Skip to content

Merge updates - #1

Open
Zero-dump wants to merge 943 commits into
tunein:mainfrom
github-aws-runners:main
Open

Merge updates#1
Zero-dump wants to merge 943 commits into
tunein:mainfrom
github-aws-runners:main

Conversation

@Zero-dump

Copy link
Copy Markdown

No description provided.

dependabot Bot and others added 30 commits November 13, 2025 20:44
…4881)

Bumps
[step-security/harden-runner](https://github.com/step-security/harden-runner)
from 2.13.1 to 2.13.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/step-security/harden-runner/releases">step-security/harden-runner's
releases</a>.</em></p>
<blockquote>
<h2>v2.13.2</h2>
<h2>What's Changed</h2>
<ul>
<li>Fixed an issue where there was a limit of 512 allowed endpoints when
using block egress policy. This restriction has been removed, allowing
for an unlimited number of endpoints to be configured.</li>
<li>Harden Runner now automatically detects if the agent is already
pre-installed on a custom VM image used by a GitHub-hosted runner. When
detected, the action will skip reinstallation and use the existing
agent.</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/step-security/harden-runner/compare/v2.13.1...v2.13.2">https://github.com/step-security/harden-runner/compare/v2.13.1...v2.13.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/step-security/harden-runner/commit/95d9a5deda9de15063e7595e9719c11c38c90ae2"><code>95d9a5d</code></a>
Merge pull request <a
href="https://redirect.github.com/step-security/harden-runner/issues/606">#606</a>
from step-security/rc-28</li>
<li><a
href="https://github.com/step-security/harden-runner/commit/87e429d3fb470bcc827f338e5cce1155ff99c6eb"><code>87e429d</code></a>
Update limitations.md</li>
<li><a
href="https://github.com/step-security/harden-runner/commit/ef891c3a30c3c15c2287ce04b33ec28b6d90a447"><code>ef891c3</code></a>
feat: add support for custom vm image</li>
<li><a
href="https://github.com/step-security/harden-runner/commit/1fa8c8a8b1b523829fe596bfc665d2bc4c0ef835"><code>1fa8c8a</code></a>
update agent</li>
<li><a
href="https://github.com/step-security/harden-runner/commit/92c522aaa6f53af082553dedc1596c80b71aba33"><code>92c522a</code></a>
Merge pull request <a
href="https://redirect.github.com/step-security/harden-runner/issues/593">#593</a>
from step-security/ak-readme-updates</li>
<li><a
href="https://github.com/step-security/harden-runner/commit/4719ad5578c61961f4f70f833580278dea5544de"><code>4719ad5</code></a>
README updates</li>
<li><a
href="https://github.com/step-security/harden-runner/commit/4fde639ab437b75bf4ecb52bbddb23ab0ac00259"><code>4fde639</code></a>
Merge pull request <a
href="https://redirect.github.com/step-security/harden-runner/issues/591">#591</a>
from eromosele-stepsecurity/Upd</li>
<li><a
href="https://github.com/step-security/harden-runner/commit/f682f2f2d06275b6ab30c2a973c1de2fa120e134"><code>f682f2f</code></a>
Update README.md</li>
<li>See full diff in <a
href="https://github.com/step-security/harden-runner/compare/f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a...95d9a5deda9de15063e7595e9719c11c38c90ae2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=step-security/harden-runner&package-manager=github_actions&previous-version=2.13.1&new-version=2.13.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the vite group in /lambdas with 2 updates:
[vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) and
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).

Updates `vite` from 7.1.12 to 7.2.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/releases">vite's
releases</a>.</em></p>
<blockquote>
<h2>plugin-legacy@7.2.0</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite/blob/plugin-legacy@7.2.0/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
<h2>v7.2.0</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite/blob/v7.2.0/packages/vite/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
<h2>v7.2.0-beta.1</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite/blob/v7.2.0-beta.1/packages/vite/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
<h2>v7.2.0-beta.0</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite/blob/v7.2.0-beta.0/packages/vite/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md">vite's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/vitejs/vite/compare/v7.2.0-beta.1...v7.2.0">7.2.0</a>
(2025-11-05)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>css:</strong> fallback to sass when sass-embedded platform
binary is missing (<a
href="https://redirect.github.com/vitejs/vite/issues/21002">#21002</a>)
(<a
href="https://github.com/vitejs/vite/commit/b1fd6161886caeb31ac646d6544116d37efe46d0">b1fd616</a>)</li>
<li><strong>module-runner:</strong> make <code>getBuiltins</code>
response JSON serializable (<a
href="https://redirect.github.com/vitejs/vite/issues/21029">#21029</a>)
(<a
href="https://github.com/vitejs/vite/commit/ad5b3bf6f3ad7b24886718c5f5de32eee923ae11">ad5b3bf</a>)</li>
<li><strong>types:</strong> add undefined to optional properties for
exactOptionalProperties type compatibility (<a
href="https://redirect.github.com/vitejs/vite/issues/21040">#21040</a>)
(<a
href="https://github.com/vitejs/vite/commit/2833c5576a87be2db450c195ccf64dfc8925a15b">2833c55</a>)</li>
</ul>
<h3>Miscellaneous Chores</h3>
<ul>
<li><strong>deps:</strong> update rolldown-related dependencies (<a
href="https://redirect.github.com/vitejs/vite/issues/21047">#21047</a>)
(<a
href="https://github.com/vitejs/vite/commit/e3a6a83406943bc59a9916cae3f25ab33c2b5802">e3a6a83</a>)</li>
</ul>
<h2><a
href="https://github.com/vitejs/vite/compare/v7.2.0-beta.0...v7.2.0-beta.1">7.2.0-beta.1</a>
(2025-10-29)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>increase stream reset rate limit for HTTP2 (<a
href="https://redirect.github.com/vitejs/vite/issues/21024">#21024</a>)
(<a
href="https://github.com/vitejs/vite/commit/4f44f22f7f4595d74c76778bd522387138775055">4f44f22</a>)</li>
<li><strong>optimizer:</strong> externalize virtual modules for html
like files (<a
href="https://redirect.github.com/vitejs/vite/issues/21001">#21001</a>)
(<a
href="https://github.com/vitejs/vite/commit/e5af352d8e1a9f187159137f836db5bedbd68a66">e5af352</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>clarify the values are escaped automatically (<a
href="https://redirect.github.com/vitejs/vite/issues/21017">#21017</a>)
(<a
href="https://github.com/vitejs/vite/commit/246df134dd58441e1e40dd361cf42419d05ea7a5">246df13</a>)</li>
</ul>
<h3>Code Refactoring</h3>
<ul>
<li>use <code>fs.cpSync</code> (<a
href="https://redirect.github.com/vitejs/vite/issues/21019">#21019</a>)
(<a
href="https://github.com/vitejs/vite/commit/a2df77812814b927880bc4d68aafa8c8fa47daf0">a2df778</a>)</li>
</ul>
<h2><a
href="https://github.com/vitejs/vite/compare/v7.1.11...v7.2.0-beta.0">7.2.0-beta.0</a>
(2025-10-28)</h2>
<h3>Features</h3>
<ul>
<li>add <code>import.meta.resolve</code> support for ESM config (bundle
config loader) (<a
href="https://redirect.github.com/vitejs/vite/issues/20962">#20962</a>)
(<a
href="https://github.com/vitejs/vite/commit/f86789a6e237bd0e31cde3a3f09bdef45bfa7d1c">f86789a</a>)</li>
<li>add <code>perEnvironmentWatchChangeDuringDev</code> (<a
href="https://redirect.github.com/vitejs/vite/issues/20996">#20996</a>)
(<a
href="https://github.com/vitejs/vite/commit/a5e98e695ee4152127977abb506029dc8f7544fb">a5e98e6</a>)</li>
<li>add vite client connect events (<a
href="https://redirect.github.com/vitejs/vite/issues/20978">#20978</a>)
(<a
href="https://github.com/vitejs/vite/commit/543d87c2cd1ec629f19de56a903a15185f20db1f">543d87c</a>)</li>
<li><strong>build:</strong> emit license (<a
href="https://redirect.github.com/vitejs/vite/issues/18546">#18546</a>)
(<a
href="https://github.com/vitejs/vite/commit/b42c3fb2cb75bb4fdf7557cb35946564d6dc4384">b42c3fb</a>)</li>
<li><strong>dev:</strong> support HTTP2 even if proxy feature is used
(<a
href="https://redirect.github.com/vitejs/vite/issues/20869">#20869</a>)
(<a
href="https://github.com/vitejs/vite/commit/fc21af7a42dd559a95f54b6165d34f36883eaa7f">fc21af7</a>)</li>
<li><strong>lib:</strong> enable minification but keep pure annotations
for es output with terser (<a
href="https://redirect.github.com/vitejs/vite/issues/20522">#20522</a>)
(<a
href="https://github.com/vitejs/vite/commit/df997d0cfca8e1dad04ac1bf8119caa2d2e4c1fc">df997d0</a>)</li>
<li><strong>optimizer:</strong> add rush lockfile support (<a
href="https://redirect.github.com/vitejs/vite/issues/20833">#20833</a>)
(<a
href="https://github.com/vitejs/vite/commit/718ca2d708dbeb393839932437a6b161851ca24c">718ca2d</a>)</li>
<li><strong>utils:</strong> support multiple certificates in
resolveServerUrls (<a
href="https://redirect.github.com/vitejs/vite/issues/20707">#20707</a>)
(<a
href="https://github.com/vitejs/vite/commit/24513e567c643d5f6fb61af6298aa3fc2b166b90">24513e5</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>build:</strong> ensure amd bundles request
<code>require</code> to be injected (<a
href="https://redirect.github.com/vitejs/vite/issues/20861">#20861</a>)
(<a
href="https://github.com/vitejs/vite/commit/bb85bd751e4568c707612b708deaba67f8af4ca3">bb85bd7</a>)</li>
<li><strong>build:</strong> replace <code>names</code> in the manifest
with unmangled <code>name</code> for CSS assets (<a
href="https://redirect.github.com/vitejs/vite/issues/20585">#20585</a>)
(<a
href="https://github.com/vitejs/vite/commit/4abf0566024a70c38a0eb5bf614f72189038247d">4abf056</a>)</li>
<li><strong>deps:</strong> downgrade commonjs plugin to 28.0.6 to avoid
rollup/plugins<a
href="https://redirect.github.com/vitejs/vite/issues/1909">#1909</a> (<a
href="https://redirect.github.com/vitejs/vite/issues/20988">#20988</a>)
(<a
href="https://github.com/vitejs/vite/commit/856e683885ed53ec6044897451608bc6518baef6">856e683</a>)</li>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/vitejs/vite/issues/21008">#21008</a>)
(<a
href="https://github.com/vitejs/vite/commit/185641e3cdae29277c41eb8028f6eac542215f01">185641e</a>)</li>
<li>disable optional peer dep handling for
<code>nodeResolveWithVite</code> (<a
href="https://redirect.github.com/vitejs/vite/issues/20989">#20989</a>)
(<a
href="https://github.com/vitejs/vite/commit/ca18b233d43a8f31883726ca565940ad1dc85f38">ca18b23</a>)</li>
<li>handle query parameters for <code>/@vite/*</code> modules (<a
href="https://redirect.github.com/vitejs/vite/issues/20998">#20998</a>)
(<a
href="https://github.com/vitejs/vite/commit/6843a6ae49df8ca523104a8ccfb9a8f9602b3881">6843a6a</a>)</li>
<li><strong>module-runner:</strong> resolve <code>resolvedSources</code>
correctly (<a
href="https://redirect.github.com/vitejs/vite/issues/20959">#20959</a>)
(<a
href="https://github.com/vitejs/vite/commit/c4f6039436657db50c610aa17eaf821dbd4ad57d">c4f6039</a>)</li>
<li><strong>resolve:</strong> match resolved subpath import path's
relative prefix with regex (fix <a
href="https://redirect.github.com/vitejs/vite/issues/20972">#20972</a>)
(<a
href="https://redirect.github.com/vitejs/vite/issues/20973">#20973</a>)
(<a
href="https://github.com/vitejs/vite/commit/ff2d83e2e7a3f7eba72f41b40686912f1e4b6843">ff2d83e</a>)</li>
<li>update build log to include environment name (<a
href="https://redirect.github.com/vitejs/vite/issues/20987">#20987</a>)
(<a
href="https://github.com/vitejs/vite/commit/77c25c16ba9f3568e55fd4135f57c70f984d3fdd">77c25c1</a>)</li>
<li>use esm entrypoint for css preprocessors and terser (<a
href="https://redirect.github.com/vitejs/vite/issues/20918">#20918</a>)
(<a
href="https://github.com/vitejs/vite/commit/14608241cc4c821e7a392f6d92ef291a926bd94d">1460824</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitejs/vite/commit/8293de0e17af8a876d49761ed6651bd38b709174"><code>8293de0</code></a>
release: v7.2.0</li>
<li><a
href="https://github.com/vitejs/vite/commit/2833c5576a87be2db450c195ccf64dfc8925a15b"><code>2833c55</code></a>
fix(types): add undefined to optional properties for
exactOptionalProperties ...</li>
<li><a
href="https://github.com/vitejs/vite/commit/e3a6a83406943bc59a9916cae3f25ab33c2b5802"><code>e3a6a83</code></a>
chore(deps): update rolldown-related dependencies (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21047">#21047</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/b1fd6161886caeb31ac646d6544116d37efe46d0"><code>b1fd616</code></a>
fix(css): fallback to sass when sass-embedded platform binary is missing
(<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21">#21</a>...</li>
<li><a
href="https://github.com/vitejs/vite/commit/ad5b3bf6f3ad7b24886718c5f5de32eee923ae11"><code>ad5b3bf</code></a>
fix(module-runner): make <code>getBuiltins</code> response JSON
serializable (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21029">#21029</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/793baa207beecb2d85860df57c80904b2e628902"><code>793baa2</code></a>
release: v7.2.0-beta.1</li>
<li><a
href="https://github.com/vitejs/vite/commit/e5af352d8e1a9f187159137f836db5bedbd68a66"><code>e5af352</code></a>
fix(optimizer): externalize virtual modules for html like files (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21001">#21001</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/4f44f22f7f4595d74c76778bd522387138775055"><code>4f44f22</code></a>
fix: increase stream reset rate limit for HTTP2 (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21024">#21024</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/a2df77812814b927880bc4d68aafa8c8fa47daf0"><code>a2df778</code></a>
refactor: use <code>fs.cpSync</code> (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21019">#21019</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/246df134dd58441e1e40dd361cf42419d05ea7a5"><code>246df13</code></a>
docs: clarify the values are escaped automatically (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21017">#21017</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vitejs/vite/commits/v7.2.0/packages/vite">compare
view</a></li>
</ul>
</details>
<br />

