTION` components. `CUSTOM_RESOURCE_PROVIDER` is intentionally skipped because `CustomResourceProviderBase` mixes `__entrypoint__.js` into the staged directory at synth time, which would cause a generate-time hash to drift from the final bundle. ### Description of how you validated changes - Added unit tests in `packages/@aws-cdk/custom-resource-handlers/test/custom-resources-framework/framework.test.ts` asserting that the generated TypeScript contains the expected `assetHash` for both `FUNCTION` and `SINGLETON_FUNCTION` components. All 11 tests in the file pass. - Rebuilt the custom-resource-handlers package and aws-cdk-lib, and synthesized a test stack containing `s3.Bucket { autoDeleteObjects: true }` (CRP-based, unchanged) and `ses.ReceiptRuleSet { dropSpam: true }` (singleton-based, hash-pinned). Confirmed: - the generated `drop-spam-provider.generated.ts` now emits a baked `assetHash`; - the S3 object key for the drop-spam asset is stable across multiple synths even after changing the handler file's mtime (2020 vs 2099) and mode (644 vs 755) — previously the fingerprint would have changed. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Issue The `onTimeout` handler in `@aws-cdk/integ-tests-alpha` serializes the full CloudFormation custom resource event into the failure reason, including the `ResponseURL` which contains pre-signed S3 credentials (temporary STS session token, access key, and signature). ### Fix Redact `ResponseURL` before stringifying in the `onTimeout` handler, matching the existing sanitization pattern already used in `handler()` and `isComplete()` log statements in the same file. ### What was changed - `packages/@aws-cdk/integ-tests-alpha/lib/assertions/providers/lambda-handler/index.ts`: Spread the event with `ResponseURL: '...'` before `JSON.stringify` in `onTimeout()` ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…#37976) ### Issue # (if applicable) n/a ### Reason for this change A recent PR proposed making a Dashboard L2 implement `ITaggableV2`, with the rationale that `TagManager.of(dashboard)` was returning `undefined`. That is the intended behavior — only L1 (`Cfn*`) resources implement `ITaggable`/`ITaggableV2`, and users tag at any scope via `Tags.of(scope).add(...)`, which traverses the construct tree and tags every taggable L1 underneath. The rule lived in our heads but was not written down anywhere, so neither human contributors nor AI authoring tools could find it; the resulting PR was sent in good faith and rejected for a reason that wasn't documented. ### Description of changes The agent-oriented rule belongs in `docs/AGENTS_CONSTRUCT_DESIGN.md`, where the existing "Tags & Secrets" entry was a single bullet. I split it into a dedicated `### Tags` section with explicit MUST/MUST NOT statements, an anti-pattern showing an L2 implementing `ITaggableV2`, and the correct pattern showing the L2 just exposing a `tags` prop wired to its L1 default child. The human-oriented `### Tags` section in `docs/DESIGN_GUIDELINES.md` was rewritten in parallel: the previous example (`myConstruct.node.apply(new cdk.Tag(...))`) referenced an API that no longer exists and was replaced with `Tags.of(myConstruct).add(...)`, and the same L2-vs-L1 callout was added with a deep link to the agents doc. I also added one bullet to the L2 design rules in `AGENTS.md` itself so the rule shows up in the layer-model section that any agent reads on entry, and a small principle bullet under "Your Role" that asks an agent to surface task mismatches when its briefing doesn't match this file's scope (the upstream cause here was an authoring tool being prompted with an RFC-shaped power for a code change). The 2019 `design/tagging-API-change.md` document was removed as part of the same change. It was a historical RFC for the `applyAspect → Tag.add` rename, predates `ITaggableV2` entirely, was not linked from anywhere, and gave conflicting advice to anyone who landed on it. There is no replacement design doc — the canonical advice now lives in the two `Tags` sections above. ### Describe any new or updated permissions being added n/a — documentation only. ### Description of how you validated changes Verified the new heading anchors resolve (`docs/AGENTS_CONSTRUCT_DESIGN.md#tags` is referenced from both `AGENTS.md` and `docs/DESIGN_GUIDELINES.md`). Ran `markdownlint` on the three modified files; the only flagged errors are pre-existing repo-wide lint debt on lines this PR did not touch. Confirmed nothing in the repo links to the deleted `design/tagging-API-change.md` before removing it. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
… on Runtime (#37812) ### Issue # (if applicable) Closes #37796. ### Reason for this change The `Runtime` L2 construct in `aws-cdk-lib/aws-bedrockagentcore` does not expose an accessor for the AgentCore-managed application log group at `/aws/bedrock-agentcore/runtimes/{agentRuntimeId}-DEFAULT` (where the default endpoint's container stdout is written). Consumers that want to attach metric filters, subscription filters, or alarms have to construct the path as a string literal: ```ts const logGroupName = `/aws/bedrock-agentcore/runtimes/${runtime.agentRuntimeId}-DEFAULT`; const logGroup = logs.LogGroup.fromLogGroupName(this, 'AppLogGroup', logGroupName); ``` Hardcoding the path is brittle. If AWS ever adjusts the format (for example by introducing an endpoint suffix), every consumer silently breaks with zero-match metric filters — and the failure mode (alarms staying in `OK` because no metric samples are produced) is hard to