Updates `vitest` from 4.0.5 to 4.0.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitest-dev/vitest/releases">vitest's
releases</a>.</em></p>
<blockquote>
<h2>v4.0.7</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Bind <code>process</code> in case global is overwritten  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8916">vitest-dev/vitest#8916</a>
<a href="https://github.com/vitest-dev/vitest/commit/6240d51a6"><!-- raw
HTML omitted -->(6240d)<!-- raw HTML omitted --></a></li>
<li>Create environment once per worker with <code>isolate: false</code>
 -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8915">vitest-dev/vitest#8915</a>
<a href="https://github.com/vitest-dev/vitest/commit/c9078a26e"><!-- raw
HTML omitted -->(c9078)<!-- raw HTML omitted --></a></li>
<li>Add Locator as a possible element type in
<code>toContainElement()</code> matcher  -  by <a
href="https://github.com/vitalybaev"><code>@​vitalybaev</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8910">vitest-dev/vitest#8910</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8927">vitest-dev/vitest#8927</a>
<a href="https://github.com/vitest-dev/vitest/commit/35a27d4b3"><!-- raw
HTML omitted -->(35a27)<!-- raw HTML omitted --></a></li>
<li><strong>browser</strong>: Inherit <code>isolate</code> option,
deprecate
<code>browser.isolate</code>/<code>browser.fileParallelism</code>  -  by
<a href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8890">vitest-dev/vitest#8890</a>
<a href="https://github.com/vitest-dev/vitest/commit/9d2b4d501"><!-- raw
HTML omitted -->(9d2b4)<!-- raw HTML omitted --></a></li>
<li><strong>cli</strong>: Parse <code>--execArgv</code> as array  -  by
<a href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8924">vitest-dev/vitest#8924</a>
<a href="https://github.com/vitest-dev/vitest/commit/751c3926f"><!-- raw
HTML omitted -->(751c3)<!-- raw HTML omitted --></a></li>
<li><strong>jsdom</strong>: Support <code>URL.createObjectURL</code>,
<code>FormData.set(prop, blob)</code>  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8935">vitest-dev/vitest#8935</a>
<a href="https://github.com/vitest-dev/vitest/commit/a1b7361ab"><!-- raw
HTML omitted -->(a1b73)<!-- raw HTML omitted --></a></li>
<li><strong>pool</strong>: Avoid <code>--require</code> argument when
running in deno  -  by <a
href="https://github.com/pi0"><code>@​pi0</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8897">vitest-dev/vitest#8897</a>
<a href="https://github.com/vitest-dev/vitest/commit/d41fa742f"><!-- raw
HTML omitted -->(d41fa)<!-- raw HTML omitted --></a></li>
<li><strong>typecheck</strong>: Handle re-runs outside <code>tsc</code>
 -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8920">vitest-dev/vitest#8920</a>
<a href="https://github.com/vitest-dev/vitest/commit/fdb2e7982"><!-- raw
HTML omitted -->(fdb2e)<!-- raw HTML omitted --></a></li>
</ul>
<h3>   🏎 Performance</h3>
<ul>
<li><strong>pool</strong>:
<ul>
<li>Sort test files by project by default  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8914">vitest-dev/vitest#8914</a>
<a href="https://github.com/vitest-dev/vitest/commit/680a612ea"><!-- raw
HTML omitted -->(680a6)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>reporters</strong>:
<ul>
<li>Optimize getting the tests stats  -  by <a
href="https://github.com/Connormiha"><code>@​Connormiha</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8908">vitest-dev/vitest#8908</a>
<a href="https://github.com/vitest-dev/vitest/commit/06d6207fb"><!-- raw
HTML omitted -->(06d62)<!-- raw HTML omitted --></a></li>
<li>Remove unnecessary <code>Array.from</code> call  -  by <a
href="https://github.com/Connormiha"><code>@​Connormiha</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8907">vitest-dev/vitest#8907</a>
<a href="https://github.com/vitest-dev/vitest/commit/b60149b27"><!-- raw
HTML omitted -->(b6014)<!-- raw HTML omitted --></a></li>
</ul>
</li>
</ul>
<h5>    <a
href="https://github.com/vitest-dev/vitest/compare/v4.0.6...v4.0.7">View
changes on GitHub</a></h5>
<h2>v4.0.6</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Don't merge errors with different diffs for reporting  -  by <a
href="https://github.com/hi-ogawa"><code>@​hi-ogawa</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8871">vitest-dev/vitest#8871</a>
<a href="https://github.com/vitest-dev/vitest/commit/3e19f27d0"><!-- raw
HTML omitted -->(3e19f)<!-- raw HTML omitted --></a></li>
<li>Do not throw when importing a type from an external package  -  by
<a href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8875">vitest-dev/vitest#8875</a>
<a href="https://github.com/vitest-dev/vitest/commit/7e6c37ae5"><!-- raw
HTML omitted -->(7e6c3)<!-- raw HTML omitted --></a></li>
<li>Improve spying types  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8878">vitest-dev/vitest#8878</a>
<a href="https://github.com/vitest-dev/vitest/commit/ca041f51a"><!-- raw
HTML omitted -->(ca041)<!-- raw HTML omitted --></a></li>
<li>Reuse the same environment when <code>isolate</code> and
<code>fileParallelism</code> are false  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8889">vitest-dev/vitest#8889</a>
<a href="https://github.com/vitest-dev/vitest/commit/31706dfe5"><!-- raw
HTML omitted -->(31706)<!-- raw HTML omitted --></a></li>
<li><strong>browser</strong>:
<ul>
<li>Support module tracking  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8877">vitest-dev/vitest#8877</a>
<a href="https://github.com/vitest-dev/vitest/commit/9e24a59f2"><!-- raw
HTML omitted -->(9e24a)<!-- raw HTML omitted --></a></li>
<li>Ensure setup files are re-evaluated on each test run  -  by <a
href="https://github.com/yjaaidi"><code>@​yjaaidi</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8883">vitest-dev/vitest#8883</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8884">vitest-dev/vitest#8884</a>
<a href="https://github.com/vitest-dev/vitest/commit/f50ea7a25"><!-- raw
HTML omitted -->(f50ea)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>coverage</strong>:
<ul>
<li>Prevent filtering out virtual files before remapping to sources  - 
by <a href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8860">vitest-dev/vitest#8860</a>
<a href="https://github.com/vitest-dev/vitest/commit/e3b777550"><!-- raw
HTML omitted -->(e3b77)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>happy-dom</strong>:
<ul>
<li>Properly teardown additional keys  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8888">vitest-dev/vitest#8888</a>
<a href="https://github.com/vitest-dev/vitest/commit/10a06d8c9"><!-- raw
HTML omitted -->(10a06)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>jsdom</strong>:
<ul>
<li>Pass down Node.js <code>FormData</code> to <code>Request</code>  - 
by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8880">vitest-dev/vitest#8880</a>
<a href="https://github.com/vitest-dev/vitest/commit/197caf2f9"><!-- raw
HTML omitted -->(197ca)<!-- raw HTML omitted --></a></li>
</ul>
</li>
</ul>
<h5>    <a
href="https://github.com/vitest-dev/vitest/compare/v4.0.5...v4.0.6">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitest-dev/vitest/commit/1f5d9d2ccfd0fb23b270e39992eed0a7aaa3f4d7"><code>1f5d9d2</code></a>
chore: release v4.0.7</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/a1b7361ab171e03daf4900141fd7502b1ccc1844"><code>a1b7361</code></a>
fix(jsdom): support <code>URL.createObjectURL</code>,
<code>FormData.set(prop, blob)</code> (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8935">#8935</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/751c3926fc13a1a1d85e8e47a6903f87dc3b60fb"><code>751c392</code></a>
fix(cli): parse <code>--execArgv</code> as array (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8924">#8924</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/c9078a26e3b5fe38acdc59d7ba282eaa5740b6ef"><code>c9078a2</code></a>
fix: create environment once per worker with <code>isolate: false</code>
(<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8915">#8915</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/9d2b4d501ad32ba1e132f9b6e42958ce140c0be7"><code>9d2b4d5</code></a>
fix(browser): inherit <code>isolate</code> option, deprecate
<code>browser.isolate</code>/`browser....</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/680a612ea73aeacde799d33bdcc2d16010bd6fa0"><code>680a612</code></a>
perf(pool): sort test files by project by default (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8914">#8914</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/fdb2e7982a73e78113db4355075d48ad80963cfc"><code>fdb2e79</code></a>
fix(typecheck): handle re-runs outside <code>tsc</code> (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8920">#8920</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/6240d51a6abff12bd830593f926588556e1c41f8"><code>6240d51</code></a>
fix: bind <code>process</code> in case global is overwritten (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8916">#8916</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/d41fa742fd0354a43003e29280b8213a72783f07"><code>d41fa74</code></a>
fix(pool): avoid <code>--require</code> argument when running in deno
(<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8897">#8897</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/b60149b274c2fe88dc41caf05aaa8d9fb6b2df17"><code>b60149b</code></a>
perf(reporters): remove unnecessary <code>Array.from</code> call (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8907">#8907</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vitest-dev/vitest/commits/v4.0.7/packages/vitest">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…4880)

Bumps
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
from 22.18.8 to 22.19.0.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=22.18.8&new-version=22.19.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@swc/core](https://github.com/swc-project/swc) from 1.13.20 to
1.15.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/swc-project/swc/blob/main/CHANGELOG.md"><code>@​swc/core</code>'s
changelog</a>.</em></p>
<blockquote>
<h2>[1.15.0] - 2025-11-04</h2>
<h3>Bug Fixes</h3>
<ul>
<li>
<p><strong>(cli)</strong> Update plugin template to use VisitMut API (<a
href="https://redirect.github.com/swc-project/swc/issues/11218">#11218</a>)
(<a
href="https://github.com/swc-project/swc/commit/6a87e41fbaf2f97e2f530d8560df7bb9e0ba1a12">6a87e41</a>)</p>
</li>
<li>
<p><strong>(hstr)</strong> Skip only <code>\u</code> for unicode (<a
href="https://redirect.github.com/swc-project/swc/issues/11216">#11216</a>)
(<a
href="https://github.com/swc-project/swc/commit/eda01e5284ad5b1eda538eda7231795d75f7136f">eda01e5</a>)</p>
</li>
</ul>
<h3>Features</h3>
<ul>
<li><strong>(hstr)</strong> Support checked <code>from_bytes</code> for
Wtf8Buf and Wtf8 (<a
href="https://redirect.github.com/swc-project/swc/issues/11211">#11211</a>)
(<a
href="https://github.com/swc-project/swc/commit/1430489460a54598300427bfc7ed0f4a30bf8d63">1430489</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>
<p><strong>(atoms)</strong> Remove temporary allocations in rkyv
serialize and deserialize (<a
href="https://redirect.github.com/swc-project/swc/issues/11202">#11202</a>)
(<a
href="https://github.com/swc-project/swc/commit/85e6e8a66f0e517512d7cd13c5b287b1ef82e191">85e6e8a</a>)</p>
</li>
<li>
<p><strong>(es/parser)</strong> Remove <code>start</code> in
<code>State</code> (<a
href="https://redirect.github.com/swc-project/swc/issues/11201">#11201</a>)
(<a
href="https://github.com/swc-project/swc/commit/b9aeaa3a3bab072f90fb8f26454cb33062bff584">b9aeaa3</a>)</p>
</li>
<li>
<p><strong>(plugin)</strong> Avoid data copy when transformation
finished (<a
href="https://redirect.github.com/swc-project/swc/issues/11223">#11223</a>)
(<a
href="https://github.com/swc-project/swc/commit/af134faecd5979126165a5462abf880c70b5b54b">af134fa</a>)</p>
</li>
</ul>
<h3>Refactor</h3>
<ul>
<li>
<p><strong>(ast)</strong> Introduce flexible serialization encoding for
AST (<a
href="https://redirect.github.com/swc-project/swc/issues/11100">#11100</a>)
(<a
href="https://github.com/swc-project/swc/commit/8ad36478160ff848466bbff2bf442224696982bf">8ad3647</a>)</p>
</li>
<li>
<p><strong>(plugin)</strong> Switch plugin abi to flexible serialization
(<a
href="https://redirect.github.com/swc-project/swc/issues/11198">#11198</a>)
(<a
href="https://github.com/swc-project/swc/commit/e5feaf15cebb2887cd8dc9d0275c4ec0fbf40d30">e5feaf1</a>)</p>
</li>
<li>
<p>Flatten cargo workspaces (<a
href="https://redirect.github.com/swc-project/swc/issues/11213">#11213</a>)
(<a
href="https://github.com/swc-project/swc/commit/622310055c59ee42b744038a33997e6f43cf4af0">6223100</a>)</p>
</li>
</ul>
<h3>Testing</h3>
<ul>
<li>Copy opt-level configs to the top level workspace (<a
href="https://redirect.github.com/swc-project/swc/issues/11210">#11210</a>)
(<a
href="https://github.com/swc-project/swc/commit/dba23f5a72d26b3b62fbafe2d8a65c69c3642669">dba23f5</a>)</li>
</ul>
<h2>[1.14.0] - 2025-10-29</h2>
<h3>Bug Fixes</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/swc-project/swc/commit/77d8c36e6368ac5c8e832d731fd58d55624cc142"><code>77d8c36</code></a>
chore: Publish <code>1.15.0</code> with <code>swc_core</code>
<code>v47.0.2</code></li>
<li><a
href="https://github.com/swc-project/swc/commit/9436f074d314db6108cfccb9f20336fc50161bde"><code>9436f07</code></a>
chore: Update changelog</li>
<li><a
href="https://github.com/swc-project/swc/commit/12366e7caf757065f429f404a0ed507f3af5b719"><code>12366e7</code></a>
chore: Publish <code>1.15.0-nightly-20251104.3</code> with
<code>swc_core</code> <code>v47.0.2</code></li>
<li><a
href="https://github.com/swc-project/swc/commit/792625c78eda0cecbbc40cbc157e607d1dcd448d"><code>792625c</code></a>
chore: Remove cache for <code>targets</code></li>
<li><a
href="https://github.com/swc-project/swc/commit/2d331248db00876632e72b94f39093e4f3b7ed2d"><code>2d33124</code></a>
chore: Improve the <code>bump</code> command (<a
href="https://redirect.github.com/swc-project/swc/issues/11226">#11226</a>)</li>
<li><a
href="https://github.com/swc-project/swc/commit/4bde508532acaa8d35bf9626c90076e80d4716d7"><code>4bde508</code></a>
chore: Publish <code>1.15.0-nightly-20251104.2</code> with
<code>swc_core</code> <code>v47.0.2</code></li>
<li><a
href="https://github.com/swc-project/swc/commit/0d5f10bbeda372cf0f0554974c7469ae85c954d8"><code>0d5f10b</code></a>
chore: FIx publish path</li>
<li><a
href="https://github.com/swc-project/swc/commit/2edbd40241b3402c8542241b1f8d82a4ebadd801"><code>2edbd40</code></a>
chore: Update changelog</li>
<li><a
href="https://github.com/swc-project/swc/commit/a7f02dec1e7857844f026c15d1f46896d81875c9"><code>a7f02de</code></a>
chore: Publish <code>1.15.0-nightly-20251104.1</code> with
<code>swc_core</code> <code>v47.0.2</code></li>
<li><a
href="https://github.com/swc-project/swc/commit/6c1e8208b93a07e7e29930f044b97e6f8312192d"><code>6c1e820</code></a>
chore: Fix version of bindings</li>
<li>Additional commits viewable in <a
href="https://github.com/swc-project/swc/compare/v1.13.20...v1.15.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@swc/core&package-manager=npm_and_yarn&previous-version=1.13.20&new-version=1.15.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
…slint group (#4877)

Bumps the eslint group in /lambdas with 1 update:
[eslint](https://github.com/eslint/eslint).