notice. ### Description of changes Add a public `applicationLogGroup: logs.ILogGroup` property to the `IBedrockAgentRuntime` interface, implemented as a memoized getter on `RuntimeBase`. The getter returns `logs.LogGroup.fromLogGroupName(this, 'ApplicationLogGroup', '/aws/bedrock-agentcore/runtimes/${agentRuntimeId}-DEFAULT')`, so the log group name (and the derived ARN) are produced from the runtime's `agentRuntimeId` instead of being hardcoded by each consumer. The reference is constructed lazily on first access so runtimes that never use it do not add an imported child to the construct tree. ### Describe any new or updated permissions being added None. The new property returns an imported `ILogGroup` reference and does not generate any IAM policy or modify any existing policy. The execution-role permissions added by `Runtime` already cover the relevant log group ARN pattern (`/aws/bedrock-agentcore/runtimes/*`). ### Description of how you validated changes Unit tests added in `packages/aws-cdk-lib/aws-bedrockagentcore/test/agentcore/runtime/runtime.test.ts` under `describe('Runtime applicationLogGroup tests')`: - The accessor's `logGroupName` resolves to `Fn::Join` over the runtime's `AgentRuntimeId` attribute, producing `/aws/bedrock-agentcore/runtimes/{ref}-DEFAULT`. - The accessor's `logGroupArn` resolves to the `COLON_RESOURCE_NAME` ARN format and ends with `:*`. - The log group can be passed directly to `logs.MetricFilter` and renders the expected `AWS::Logs::MetricFilter` resource referencing the runtime's `AgentRuntimeId`. - The getter is memoized — `runtime.applicationLogGroup === runtime.applicationLogGroup`. - `Runtime.fromAgentRuntimeAttributes` exposes the property using the literal `agentRuntimeId` from attributes. An integration test was also added at `packages/@aws-cdk-testing/framework-integ/test/aws-bedrockagentcore/test/agentcore/runtime/integ.runtime-application-log-group.ts`, which deploys a `Runtime` and wires `applicationLogGroup` into a `MetricFilter` and a CloudWatch `Alarm`. It was deployed successfully and its snapshot is included. A README example was added under `#### Application log group` using the `fixture=default` rosetta fixture. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Reason for this change The CDK CLI `validate` command (aws/aws-cdk-cli#1515) introduces a new validation report schema in `cloud-assembly-schema`. The framework needs to produce output matching this new schema so the CLI can consume it via `Manifest.loadValidationReport`. The old report format (`policy-validation-report.json`) must remain available for backwards compatibility with older CLI versions. ### Description of changes - Adds a new `formatJson` method to `PolicyValidationReportFormatter` that produces the new schema-compliant report format: - Top-level `version` field (cloud assembly schema version) - Flat `pluginName`/`conclusion` (replaces nested `summary`) - Typed `severity` enum (`fatal|error|warning|info|custom`) - `violatingConstructs` with `constructFqn`, `libraryVersion`, `cloudFormationResource`, `stackTraces` - `suggestedFix` (replaces `fix`) - New report is written to `validation-report.json` by default - Old report (`policy-validation-report.json`) is only written when `@aws-cdk/core:validationReportJson` context key is set to `true` - Renames old format interfaces to `Legacy*`, new ones get the clean names - Adds constants to `cx-api`: `VALIDATION_REPORT_FILE`, `LEGACY_VALIDATION_REPORT_FILE`, `VALIDATION_REPORT_JSON_CONTEXT` ### Describe any new or updated permissions being added N/A ### Description of how you validated changes - All 47 validation unit tests pass - Added tests for legacy report opt-in and default behavior - Verified report output passes JSON schema validation matching `validation-report.schema.json` from the CLI PR ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
Make the code slightly more tailored to the specific use cases, bypassing slow paths more often if we can quickly determine that a particular field doesn't contain tokens. Improves token resolution speed by ~25%, saving around a second on complex applications. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…update (#37979) Bumps the npm_and_yarn group with 1 update in the /packages/@aws-cdk-testing/framework-integ/test/aws-route53-targets/test/integ.elastic-beanstalk-environment-target-assets directory: [qs](https://github.com/ljharb/qs). Bumps the npm_and_yarn group with 1 update in the /packages/@aws-cdk-testing/framework-integ/test/aws-route53-targets/test/integ.elastic-beanstalk-environment-target.js.snapshot/asset.fdbbabeab76a41188fbdf182a8c09848a1ea72525524d7bc2c373c6e1eb2c1c4.elastic-beanstalk-environment-target-assets directory: [qs](https://github.com/ljharb/qs). Updates `qs` from 6.14.2 to 6.15.2 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ljharb/qs/blob/main/CHANGELOG.md">qs's changelog</a>.</em></p> <blockquote> <h2><strong>6.15.2</strong></h2> <ul> <li>[Fix] <code>stringify</code>: skip null/undefined entries in <code>arrayFormat: 'comma'</code> + <code>encodeValuesOnly</code> instead of crashing in <code>encoder</code></li> <li>[Fix] <code>stringify</code>: use configured <code>delimiter</code> after <code>charsetSentinel</code> (<a href="https://redirect.github.com/ljharb/qs/issues/555">#555</a>)</li> <li>[Fix] <code>stringify</code>: apply <code>formatter</code> to encoded key under <code>strictNullHandling</code> (<a href="https://redirect.github.com/ljharb/qs/issues/554">#554</a>)</li> <li>[Fix] <code>stringify</code>: skip null/undefined filter-array entries instead of crashing in <code>encoder</code> (<a href="https://redirect.github.com/ljharb/qs/issues/551">#551</a>)</li> <li>[Fix] <code>parse</code>: handle nested bracket groups and add regression tests (<a href="https://redirect.github.com/ljharb/qs/issues/530">#530</a>)</li> <li>[readme] fix grammar (<a href="https://redirect.github.com/ljharb/qs/issues/550">#550</a>)</li> <li>[Dev Deps] update <code>@ljharb/eslint-config</code></li> <li>[Tests] add regression tests for keys containing percent-encoded bracket text</li> </ul> <h2><strong>6.15.1</strong></h2> <ul> <li>[Fix] <code>parse</code>: <code>parameterLimit: Infinity</code> with <code>throwOnLimitExceeded: true</code> silently drops all parameters</li> <li>[Deps] update <code>@ljharb/eslint-config</code></li> <li>[Dev Deps] update <code>@ljharb/eslint-config</code>, <code>iconv-lite</code></li> <li>[Tests] increase coverage</li> </ul> <h2><strong>6.15.0</strong></h2> <ul> <li>[New] <code>parse</code>: add <code>strictMerge</code> option to wrap object/primitive conflicts in an array (<a href="https://redirect.github.com/ljharb/qs/issues/425">#425</a>, <a href="https://redirect.github.com/ljharb/qs/issues/122">#122</a>)</li> <li>[Fix] <code>duplicates</code> option should not apply to bracket notation keys (<a href="https://redirect.github.com/ljharb/qs/issues/514">#514</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ljharb/qs/commit/9aca4076fe788338c67cf7e115f0be6bc58d85a8"><code>9aca407</code></a> v6.15.2</li> <li><a href="https://github.com/ljharb/qs/commit/5e33d33447ed0bf1ddab9abc41d27dea4687d992"><code>5e33d33</code></a> [Dev Deps] update <code>@ljharb/eslint-config</code></li> <li><a href="https://github.com/ljharb/qs/commit/21f80b33e5c8b3f7eba1034fff0da4a4a37a1d41"><code>21f80b3</code></a> [Fix] <code>stringify</code>: skip null/undefined entries in <code>arrayFormat: 'comma'</code> + `e...</li> <li><a href="https://github.com/ljharb/qs/commit/a0a81ea2071acce3eff41a040f719ac8f5c4f64c"><code>a0a81ea</code></a> [Fix] <code>stringify</code>: use configured <code>delimiter</code> after <code>charsetSentinel</code></li> <li><a href="https://github.com/ljharb/qs/commit/e3062f78f5233b338ceeb8e8dfa5a07dea4b32a8"><code>e3062f7</code></a> [Fix] <code>stringify</code>: apply <code>formatter</code> to encoded key under <code>strictNullHandling</code></li> <li><a href="https://github.com/ljharb/qs/commit/0c180a40adb8c6703fffc85b2ff06ca209f5c1e0"><code>0c180a4</code></a> [Fix] <code>stringify</code>: skip null/undefined filter-array entries instead of crashi...</li> <li><a href="https://github.com/ljharb/qs/commit/3a8b94aec19bd664720f6f6b1e66c4a0dfe4b656"><code>3a8b94a</code></a> [Tests] add regression tests for keys containing percent-encoded bracket text</li> <li><a href="https://github.com/ljharb/qs/commit/96755abd357c0e534dd3442a84a04d08864bfe0d"><code>96755ab</code></a> [readme] fix grammar</li> <li><a href="https://github.com/ljharb/qs/commit/a419ce5bbfcdb98a299f1a0bb47ea055baef20e6"><code>a419ce5</code></a> [Fix] <code>parse</code>: handle nested bracket groups and add regression tests</li> <li><a href="https://github.com/ljharb/qs/commit/3f5e1c528c967d915096787efbffa73cf6044170"><code>3f5e1c5</code></a> v6.15.1</li> <li>Additional commits viewable in <a href="https://github.com/ljharb/qs/compare/v6.14.2...v6.15.2">compare view</a></li> </ul> </details> <br /> Updates `qs` from 6.14.2 to 6.15.2 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ljharb/qs/blob/main/CHANGELOG.md">qs's changelog</a>.</em></p> <blockquote> <h2><strong>6.15.2</strong></h2> <ul> <li>[Fix] <code>stringify</code>: skip null/undefined entries in <code>arrayFormat: 'comma'</code> + <code>encodeValuesOnly</code> instead of crashing in <code>encoder</code></li> <li>[Fix] <code>stringify</code>: use configured <code>delimiter</code> after <code>charsetSentinel</code> (<a href="https://redirect.github.com/ljharb/qs/issues/555">#555</a>)</li> <li>[Fix] <code>stringify</code>: apply <code>formatter</code> to encoded key under <code>strictNullHandling</code> (<a href="https://redirect.github.com/ljharb/qs/issues/554">#554</a>)</li> <li>[Fix] <code>stringify</code>: skip null/undefined filter-array entries instead of crashing in <code>encoder</code> (<a href="https://redirect.github.com/ljharb/qs/issues/551">#551</a>)</li> <li>[Fix] <code>parse</code>: handle nested bracket groups and add regression tests (<a href="https://redirect.github.com/ljharb/qs/issues/530">#530</a>)</li> <li>[readme] fix grammar (<a href="https://redirect.github.com/ljharb/qs/issues/550">#550</a>)</li> <li>[Dev Deps] update <code>@ljharb/eslint-config</code></li> <li>[Tests] add regression tests for keys containing percent-encoded bracket text</li> </ul> <h2><strong>6.15.1</strong></h2> <ul> <li>[Fix] <code>parse</code>: <code>parameterLimit: Infinity</code> with <code>throwOnLimitExceeded: true</code> silently drops all parameters</li> <li>[Deps] update <code>@ljharb/eslint-config</code></li> <li>[Dev Deps] update <code>@ljharb/eslint-config</code>, <code>iconv-lite</code></li> <li>[Tests] increase coverage</li> </ul> <h2><strong>6.15.0</strong></h2> <ul> <li>[New] <code>parse</code>: add <code>strictMerge</code> option to wrap object/primitive conflicts in an array (<a href="https://redirect.github.com/ljharb/qs/issues/425">#425</a>, <a href="https://redirect.github.com/ljharb/qs/issues/122">#122</a>)</li> <li>[Fix] <code>duplicates</code> option should not apply to bracket notation keys (<a href="https://redirect.github.com/ljharb/qs/issues/514">#514</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ljharb/qs/commit/9aca4076fe788338c67cf7e115f0be6bc58d85a8"><code>9aca407</code></a> v6.15.2</li> <li><a href="https://github.com/ljharb/qs/commit/5e33d33447ed0bf1ddab9abc41d27dea4687d992"><code>5e33d33</code></a> [Dev Deps] update <code>@ljharb/eslint-config</code></li> <li><a href="https://github.com/ljharb/qs/commit/21f80b33e5c8b3f7eba1034fff0da4a4a37a1d41"><code>21f80b3</code></a> [Fix] <code>stringify</code>: skip null/undefined entries in <code>arrayFormat: 'comma'</code> + `e...