Updates `eslint` from 9.38.0 to 9.39.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/eslint/eslint/releases">eslint's
releases</a>.</em></p>
<blockquote>
<h2>v9.39.1</h2>
<h2>Bug Fixes</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/650753ee3976784343ceb40170619dab1aa9fe0d"><code>650753e</code></a>
fix: Only pass node to JS lang visitor methods (<a
href="https://redirect.github.com/eslint/eslint/issues/20283">#20283</a>)
(Nicholas C. Zakas)</li>
</ul>
<h2>Documentation</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/51b51f4f1ce82ef63264c4e45d9ef579bcd73f8e"><code>51b51f4</code></a>
docs: add a section on when to use extends vs cascading (<a
href="https://redirect.github.com/eslint/eslint/issues/20268">#20268</a>)
(Tanuj Kanti)</li>
<li><a
href="https://github.com/eslint/eslint/commit/b44d42699dcd1729b7ecb50ca70e4c1c17f551f1"><code>b44d426</code></a>
docs: Update README (GitHub Actions Bot)</li>
</ul>
<h2>Chores</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/92db329211c8da5ce8340a4d4c05ce9c12845381"><code>92db329</code></a>
chore: update <code>@eslint/js</code> version to 9.39.1 (<a
href="https://redirect.github.com/eslint/eslint/issues/20284">#20284</a>)
(Francesco Trotta)</li>
<li><a
href="https://github.com/eslint/eslint/commit/c7ebefc9eaf99b76b30b0d3cf9960807a47367c4"><code>c7ebefc</code></a>
chore: package.json update for <code>@​eslint/js</code> release
(Jenkins)</li>
<li><a
href="https://github.com/eslint/eslint/commit/61778f6ca33c0f63962a91d6a75a4fa5db9f47d2"><code>61778f6</code></a>
chore: update eslint-config-eslint dependency <code>@​eslint/js</code>
to ^9.39.0 (<a
href="https://redirect.github.com/eslint/eslint/issues/20275">#20275</a>)
(renovate[bot])</li>
<li><a
href="https://github.com/eslint/eslint/commit/d9ca2fcd9ad63331bfd329a69534e1ff04f231e8"><code>d9ca2fc</code></a>
ci: Add rangeStrategy to eslint group in renovate config (<a
href="https://redirect.github.com/eslint/eslint/issues/20266">#20266</a>)
(唯然)</li>
<li><a
href="https://github.com/eslint/eslint/commit/009e5076ff5a4bd845f55e17676e3bb88f47c280"><code>009e507</code></a>
test: fix version tests for ESLint v10 (<a
href="https://redirect.github.com/eslint/eslint/issues/20274">#20274</a>)
(Milos Djermanovic)</li>
</ul>
<h2>v9.39.0</h2>
<h2>Features</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/cc57d87a3f119e9d39c55e044e526ae067fa31ce"><code>cc57d87</code></a>
feat: update error loc to key in <code>no-dupe-class-members</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/20259">#20259</a>)
(Tanuj Kanti)</li>
<li><a
href="https://github.com/eslint/eslint/commit/126552fcf35da3ddcefa527db06dabc54c04041c"><code>126552f</code></a>
feat: update error location in <code>for-direction</code> and
<code>no-dupe-args</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/20258">#20258</a>)
(Tanuj Kanti)</li>
<li><a
href="https://github.com/eslint/eslint/commit/167d0970d3802a66910e9820f31dcd717fab0b2a"><code>167d097</code></a>
feat: update <code>complexity</code> rule to highlight only static block
header (<a
href="https://redirect.github.com/eslint/eslint/issues/20245">#20245</a>)
(jaymarvelz)</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/15f5c7c168d0698683943f51dd617f14a5e6815c"><code>15f5c7c</code></a>
fix: forward traversal <code>step.args</code> to visitors (<a
href="https://redirect.github.com/eslint/eslint/issues/20253">#20253</a>)
(jaymarvelz)</li>
<li><a
href="https://github.com/eslint/eslint/commit/5a1a534e877f7c4c992885867f923df307c3929d"><code>5a1a534</code></a>
fix: allow JSDoc comments in object-shorthand rule (<a
href="https://redirect.github.com/eslint/eslint/issues/20167">#20167</a>)
(Nitin Kumar)</li>
<li><a
href="https://github.com/eslint/eslint/commit/e86b813eb660f1a5adc8e143a70d9b683cd12362"><code>e86b813</code></a>
fix: Use more types from <code>@​eslint/core</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/20257">#20257</a>)
(Nicholas C. Zakas)</li>
<li><a
href="https://github.com/eslint/eslint/commit/927272d1f0d5683b029b729d368a96527f283323"><code>927272d</code></a>
fix: correct <code>Scope</code> typings (<a
href="https://redirect.github.com/eslint/eslint/issues/20198">#20198</a>)
(jaymarvelz)</li>
<li><a
href="https://github.com/eslint/eslint/commit/37f76d9c539bb6fc816fedb7be4486b71a58620a"><code>37f76d9</code></a>
fix: use <code>AST.Program</code> type for Program node (<a
href="https://redirect.github.com/eslint/eslint/issues/20244">#20244</a>)
(Francesco Trotta)</li>
<li><a
href="https://github.com/eslint/eslint/commit/ae07f0b3334ebd22ae2e7b09bca5973b96aa9768"><code>ae07f0b</code></a>
fix: unify timing report for concurrent linting (<a
href="https://redirect.github.com/eslint/eslint/issues/20188">#20188</a>)
(jaymarvelz)</li>
<li><a
href="https://github.com/eslint/eslint/commit/b165d471be6062f4475b972155b02654a974a0e9"><code>b165d47</code></a>
fix: correct <code>Rule</code> typings (<a
href="https://redirect.github.com/eslint/eslint/issues/20199">#20199</a>)
(jaymarvelz)</li>
<li><a
href="https://github.com/eslint/eslint/commit/fb97cda70d87286a7dbd2457f578ef578d6905e8"><code>fb97cda</code></a>
fix: improve error message for missing fix function in suggestions (<a
href="https://redirect.github.com/eslint/eslint/issues/20218">#20218</a>)
(jaymarvelz)</li>
</ul>
<h2>Documentation</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/d3e81e30ee6be5a21151b7a17ef10a714b6059c0"><code>d3e81e3</code></a>
docs: Always recommend to include a files property (<a
href="https://redirect.github.com/eslint/eslint/issues/20158">#20158</a>)
(Percy Ma)</li>
<li><a
href="https://github.com/eslint/eslint/commit/0f0385f1404dcadaba4812120b1ad02334dbd66a"><code>0f0385f</code></a>
docs: use consistent naming recommendation (<a
href="https://redirect.github.com/eslint/eslint/issues/20250">#20250</a>)
(Alex M. Spieslechner)</li>
<li><a
href="https://github.com/eslint/eslint/commit/a3b145609ac649fac837c8c0515cbb2a9321ca40"><code>a3b1456</code></a>
docs: Update README (GitHub Actions Bot)</li>
<li><a
href="https://github.com/eslint/eslint/commit/cf5f2dd58dd98084a21da04fe7b9054b9478d552"><code>cf5f2dd</code></a>
docs: fix correct tag of <code>no-useless-constructor</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/20255">#20255</a>)
(Tanuj Kanti)</li>
<li><a
href="https://github.com/eslint/eslint/commit/10b995c8e5473de8d66d3cd99d816e046f35e3ec"><code>10b995c</code></a>
docs: add TS options and examples for <code>nofunc</code> in
<code>no-use-before-define</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/20249">#20249</a>)
(Tanuj Kanti)</li>
<li><a
href="https://github.com/eslint/eslint/commit/2584187e4a305ea7a98e1a5bd4dca2a60ad132f8"><code>2584187</code></a>
docs: remove repetitive word in comment (<a
href="https://redirect.github.com/eslint/eslint/issues/20242">#20242</a>)
(reddaisyy)</li>
<li><a
href="https://github.com/eslint/eslint/commit/637216bd4f2aae7c928ad04a4e40eecffb50c9e5"><code>637216b</code></a>
docs: update CLI flags migration instructions (<a
href="https://redirect.github.com/eslint/eslint/issues/20238">#20238</a>)
(jaymarvelz)</li>
<li><a
href="https://github.com/eslint/eslint/commit/e7cda3bdf1bdd664e6033503a3315ad81736b200"><code>e7cda3b</code></a>
docs: Update README (GitHub Actions Bot)</li>
<li><a
href="https://github.com/eslint/eslint/commit/7b9446f7cc2054aa2cdf8e6225f4ac15a03671a8"><code>7b9446f</code></a>
docs: handle empty flags sections on the feature flags page (<a
href="https://redirect.github.com/eslint/eslint/issues/20222">#20222</a>)
(sethamus)</li>
</ul>
<h2>Chores</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/dfe3c1b2034228765c48c8a445554223767dd16d"><code>dfe3c1b</code></a>
chore: update <code>@eslint/js</code> version to 9.39.0 (<a
href="https://redirect.github.com/eslint/eslint/issues/20270">#20270</a>)
(Francesco Trotta)</li>
<li><a
href="https://github.com/eslint/eslint/commit/2375a6de8263393c129d41cac1b407b40111a73c"><code>2375a6d</code></a>
chore: package.json update for <code>@​eslint/js</code> release
(Jenkins)</li>
<li><a
href="https://github.com/eslint/eslint/commit/a1f4e52d67c94bef61edd1607dcd130047c1baf0"><code>a1f4e52</code></a>
chore: update <code>@eslint</code> dependencies (<a
href="https://redirect.github.com/eslint/eslint/issues/20265">#20265</a>)
(Francesco Trotta)</li>
<li><a
href="https://github.com/eslint/eslint/commit/c7d32298482752eeac9fb46378d4f1ea095f3836"><code>c7d3229</code></a>
chore: update dependency <code>@​eslint/core</code> to ^0.17.0 (<a
href="https://redirect.github.com/eslint/eslint/issues/20256">#20256</a>)
(renovate[bot])</li>
<li><a
href="https://github.com/eslint/eslint/commit/27549bc774c7c2dc5c569070a3e87c62f602bf7d"><code>27549bc</code></a>
chore: update fuzz testing to not error if code sample minimizer fails
(<a
href="https://redirect.github.com/eslint/eslint/issues/20252">#20252</a>)
(Milos Djermanovic)</li>
<li><a
href="https://github.com/eslint/eslint/commit/a1370ee40e9d8e0e41843f3278cd745fc1ad543f"><code>a1370ee</code></a>
ci: bump actions/setup-node from 5 to 6 (<a
href="https://redirect.github.com/eslint/eslint/issues/20230">#20230</a>)
(dependabot[bot])</li>
<li><a
href="https://github.com/eslint/eslint/commit/9e7fad4a1867709060686d03e0ec1d0d69671cfb"><code>9e7fad4</code></a>
chore: add script to auto-generate eslint:recommended configuration (<a
href="https://redirect.github.com/eslint/eslint/issues/20208">#20208</a>)
(唯然)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/e2772811a8595d161870835ff04822b25a2cdf45"><code>e277281</code></a>
9.39.1</li>
<li><a
href="https://github.com/eslint/eslint/commit/4cdf397b30b2b749865ea0fcf4d30eb8ba458896"><code>4cdf397</code></a>
Build: changelog update for 9.39.1</li>
<li><a
href="https://github.com/eslint/eslint/commit/92db329211c8da5ce8340a4d4c05ce9c12845381"><code>92db329</code></a>
chore: update <code>@eslint/js</code> version to 9.39.1 (<a
href="https://redirect.github.com/eslint/eslint/issues/20284">#20284</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/c7ebefc9eaf99b76b30b0d3cf9960807a47367c4"><code>c7ebefc</code></a>
chore: package.json update for <code>@​eslint/js</code> release</li>
<li><a
href="https://github.com/eslint/eslint/commit/650753ee3976784343ceb40170619dab1aa9fe0d"><code>650753e</code></a>
fix: Only pass node to JS lang visitor methods (<a
href="https://redirect.github.com/eslint/eslint/issues/20283">#20283</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/51b51f4f1ce82ef63264c4e45d9ef579bcd73f8e"><code>51b51f4</code></a>
docs: add a section on when to use extends vs cascading (<a
href="https://redirect.github.com/eslint/eslint/issues/20268">#20268</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/61778f6ca33c0f63962a91d6a75a4fa5db9f47d2"><code>61778f6</code></a>
chore: update eslint-config-eslint dependency <code>@​eslint/js</code>
to ^9.39.0 (<a
href="https://redirect.github.com/eslint/eslint/issues/20275">#20275</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/d9ca2fcd9ad63331bfd329a69534e1ff04f231e8"><code>d9ca2fc</code></a>
ci: Add rangeStrategy to eslint group in renovate config (<a
href="https://redirect.github.com/eslint/eslint/issues/20266">#20266</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/009e5076ff5a4bd845f55e17676e3bb88f47c280"><code>009e507</code></a>
test: fix version tests for ESLint v10 (<a
href="https://redirect.github.com/eslint/eslint/issues/20274">#20274</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/b44d42699dcd1729b7ecb50ca70e4c1c17f551f1"><code>b44d426</code></a>
docs: Update README</li>
<li>Additional commits viewable in <a
href="https://github.com/eslint/eslint/compare/v9.38.0...v9.39.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=eslint&package-manager=npm_and_yarn&previous-version=9.38.0&new-version=9.39.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#4790) (#4792)

### **PR Description**

Implements support for splitting the runner matcher configuration across
multiple SSM parameters.
`PARAMETER_RUNNER_MATCHER_CONFIG_PATH` can now accept multiple parameter
paths separated by a colon (`:`).

This avoids SSM size limits for large configurations and improves
scalability for environments with many runner types and labels.

Closes #4790

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
🤖 I have created a release *beep* *boop*
---


##
[6.9.0](v6.8.5...v6.9.0)
(2025-11-13)


### Features

* support multiple SSM parameters for large runner matcher configs
([#4790](#4790))
([#4792](#4792))
([4d4872f](4d4872f))
@edersonbrilhante


### Bug Fixes

* **lambda:** bump @octokit/rest from 22.0.0 to 22.0.1 in /lambdas in
the octokit group
([#4876](#4876))
([807aeef](807aeef))
* **lambda:** bump the aws group across 1 directory with 7 updates
([#4871](#4871))
([8737fe2](8737fe2))
* **lambda:** bump the aws-powertools group in /lambdas with 4 updates
([#4865](#4865))
([8c76e12](8c76e12))
* **lambda:** bump the octokit group across 1 directory with 4 updates
([#4873](#4873))
([39fc3cf](39fc3cf))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: runners-releaser[bot] <194412594+runners-releaser[bot]@users.noreply.github.com>
This fixes a few typos in the setup-iam-permissions README.md
This fixes a small typo in the job retry section.

Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
This only fixes a small typo in examples/prebuilt/README.md

Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
This fixes the formatting of the default AMI list in the configuration
docs. See
https://github-aws-runners.github.io/terraform-aws-github-runner/configuration/#ami-configuration.

Without this newline mkdocs does not render the list properly:
<img width="1903" height="572" alt="image"
src="https://github.com/user-attachments/assets/950c1a64-8adb-42c9-856c-1c38cc89f160"
/>

Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
This only fixes a small typo in variables.tf.

Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
Bumps [axios](https://github.com/axios/axios) from 1.12.2 to 1.13.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/releases">axios's
releases</a>.</em></p>
<blockquote>
<h2>Release v1.13.2</h2>
<h2>Release notes:</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>http:</strong> fix 'socket hang up' bug for keep-alive
requests when using timeouts; (<a
href="https://redirect.github.com/axios/axios/issues/7206">#7206</a>)
(<a
href="https://github.com/axios/axios/commit/8d372335f5c50ecd01e8615f2468a9eb19703117">8d37233</a>)</li>
<li><strong>http:</strong> use default export for http2 module to
support stubs; (<a
href="https://redirect.github.com/axios/axios/issues/7196">#7196</a>)
(<a
href="https://github.com/axios/axios/commit/0588880ac7ddba7594ef179930493884b7e90bf5">0588880</a>)</li>
</ul>
<h3>Performance Improvements</h3>
<ul>
<li><strong>http:</strong> fix early loop exit; (<a
href="https://redirect.github.com/axios/axios/issues/7202">#7202</a>)
(<a
href="https://github.com/axios/axios/commit/12c314b603e7852a157e93e47edb626a471ba6c5">12c314b</a>)</li>
</ul>
<h3>Contributors to this release</h3>
<ul>
<li><!-- raw HTML omitted --> <a
href="https://github.com/DigitalBrainJS" title="+28/-9
([#7206](axios/axios#7206)
[#7202](axios/axios#7202) )">Dmitriy
Mozgovoy</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/kasperisager"
title="+9/-9 ([#7196](axios/axios#7196)
)">Kasper Isager Dalsgarð</a></li>
</ul>
<h2>Release v1.13.1</h2>
<h2>Release notes:</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>http:</strong> fixed a regression that caused the data
stream to be interrupted for responses with non-OK HTTP statuses; (<a
href="https://redirect.github.com/axios/axios/issues/7193">#7193</a>)
(<a
href="https://github.com/axios/axios/commit/bcd5581d208cd372055afdcb2fd10b68ca40613c">bcd5581</a>)</li>
</ul>
<h3>Contributors to this release</h3>
<ul>
<li><!-- raw HTML omitted --> <a href="https://github.com/imanchalsingh"
title="+220/-111 ([#7173](axios/axios#7173)
)">Anchal Singh</a></li>
<li><!-- raw HTML omitted --> <a
href="https://github.com/DigitalBrainJS" title="+18/-1
([#7193](axios/axios#7193) )">Dmitriy
Mozgovoy</a></li>
</ul>
<h2>Release v1.13.0</h2>
<h2>Release notes:</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>fetch:</strong> prevent TypeError when config.env is
undefined (<a
href="https://redirect.github.com/axios/axios/issues/7155">#7155</a>)
(<a
href="https://github.com/axios/axios/commit/015faeca9f26db76f9562760f04bb9f8229f4db1">015faec</a>)</li>
<li>resolve issue <a
href="https://redirect.github.com/axios/axios/issues/7131">#7131</a>
(added spacing in mergeConfig.js) (<a
href="https://redirect.github.com/axios/axios/issues/7133">#7133</a>)
(<a
href="https://github.com/axios/axios/commit/9b9ec98548d93e9f2204deea10a5f1528bf3ce62">9b9ec98</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li><strong>http:</strong> add HTTP2 support; (<a
href="https://redirect.github.com/axios/axios/issues/7150">#7150</a>)
(<a
href="https://github.com/axios/axios/commit/d676df772244726533ca320f42e967f5af056bac">d676df7</a>)</li>
</ul>
<h3>Contributors to this release</h3>
<ul>
<li><!-- raw HTML omitted --> <a
href="https://github.com/DigitalBrainJS" title="+794/-180
([#7186](axios/axios#7186)
[#7150](axios/axios#7150)
[#7039](axios/axios#7039) )">Dmitriy
Mozgovoy</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/noritaka1166"
title="+24/-509 ([#7032](axios/axios#7032)
)">Noritaka Kobayashi</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Aviraj2929"
title="+211/-93 ([#7136](axios/axios#7136)
[#7135](axios/axios#7135)
[#7134](axios/axios#7134)
[#7112](axios/axios#7112)
)">Aviraj2929</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Prasoon52"
title="+167/-6 ([#7099](axios/axios#7099)
)">prasoon patel</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Samy-in"
title="+134/-0 ([#7171](axios/axios#7171)
)">Samyak Dandge</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/imanchalsingh"
title="+53/-56 ([#7170](axios/axios#7170)
)">Anchal Singh</a></li>
<li><!-- raw HTML omitted --> <a
href="https://github.com/jaiyankargupta" title="+28/-28
([#7073](axios/axios#7073) )">Rahul
Kumar</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Amitverma0509"
title="+24/-13 ([#7129](axios/axios#7129)
)">Amit Verma</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md">axios's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/axios/axios/compare/v1.13.1...v1.13.2">1.13.2</a>
(2025-11-04)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>http:</strong> fix 'socket hang up' bug for keep-alive
requests when using timeouts; (<a
href="https://redirect.github.com/axios/axios/issues/7206">#7206</a>)
(<a
href="https://github.com/axios/axios/commit/8d372335f5c50ecd01e8615f2468a9eb19703117">8d37233</a>)</li>
<li><strong>http:</strong> use default export for http2 module to
support stubs; (<a
href="https://redirect.github.com/axios/axios/issues/7196">#7196</a>)
(<a
href="https://github.com/axios/axios/commit/0588880ac7ddba7594ef179930493884b7e90bf5">0588880</a>)</li>
</ul>
<h3>Performance Improvements</h3>
<ul>
<li><strong>http:</strong> fix early loop exit; (<a
href="https://redirect.github.com/axios/axios/issues/7202">#7202</a>)
(<a
href="https://github.com/axios/axios/commit/12c314b603e7852a157e93e47edb626a471ba6c5">12c314b</a>)</li>
</ul>
<h3>Contributors to this release</h3>
<ul>
<li><!-- raw HTML omitted --> <a
href="https://github.com/DigitalBrainJS" title="+28/-9
([#7206](axios/axios#7206)
[#7202](axios/axios#7202) )">Dmitriy
Mozgovoy</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/kasperisager"
title="+9/-9 ([#7196](axios/axios#7196)
)">Kasper Isager Dalsgarð</a></li>
</ul>
<h2><a
href="https://github.com/axios/axios/compare/v1.13.0...v1.13.1">1.13.1</a>
(2025-10-28)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>http:</strong> fixed a regression that caused the data
stream to be interrupted for responses with non-OK HTTP statuses; (<a
href="https://redirect.github.com/axios/axios/issues/7193">#7193</a>)
(<a
href="https://github.com/axios/axios/commit/bcd5581d208cd372055afdcb2fd10b68ca40613c">bcd5581</a>)</li>
</ul>
<h3>Contributors to this release</h3>
<ul>
<li><!-- raw HTML omitted --> <a href="https://github.com/imanchalsingh"
title="+220/-111 ([#7173](axios/axios#7173)
)">Anchal Singh</a></li>
<li><!-- raw HTML omitted --> <a
href="https://github.com/DigitalBrainJS" title="+18/-1
([#7193](axios/axios#7193) )">Dmitriy
Mozgovoy</a></li>
</ul>
<h1><a
href="https://github.com/axios/axios/compare/v1.12.2...v1.13.0">1.13.0</a>
(2025-10-27)</h1>
<h3>Bug Fixes</h3>
<ul>
<li><strong>fetch:</strong> prevent TypeError when config.env is
undefined (<a
href="https://redirect.github.com/axios/axios/issues/7155">#7155</a>)
(<a
href="https://github.com/axios/axios/commit/015faeca9f26db76f9562760f04bb9f8229f4db1">015faec</a>)</li>
<li>resolve issue <a
href="https://redirect.github.com/axios/axios/issues/7131">#7131</a>
(added spacing in mergeConfig.js) (<a
href="https://redirect.github.com/axios/axios/issues/7133">#7133</a>)
(<a
href="https://github.com/axios/axios/commit/9b9ec98548d93e9f2204deea10a5f1528bf3ce62">9b9ec98</a>)</li>
</ul>
<h3>Features</h3>
<ul>
<li><strong>http:</strong> add HTTP2 support; (<a
href="https://redirect.github.com/axios/axios/issues/7150">#7150</a>)
(<a
href="https://github.com/axios/axios/commit/d676df772244726533ca320f42e967f5af056bac">d676df7</a>)</li>
</ul>
<h3>Contributors to this release</h3>
<ul>
<li><!-- raw HTML omitted --> <a
href="https://github.com/DigitalBrainJS" title="+794/-180
([#7186](axios/axios#7186)
[#7150](axios/axios#7150)
[#7039](axios/axios#7039) )">Dmitriy
Mozgovoy</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/noritaka1166"
title="+24/-509 ([#7032](axios/axios#7032)
)">Noritaka Kobayashi</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Aviraj2929"
title="+211/-93 ([#7136](axios/axios#7136)
[#7135](axios/axios#7135)
[#7134](axios/axios#7134)
[#7112](axios/axios#7112)
)">Aviraj2929</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Prasoon52"
title="+167/-6 ([#7099](axios/axios#7099)
)">prasoon patel</a></li>
<li><!-- raw HTML omitted --> <a href="https://github.com/Samy-in"
title="+134/-0 ([#7171](axios/axios#7171)
)">Samyak Dandge</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/axios/axios/commit/08b84b52d5835d0c7b81049c365c3d271ade8bff"><code>08b84b5</code></a>
chore(release): v1.13.2 (<a
href="https://redirect.github.com/axios/axios/issues/7207">#7207</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/8d372335f5c50ecd01e8615f2468a9eb19703117"><code>8d37233</code></a>
fix(http): fix 'socket hang up' bug for keep-alive requests when using
timeou...</li>
<li><a
href="https://github.com/axios/axios/commit/12c314b603e7852a157e93e47edb626a471ba6c5"><code>12c314b</code></a>
perf(http): fix early loop exit; (<a
href="https://redirect.github.com/axios/axios/issues/7202">#7202</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/f6d79e773baf70bf4e6d888e72d4bcf589060a84"><code>f6d79e7</code></a>
chore(sponsor): update sponsor block (<a
href="https://redirect.github.com/axios/axios/issues/7203">#7203</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/0588880ac7ddba7594ef179930493884b7e90bf5"><code>0588880</code></a>
fix(http): use default export for http2 module to support stubs; (<a
href="https://redirect.github.com/axios/axios/issues/7196">#7196</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/1ef8e7218b085ac28b675b07349c6d7906a7b6ac"><code>1ef8e72</code></a>
chore(release): v1.13.1 (<a
href="https://redirect.github.com/axios/axios/issues/7194">#7194</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/bcd5581d208cd372055afdcb2fd10b68ca40613c"><code>bcd5581</code></a>
fix(http): fixed a regression that caused the data stream to be
interrupted f...</li>
<li><a
href="https://github.com/axios/axios/commit/c9b33712aac00ca6da7e9767426ff2e0a36c7eed"><code>c9b3371</code></a>
chore: enhance styling and responsiveness in client.html (<a
href="https://redirect.github.com/axios/axios/issues/7173">#7173</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/9ead04d8abbcd53718dbc31b1250ea74300921c8"><code>9ead04d</code></a>
[Release] v1.13.0 (<a
href="https://redirect.github.com/axios/axios/issues/7189">#7189</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/d000fbfd0722a9c3bd0bcea3451c6d515813635d"><code>d000fbf</code></a>
fix(http2): fix possible race condition when handling http2 stream on
almost ...</li>
<li>Additional commits viewable in <a
href="https://github.com/axios/axios/compare/v1.12.2...v1.13.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=axios&package-manager=npm_and_yarn&previous-version=1.12.2&new-version=1.13.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
)