</li> <li><a href="https://github.com/ljharb/qs/commit/a0a81ea2071acce3eff41a040f719ac8f5c4f64c"><code>a0a81ea</code></a> [Fix] <code>stringify</code>: use configured <code>delimiter</code> after <code>charsetSentinel</code></li> <li><a href="https://github.com/ljharb/qs/commit/e3062f78f5233b338ceeb8e8dfa5a07dea4b32a8"><code>e3062f7</code></a> [Fix] <code>stringify</code>: apply <code>formatter</code> to encoded key under <code>strictNullHandling</code></li> <li><a href="https://github.com/ljharb/qs/commit/0c180a40adb8c6703fffc85b2ff06ca209f5c1e0"><code>0c180a4</code></a> [Fix] <code>stringify</code>: skip null/undefined filter-array entries instead of crashi...</li> <li><a href="https://github.com/ljharb/qs/commit/3a8b94aec19bd664720f6f6b1e66c4a0dfe4b656"><code>3a8b94a</code></a> [Tests] add regression tests for keys containing percent-encoded bracket text</li> <li><a href="https://github.com/ljharb/qs/commit/96755abd357c0e534dd3442a84a04d08864bfe0d"><code>96755ab</code></a> [readme] fix grammar</li> <li><a href="https://github.com/ljharb/qs/commit/a419ce5bbfcdb98a299f1a0bb47ea055baef20e6"><code>a419ce5</code></a> [Fix] <code>parse</code>: handle nested bracket groups and add regression tests</li> <li><a href="https://github.com/ljharb/qs/commit/3f5e1c528c967d915096787efbffa73cf6044170"><code>3f5e1c5</code></a> v6.15.1</li> <li>Additional commits viewable in <a href="https://github.com/ljharb/qs/compare/v6.14.2...v6.15.2">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/aws/aws-cdk/network/alerts). </details>
…tion (#37989) ## Summary - Context values passed via `--context key=value` on the CLI arrive as strings in `CDK_CONTEXT_JSON`. The previous code used `?? true` which only catches `null`/`undefined`, so the string `"false"` (truthy in JS) caused `failSynthOnValidationErrors` to erroneously trigger — printing the legacy report to stderr and setting `process.exitCode = 1`, killing the synth subprocess before the CLI could read `validation-report.json`. - Introduced a `getBooleanContext` helper that correctly handles both boolean `false` and string `"false"`, with a configurable default. - Applied the same fix to `writeLegacyReport` context key for consistency. Context: https://github.com/aws/aws-cdk-cli/pull/630/changes establishes that context values arriving from the CLI are always strings, so boolean context keys must handle the string `"false"` explicitly. ## Test plan - [x] Added unit test: `failSynthOnValidationErrors="false" (string) works the same as boolean false` - [x] Existing test `failSynthOnValidationErrors=false writes JSON but does not print or fail` continues to pass - [x] Full validation test suite passes (48/48)
…nown identifiers (#37977) Metric math validation reports the following incorrect warning: ``` Math expression 'LAMBDA("${Token[TOKEN.1937]}", "gc", "count")' references unknown identifiers: oken, gc, count. Please add them to the 'usingMetrics' map. [ack: CloudWatch:Math:UnknownIdentifier] ``` Words inside quotation marks should not be considered identifiers, so do not need to be validated. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Issue # (if applicable) N/A — follow-up to #37876 (graduation to stable). ### Reason for this change The bedrock-agentcore module graduated to stable (`aws-cdk-lib/aws-bedrockagentcore`) in #37876. All submodules except Policy moved to stable. This PR marks the graduated exports in the alpha package as `@deprecated` so customers know to migrate. ### Description of changes Added `@deprecated` JSDoc tags to all non-Policy exports in `@aws-cdk/aws-bedrock-agentcore-alpha`, pointing users to `aws-cdk-lib/aws-bedrockagentcore`. Deprecated submodules: Runtime, Gateway, Memory, Tools, Evaluation, Identity, Network, Common. The Policy submodule (PolicyEngine, Policy, PolicyStatement, PolicyValidationMode) remains active in alpha due to a pending CloudFormation stabilization. ### Describe any new or updated permissions being added None. ### Description of how you validated changes - Build the package with current changes ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…#37752) ### Issue # (if applicable) Closes #37414. ### Reason for this change `AlbControllerVersion` only included versions up to `V2_8_2`. Users who needed v2.8.3+ or v3.x were forced to use the `AlbControllerVersion.of()` escape hatch and maintain their own IAM policy document — tracking upstream policy changes manually and passing the policy explicitly via the `policy` prop. This was brittle and created ongoing operational burden, especially when security scanners flagged outdated controller versions. ### Description of changes Added built-in support for AWS Load Balancer Controller versions v2.8.3 through v3.2.2 (24 versions) in both `aws-eks` and `aws-eks-v2` modules. - Added `AlbControllerVersion` static constants `V2_8_3` through `V3_2_2` with correct Helm chart version mappings sourced from the [eks-charts Chart.yaml history](https://github.com/aws/eks-charts) - Bundled