Bumps the aws group with 7 updates in the /lambdas directory:

| Package | From | To |
| --- | --- | --- |
|
[@aws-sdk/client-ec2](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ec2)
| `3.923.0` | `3.930.0` |
|
[@aws-sdk/client-ssm](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm)
| `3.922.0` | `3.930.0` |
|
[@aws-sdk/types](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/types)
| `3.922.0` | `3.930.0` |
|
[@aws-sdk/client-sqs](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sqs)
| `3.922.0` | `3.930.0` |
|
[@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3)
| `3.922.0` | `3.930.0` |
|
[@aws-sdk/lib-storage](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-storage)
| `3.922.0` | `3.930.0` |
|
[@aws-sdk/client-eventbridge](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-eventbridge)
| `3.922.0` | `3.930.0` |


Updates `@aws-sdk/client-ec2` from 3.923.0 to 3.930.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-ec2</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.930.0</h2>
<h4>3.930.0(2025-11-12)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> sync for idempotencyToken fix in http
binding protocols (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7495">#7495</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4">6362fe25</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-sagemaker:</strong> Add support for trn2.3xlarge
instance type for SageMaker Hyperpod (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bf8d2ce31a86d2f50b41b5024e3bb257b7e3ec89">bf8d2ce3</a>)</li>
<li><strong>client-redshift:</strong> Added GetIdentityCenterAuthToken
API to retrieve encrypted authentication tokens for Identity Center
integrated applications. This API enables programmatic access to secure
Identity Center tokens with proper error handling and parameter
validation across supported SDK languages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/145a8368b0b17a727b27f1c0c0eec4757bf4ac5f">145a8368</a>)</li>
<li><strong>client-amp:</strong> Add VPC source configuration support
enabling Amazon Managed Service for Prometheus Collector to collect
metrics from MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4aca00ff44c8e02279f268beb7ff0c33e4c9dfc9">4aca00ff</a>)</li>
<li><strong>client-s3tables:</strong> Adds support for request metrics
metrics APIs for S3 Tables (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0cb01631301a83760446952a0b192046125ef25d">0cb01631</a>)</li>
<li><strong>client-database-migration-service:</strong> Added support of
SQL statements creation, metadata model discovery and selection rules
transformation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/95bd643bf8be824c592679188177b682d329ab29">95bd643b</a>)</li>
<li><strong>client-ec2:</strong> Adds complete AMI ancestry tracing from
immediate parent through each preceding generation back to the root AMI
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d">fa8c029b</a>)</li>
<li><strong>client-elastic-load-balancing-v2:</strong> This release
expands ALB Authentication to support JWT verification and adds support
for a new JWT validation action in listener rule. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/46928a72b5278d83b6f42b1ed40820f374d47b17">46928a72</a>)</li>
<li><strong>client-connect:</strong> Updated Authentication Profile APIs
to add support for automatic logout on user inactivity (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99b0f8d9d7d620e2f65d68dcdeb96f6708b407ff">99b0f8d9</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS Query &amp; EC2
Query clients (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7489">#7489</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082">e9b6da8f</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-cloudwatch:</strong> e2e test of protocol selection
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7491">#7491</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bb14b543035ff5bfff16e30ca784bfb2463aa78c">bb14b543</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.930.0.zip</strong></p>
<h2>v3.929.0</h2>
<h4>3.929.0(2025-11-11)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-batch:</strong> Documentation-only update: update API
and doc descriptions per EKS ImageType default value switch from AL2 to
AL2023. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/42db21d3e829d0728a60be76a31119fb68d3955b">42db21d3</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-bedrock-data-automation:</strong> Added support for
Language Expansion feature for BDA Audio modality. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e2374dbd19e2d414a9691af8550e0f603fdb8ec5">e2374dbd</a>)</li>
<li><strong>client-medical-imaging:</strong> Added new fields in
existing APIs. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8e8ee4a00203ed57c84d5071695367e704d6bc1c">8e8ee4a0</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
connections with up to 5 Gbps bandwidth per tunnel, a 4x improvement
from existing limit of 1.25 Gbps. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992">165cccca</a>)</li>
<li><strong>client-security-ir:</strong> Added support for configuring
communication preferences as well as clearly displaying case comment
author identities. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6c2d4f91937a37c5cecbb0194b536ac903dc46b4">6c2d4f91</a>)</li>
<li><strong>client-rtbfabric:</strong> Added LogSettings and
LinkAttribute fields to external links (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5f3dd496015b734795c5aa59e154fa2eb45d89a3">5f3dd496</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS REST JSON clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7485">#7485</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99a36932937fa5def2b0371b989c6df4d9358044">99a36932</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-s3vectors:</strong> add e2e test (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7487">#7487</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8d3df6ffd3725ff33eb87c050660d95ab8b5d344">8d3df6ff</a>)</li>
<li><strong>client-dynamodb:</strong> e2e test for type registry based
error handling (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7486">#7486</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ba1aeb67ed812f106ea9a039b94e1e5c96c3ff06">ba1aeb67</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> e2e test for live tail
event streams (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7484">#7484</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/3d7ac1614380f54b4f0530917030df65bef0353a">3d7ac161</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ec2/CHANGELOG.md"><code>@​aws-sdk/client-ec2</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.929.0...v3.930.0">3.930.0</a>
(2025-11-12)</h1>
<h3>Features</h3>
<ul>
<li><strong>client-ec2:</strong> Adds complete AMI ancestry tracing from
immediate parent through each preceding generation back to the root AMI
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d">fa8c029</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS Query &amp; EC2
Query clients (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/issues/7489">#7489</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082">e9b6da8</a>)</li>
</ul>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.928.0...v3.929.0">3.929.0</a>
(2025-11-11)</h1>
<h3>Features</h3>
<ul>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
connections with up to 5 Gbps bandwidth per tunnel, a 4x improvement
from existing limit of 1.25 Gbps. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992">165cccc</a>)</li>
</ul>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.927.0...v3.928.0">3.928.0</a>
(2025-11-10)</h1>
<h3>Features</h3>
<ul>
<li><strong>client-ec2:</strong> Amazon EC2 Fleet customers can now
filter instance types based on encryption-in-transit support using
Attribute-Based Instance Type Selection (ABIS), eliminating the manual
effort of identifying and selecting compatible instance types for
security-sensitive workloads. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/2b4fb8055ba029e7ccb89f97b764e3af5bf98236">2b4fb80</a>)</li>
</ul>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.926.0...v3.927.0">3.927.0</a>
(2025-11-07)</h1>
<h3>Features</h3>
<ul>
<li><strong>client-ec2:</strong> Adds PrivateDnsPreference and
PrivateDnsSpecifiedDomains to control private DNS resolution for
resource and service network VPC endpoints and
IpamScopeExternalAuthorityConfiguration to integrate Amazon VPC IPAM
with a third-party IPAM service (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/650aa6de99e961e06fb85b3e447bced743b30a12">650aa6d</a>)</li>
</ul>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.925.0...v3.926.0">3.926.0</a>
(2025-11-06)</h1>
<h3>Features</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2a1737eb76705bcde9f3aa42cae89292ae7ad865"><code>2a1737e</code></a>
Publish v3.930.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d"><code>fa8c029</code></a>
feat(client-ec2): Adds complete AMI ancestry tracing from immediate
parent th...</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4"><code>6362fe2</code></a>
chore(codegen): sync for idempotencyToken fix in http binding protocols
(<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ec2/issues/7495">#7495</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082"><code>e9b6da8</code></a>
feat(clients): use schema-serde in AWS Query &amp; EC2 Query clients (<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ec2/issues/7489">#7489</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/e0c0a7c444232a8c48330ddf918ddf9f716e8334"><code>e0c0a7c</code></a>
Publish v3.929.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992"><code>165cccc</code></a>
feat(client-ec2): AWS Site-to-Site VPN now supports VPN connections with
up t...</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/cbdbdf80b7753988bbde4888d58d705e06414f9b"><code>cbdbdf8</code></a>
Publish v3.928.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2b4fb8055ba029e7ccb89f97b764e3af5bf98236"><code>2b4fb80</code></a>
feat(client-ec2): Amazon EC2 Fleet customers can now filter instance
types ba...</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/73e72810faac8bec7cef525cfaed69e8c9e02d07"><code>73e7281</code></a>
Publish v3.927.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/650aa6de99e961e06fb85b3e447bced743b30a12"><code>650aa6d</code></a>
feat(client-ec2): Adds PrivateDnsPreference and
PrivateDnsSpecifiedDomains to...</li>
<li>Additional commits viewable in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.930.0/clients/client-ec2">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/client-ssm` from 3.922.0 to 3.930.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-ssm</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.930.0</h2>
<h4>3.930.0(2025-11-12)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> sync for idempotencyToken fix in http
binding protocols (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7495">#7495</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4">6362fe25</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-sagemaker:</strong> Add support for trn2.3xlarge
instance type for SageMaker Hyperpod (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bf8d2ce31a86d2f50b41b5024e3bb257b7e3ec89">bf8d2ce3</a>)</li>
<li><strong>client-redshift:</strong> Added GetIdentityCenterAuthToken
API to retrieve encrypted authentication tokens for Identity Center
integrated applications. This API enables programmatic access to secure
Identity Center tokens with proper error handling and parameter
validation across supported SDK languages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/145a8368b0b17a727b27f1c0c0eec4757bf4ac5f">145a8368</a>)</li>
<li><strong>client-amp:</strong> Add VPC source configuration support
enabling Amazon Managed Service for Prometheus Collector to collect
metrics from MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4aca00ff44c8e02279f268beb7ff0c33e4c9dfc9">4aca00ff</a>)</li>
<li><strong>client-s3tables:</strong> Adds support for request metrics
metrics APIs for S3 Tables (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0cb01631301a83760446952a0b192046125ef25d">0cb01631</a>)</li>
<li><strong>client-database-migration-service:</strong> Added support of
SQL statements creation, metadata model discovery and selection rules
transformation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/95bd643bf8be824c592679188177b682d329ab29">95bd643b</a>)</li>
<li><strong>client-ec2:</strong> Adds complete AMI ancestry tracing from
immediate parent through each preceding generation back to the root AMI
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d">fa8c029b</a>)</li>
<li><strong>client-elastic-load-balancing-v2:</strong> This release
expands ALB Authentication to support JWT verification and adds support
for a new JWT validation action in listener rule. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/46928a72b5278d83b6f42b1ed40820f374d47b17">46928a72</a>)</li>
<li><strong>client-connect:</strong> Updated Authentication Profile APIs
to add support for automatic logout on user inactivity (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99b0f8d9d7d620e2f65d68dcdeb96f6708b407ff">99b0f8d9</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS Query &amp; EC2
Query clients (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7489">#7489</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082">e9b6da8f</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-cloudwatch:</strong> e2e test of protocol selection
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7491">#7491</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bb14b543035ff5bfff16e30ca784bfb2463aa78c">bb14b543</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.930.0.zip</strong></p>
<h2>v3.929.0</h2>
<h4>3.929.0(2025-11-11)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-batch:</strong> Documentation-only update: update API
and doc descriptions per EKS ImageType default value switch from AL2 to
AL2023. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/42db21d3e829d0728a60be76a31119fb68d3955b">42db21d3</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-bedrock-data-automation:</strong> Added support for
Language Expansion feature for BDA Audio modality. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e2374dbd19e2d414a9691af8550e0f603fdb8ec5">e2374dbd</a>)</li>
<li><strong>client-medical-imaging:</strong> Added new fields in
existing APIs. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8e8ee4a00203ed57c84d5071695367e704d6bc1c">8e8ee4a0</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
connections with up to 5 Gbps bandwidth per tunnel, a 4x improvement
from existing limit of 1.25 Gbps. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992">165cccca</a>)</li>
<li><strong>client-security-ir:</strong> Added support for configuring
communication preferences as well as clearly displaying case comment
author identities. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6c2d4f91937a37c5cecbb0194b536ac903dc46b4">6c2d4f91</a>)</li>
<li><strong>client-rtbfabric:</strong> Added LogSettings and
LinkAttribute fields to external links (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5f3dd496015b734795c5aa59e154fa2eb45d89a3">5f3dd496</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS REST JSON clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7485">#7485</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99a36932937fa5def2b0371b989c6df4d9358044">99a36932</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-s3vectors:</strong> add e2e test (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7487">#7487</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8d3df6ffd3725ff33eb87c050660d95ab8b5d344">8d3df6ff</a>)</li>
<li><strong>client-dynamodb:</strong> e2e test for type registry based
error handling (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7486">#7486</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ba1aeb67ed812f106ea9a039b94e1e5c96c3ff06">ba1aeb67</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> e2e test for live tail
event streams (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7484">#7484</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/3d7ac1614380f54b4f0530917030df65bef0353a">3d7ac161</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ssm/CHANGELOG.md"><code>@​aws-sdk/client-ssm</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.929.0...v3.930.0">3.930.0</a>
(2025-11-12)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-ssm</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.928.0...v3.929.0">3.929.0</a>
(2025-11-11)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-ssm</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.927.0...v3.928.0">3.928.0</a>
(2025-11-10)</h1>
<h3>Features</h3>
<ul>
<li><strong>clients:</strong> use schema-serde in AWS JSON RPC clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/issues/7483">#7483</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b0f07b49d20d0e1733d36208ad8b2fe052648771">b0f07b4</a>)</li>
</ul>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.926.0...v3.927.0">3.927.0</a>
(2025-11-07)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-ssm</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.925.0...v3.926.0">3.926.0</a>
(2025-11-06)</h1>
<h3>Features</h3>
<ul>
<li><strong>client-ssm:</strong> Provides NoLongerSupportedException
error message (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/70be2a35105b234a082308dbfddd62e70d6204b6">70be2a3</a>)</li>
</ul>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.924.0...v3.925.0">3.925.0</a>
(2025-11-05)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-ssm</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2a1737eb76705bcde9f3aa42cae89292ae7ad865"><code>2a1737e</code></a>
Publish v3.930.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4"><code>6362fe2</code></a>
chore(codegen): sync for idempotencyToken fix in http binding protocols
(<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm/issues/7495">#7495</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/e0c0a7c444232a8c48330ddf918ddf9f716e8334"><code>e0c0a7c</code></a>
Publish v3.929.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/cbdbdf80b7753988bbde4888d58d705e06414f9b"><code>cbdbdf8</code></a>
Publish v3.928.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/b0f07b49d20d0e1733d36208ad8b2fe052648771"><code>b0f07b4</code></a>
feat(clients): use schema-serde in AWS JSON RPC clients (<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm/issues/7483">#7483</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/73e72810faac8bec7cef525cfaed69e8c9e02d07"><code>73e7281</code></a>
Publish v3.927.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/065860aeb0018a8d396f5abaca3874fe2ef789c4"><code>065860a</code></a>
Publish v3.926.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/70be2a35105b234a082308dbfddd62e70d6204b6"><code>70be2a3</code></a>
feat(client-ssm): Provides NoLongerSupportedException error message</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/b554e95e492cf5c4121890932c49755c2d230330"><code>b554e95</code></a>
Publish v3.925.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/4a796b6cf09fe2ca1ffb97294f5b456f31931a98"><code>4a796b6</code></a>
chore(deps): bump smithy package versions (<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm/issues/7475">#7475</a>)</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.930.0/clients/client-ssm">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/types` from 3.922.0 to 3.930.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/types</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.930.0</h2>
<h4>3.930.0(2025-11-12)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> sync for idempotencyToken fix in http
binding protocols (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7495">#7495</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4">6362fe25</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-sagemaker:</strong> Add support for trn2.3xlarge
instance type for SageMaker Hyperpod (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bf8d2ce31a86d2f50b41b5024e3bb257b7e3ec89">bf8d2ce3</a>)</li>
<li><strong>client-redshift:</strong> Added GetIdentityCenterAuthToken
API to retrieve encrypted authentication tokens for Identity Center
integrated applications. This API enables programmatic access to secure
Identity Center tokens with proper error handling and parameter
validation across supported SDK languages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/145a8368b0b17a727b27f1c0c0eec4757bf4ac5f">145a8368</a>)</li>
<li><strong>client-amp:</strong> Add VPC source configuration support
enabling Amazon Managed Service for Prometheus Collector to collect
metrics from MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4aca00ff44c8e02279f268beb7ff0c33e4c9dfc9">4aca00ff</a>)</li>
<li><strong>client-s3tables:</strong> Adds support for request metrics
metrics APIs for S3 Tables (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0cb01631301a83760446952a0b192046125ef25d">0cb01631</a>)</li>
<li><strong>client-database-migration-service:</strong> Added support of
SQL statements creation, metadata model discovery and selection rules
transformation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/95bd643bf8be824c592679188177b682d329ab29">95bd643b</a>)</li>
<li><strong>client-ec2:</strong> Adds complete AMI ancestry tracing from
immediate parent through each preceding generation back to the root AMI
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d">fa8c029b</a>)</li>
<li><strong>client-elastic-load-balancing-v2:</strong> This release
expands ALB Authentication to support JWT verification and adds support
for a new JWT validation action in listener rule. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/46928a72b5278d83b6f42b1ed40820f374d47b17">46928a72</a>)</li>
<li><strong>client-connect:</strong> Updated Authentication Profile APIs
to add support for automatic logout on user inactivity (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99b0f8d9d7d620e2f65d68dcdeb96f6708b407ff">99b0f8d9</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS Query &amp; EC2
Query clients (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7489">#7489</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082">e9b6da8f</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-cloudwatch:</strong> e2e test of protocol selection
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7491">#7491</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bb14b543035ff5bfff16e30ca784bfb2463aa78c">bb14b543</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.930.0.zip</strong></p>
<h2>v3.929.0</h2>
<h4>3.929.0(2025-11-11)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-batch:</strong> Documentation-only update: update API
and doc descriptions per EKS ImageType default value switch from AL2 to
AL2023. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/42db21d3e829d0728a60be76a31119fb68d3955b">42db21d3</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-bedrock-data-automation:</strong> Added support for
Language Expansion feature for BDA Audio modality. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e2374dbd19e2d414a9691af8550e0f603fdb8ec5">e2374dbd</a>)</li>
<li><strong>client-medical-imaging:</strong> Added new fields in
existing APIs. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8e8ee4a00203ed57c84d5071695367e704d6bc1c">8e8ee4a0</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
connections with up to 5 Gbps bandwidth per tunnel, a 4x improvement
from existing limit of 1.25 Gbps. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992">165cccca</a>)</li>
<li><strong>client-security-ir:</strong> Added support for configuring
communication preferences as well as clearly displaying case comment
author identities. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6c2d4f91937a37c5cecbb0194b536ac903dc46b4">6c2d4f91</a>)</li>
<li><strong>client-rtbfabric:</strong> Added LogSettings and
LinkAttribute fields to external links (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5f3dd496015b734795c5aa59e154fa2eb45d89a3">5f3dd496</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS REST JSON clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7485">#7485</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99a36932937fa5def2b0371b989c6df4d9358044">99a36932</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-s3vectors:</strong> add e2e test (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7487">#7487</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8d3df6ffd3725ff33eb87c050660d95ab8b5d344">8d3df6ff</a>)</li>
<li><strong>client-dynamodb:</strong> e2e test for type registry based
error handling (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7486">#7486</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ba1aeb67ed812f106ea9a039b94e1e5c96c3ff06">ba1aeb67</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> e2e test for live tail
event streams (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7484">#7484</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/3d7ac1614380f54b4f0530917030df65bef0353a">3d7ac161</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/packages/types/CHANGELOG.md"><code>@​aws-sdk/types</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.929.0...v3.930.0">3.930.0</a>
(2025-11-12)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/types</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2a1737eb76705bcde9f3aa42cae89292ae7ad865"><code>2a1737e</code></a>
Publish v3.930.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4"><code>6362fe2</code></a>
chore(codegen): sync for idempotencyToken fix in http binding protocols
(<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/types/issues/7495">#7495</a>)</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.930.0/packages/types">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/client-sqs` from 3.922.0 to 3.930.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-sqs</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.930.0</h2>
<h4>3.930.0(2025-11-12)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> sync for idempotencyToken fix in http
binding protocols (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7495">#7495</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4">6362fe25</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-sagemaker:</strong> Add support for trn2.3xlarge
instance type for SageMaker Hyperpod (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bf8d2ce31a86d2f50b41b5024e3bb257b7e3ec89">bf8d2ce3</a>)</li>
<li><strong>client-redshift:</strong> Added GetIdentityCenterAuthToken
API to retrieve encrypted authentication tokens for Identity Center
integrated applications. This API enables programmatic access to secure
Identity Center tokens with proper error handling and parameter
validation across supported SDK languages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/145a8368b0b17a727b27f1c0c0eec4757bf4ac5f">145a8368</a>)</li>
<li><strong>client-amp:</strong> Add VPC source configuration support
enabling Amazon Managed Service for Prometheus Collector to collect
metrics from MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4aca00ff44c8e02279f268beb7ff0c33e4c9dfc9">4aca00ff</a>)</li>
<li><strong>client-s3tables:</strong> Adds support for request metrics
metrics APIs for S3 Tables (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0cb01631301a83760446952a0b192046125ef25d">0cb01631</a>)</li>
<li><strong>client-database-migration-service:</strong> Added support of
SQL statements creation, metadata model discovery and selection rules
transformation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/95bd643bf8be824c592679188177b682d329ab29">95bd643b</a>)</li>
<li><strong>client-ec2:</strong> Adds complete AMI ancestry tracing from
immediate parent through each preceding generation back to the root AMI
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d">fa8c029b</a>)</li>
<li><strong>client-elastic-load-balancing-v2:</strong> This release
expands ALB Authentication to support JWT verification and adds support
for a new JWT validation action in listener rule. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/46928a72b5278d83b6f42b1ed40820f374d47b17">46928a72</a>)</li>
<li><strong>client-connect:</strong> Updated Authentication Profile APIs