IAM policy JSON files for each new version, sourced from the [upstream releases](https://github.com/kubernetes-sigs/aws-load-balancer-controller/releases) - Updated README examples and integ test `LATEST_VERSION` to `V3_2_2` - Switched integ tests from deprecated `OpenIdConnectProvider` to `OidcProviderNative` (`EKS_USE_NATIVE_OIDC_PROVIDER: true`) to resolve a `DeprecationError` that caused integ test synthesis to fail under `JSII_DEPRECATED=fail` ### Describe any new or updated permissions being added No new IAM permissions are introduced by the CDK construct itself. The bundled IAM policy JSON files reflect the permissions required by each version of the AWS Load Balancer Controller as published upstream. The policy content for v3.x differs from v2.x (upstream change), but the CDK construct logic for applying the policy is unchanged. ### Description of how you validated changes - Unit tests pass for `aws-eks` and `aws-eks-v2` with no modifications required — the existing `test.each(Object.values(AlbControllerVersion))` and `all vended policies are valid` tests automatically cover all newly added versions and policy files - Integration test `integ.alb-controller` passed in `ap-northeast-1` for both `aws-eks` and `aws-eks-v2` with `LATEST_VERSION` set to `V3_2_2` - Integ test snapshots were fully regenerated due to the `EKS_USE_NATIVE_OIDC_PROVIDER` switch (existing snapshot used the deprecated Custom Resource-backed OIDC provider; new snapshot uses the native `AWS::IAM::OIDCProvider` resource) ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…38004) (This is a re-roll of #37919, which mysteriously got reverted by a cherry-picked `revert` that predates it. That PR was itself a re-roll of #37843, to account for the warning emitted by `fs-extra` if it detects monkey patching) If the framework determines that synthesis is taking a long time (more than 10 seconds per stack, which is extremely unlikely high; we may adjust this threshold over time) it will emit a file with performance counters to the file indicated by the `$CDK_PERF_COUNTERS_FILE` environment variable. The CLI is responsible for sending this report in as telemetry, or not if disabled. The reporting can be disabled altogether by passing a property to `App`, or setting a context key in `cdk.json`: ```ts new App({ performanceReporting: false, }); ``` ```js { "context": { "aws:cdk:performance-reporting": false, }, } ``` Performance profiling works by making functions emit `measure` events to the Node [performance measurement APIs](https://nodejs.org/api/perf_hooks.html). The new `perf.ts` file provides a number of helper functions to decorate classes and functions to make them emit measurement information. A number of CDK APIs that we suspect of being slow are annotated by default, and some global NodeJS APIs that are typical sources of slowness (filesystem access, subprocess spawns) are annotated as well. CDK users are free to use these functions as well and the `printPerfCounters()` function to do their own profiling. At the end of synthesis, only those counters annotated with `{ telemetry: true }` are written to the telemetry file and sent to the server. Here is an example of a set of perf counters (extracted from a test): ```js { 'phase:Construction': 12154, 'phase:Construction(cnt)': 1, 'bundle:NodejsFunction': 12133, 'bundle:NodejsFunction(cnt)': 2, 'DockerImage.fromBuild': 10957, 'DockerImage.fromBuild(cnt)': 1, 'phase:Load': 3940, 'phase:Load(cnt)': 1, 'AssetBundlingBindMount.run': 1176, 'AssetBundlingBindMount.run(cnt)': 1, 'phase:Synthesis': 26, 'phase:Synthesis(cnt)': 1, 'Stack.resolve': 7, 'Stack.resolve(cnt)': 47, 'FileSystem.fingerprint': 1, 'FileSystem.fingerprint(cnt)': 1, 'FileSystem.isEmpty': 0, 'FileSystem.isEmpty(cnt)': 1 } ``` ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license* ### Issue # (if applicable) Closes #<issue number here>. ### Reason for this change ### Description of changes ### Describe any new or updated permissions being added ### Description of how you validated changes ### Checklist - [ ] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license* ### Issue # (if applicable) Closes #<issue number here>. ### Reason for this change ### Description of changes ### Describe any new or updated permissions being added ### Description of how you validated changes ### Checklist - [ ] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Issue # (if applicable)
N/A — Integration test remediation.
### Reason for this change
5 of 7 integration tests in `aws-stepfunctions-tasks` were failing due to:
1. **Bedrock guardrail trace** (`integ.invoke-model-guardrail-trace`): Amazon Titan Text G1 Express reached End-of-Life on August 15, 2025 and is no longer available in any region.
2. **Cross-region Lambda** (`integ.call-aws-service-cross-region-lambda`): Test creates a Lambda in the stack's region but invokes it via the us-east-1 Lambda endpoint. Lambda Invoke API is regional — calling us-east-1 with an ARN from another region returns ResourceNotFoundException.
3. **SageMaker training job** (`integ.create-training-job-image`): Hardcoded ECR account `811284229777` for BlazingText is only valid for us-east-1. Hardcoded training job name causes NAME_COLLISION on re-runs. S3 bucket had no cleanup policy.
4. **EMR tests** (`integ.emr-create-cluster-with-auto-deletion-policy-idle-timeout`, `integ.emr-create-cluster-with-ebs`): EMR clusters create ENIs in VPC subnets that linger after cluster termination, preventing VPC/subnet deletion during stack teardown.