to add support for automatic logout on user inactivity (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99b0f8d9d7d620e2f65d68dcdeb96f6708b407ff">99b0f8d9</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS Query &amp; EC2
Query clients (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7489">#7489</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082">e9b6da8f</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-cloudwatch:</strong> e2e test of protocol selection
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7491">#7491</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bb14b543035ff5bfff16e30ca784bfb2463aa78c">bb14b543</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.930.0.zip</strong></p>
<h2>v3.929.0</h2>
<h4>3.929.0(2025-11-11)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-batch:</strong> Documentation-only update: update API
and doc descriptions per EKS ImageType default value switch from AL2 to
AL2023. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/42db21d3e829d0728a60be76a31119fb68d3955b">42db21d3</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-bedrock-data-automation:</strong> Added support for
Language Expansion feature for BDA Audio modality. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e2374dbd19e2d414a9691af8550e0f603fdb8ec5">e2374dbd</a>)</li>
<li><strong>client-medical-imaging:</strong> Added new fields in
existing APIs. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8e8ee4a00203ed57c84d5071695367e704d6bc1c">8e8ee4a0</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
connections with up to 5 Gbps bandwidth per tunnel, a 4x improvement
from existing limit of 1.25 Gbps. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992">165cccca</a>)</li>
<li><strong>client-security-ir:</strong> Added support for configuring
communication preferences as well as clearly displaying case comment
author identities. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6c2d4f91937a37c5cecbb0194b536ac903dc46b4">6c2d4f91</a>)</li>
<li><strong>client-rtbfabric:</strong> Added LogSettings and
LinkAttribute fields to external links (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5f3dd496015b734795c5aa59e154fa2eb45d89a3">5f3dd496</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS REST JSON clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7485">#7485</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99a36932937fa5def2b0371b989c6df4d9358044">99a36932</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-s3vectors:</strong> add e2e test (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7487">#7487</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8d3df6ffd3725ff33eb87c050660d95ab8b5d344">8d3df6ff</a>)</li>
<li><strong>client-dynamodb:</strong> e2e test for type registry based
error handling (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7486">#7486</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ba1aeb67ed812f106ea9a039b94e1e5c96c3ff06">ba1aeb67</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> e2e test for live tail
event streams (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7484">#7484</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/3d7ac1614380f54b4f0530917030df65bef0353a">3d7ac161</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sqs/CHANGELOG.md"><code>@​aws-sdk/client-sqs</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.929.0...v3.930.0">3.930.0</a>
(2025-11-12)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-sqs</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.928.0...v3.929.0">3.929.0</a>
(2025-11-11)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-sqs</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.927.0...v3.928.0">3.928.0</a>
(2025-11-10)</h1>
<h3>Features</h3>
<ul>
<li><strong>clients:</strong> use schema-serde in AWS JSON RPC clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/issues/7483">#7483</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b0f07b49d20d0e1733d36208ad8b2fe052648771">b0f07b4</a>)</li>
</ul>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.926.0...v3.927.0">3.927.0</a>
(2025-11-07)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-sqs</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.925.0...v3.926.0">3.926.0</a>
(2025-11-06)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-sqs</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.924.0...v3.925.0">3.925.0</a>
(2025-11-05)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-sqs</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2a1737eb76705bcde9f3aa42cae89292ae7ad865"><code>2a1737e</code></a>
Publish v3.930.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4"><code>6362fe2</code></a>
chore(codegen): sync for idempotencyToken fix in http binding protocols
(<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sqs/issues/7495">#7495</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/e0c0a7c444232a8c48330ddf918ddf9f716e8334"><code>e0c0a7c</code></a>
Publish v3.929.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/cbdbdf80b7753988bbde4888d58d705e06414f9b"><code>cbdbdf8</code></a>
Publish v3.928.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/b0f07b49d20d0e1733d36208ad8b2fe052648771"><code>b0f07b4</code></a>
feat(clients): use schema-serde in AWS JSON RPC clients (<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sqs/issues/7483">#7483</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/73e72810faac8bec7cef525cfaed69e8c9e02d07"><code>73e7281</code></a>
Publish v3.927.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/065860aeb0018a8d396f5abaca3874fe2ef789c4"><code>065860a</code></a>
Publish v3.926.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/b554e95e492cf5c4121890932c49755c2d230330"><code>b554e95</code></a>
Publish v3.925.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/4a796b6cf09fe2ca1ffb97294f5b456f31931a98"><code>4a796b6</code></a>
chore(deps): bump smithy package versions (<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sqs/issues/7475">#7475</a>)</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.930.0/clients/client-sqs">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/client-s3` from 3.922.0 to 3.930.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-s3</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.930.0</h2>
<h4>3.930.0(2025-11-12)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> sync for idempotencyToken fix in http
binding protocols (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7495">#7495</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4">6362fe25</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-sagemaker:</strong> Add support for trn2.3xlarge
instance type for SageMaker Hyperpod (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bf8d2ce31a86d2f50b41b5024e3bb257b7e3ec89">bf8d2ce3</a>)</li>
<li><strong>client-redshift:</strong> Added GetIdentityCenterAuthToken
API to retrieve encrypted authentication tokens for Identity Center
integrated applications. This API enables programmatic access to secure
Identity Center tokens with proper error handling and parameter
validation across supported SDK languages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/145a8368b0b17a727b27f1c0c0eec4757bf4ac5f">145a8368</a>)</li>
<li><strong>client-amp:</strong> Add VPC source configuration support
enabling Amazon Managed Service for Prometheus Collector to collect
metrics from MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4aca00ff44c8e02279f268beb7ff0c33e4c9dfc9">4aca00ff</a>)</li>
<li><strong>client-s3tables:</strong> Adds support for request metrics
metrics APIs for S3 Tables (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0cb01631301a83760446952a0b192046125ef25d">0cb01631</a>)</li>
<li><strong>client-database-migration-service:</strong> Added support of
SQL statements creation, metadata model discovery and selection rules
transformation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/95bd643bf8be824c592679188177b682d329ab29">95bd643b</a>)</li>
<li><strong>client-ec2:</strong> Adds complete AMI ancestry tracing from
immediate parent through each preceding generation back to the root AMI
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d">fa8c029b</a>)</li>
<li><strong>client-elastic-load-balancing-v2:</strong> This release
expands ALB Authentication to support JWT verification and adds support
for a new JWT validation action in listener rule. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/46928a72b5278d83b6f42b1ed40820f374d47b17">46928a72</a>)</li>
<li><strong>client-connect:</strong> Updated Authentication Profile APIs
to add support for automatic logout on user inactivity (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99b0f8d9d7d620e2f65d68dcdeb96f6708b407ff">99b0f8d9</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS Query &amp; EC2
Query clients (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7489">#7489</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082">e9b6da8f</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-cloudwatch:</strong> e2e test of protocol selection
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7491">#7491</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bb14b543035ff5bfff16e30ca784bfb2463aa78c">bb14b543</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.930.0.zip</strong></p>
<h2>v3.929.0</h2>
<h4>3.929.0(2025-11-11)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-batch:</strong> Documentation-only update: update API
and doc descriptions per EKS ImageType default value switch from AL2 to
AL2023. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/42db21d3e829d0728a60be76a31119fb68d3955b">42db21d3</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-bedrock-data-automation:</strong> Added support for
Language Expansion feature for BDA Audio modality. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e2374dbd19e2d414a9691af8550e0f603fdb8ec5">e2374dbd</a>)</li>
<li><strong>client-medical-imaging:</strong> Added new fields in
existing APIs. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8e8ee4a00203ed57c84d5071695367e704d6bc1c">8e8ee4a0</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
connections with up to 5 Gbps bandwidth per tunnel, a 4x improvement
from existing limit of 1.25 Gbps. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992">165cccca</a>)</li>
<li><strong>client-security-ir:</strong> Added support for configuring
communication preferences as well as clearly displaying case comment
author identities. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6c2d4f91937a37c5cecbb0194b536ac903dc46b4">6c2d4f91</a>)</li>
<li><strong>client-rtbfabric:</strong> Added LogSettings and
LinkAttribute fields to external links (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5f3dd496015b734795c5aa59e154fa2eb45d89a3">5f3dd496</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS REST JSON clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7485">#7485</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99a36932937fa5def2b0371b989c6df4d9358044">99a36932</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-s3vectors:</strong> add e2e test (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7487">#7487</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8d3df6ffd3725ff33eb87c050660d95ab8b5d344">8d3df6ff</a>)</li>
<li><strong>client-dynamodb:</strong> e2e test for type registry based
error handling (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7486">#7486</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ba1aeb67ed812f106ea9a039b94e1e5c96c3ff06">ba1aeb67</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> e2e test for live tail
event streams (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7484">#7484</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/3d7ac1614380f54b4f0530917030df65bef0353a">3d7ac161</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md"><code>@​aws-sdk/client-s3</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.929.0...v3.930.0">3.930.0</a>
(2025-11-12)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.928.0...v3.929.0">3.929.0</a>
(2025-11-11)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.927.0...v3.928.0">3.928.0</a>
(2025-11-10)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.926.0...v3.927.0">3.927.0</a>
(2025-11-07)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.925.0...v3.926.0">3.926.0</a>
(2025-11-06)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.924.0...v3.925.0">3.925.0</a>
(2025-11-05)</h1>
<h3>Features</h3>
<ul>
<li><strong>client-s3:</strong> Launch IPv6 dual-stack support for S3
Express (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/a6a3e2980d299734956f0bccc69c094a8757549f">a6a3e29</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2a1737eb76705bcde9f3aa42cae89292ae7ad865"><code>2a1737e</code></a>
Publish v3.930.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4"><code>6362fe2</code></a>
chore(codegen): sync for idempotencyToken fix in http binding protocols
(<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3/issues/7495">#7495</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/e0c0a7c444232a8c48330ddf918ddf9f716e8334"><code>e0c0a7c</code></a>
Publish v3.929.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/cbdbdf80b7753988bbde4888d58d705e06414f9b"><code>cbdbdf8</code></a>
Publish v3.928.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/73e72810faac8bec7cef525cfaed69e8c9e02d07"><code>73e7281</code></a>
Publish v3.927.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/065860aeb0018a8d396f5abaca3874fe2ef789c4"><code>065860a</code></a>
Publish v3.926.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/b554e95e492cf5c4121890932c49755c2d230330"><code>b554e95</code></a>
Publish v3.925.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/a6a3e2980d299734956f0bccc69c094a8757549f"><code>a6a3e29</code></a>
feat(client-s3): Launch IPv6 dual-stack support for S3 Express</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/4a796b6cf09fe2ca1ffb97294f5b456f31931a98"><code>4a796b6</code></a>
chore(deps): bump smithy package versions (<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3/issues/7475">#7475</a>)</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.930.0/clients/client-s3">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/lib-storage` from 3.922.0 to 3.930.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/lib-storage</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.930.0</h2>
<h4>3.930.0(2025-11-12)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> sync for idempotencyToken fix in http
binding protocols (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7495">#7495</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4">6362fe25</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-sagemaker:</strong> Add support for trn2.3xlarge
instance type for SageMaker Hyperpod (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bf8d2ce31a86d2f50b41b5024e3bb257b7e3ec89">bf8d2ce3</a>)</li>
<li><strong>client-redshift:</strong> Added GetIdentityCenterAuthToken
API to retrieve encrypted authentication tokens for Identity Center
integrated applications. This API enables programmatic access to secure
Identity Center tokens with proper error handling and parameter
validation across supported SDK languages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/145a8368b0b17a727b27f1c0c0eec4757bf4ac5f">145a8368</a>)</li>
<li><strong>client-amp:</strong> Add VPC source configuration support
enabling Amazon Managed Service for Prometheus Collector to collect
metrics from MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4aca00ff44c8e02279f268beb7ff0c33e4c9dfc9">4aca00ff</a>)</li>
<li><strong>client-s3tables:</strong> Adds support for request metrics
metrics APIs for S3 Tables (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0cb01631301a83760446952a0b192046125ef25d">0cb01631</a>)</li>
<li><strong>client-database-migration-service:</strong> Added support of
SQL statements creation, metadata model discovery and selection rules
transformation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/95bd643bf8be824c592679188177b682d329ab29">95bd643b</a>)</li>
<li><strong>client-ec2:</strong> Adds complete AMI ancestry tracing from
immediate parent through each preceding generation back to the root AMI
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d">fa8c029b</a>)</li>
<li><strong>client-elastic-load-balancing-v2:</strong> This release
expands ALB Authentication to support JWT verification and adds support
for a new JWT validation action in listener rule. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/46928a72b5278d83b6f42b1ed40820f374d47b17">46928a72</a>)</li>
<li><strong>client-connect:</strong> Updated Authentication Profile APIs
to add support for automatic logout on user inactivity (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99b0f8d9d7d620e2f65d68dcdeb96f6708b407ff">99b0f8d9</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS Query &amp; EC2
Query clients (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7489">#7489</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082">e9b6da8f</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-cloudwatch:</strong> e2e test of protocol selection
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7491">#7491</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bb14b543035ff5bfff16e30ca784bfb2463aa78c">bb14b543</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.930.0.zip</strong></p>
<h2>v3.929.0</h2>
<h4>3.929.0(2025-11-11)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-batch:</strong> Documentation-only update: update API
and doc descriptions per EKS ImageType default value switch from AL2 to
AL2023. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/42db21d3e829d0728a60be76a31119fb68d3955b">42db21d3</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-bedrock-data-automation:</strong> Added support for
Language Expansion feature for BDA Audio modality. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e2374dbd19e2d414a9691af8550e0f603fdb8ec5">e2374dbd</a>)</li>
<li><strong>client-medical-imaging:</strong> Added new fields in
existing APIs. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8e8ee4a00203ed57c84d5071695367e704d6bc1c">8e8ee4a0</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
connections with up to 5 Gbps bandwidth per tunnel, a 4x improvement
from existing limit of 1.25 Gbps. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992">165cccca</a>)</li>
<li><strong>client-security-ir:</strong> Added support for configuring
communication preferences as well as clearly displaying case comment
author identities. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6c2d4f91937a37c5cecbb0194b536ac903dc46b4">6c2d4f91</a>)</li>
<li><strong>client-rtbfabric:</strong> Added LogSettings and
LinkAttribute fields to external links (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5f3dd496015b734795c5aa59e154fa2eb45d89a3">5f3dd496</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS REST JSON clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7485">#7485</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99a36932937fa5def2b0371b989c6df4d9358044">99a36932</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-s3vectors:</strong> add e2e test (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7487">#7487</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8d3df6ffd3725ff33eb87c050660d95ab8b5d344">8d3df6ff</a>)</li>
<li><strong>client-dynamodb:</strong> e2e test for type registry based
error handling (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7486">#7486</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ba1aeb67ed812f106ea9a039b94e1e5c96c3ff06">ba1aeb67</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> e2e test for live tail
event streams (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7484">#7484</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/3d7ac1614380f54b4f0530917030df65bef0353a">3d7ac161</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-storage/CHANGELOG.md"><code>@​aws-sdk/lib-storage</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.929.0...v3.930.0">3.930.0</a>
(2025-11-12)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/lib-storage</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.928.0...v3.929.0">3.929.0</a>
(2025-11-11)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/lib-storage</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.927.0...v3.928.0">3.928.0</a>
(2025-11-10)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/lib-storage</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.926.0...v3.927.0">3.927.0</a>
(2025-11-07)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/lib-storage</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.925.0...v3.926.0">3.926.0</a>
(2025-11-06)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/lib-storage</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.924.0...v3.925.0">3.925.0</a>
(2025-11-05)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/lib-storage</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2a1737eb76705bcde9f3aa42cae89292ae7ad865"><code>2a1737e</code></a>
Publish v3.930.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4"><code>6362fe2</code></a>
chore(codegen): sync for idempotencyToken fix in http binding protocols
(<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-storage/issues/7495">#7495</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/e0c0a7c444232a8c48330ddf918ddf9f716e8334"><code>e0c0a7c</code></a>
Publish v3.929.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/cbdbdf80b7753988bbde4888d58d705e06414f9b"><code>cbdbdf8</code></a>
Publish v3.928.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/73e72810faac8bec7cef525cfaed69e8c9e02d07"><code>73e7281</code></a>
Publish v3.927.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/065860aeb0018a8d396f5abaca3874fe2ef789c4"><code>065860a</code></a>
Publish v3.926.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/b554e95e492cf5c4121890932c49755c2d230330"><code>b554e95</code></a>
Publish v3.925.0</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.930.0/lib/lib-storage">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/client-eventbridge` from 3.922.0 to 3.930.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-eventbridge</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.930.0</h2>
<h4>3.930.0(2025-11-12)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> sync for idempotencyToken fix in http
binding protocols (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7495">#7495</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6362fe25f8fae78b0025ff3c8faec4570bcb4bd4">6362fe25</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-sagemaker:</strong> Add support for trn2.3xlarge
instance type for SageMaker Hyperpod (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bf8d2ce31a86d2f50b41b5024e3bb257b7e3ec89">bf8d2ce3</a>)</li>
<li><strong>client-redshift:</strong> Added GetIdentityCenterAuthToken
API to retrieve encrypted authentication tokens for Identity Center
integrated applications. This API enables programmatic access to secure
Identity Center tokens with proper error handling and parameter
validation across supported SDK languages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/145a8368b0b17a727b27f1c0c0eec4757bf4ac5f">145a8368</a>)</li>
<li><strong>client-amp:</strong> Add VPC source configuration support
enabling Amazon Managed Service for Prometheus Collector to collect
metrics from MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4aca00ff44c8e02279f268beb7ff0c33e4c9dfc9">4aca00ff</a>)</li>
<li><strong>client-s3tables:</strong> Adds support for request metrics
metrics APIs for S3 Tables (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0cb01631301a83760446952a0b192046125ef25d">0cb01631</a>)</li>
<li><strong>client-database-migration-service:</strong> Added support of
SQL statements creation, metadata model discovery and selection rules
transformation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/95bd643bf8be824c592679188177b682d329ab29">95bd643b</a>)</li>
<li><strong>client-ec2:</strong> Adds complete AMI ancestry tracing from
immediate parent through each preceding generation back to the root AMI
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa8c029baf52f395a7250b0061646a601a1aad1d">fa8c029b</a>)</li>
<li><strong>client-elastic-load-balancing-v2:</strong> This release
expands ALB Authentication to support JWT verification and adds support
for a new JWT validation action in listener rule. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/46928a72b5278d83b6f42b1ed40820f374d47b17">46928a72</a>)</li>
<li><strong>client-connect:</strong> Updated Authentication Profile APIs
to add support for automatic logout on user inactivity (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99b0f8d9d7d620e2f65d68dcdeb96f6708b407ff">99b0f8d9</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS Query &amp; EC2
Query clients (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7489">#7489</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e9b6da8fd2a66809bb67e642fc254ede6bc16082">e9b6da8f</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-cloudwatch:</strong> e2e test of protocol selection
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7491">#7491</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/bb14b543035ff5bfff16e30ca784bfb2463aa78c">bb14b543</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.930.0.zip</strong></p>
<h2>v3.929.0</h2>
<h4>3.929.0(2025-11-11)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-batch:</strong> Documentation-only update: update API
and doc descriptions per EKS ImageType default value switch from AL2 to
AL2023. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/42db21d3e829d0728a60be76a31119fb68d3955b">42db21d3</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-bedrock-data-automation:</strong> Added support for
Language Expansion feature for BDA Audio modality. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e2374dbd19e2d414a9691af8550e0f603fdb8ec5">e2374dbd</a>)</li>
<li><strong>client-medical-imaging:</strong> Added new fields in
existing APIs. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8e8ee4a00203ed57c84d5071695367e704d6bc1c">8e8ee4a0</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
connections with up to 5 Gbps bandwidth per tunnel, a 4x improvement
from existing limit of 1.25 Gbps. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/165ccccacac38eca73c45fe5e21c04cf82751992">165cccca</a>)</li>
<li><strong>client-security-ir:</strong> Added support for configuring
communication preferences as well as clearly displaying case comment
author identities. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6c2d4f91937a37c5cecbb0194b536ac903dc46b4">6c2d4f91</a>)</li>
<li><strong>client-rtbfabric:</strong> Added LogSettings and
LinkAttribute fields to external links (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5f3dd496015b734795c5aa59e154fa2eb45d89a3">5f3dd496</a>)</li>
<li><strong>clients:</strong> use schema-serde in AWS REST JSON clients
(<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7485">#7485</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/99a36932937fa5def2b0371b989c6df4d9358044">99a36932</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>client-s3vectors:</strong> add e2e test (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7487">#7487</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/8d3df6ffd3725ff33eb87c050660d95ab8b5d344">8d3df6ff</a>)</li>
<li><strong>client-dynamodb:</strong> e2e test for type registry based
error handling (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7486">#7486</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ba1aeb67ed812f106ea9a039b94e1e5c96c3ff06">ba1aeb67</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> e2e test for live tail
event streams (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7484">#7484</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/3d7ac1614380f54b4f0530917030df65bef0353a">3d7ac161</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-eventbridge/CHANGELOG.md"><code>@​aws-sdk/client-eventbridge</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.929.0...v3.930.0">3.930.0</a>
(2025-11-12)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-eventbridge</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.928.0...v3.929.0">3.929.0</a>
(2025-11-11)<...

_Description has been truncated_…
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.14.1 to
3.14.2.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md">js-yaml's
changelog</a>.</em></p>
<blockquote>
<h2>[3.14.2] - 2025-11-15</h2>
<h3>Security</h3>
<ul>
<li>Backported v4.1.1 fix to v3</li>
</ul>
<h2>[4.1.1] - 2025-11-12</h2>
<h3>Security</h3>
<ul>
<li>Fix prototype pollution issue in yaml merge (&lt;&lt;)
operator.</li>
</ul>
<h2>[4.1.0] - 2021-04-15</h2>
<h3>Added</h3>
<ul>
<li>Types are now exported as <code>yaml.types.XXX</code>.</li>
<li>Every type now has <code>options</code> property with original
arguments kept as they were
(see <code>yaml.types.int.options</code> as an example).</li>
</ul>
<h3>Changed</h3>
<ul>
<li><code>Schema.extend()</code> now keeps old type order in case of
conflicts
(e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as
<code>abcd</code> instead of <code>cbad</code>).</li>
</ul>
<h2>[4.0.0] - 2021-01-03</h2>
<h3>Changed</h3>
<ul>
<li>Check <a
href="https://github.com/nodeca/js-yaml/blob/master/migrate_v3_to_v4.md">migration
guide</a> to see details for all breaking changes.</li>
<li>Breaking: &quot;unsafe&quot; tags <code>!!js/function</code>,
<code>!!js/regexp</code>, <code>!!js/undefined</code> are
moved to <a
href="https://github.com/nodeca/js-yaml-js-types">js-yaml-js-types</a>
package.</li>
<li>Breaking: removed <code>safe*</code> functions. Use
<code>load</code>, <code>loadAll</code>, <code>dump</code>
instead which are all now safe by default.</li>
<li><code>yaml.DEFAULT_SAFE_SCHEMA</code> and
<code>yaml.DEFAULT_FULL_SCHEMA</code> are removed, use
<code>yaml.DEFAULT_SCHEMA</code> instead.</li>
<li><code>yaml.Schema.create(schema, tags)</code> is removed, use
<code>schema.extend(tags)</code> instead.</li>
<li><code>!!binary</code> now always mapped to <code>Uint8Array</code>
on load.</li>
<li>Reduced nesting of <code>/lib</code> folder.</li>
<li>Parse numbers according to YAML 1.2 instead of YAML 1.1
(<code>01234</code> is now decimal,
<code>0o1234</code> is octal, <code>1:23</code> is parsed as string
instead of base60).</li>
<li><code>dump()</code> no longer quotes <code>:</code>, <code>[</code>,
<code>]</code>, <code>(</code>, <code>)</code> except when necessary, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/470">#470</a>,
<a
href="https://redirect.github.com/nodeca/js-yaml/issues/557">#557</a>.</li>
<li>Line and column in exceptions are now formatted as
<code>(X:Y)</code> instead of
<code>at line X, column Y</code> (also present in compact format), <a
href="https://redirect.github.com/nodeca/js-yaml/issues/332">#332</a>.</li>
<li>Code snippet created in exceptions now contains multiple lines with
line numbers.</li>
<li><code>dump()</code> now serializes <code>undefined</code> as
<code>null</code> in collections and removes keys with
<code>undefined</code> in mappings, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/571">#571</a>.</li>
<li><code>dump()</code> with <code>skipInvalid=true</code> now
serializes invalid items in collections as null.</li>
<li>Custom tags starting with <code>!</code> are now dumped as
<code>!tag</code> instead of <code>!&lt;!tag&gt;</code>, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/576">#576</a>.</li>
<li>Custom tags starting with <code>tag:yaml.org,2002:</code> are now
shorthanded using <code>!!</code>, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/258">#258</a>.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>.mjs</code> (es modules) support.</li>
<li>Added <code>quotingType</code> and <code>forceQuotes</code> options
for dumper to configure
string literal style, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/290">#290</a>,
<a
href="https://redirect.github.com/nodeca/js-yaml/issues/529">#529</a>.</li>
<li>Added <code>styles: { '!!null': 'empty' }</code> option for dumper
(serializes <code>{ foo: null }</code> as &quot;<code>foo:
</code>&quot;), <a
href="https://redirect.github.com/nodeca/js-yaml/issues/570">#570</a>.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodeca/js-yaml/commit/9963d366dfbde0c69722452bcd40b41e7e4160a0"><code>9963d36</code></a>
3.14.2 released</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/10d3c8e70a6888543f5cdb656bb39f73e0ea77c1"><code>10d3c8e</code></a>
dist rebuild</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/5278870a17454fe8621dbd8c445c412529525266"><code>5278870</code></a>
fix prototype pollution in merge (&lt;&lt;) (<a
href="https://redirect.github.com/nodeca/js-yaml/issues/731">#731</a>)</li>
<li>See full diff in <a
href="https://github.com/nodeca/js-yaml/compare/3.14.1...3.14.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=js-yaml&package-manager=npm_and_yarn&previous-version=3.14.1&new-version=3.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github-aws-runners/terraform-aws-github-runner/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…2 in the github group (#4891)

Bumps the github group with 1 update:
[actions/dependency-review-action](https://github.com/actions/dependency-review-action).

Updates `actions/dependency-review-action` from 4.8.1 to 4.8.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/dependency-review-action/releases">actions/dependency-review-action's
releases</a>.</em></p>
<blockquote>
<h2>v4.8.2</h2>
<p>Minor fixes:</p>
<ul>
<li>Fix PURL parsing for scoped packages (<a
href="https://redirect.github.com/actions/dependency-review-action/issues/1008">#1008</a>
from <a
href="https://github.com/danielhardej"><code>@​danielhardej</code></a>)</li>
<li>Fix for large summaries (<a
href="https://redirect.github.com/actions/dependency-review-action/issues/1007">#1007</a>
from <a
href="https://github.com/gitulisca"><code>@​gitulisca</code></a>)</li>
<li>README includes a working example for allow-dependencies-licenses
(<a
href="https://redirect.github.com/actions/dependency-review-action/issues/1009">#1009</a>
from <a
href="https://github.com/danielhardej"><code>@​danielhardej</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/dependency-review-action/commit/3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261"><code>3c4e3dc</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/dependency-review-action/issues/1016">#1016</a>
from actions/dra-release</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/02930b20720cb37e7293c96576ceb2f02ce79c71"><code>02930b2</code></a>
Update CONTRIBUTING to reflect new guidelines</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/49ffd9f63637913e4278660c97bdd9bac6ecea38"><code>49ffd9f</code></a>
Update CONTRIBUTING to reflect the need to build</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/70cb25ec56c23f6b008aa8cc4dd3a75e22332068"><code>70cb25e</code></a>
4.8.2 release</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/ebabd31cea6586a03e892ca61a418ff50fd4c0ad"><code>ebabd31</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/dependency-review-action/issues/1008">#1008</a>
from danielhardej/danielhardej-patch-20251023</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/19f9360983096b13b12d6095ff298528ffbfe9cf"><code>19f9360</code></a>
Update package-lock.json</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/5fd2f98b4f14a64e9282b091e56b3d23ea8cb6d8"><code>5fd2f98</code></a>
Bump <code>@​types/jest</code> to version 29.5.14</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/28647f4804ba29122df4b83b4bf78c2377efcbb1"><code>28647f4</code></a>
Fix PURL parsing by removing encodeURI</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/f620fd175c123251c10ec99199c434acc0f47438"><code>f620fd1</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/dependency-review-action/issues/1013">#1013</a>
from actions/dangoor/token-fix</li>
<li><a
href="https://github.com/actions/dependency-review-action/commit/9b42b7e9a9f440759477243274165b8398354f4e"><code>9b42b7e</code></a>
Remove bad token reference</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/dependency-review-action/compare/40c09b7dc99638e5ddb0bfd91c1673effc064d8a...3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/dependency-review-action&package-manager=github_actions&previous-version=4.8.1&new-version=4.8.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…rkflows/mkdocs in the python-deps group (#4896)

Bumps the python-deps group in /.github/workflows/mkdocs with 1 update:
[mkdocs-material](https://github.com/squidfunk/mkdocs-material).