### Description of changes
**integ.invoke-model-guardrail-trace.ts:**
- Replaced EOL `AMAZON_TITAN_TEXT_G1_EXPRESS_V1` with `AMAZON_NOVA_MICRO_V1_0`
- Updated request body from Titan format (`inputText`/`textGenerationConfig`) to Nova format (`messages`/`inferenceConfig`)
- Removed `resultSelector` and `resultPath` — the guardrail blocks the "test attack" input (word filter), and the blocked response body doesn't contain the model output structure
- Added `regions` constraint for Nova Micro + Guardrails supported regions
**integ.call-aws-service-cross-region-lambda.ts:**
- Changed `region: 'us-east-1'` to `region: this.region` — uses the stack's own region so the Lambda is reachable
**integ.create-training-job-image.ts:**
- Added `regions: ['us-east-1']` constraint to IntegTest (BlazingText ECR account is us-east-1 specific)
- Replaced hardcoded `trainingJobName` with `JsonPath.format('BlazingText-{}', JsonPath.executionName)` for unique names
- Added `removalPolicy: DESTROY` and `autoDeleteObjects: true` to S3 bucket
- Increased assertion timeout from 10 to 30 minutes
**integ.emr-create-cluster-with-auto-deletion-policy-idle-timeout.ts:**
- Added `cdkCommandOptions: { destroy: { expectError: true } }` for known EMR VPC teardown failures
**integ.emr-create-cluster-with-ebs.ts:**
- Added `cdkCommandOptions: { destroy: { expectError: true } }` for known EMR VPC teardown failures
### Describe any new or updated permissions being added
- **Bedrock guardrail trace**: IAM policy updated from `bedrock:InvokeModel` on `amazon.titan-text-express-v1` to `amazon.nova-micro-v1:0`
- **SageMaker training job**: Added S3 auto-delete objects custom resource role (standard CDK auto-delete pattern)
### Description of how you validated changes
All 7 tests validated via integ-runner deployment:
```bash
# Bedrock guardrail trace (us-east-1 for Nova Micro + Guardrails)
yarn integ test/aws-stepfunctions-tasks/test/bedrock/integ.invoke-model-guardrail-trace.js \
--disable-update-workflow --update-on-failed --force --parallel-regions us-east-1
# SageMaker training job (us-east-1 for BlazingText ECR account)
yarn integ test/aws-stepfunctions-tasks/test/sagemaker/integ.create-training-job-image.js \
--disable-update-workflow --update-on-failed --force --parallel-regions us-east-1
# Cross-region Lambda, ECS (any region)
yarn integ \
test/aws-stepfunctions-tasks/test/lambda/integ.call-aws-service-cross-region-lambda.js \
test/aws-stepfunctions-tasks/test/ecs/integ.ec2-run-task-ref-definition.js \
test/aws-stepfunctions-tasks/test/ecs/integ.fargate-run-task.js \
--disable-update-workflow --update-on-failed --force \
--parallel-regions us-east-1 --parallel-regions us-west-2 --parallel-regions eu-west-1
# EMR tests (any region with VPC headroom)
yarn integ \
test/aws-stepfunctions-tasks/test/emr/integ.emr-create-cluster-with-auto-deletion-policy-idle-timeout.js \
test/aws-stepfunctions-tasks/test/emr/integ.emr-create-cluster-with-ebs.js \
--disable-update-workflow --update-on-failed --force \
--parallel-regions eu-west-1 --parallel-regions ap-southeast-2
```
**Note:** IntegTest `regions` property is NOT respected by integ-runner `--parallel-regions`. Region-constrained tests (bedrock, sagemaker) must be run with only their supported regions.
**Destructive change:** `sfn-sm-training-job-image` stack — `TrainSetAwsCliLayer57B94C48` will be replaced (asset hash change from adding auto-delete objects).
### Checklist
- [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md)
----
*By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
… information (#37974) When assertions fail to stabilize, the failure message that is returned includes the entire CloudFormation request. That contains a bunch of information that is of no interest to the user looking at the error message. Limit it to the actual input sent into the custom resource. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
Use of this propery leads to CloudFormation stack drift. The only thing that will come from these is broken stack deployments. We can't take away the `endTime` property but we can recommend against using it. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…embly (#38007) ## Summary - Changes the validation plugin integrity check from fingerprinting the entire `outdir` to snapshotting only pre-existing file hashes before plugins run. - Plugins may now **create new files** in the cloud assembly directory (e.g. SARIF reports, custom output files) without triggering the "modified the cloud assembly" error. - **Modifications** or **deletions** of pre-existing files are still caught and throw. - Replaces `FileSystem.fingerprint` with per-file SHA-256 hashes because `fingerprint` computes a single hash over the entire directory tree, making it impossible to distinguish new files from modifications to existing ones. The plugin contract is updated from "plugins cannot modify the cloud assembly" to "plugins cannot modify or delete files that existed in the cloud assembly prior to plugin execution." ## Test plan - [x] Existing test: `plugin tries to modify a template` — still throws (modification of pre-existing file) - [x] New test: `plugin that writes new files to assembly is allowed` — creates a file, no error, file contents verified - [x] New test: `plugin that deletes pre-existing file is caught` — deletion detected and throws - [x] Full validation test suite passes (50/50)
## Summary - Adds an optional `scope` property to `IPolicyValidationContext` (and the deprecated `IPolicyValidationContextBeta1`) exposing the root construct of the app being validated. - Plugins can now walk the construct tree for typed L1 property access and token resolution via `Stack.of(node).resolve()`, rather than re-parsing synthesized JSON templates. - The field is optional — existing plugins continue to work unchanged. ## Test plan - [x] New unit test: `validate context includes scope as the root construct` — verifies plugin receives the App as `scope` - [x] Updated existing multi-stage tests to use `expect.objectContaining` (they were exact-matching the context shape) - [x] Full validation test suite passes (49/49)
…38009) ## Summary - Suppressed violations are now included in `validation-report.json` under a `suppressedViolations` array per plugin report, providing an audit trail. - Each suppressed violation entry includes the full violation details plus `acknowledgedId`, `reason`, and `acknowledgedAt` (the construct path where `acknowledge()` was called). - Suppressed violations remain excluded from the active `violations` list, the pretty-printed output, and the success/failure determination. - `collectAcknowledgedRuleIds` now returns a `Map<string, AcknowledgedRule>` (with reason + construct path) instead of a bare `Set<string>`. Schema: aws/aws-cdk-cli#1556 ## Test plan - [x] New test: `suppressed violations appear in validation-report.json` — verifies the JSON report contains the suppressed violation with all metadata - [x] Existing suppression tests continue to pass (active violations removed, fatal violations retained) - [x] Full validation test suite passes (49/49)