Updates `mkdocs-material` from 9.6.23 to 9.7.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/squidfunk/mkdocs-material/releases">mkdocs-material's
releases</a>.</em></p>
<blockquote>
<h2>mkdocs-material-9.7.0</h2>
<blockquote>
<p>[!WARNING]</p>
<p><strong>Material for MkDocs is now in maintenance mode</strong></p>
<p>This is the last release of Material for MkDocs that will receive new
features. Going forward, the Material for MkDocs team focuses on <a
href="https://zensical.org">Zensical</a>, a next-gen static site
generator built from first principles. We will provide critical bug
fixes and security updates for Material for MkDocs for 12 months at
least.</p>
</blockquote>
<p>→ <a
href="https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/">Read
the full announcement on our blog</a></p>
<p>This release includes all features that were previously exclusive to
the Insiders edition. These features are now freely available to
everyone.</p>
<p><strong>Note on deprecated plugins</strong>: The <a
href="https://squidfunk.github.io/mkdocs-material/plugins/projects/">projects</a>
and <a
href="https://squidfunk.github.io/mkdocs-material/plugins/typeset/">typeset</a>
plugins are included in this release, but must be considered deprecated.
Both plugins proved unsustainable to maintain and represent
architectural dead ends. They are provided as-is without ongoing
support.</p>
<p><strong>Changes</strong>:</p>
<ul>
<li>Added support for projects plugin (for compat, now deprecated)</li>
<li>Added support for typeset plugin (for compat, now deprecated)</li>
<li>Added support for pinned blog posts and author profiles</li>
<li>Added support for customizing pagination for blog index pages</li>
<li>Added support for customizing blog category sort order</li>
<li>Added support for staying on page when switching languages</li>
<li>Added support for disabling tags in table of contents</li>
<li>Added support for nested tags and shadow tags</li>
<li>Added support for footnote tooltips</li>
<li>Added support for instant previews</li>
<li>Added support for instant prefetching</li>
<li>Added support for custom social card layouts</li>
<li>Added support for custom social card background images</li>
<li>Added support for selectable rangs in code blocks</li>
<li>Added support for custom selectors for code annotations</li>
<li>Added support for configurable log level in privacy plugin</li>
<li>Added support for processing of external links in privacy
plugin</li>
<li>Added support for automatic image optimization via optimize
plugin</li>
<li>Added support for navigation paths (breadcrumbs)</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8519">#8519</a>:
Vector accents do not render when using KaTeX</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG">mkdocs-material's
changelog</a>.</em></p>
<blockquote>
<p>mkdocs-material-9.7.0 (2025-11-11)</p>
<p>⚠️ Material for MkDocs is now in maintenance mode</p>
<p>This is the last release of Material for MkDocs that will receive new
features.
Going forward, the Material for MkDocs team focuses on Zensical, a
next-gen
static site generator built from first principles. We will provide
critical
bug fixes and security updates for Material for MkDocs for 12 months at
least.</p>
<p>Read the full announcement on our blog:
<a
href="https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/">https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/</a></p>
<p>This release includes all features that were previously exclusive to
the
Insiders edition. These features are now freely available to
everyone.</p>
<p>Note on deprecated plugins: The projects and typeset plugins are
included in
this release, but must be considered deprecated. Both plugins proved
unsustainable to maintain and represent architectural dead ends. They
are
provided as-is without ongoing support.</p>
<p>Changes:</p>
<ul>
<li>Added support for pinned blog posts and author profiles</li>
<li>Added support for customizing pagination for blog index pages</li>
<li>Added support for customizing blog category sort order</li>
<li>Added support for staying on page when switching languages</li>
<li>Added support for disabling tags in table of contents</li>
<li>Added support for nested tags and shadow tags</li>
<li>Added support for footnote tooltips</li>
<li>Added support for instant previews</li>
<li>Added support for instant prefetching</li>
<li>Added support for custom social card layouts</li>
<li>Added support for custom social card background images</li>
<li>Added support for selectable rangs in code blocks</li>
<li>Added support for custom selectors for code annotations</li>
<li>Added support for configurable log level in privacy plugin</li>
<li>Added support for processing of external links in privacy
plugin</li>
<li>Added support for automatic image optimization via optimize
plugin</li>
<li>Added support for navigation paths (breadcrumbs)</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8519">#8519</a>:
Vector accents do not render when using KaTeX</li>
</ul>
<p>mkdocs-material-9.6.23 (2025-11-01)</p>
<ul>
<li>Updated Burmese translation</li>
</ul>
<p>mkdocs-material-9.6.22 (2025-10-15)</p>
<ul>
<li>Updated Georgian translation</li>
</ul>
<p>mkdocs-material-9.6.21 (2025-09-30)</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/3308731f1dce2e72809a2167d900b3381ca8d0d1"><code>3308731</code></a>
Updated changelog</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/dba54f7be6532893f8acddc6b89aa3c6491b90de"><code>dba54f7</code></a>
Fixed back-to-top button partial</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/7702610fd3f06ebcf4fd048b1839173926dd3290"><code>7702610</code></a>
Updated blog posts</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/3815f607a56c7390f41ebc30f36fd46a0d121ae1"><code>3815f60</code></a>
Documentation</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/b583ea7765ea770505cafea5c0ca931e12289ad1"><code>b583ea7</code></a>
Prepare 9.7.0 release</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/764178b0121523f7d77bda77b9a024627d1884e7"><code>764178b</code></a>
Merge Insiders features</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/9853cc3a10710e1ee8f641d32fe0cdc83a19673e"><code>9853cc3</code></a>
Documentation</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/f31cfa535509e46d23c4bc22994d02f49ec74826"><code>f31cfa5</code></a>
Removed documentation on sponsoring</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/a8b9ace30ae6f541314baac0e86dc7ba54aa2651"><code>a8b9ace</code></a>
Fixed height of symbols for KaTeX inline rendering</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/c0addd8addc34b38d3049b214265e2b3bd3fc8d3"><code>c0addd8</code></a>
Updated blog post</li>
<li>Additional commits viewable in <a
href="https://github.com/squidfunk/mkdocs-material/compare/9.6.23...9.7.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=mkdocs-material&package-manager=pip&previous-version=9.6.23&new-version=9.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the nx group in /lambdas with 3 updates:
[@nx/eslint](https://github.com/nrwl/nx/tree/HEAD/packages/eslint),
[@nx/js](https://github.com/nrwl/nx/tree/HEAD/packages/js) and
[@nx/vite](https://github.com/nrwl/nx/tree/HEAD/packages/vite).

Updates `@nx/eslint` from 22.0.2 to 22.0.3
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nrwl/nx/releases"><code>@​nx/eslint</code>'s
releases</a>.</em></p>
<blockquote>
<h2>22.0.3 (2025-11-10)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>core:</strong> batch hash tasks without custom hashers (<a
href="https://redirect.github.com/nrwl/nx/pull/33327">#33327</a>)</li>
<li><strong>core:</strong> add OSC 9;4 progress indicator support to TUI
(<a
href="https://redirect.github.com/nrwl/nx/pull/33325">#33325</a>)</li>
<li><strong>core:</strong> disable interactivity by default for run-one
task outputs in tui (<a
href="https://redirect.github.com/nrwl/nx/pull/33358">#33358</a>)</li>
<li><strong>gradle:</strong> use gitignore to determine dependant task
output files (<a
href="https://redirect.github.com/nrwl/nx/pull/33402">#33402</a>)</li>
<li><strong>maven:</strong> upgrade to version 0.0.8 with automated
migration (<a
href="https://redirect.github.com/nrwl/nx/pull/33315">#33315</a>)</li>
<li><strong>maven:</strong> add ci-workflow generator (<a
href="https://redirect.github.com/nrwl/nx/pull/33346">#33346</a>)</li>
<li><strong>maven:</strong> bump version from 0.0.8 to 0.0.9 (<a
href="https://redirect.github.com/nrwl/nx/pull/33405">#33405</a>)</li>
<li><strong>misc:</strong> remove CI investigation recommendations from
agent rules (<a
href="https://redirect.github.com/nrwl/nx/pull/33309">#33309</a>)</li>
<li><strong>vite:</strong> add vitest 4 to peerDep range to prevent
conflicts (<a
href="https://redirect.github.com/nrwl/nx/pull/33394">#33394</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>core:</strong> also look in .nx installation when reading
nx.json extends (<a
href="https://redirect.github.com/nrwl/nx/pull/33306">#33306</a>)</li>
<li><strong>core:</strong> handle various directories when importing
prettier (<a
href="https://redirect.github.com/nrwl/nx/pull/33383">#33383</a>)</li>
<li><strong>core:</strong> prevent args from being split by spaces when
executing through nx wrapper (<a
href="https://redirect.github.com/nrwl/nx/pull/33362">#33362</a>)</li>
<li><strong>core:</strong> correctly identify local workspace
dependencies on windows (<a
href="https://redirect.github.com/nrwl/nx/pull/33408">#33408</a>)</li>
<li><strong>maven:</strong> resolve maven dependencies from project
roots (<a
href="https://redirect.github.com/nrwl/nx/pull/33313">#33313</a>)</li>
<li><strong>maven:</strong> set migration version to 22.1.0-beta.4 (<a
href="https://redirect.github.com/nrwl/nx/pull/33345">#33345</a>)</li>
<li><strong>maven:</strong> forward parameters through target
dependencies (<a
href="https://redirect.github.com/nrwl/nx/pull/33365">#33365</a>)</li>
<li><strong>module-federation:</strong> update <a
href="https://github.com/module-federation"><code>@​module-federation</code></a>
packages to fix Koa vulnerability (<a
href="https://redirect.github.com/nrwl/nx/pull/33285">#33285</a>, <a
href="https://redirect.github.com/nrwl/nx/pull/33380">#33380</a>)</li>
<li><strong>nextjs:</strong> ensure <code>eslint-config-next</code>
matches Next.js 14 and 15 versions (<a
href="https://redirect.github.com/nrwl/nx/pull/30259">#30259</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/30258">#30258</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/30257">#30257</a>)</li>
<li><strong>nx-dev:</strong> fix GitHub star button styling in mobile
view (<a
href="https://redirect.github.com/nrwl/nx/pull/33385">#33385</a>)</li>
<li><strong>testing:</strong> use .cts config files for Jest 30+ to fix
__dirname issues (<a
href="https://redirect.github.com/nrwl/nx/pull/33349">#33349</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/32236">#32236</a>)</li>
<li><strong>vite:</strong> prevent race-condition when importing
<code>@​vitejs/plugin-vue</code> (<a
href="https://redirect.github.com/nrwl/nx/pull/33307">#33307</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Claude</li>
<li>Colum Ferry <a
href="https://github.com/Coly010"><code>@​Coly010</code></a></li>
<li>Eric Büttner <a
href="https://github.com/tuffz"><code>@​tuffz</code></a></li>
<li>Jack Hsu <a
href="https://github.com/jaysoo"><code>@​jaysoo</code></a></li>
<li>James Henry <a
href="https://github.com/JamesHenry"><code>@​JamesHenry</code></a></li>
<li>Jason Jean <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Leosvel Pérez Espinosa <a
href="https://github.com/leosvelperez"><code>@​leosvelperez</code></a></li>
<li>Louie Weng <a
href="https://github.com/lourw"><code>@​lourw</code></a></li>
<li>MaxKless <a
href="https://github.com/MaxKless"><code>@​MaxKless</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nrwl/nx/commit/8801be32dd4c2d72844f934d207fc09614983449"><code>8801be3</code></a>
chore(repo): rename jest.config.ts to jest.config.cts to be compat with
Node ...</li>
<li><a
href="https://github.com/nrwl/nx/commit/f958ebc05694cd9ee0dd8673b632e8db849019ed"><code>f958ebc</code></a>
fix(testing): use .cts config files for Jest 30+ to fix __dirname issues
(<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/eslint/issues/33">#33</a>...</li>
<li>See full diff in <a
href="https://github.com/nrwl/nx/commits/22.0.3/packages/eslint">compare
view</a></li>
</ul>
</details>
<br />

Updates `@nx/js` from 22.0.2 to 22.0.3
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nrwl/nx/releases"><code>@​nx/js</code>'s
releases</a>.</em></p>
<blockquote>
<h2>22.0.3 (2025-11-10)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>core:</strong> batch hash tasks without custom hashers (<a
href="https://redirect.github.com/nrwl/nx/pull/33327">#33327</a>)</li>
<li><strong>core:</strong> add OSC 9;4 progress indicator support to TUI
(<a
href="https://redirect.github.com/nrwl/nx/pull/33325">#33325</a>)</li>
<li><strong>core:</strong> disable interactivity by default for run-one
task outputs in tui (<a
href="https://redirect.github.com/nrwl/nx/pull/33358">#33358</a>)</li>
<li><strong>gradle:</strong> use gitignore to determine dependant task
output files (<a
href="https://redirect.github.com/nrwl/nx/pull/33402">#33402</a>)</li>
<li><strong>maven:</strong> upgrade to version 0.0.8 with automated
migration (<a
href="https://redirect.github.com/nrwl/nx/pull/33315">#33315</a>)</li>
<li><strong>maven:</strong> add ci-workflow generator (<a
href="https://redirect.github.com/nrwl/nx/pull/33346">#33346</a>)</li>
<li><strong>maven:</strong> bump version from 0.0.8 to 0.0.9 (<a
href="https://redirect.github.com/nrwl/nx/pull/33405">#33405</a>)</li>
<li><strong>misc:</strong> remove CI investigation recommendations from
agent rules (<a
href="https://redirect.github.com/nrwl/nx/pull/33309">#33309</a>)</li>
<li><strong>vite:</strong> add vitest 4 to peerDep range to prevent
conflicts (<a
href="https://redirect.github.com/nrwl/nx/pull/33394">#33394</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>core:</strong> also look in .nx installation when reading
nx.json extends (<a
href="https://redirect.github.com/nrwl/nx/pull/33306">#33306</a>)</li>
<li><strong>core:</strong> handle various directories when importing
prettier (<a
href="https://redirect.github.com/nrwl/nx/pull/33383">#33383</a>)</li>
<li><strong>core:</strong> prevent args from being split by spaces when
executing through nx wrapper (<a
href="https://redirect.github.com/nrwl/nx/pull/33362">#33362</a>)</li>
<li><strong>core:</strong> correctly identify local workspace
dependencies on windows (<a
href="https://redirect.github.com/nrwl/nx/pull/33408">#33408</a>)</li>
<li><strong>maven:</strong> resolve maven dependencies from project
roots (<a
href="https://redirect.github.com/nrwl/nx/pull/33313">#33313</a>)</li>
<li><strong>maven:</strong> set migration version to 22.1.0-beta.4 (<a
href="https://redirect.github.com/nrwl/nx/pull/33345">#33345</a>)</li>
<li><strong>maven:</strong> forward parameters through target
dependencies (<a
href="https://redirect.github.com/nrwl/nx/pull/33365">#33365</a>)</li>
<li><strong>module-federation:</strong> update <a
href="https://github.com/module-federation"><code>@​module-federation</code></a>
packages to fix Koa vulnerability (<a
href="https://redirect.github.com/nrwl/nx/pull/33285">#33285</a>, <a
href="https://redirect.github.com/nrwl/nx/pull/33380">#33380</a>)</li>
<li><strong>nextjs:</strong> ensure <code>eslint-config-next</code>
matches Next.js 14 and 15 versions (<a
href="https://redirect.github.com/nrwl/nx/pull/30259">#30259</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/30258">#30258</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/30257">#30257</a>)</li>
<li><strong>nx-dev:</strong> fix GitHub star button styling in mobile
view (<a
href="https://redirect.github.com/nrwl/nx/pull/33385">#33385</a>)</li>
<li><strong>testing:</strong> use .cts config files for Jest 30+ to fix
__dirname issues (<a
href="https://redirect.github.com/nrwl/nx/pull/33349">#33349</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/32236">#32236</a>)</li>
<li><strong>vite:</strong> prevent race-condition when importing
<code>@​vitejs/plugin-vue</code> (<a
href="https://redirect.github.com/nrwl/nx/pull/33307">#33307</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Claude</li>
<li>Colum Ferry <a
href="https://github.com/Coly010"><code>@​Coly010</code></a></li>
<li>Eric Büttner <a
href="https://github.com/tuffz"><code>@​tuffz</code></a></li>
<li>Jack Hsu <a
href="https://github.com/jaysoo"><code>@​jaysoo</code></a></li>
<li>James Henry <a
href="https://github.com/JamesHenry"><code>@​JamesHenry</code></a></li>
<li>Jason Jean <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Leosvel Pérez Espinosa <a
href="https://github.com/leosvelperez"><code>@​leosvelperez</code></a></li>
<li>Louie Weng <a
href="https://github.com/lourw"><code>@​lourw</code></a></li>
<li>MaxKless <a
href="https://github.com/MaxKless"><code>@​MaxKless</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nrwl/nx/commit/8801be32dd4c2d72844f934d207fc09614983449"><code>8801be3</code></a>
chore(repo): rename jest.config.ts to jest.config.cts to be compat with
Node ...</li>
<li><a
href="https://github.com/nrwl/nx/commit/f958ebc05694cd9ee0dd8673b632e8db849019ed"><code>f958ebc</code></a>
fix(testing): use .cts config files for Jest 30+ to fix __dirname issues
(<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/js/issues/33">#33</a>...</li>
<li>See full diff in <a
href="https://github.com/nrwl/nx/commits/22.0.3/packages/js">compare
view</a></li>
</ul>
</details>
<br />