…cross 1 directory (#38027) Bumps the npm_and_yarn group with 1 update in the / directory: [tmp](https://github.com/raszi/node-tmp). Updates `tmp` from 0.2.5 to 0.2.6 <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/raszi/node-tmp/commit/41f71598d03f104a67e0448a7cb9bd4efcdd5980"><code>41f7159</code></a> Bump up the version</li> <li><a href="https://github.com/raszi/node-tmp/commit/efa4a06f24374797ae32ab2b6ae39b7a611ae429"><code>efa4a06</code></a> Merge commit from fork</li> <li><a href="https://github.com/raszi/node-tmp/commit/7ef2728ce0211b8110b2033dfe62eaf030341acf"><code>7ef2728</code></a> Check for relative values</li> <li>See full diff in <a href="https://github.com/raszi/node-tmp/compare/v0.2.5...v0.2.6">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/aws/aws-cdk/network/alerts). </details>
…e classes (#37816) ### Issue # (if applicable) Closes #37813. ### Reason for this change The `CacheEngine` and `UserEngine` types in `@aws-cdk/aws-elasticache-alpha` are raw TypeScript enums. Since enums are a closed set, users cannot target new engine versions until a CDK release adds them — most recently, [Valkey 9.0 for ElastiCache Serverless (May 2026)](https://aws.amazon.com/about-aws/whats-new/2026/05/valkey-amazon-elasticache/) is not usable today. The CDK [design guidelines](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md#enums) recommend the Enum-like Class pattern for this case. The module is still alpha, so this is the right time to change it. ### Description of changes Converts `CacheEngine` and `UserEngine` to enum-like classes following the `PostgresEngineVersion` pattern. Existing call-site syntax (`engine: CacheEngine.VALKEY_8`) is preserved; future versions can be targeted with `CacheEngine.of('valkey', '9')` without waiting for a CDK release. Also adds `CacheEngine.VALKEY_9` as a named member, and fixes a latent validation bug at `lib/serverless-cache.ts:593,597` where the engine-compatibility checks only matched the `_LATEST` members (so e.g. `CacheEngine.MEMCACHED_1_6` with a user group bypassed CDK-side validation). ### Describe any new or updated permissions being added None. ### Description of how you validated changes - New unit tests cover the `.of()` factory, `toString()` formats, `VALKEY_9` synth output, the two bugfix paths, and reference-equality semantics. - All 3 existing integ snapshots remain byte-identical — CloudFormation output is unchanged for every existing call site. - README updated with a `.of(...)` example; rosetta extraction passes for all jsii target languages. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) BREAKING CHANGE: `CacheEngine` and `UserEngine` are now classes instead of string enums. Usage as props (`CacheEngine.VALKEY_8`, `UserEngine.REDIS`) is unchanged; code reading these values must use `.engineType` / `.majorEngineVersion` instead of string comparisons. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…38033) ### Reason for this change The `performance counters are emitted` e2e test in `aws-lambda-nodejs` fails deterministically after upgrading `@aws-cdk/integ-runner` to `^2.198.0` (which pulls in `aws-cdk@2.1125.0`). The new CLI version unconditionally sets `CDK_PERF_COUNTERS_FILE` to `performance-counters.json` in the output directory, overriding the value the test sets. The test then looks for `counters.json` which was never written. ### Description of changes Update the test to set `CDK_PERF_COUNTERS_FILE` to `performance-counters.json` (matching the filename the new CLI uses). This makes the test work with both old CLI versions (which pass through the env var) and new ones (which override it to the same value). ### Description of how you validated changes Reproduced the failure locally, applied the fix, confirmed both `local` and `in docker` variants pass. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…ETL jobs (#37815) ### Issue Fixes #33839 ### Problem `notifyDelayAfter` was accidentally removed from `PySparkEtlJob` and `ScalaSparkEtlJob` during the refactor in commit `1a18dc9`. The Flex variants still have it — this restores parity. ### Changes - Added `notifyDelayAfter?: cdk.Duration` property to both `PySparkEtlJobProps` and `ScalaSparkEtlJobProps` - Wired `notificationProperty` in both job constructors (same pattern as Flex variants) - Added unit tests for both job types ### Regression details - **Last working:** v2.176.0 - **Breaking commit:** `1a18dc951a3946430231b685bd3584f62055127c` --- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license.*
…37840) ## Summary Adds fine-grained control over cross-stack reference at three levels: - Per-scope (consumer side): `CrossStackReferences.of(scope).consume(strength)` — sets the `@aws-cdk/core:defaultCrossStackReferences` context key on the scope, affecting all references consumed by that scope and its descendants. - Per-resource (producer side): `CrossStackReferences.of(resource).produce(strength)` — overrides the strength for all references pointing at that resource. Delegates to `resource.applyCrossStackReferenceStrength(strength)`, which stores the override on the `CfnResource`. - Per-usage (consumer side): `Stack.consumeReference(value, strength)` — overrides the strength for a single reference usage without affecting other usages of the same resource. Creates a `CustomCoupledReference` wrapper token that carries the override. Resolution priority: per-usage override > per-resource override > scope context > default ( `strong`). ## Motivation The existing context key (`@aws-cdk/core:defaultCrossStackReferences`) is all-or-nothing for a scope. Users who hit the deadly embrace on a single resource had no way to weaken just that reference without affecting the entire app. These APIs solve that by providing targeted overrides at both the producing and consuming ends. ## API ```ts // Weaken all references to this resource (producer side) CrossStackReferences.of(bucket).produce(ReferenceStrength.WEAK); // Weaken a single reference usage (consumer side) consumer.consumeReference(bucket.bucketArn, ReferenceStrength.WEAK); // Set default strength for a scope (consumer side) CrossStackReferences.of(consumer).consume(ReferenceStrength.WEAK); ```
…schema (#37969) ### Issue # (if applicable) Closes #37964. ### Reason for this change The `validateRequestHeaderConfiguration` method uses an outdated regex that only allows `Authorization` and `X-Amzn-Bedrock-AgentCore-Runtime-Custom-*` headers. The CloudFormation schema for `AWS::BedrockAgentCore::Runtime` has been updated and deployed to all regions to accept `^[A-Za-z][A-Za-z0-9_-]{0,255}$` (any valid HTTP header name). This causes `cdk synth` to throw `InvalidRequestHeaderConfiguration` for valid headers that the service fully supports. Customers must use a CFN escape hatch to work around this. ### Description of changes Updated the regex in `validateRequestHeaderConfiguration` from `/(Authorization|X-Amzn-Bedrock-AgentCore-Runtime-Custom-[a-zA-Z0-9-]+)/` to `/^[A-Za-z][A-Za-z0-9_-]{0,255}$/` in the stable module: - **`aws-cdk-lib/aws-bedrockagentcore`** — `lib/runtime/runtime.ts` The alpha module (`@aws-cdk/aws-bedrock-agentcore-alpha`) is deprecated and was not modified per maintainer guidance. Policy enforcement (blocking restricted headers) is handled server-side in the control plane — the CDK construct only needs format validation. ### Describe any new or updated permissions being added N/A — no IAM permission changes. ### Description of how you validated changes - Added unit tests to the existing `Runtime request header configuration tests` block: - Headers beyond the old `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix (should pass) - Headers with invalid characters like spaces (should fail) - Headers starting with a number (should fail) - Headers with underscores (should pass) - Added integration test with snapshot in the stable module location (`@aws-cdk-testing/framework-integ/test/aws-bedrockagentcore/test/agentcore/runtime/`) - All 135 unit tests pass locally ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
Add a new model. ### Ref - https://aws.amazon.com/about-aws/whats-new/2026/05/claude-opus-4.8-aws/ - https://docs.aws.amazon.com/bedrock/latest/userguide/models-supported.html ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…ired policy (#38013) ### Issue # (if applicable) Closes #<issue number here>. ### Reason for this change ### Description of changes Setting `cdnAuth` on `OriginEndpoint` previously stored the configuration but did not by itself produce a working endpoint policy — the `CdnAuthConfiguration` block on `OriginEndpointPolicy` is non-functional without an accompanying gating policy statement that requires the matching `mediapackagev2:RequestHasMatchingCdnAuthHeader` condition. Per the AWS docs [1], both the gating statement and the configuration block are required. This change: - Auto-emits the AWS-documented gating policy statement when `cdnAuth` is set on `OriginEndpointProps`. The resulting `OriginEndpointPolicy` now contains both the gating statement and the `CdnAuthConfiguration` block. - Drops the optional `cdnAuth` second argument from `addToResourcePolicy(...)` on `IOriginEndpoint` — the field had no clean home there and only the first call ever applied. CDN auth now lives only on the endpoint props. - Drops the `cdnAuth` prop on `MediaPackageV2OriginProps` for the same reason — set `cdnAuth` on the `OriginEndpoint` directly. - Adds an integ test that deploys the full pipeline. - Updates the README to document the new pattern, including the JSON shape the secret must use (`MediaPackageV2CDNIdentifier` key). [1] https://docs.aws.amazon.com/mediapackage/latest/userguide/cdn-auth-setup.html BREAKING CHANGE: `OriginEndpoint.addToResourcePolicy()` no longer accepts an optional `cdnAuth` second argument. `MediaPackageV2OriginProps.cdnAuth` has been removed. Set `cdnAuth` on `OriginEndpointProps` instead. ### Describe any new or updated permissions being added ### Description of how you validated changes ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
… previous python is end of life (#37660) Update the semantic versions for the SecretsManager rotation serverless applications - The latest semantic versions use Python 3.12 for the rotation lambda functions, instead of Python 3.10 - The latest semantic versions have fixes for a CWE related to logging raw input to the rotation functions Add SecretRotationApplications for RDS IBM Db2 secret rotation - These rotation applications are the most recent secret rotation applications ### Issue # (if applicable) Closes #37462. ### Reason for this change Update to the latest serverless application repository semantic versions for the secret rotation applications. ### Description of changes Updated the version numbers for all SecretRotationApplication and added support for inconsistent versioning in each of the three supported partitions. ### Describe any new or updated permissions being added None ### Description of how you validated changes Unit tests have been updated to match the new semantic versions. Tests are passing locally. ### Checklist - [ x ] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
aws-cdk-automation
temporarily deployed
to
automation
June 4, 2026 08:00 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
June 4, 2026 08:00 — with
GitHub Actions
Inactive
Contributor
|
PRs without a linked issue will receive lower priority for review and merging. Please update the description to follow the PR template and include a line like |
This reverts commit ca23898.
Contributor
|
Thank you for contributing! Your pull request will be automatically updated and merged without squashing (do not update manually, and be sure to allow changes to be pushed to your fork). |
Contributor
Merge Queue Status
This pull request spent 30 seconds in the queue, including 2 seconds running CI. Required conditions to merge
|
Contributor
|
Comments on closed issues and PRs are hard for our team to see. |
aws-cdk-automation
temporarily deployed
to
automation
June 4, 2026 10:24 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
June 4, 2026 10:24 — with
GitHub Actions
Inactive
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See CHANGELOG