Updates `@nx/vite` from 22.0.2 to 22.0.3
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nrwl/nx/releases"><code>@​nx/vite</code>'s
releases</a>.</em></p>
<blockquote>
<h2>22.0.3 (2025-11-10)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>core:</strong> batch hash tasks without custom hashers (<a
href="https://redirect.github.com/nrwl/nx/pull/33327">#33327</a>)</li>
<li><strong>core:</strong> add OSC 9;4 progress indicator support to TUI
(<a
href="https://redirect.github.com/nrwl/nx/pull/33325">#33325</a>)</li>
<li><strong>core:</strong> disable interactivity by default for run-one
task outputs in tui (<a
href="https://redirect.github.com/nrwl/nx/pull/33358">#33358</a>)</li>
<li><strong>gradle:</strong> use gitignore to determine dependant task
output files (<a
href="https://redirect.github.com/nrwl/nx/pull/33402">#33402</a>)</li>
<li><strong>maven:</strong> upgrade to version 0.0.8 with automated
migration (<a
href="https://redirect.github.com/nrwl/nx/pull/33315">#33315</a>)</li>
<li><strong>maven:</strong> add ci-workflow generator (<a
href="https://redirect.github.com/nrwl/nx/pull/33346">#33346</a>)</li>
<li><strong>maven:</strong> bump version from 0.0.8 to 0.0.9 (<a
href="https://redirect.github.com/nrwl/nx/pull/33405">#33405</a>)</li>
<li><strong>misc:</strong> remove CI investigation recommendations from
agent rules (<a
href="https://redirect.github.com/nrwl/nx/pull/33309">#33309</a>)</li>
<li><strong>vite:</strong> add vitest 4 to peerDep range to prevent
conflicts (<a
href="https://redirect.github.com/nrwl/nx/pull/33394">#33394</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>core:</strong> also look in .nx installation when reading
nx.json extends (<a
href="https://redirect.github.com/nrwl/nx/pull/33306">#33306</a>)</li>
<li><strong>core:</strong> handle various directories when importing
prettier (<a
href="https://redirect.github.com/nrwl/nx/pull/33383">#33383</a>)</li>
<li><strong>core:</strong> prevent args from being split by spaces when
executing through nx wrapper (<a
href="https://redirect.github.com/nrwl/nx/pull/33362">#33362</a>)</li>
<li><strong>core:</strong> correctly identify local workspace
dependencies on windows (<a
href="https://redirect.github.com/nrwl/nx/pull/33408">#33408</a>)</li>
<li><strong>maven:</strong> resolve maven dependencies from project
roots (<a
href="https://redirect.github.com/nrwl/nx/pull/33313">#33313</a>)</li>
<li><strong>maven:</strong> set migration version to 22.1.0-beta.4 (<a
href="https://redirect.github.com/nrwl/nx/pull/33345">#33345</a>)</li>
<li><strong>maven:</strong> forward parameters through target
dependencies (<a
href="https://redirect.github.com/nrwl/nx/pull/33365">#33365</a>)</li>
<li><strong>module-federation:</strong> update <a
href="https://github.com/module-federation"><code>@​module-federation</code></a>
packages to fix Koa vulnerability (<a
href="https://redirect.github.com/nrwl/nx/pull/33285">#33285</a>, <a
href="https://redirect.github.com/nrwl/nx/pull/33380">#33380</a>)</li>
<li><strong>nextjs:</strong> ensure <code>eslint-config-next</code>
matches Next.js 14 and 15 versions (<a
href="https://redirect.github.com/nrwl/nx/pull/30259">#30259</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/30258">#30258</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/30257">#30257</a>)</li>
<li><strong>nx-dev:</strong> fix GitHub star button styling in mobile
view (<a
href="https://redirect.github.com/nrwl/nx/pull/33385">#33385</a>)</li>
<li><strong>testing:</strong> use .cts config files for Jest 30+ to fix
__dirname issues (<a
href="https://redirect.github.com/nrwl/nx/pull/33349">#33349</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/32236">#32236</a>)</li>
<li><strong>vite:</strong> prevent race-condition when importing
<code>@​vitejs/plugin-vue</code> (<a
href="https://redirect.github.com/nrwl/nx/pull/33307">#33307</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Claude</li>
<li>Colum Ferry <a
href="https://github.com/Coly010"><code>@​Coly010</code></a></li>
<li>Eric Büttner <a
href="https://github.com/tuffz"><code>@​tuffz</code></a></li>
<li>Jack Hsu <a
href="https://github.com/jaysoo"><code>@​jaysoo</code></a></li>
<li>James Henry <a
href="https://github.com/JamesHenry"><code>@​JamesHenry</code></a></li>
<li>Jason Jean <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Leosvel Pérez Espinosa <a
href="https://github.com/leosvelperez"><code>@​leosvelperez</code></a></li>
<li>Louie Weng <a
href="https://github.com/lourw"><code>@​lourw</code></a></li>
<li>MaxKless <a
href="https://github.com/MaxKless"><code>@​MaxKless</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nrwl/nx/commit/8801be32dd4c2d72844f934d207fc09614983449"><code>8801be3</code></a>
chore(repo): rename jest.config.ts to jest.config.cts to be compat with
Node ...</li>
<li><a
href="https://github.com/nrwl/nx/commit/f958ebc05694cd9ee0dd8673b632e8db849019ed"><code>f958ebc</code></a>
fix(testing): use .cts config files for Jest 30+ to fix __dirname issues
(<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/vite/issues/33">#33</a>...</li>
<li><a
href="https://github.com/nrwl/nx/commit/66a50ed7cf4264d216cb452cf225c13cdd5a9454"><code>66a50ed</code></a>
feat(vite): add vitest 4 to peerDep range to prevent conflicts (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/vite/issues/33394">#33394</a>)</li>
<li><a
href="https://github.com/nrwl/nx/commit/16b8eeac902509c5456ab481debd02cae31b5918"><code>16b8eea</code></a>
fix(vite): prevent race-condition when importing
<code>@​vitejs/plugin-vue</code> (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/vite/issues/33307">#33307</a>)</li>
<li>See full diff in <a
href="https://github.com/nrwl/nx/commits/22.0.3/packages/vite">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [nx](https://github.com/nrwl/nx/tree/HEAD/packages/nx) from 21.6.5
to 22.0.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/nrwl/nx/releases">nx's
releases</a>.</em></p>
<blockquote>
<h2>22.0.3 (2025-11-10)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>core:</strong> batch hash tasks without custom hashers (<a
href="https://redirect.github.com/nrwl/nx/pull/33327">#33327</a>)</li>
<li><strong>core:</strong> add OSC 9;4 progress indicator support to TUI
(<a
href="https://redirect.github.com/nrwl/nx/pull/33325">#33325</a>)</li>
<li><strong>core:</strong> disable interactivity by default for run-one
task outputs in tui (<a
href="https://redirect.github.com/nrwl/nx/pull/33358">#33358</a>)</li>
<li><strong>gradle:</strong> use gitignore to determine dependant task
output files (<a
href="https://redirect.github.com/nrwl/nx/pull/33402">#33402</a>)</li>
<li><strong>maven:</strong> upgrade to version 0.0.8 with automated
migration (<a
href="https://redirect.github.com/nrwl/nx/pull/33315">#33315</a>)</li>
<li><strong>maven:</strong> add ci-workflow generator (<a
href="https://redirect.github.com/nrwl/nx/pull/33346">#33346</a>)</li>
<li><strong>maven:</strong> bump version from 0.0.8 to 0.0.9 (<a
href="https://redirect.github.com/nrwl/nx/pull/33405">#33405</a>)</li>
<li><strong>misc:</strong> remove CI investigation recommendations from
agent rules (<a
href="https://redirect.github.com/nrwl/nx/pull/33309">#33309</a>)</li>
<li><strong>vite:</strong> add vitest 4 to peerDep range to prevent
conflicts (<a
href="https://redirect.github.com/nrwl/nx/pull/33394">#33394</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>core:</strong> also look in .nx installation when reading
nx.json extends (<a
href="https://redirect.github.com/nrwl/nx/pull/33306">#33306</a>)</li>
<li><strong>core:</strong> handle various directories when importing
prettier (<a
href="https://redirect.github.com/nrwl/nx/pull/33383">#33383</a>)</li>
<li><strong>core:</strong> prevent args from being split by spaces when
executing through nx wrapper (<a
href="https://redirect.github.com/nrwl/nx/pull/33362">#33362</a>)</li>
<li><strong>core:</strong> correctly identify local workspace
dependencies on windows (<a
href="https://redirect.github.com/nrwl/nx/pull/33408">#33408</a>)</li>
<li><strong>maven:</strong> resolve maven dependencies from project
roots (<a
href="https://redirect.github.com/nrwl/nx/pull/33313">#33313</a>)</li>
<li><strong>maven:</strong> set migration version to 22.1.0-beta.4 (<a
href="https://redirect.github.com/nrwl/nx/pull/33345">#33345</a>)</li>
<li><strong>maven:</strong> forward parameters through target
dependencies (<a
href="https://redirect.github.com/nrwl/nx/pull/33365">#33365</a>)</li>
<li><strong>module-federation:</strong> update <a
href="https://github.com/module-federation"><code>@​module-federation</code></a>
packages to fix Koa vulnerability (<a
href="https://redirect.github.com/nrwl/nx/pull/33285">#33285</a>, <a
href="https://redirect.github.com/nrwl/nx/pull/33380">#33380</a>)</li>
<li><strong>nextjs:</strong> ensure <code>eslint-config-next</code>
matches Next.js 14 and 15 versions (<a
href="https://redirect.github.com/nrwl/nx/pull/30259">#30259</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/30258">#30258</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/30257">#30257</a>)</li>
<li><strong>nx-dev:</strong> fix GitHub star button styling in mobile
view (<a
href="https://redirect.github.com/nrwl/nx/pull/33385">#33385</a>)</li>
<li><strong>testing:</strong> use .cts config files for Jest 30+ to fix
__dirname issues (<a
href="https://redirect.github.com/nrwl/nx/pull/33349">#33349</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/32236">#32236</a>)</li>
<li><strong>vite:</strong> prevent race-condition when importing
<code>@​vitejs/plugin-vue</code> (<a
href="https://redirect.github.com/nrwl/nx/pull/33307">#33307</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Claude</li>
<li>Colum Ferry <a
href="https://github.com/Coly010"><code>@​Coly010</code></a></li>
<li>Eric Büttner <a
href="https://github.com/tuffz"><code>@​tuffz</code></a></li>
<li>Jack Hsu <a
href="https://github.com/jaysoo"><code>@​jaysoo</code></a></li>
<li>James Henry <a
href="https://github.com/JamesHenry"><code>@​JamesHenry</code></a></li>
<li>Jason Jean <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Leosvel Pérez Espinosa <a
href="https://github.com/leosvelperez"><code>@​leosvelperez</code></a></li>
<li>Louie Weng <a
href="https://github.com/lourw"><code>@​lourw</code></a></li>
<li>MaxKless <a
href="https://github.com/MaxKless"><code>@​MaxKless</code></a></li>
</ul>
<h2>22.0.2 (2025-10-28)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>docker:</strong> support inferring additional args for
targets with interpolation support (<a
href="https://redirect.github.com/nrwl/nx/pull/32892">#32892</a>)</li>
<li><strong>gradle:</strong> add custom installation path to options (<a
href="https://redirect.github.com/nrwl/nx/pull/33187">#33187</a>)</li>
<li><strong>nx-dev:</strong> add downloadable resources page and React
book blog post (<a
href="https://github.com/nrwl/nx/commit/4b6009764a">4b6009764a</a>)</li>
<li><strong>release:</strong> support {versionActionsVersion} in docker
version scheme (<a
href="https://redirect.github.com/nrwl/nx/pull/33178">#33178</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nrwl/nx/commit/2d53ffdb9e57d6ee440b3f555c7f87e907eff397"><code>2d53ffd</code></a>
fix(core): correctly identify local workspace dependencies on windows
(<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/33408">#33408</a>)</li>
<li><a
href="https://github.com/nrwl/nx/commit/2a082f8701736066ec418256b75e12bdbbe88d1e"><code>2a082f8</code></a>
fix(core): prevent args from being split by spaces when executing
through nx ...</li>
<li><a
href="https://github.com/nrwl/nx/commit/8801be32dd4c2d72844f934d207fc09614983449"><code>8801be3</code></a>
chore(repo): rename jest.config.ts to jest.config.cts to be compat with
Node ...</li>
<li><a
href="https://github.com/nrwl/nx/commit/c03434cfe2f93a97f2d6a2aae45c6eb48f7f5ce4"><code>c03434c</code></a>
feat(core): disable interactivity by default for run-one task outputs in
tui ...</li>
<li><a
href="https://github.com/nrwl/nx/commit/e46a7e16fdf6d1e6842f6c8ab2a3ce62b0a9e544"><code>e46a7e1</code></a>
fix(core): handle various directories when importing prettier (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/33383">#33383</a>)</li>
<li><a
href="https://github.com/nrwl/nx/commit/657c39829433bb3e41eefba963a3488af47f9b38"><code>657c398</code></a>
cleanup(core): remove unused mouse event listeners from tui (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/33368">#33368</a>)</li>
<li><a
href="https://github.com/nrwl/nx/commit/6d2389db730e9956c7351b90931efbd01ab3b605"><code>6d2389d</code></a>
feat(core): add OSC 9;4 progress indicator support to TUI (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/33325">#33325</a>)</li>
<li><a
href="https://github.com/nrwl/nx/commit/f07d064b877adca19fcc01085530f3f42a4ed53d"><code>f07d064</code></a>
feat(core): batch hash tasks without custom hashers (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/33327">#33327</a>)</li>
<li><a
href="https://github.com/nrwl/nx/commit/dceed642ba2d84800d99ada016f1ad9a4601aa82"><code>dceed64</code></a>
fix(maven): resolve maven dependencies from project roots (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/33313">#33313</a>)</li>
<li><a
href="https://github.com/nrwl/nx/commit/15c567c8a37c50d519db7f603e9c7b92e0436c36"><code>15c567c</code></a>
feat(misc): remove CI investigation recommendations from agent rules (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/33309">#33309</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/nrwl/nx/commits/22.0.3/packages/nx">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=nx&package-manager=npm_and_yarn&previous-version=21.6.5&new-version=22.0.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
# Description

Fix the issue found in #4901.

It now uses a static key instead of waiting for the queue ID to be
created before generating the object, allowing the size to be calculated
immediately.

---------

Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
🤖 I have created a release *beep* *boop*
---


##
[6.9.1](v6.9.0...v6.9.1)
(2025-11-21)


### Bug Fixes

* **lambda:** bump axios from 1.12.2 to 1.13.2 in /lambdas
([#4895](#4895))
([59e231d](59e231d))
* **lambda:** bump js-yaml from 3.14.1 to 3.14.2 in /lambdas
([#4890](#4890))
([18b8c4e](18b8c4e))
* **lambda:** bump the aws group across 1 directory with 7 updates
([#4898](#4898))
([cf7f4ad](cf7f4ad))
* use a static key in runner_matcher_config
([#4901](#4901))
([#4903](#4903))
([cc5dc65](cc5dc65))
@edersonbrilhante

 
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: runners-releaser[bot] <194412594+runners-releaser[bot]@users.noreply.github.com>
Some AMIs, like the `AWS Deep Learning Base GPU AMI (Ubuntu 24.04)`,
have parentheses in the name. Parentheses are not allowed in AWS tags,
leading to an error. This commit strips the parentheses out of the name.

Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
…bucket tagging (#4832)

This pull request introduces an option to provide additional tags for S3
buckets created by the `binaries-syncer` module.

S3 tags can be specified using the `runner_binaries_s3_tags` variable at
the module level to apply tags to all S3 buckets at once, or at the
individual runner configuration level to define different tags for
specific runners. Tags defined at both the module and runner
configuration levels are merged when their OS and architecture match.

---------

Co-authored-by: Damian Rekosz <damian.rekosz@lcloud.pl>
Co-authored-by: Niek Palm <npalm@users.noreply.github.com>
Bumps the aws group in /lambdas with 6 updates:

| Package | From | To |
| --- | --- | --- |
|
[@aws-sdk/client-ec2](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ec2)
| `3.933.0` | `3.934.0` |
|
[@aws-sdk/client-ssm](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm)
| `3.933.0` | `3.934.0` |
|
[@aws-sdk/client-sqs](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sqs)
| `3.933.0` | `3.934.0` |
|
[@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3)
| `3.933.0` | `3.934.0` |
|
[@aws-sdk/lib-storage](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-storage)
| `3.933.0` | `3.934.0` |
|
[@aws-sdk/client-eventbridge](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-eventbridge)
| `3.933.0` | `3.934.0` |

Updates `@aws-sdk/client-ec2` from 3.933.0 to 3.934.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-ec2</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.934.0</h2>
<h4>3.934.0(2025-11-18)</h4>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2025-11-18
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0f98925410ab7b21c1c92bd6a507e3b571f1b337">0f989254</a>)</li>
<li><strong>client-connect:</strong> This release added support for ring
timer configuration for campaign calls. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ae3d76000b552fa56dad59d65f3241b0404c32df">ae3d7600</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> CloudWatch Logs updates:
Added capability to setup a recurring schedule for log insights queries.
Logs introduced Scheduled Queries (managed through
Create/Update/Get/Delete/List/History Scheduled Query APIs). For more
information, see CloudWatch Logs API documentation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/467947d43202b1e0ee40288e3482aa6a1b7db760">467947d4</a>)</li>
<li><strong>client-wafv2:</strong> AssociateWebACL, UpdateWebACL and
PutLoggingConfiguration will now throw
WAFFeatureNotIncludedInPricingPlanException when the request contains a
feature that is not included in the CloudFront pricing plan of the
WebACL. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6da7a3dbfa7d5d5f824e1ee6e8a3e414ee6ed10b">6da7a3db</a>)</li>
<li><strong>client-storage-gateway:</strong> Adds support for European
Sovereign Cloud ARNs in Storage Gateway API parameters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/c7dd6fd72f0c688fbd0030167104dd9bdc8a8bf5">c7dd6fd7</a>)</li>
<li><strong>client-cloudformation:</strong> New CloudFormation
DescribeEvents API with operation ID tracking and failure filtering
capabilities to quickly identify root causes of deployment failures.
Also, a DeploymentMode parameter for the CreateChangeSet API that
enables creation of drift-aware change sets for safe drift management.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/04624df229903dcdcb0058cab7f2600c430f3adb">04624df2</a>)</li>
<li><strong>client-kafka:</strong> Amazon MSK adds three new APIs,
ListTopics, DescribeTopic, and DescribeTopicPartitions for viewing Kafka
topics in your MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/12ad701d38579bc63130dd7b0cbb054ed69f6f3d">12ad701d</a>)</li>
<li><strong>client-backup:</strong> AWS Backup now supports a low-cost
warm storage tier for Amazon S3 backup data. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0b0c9b8f6a3e9719499db5a0cdaf0b9b31b70ed1">0b0c9b8f</a>)</li>
<li><strong>client-iam:</strong> Added the AssociateDelegationRequest,
GetDelegationRequest, AcceptDelegationRequest, RejectDelegatonRequest,
ListDelegationRequests, UpdateDelegationRequest, SendDelegationToken and
GetHumanReadableSummary APIs for the IAM temporary delegation feature.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b200679b040a3e3158a2cb4773360fab5cf4bbd8">b200679b</a>)</li>
<li><strong>client-resource-groups-tagging-api:</strong> Add support for
new ListRequiredTags API used to retrieve the required tags specified in
a customer's effective tag policy. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa50551511be7be35117b486ddfc84126623be3b">fa505515</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
Concentrator, a new feature that enables customers to connect multiple
low-bandwidth sites connections through a single attachment, simplifying
multi-site connectivity for distributed enterprises. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b94cadfd704fa2cc3df6d60075aae1ce99212b2d">b94cadfd</a>)</li>
<li><strong>client-bedrock-runtime:</strong> Amazon Bedrock Runtime
Service Tier Support Launch (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ea418df5de064d09ca66470f7452fc6d41c0caf4">ea418df5</a>)</li>
<li><strong>client-auto-scaling:</strong> This release adds the new
LaunchInstances API, which can launch instances synchronously in an
AutoScaling group. The API also returns instances info and launch error
back immediately. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5d96b6881d2b6ace315029f471dca7cd058aa643">5d96b688</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>core/protocols:</strong> add json rpc perf baseline (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7505">#7505</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/114920c68764e2ea9d3a6b8a00851cf132db8dad">114920c6</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.934.0.zip</strong></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ec2/CHANGELOG.md"><code>@​aws-sdk/client-ec2</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.933.0...v3.934.0">3.934.0</a>
(2025-11-18)</h1>
<h3>Features</h3>
<ul>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
Concentrator, a new feature that enables customers to connect multiple
low-bandwidth sites connections through a single attachment, simplifying
multi-site connectivity for distributed enterprises. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b94cadfd704fa2cc3df6d60075aae1ce99212b2d">b94cadf</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/3b6a4d9a2d9e26564506d833431c43ae0de335c6"><code>3b6a4d9</code></a>
Publish v3.934.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/b94cadfd704fa2cc3df6d60075aae1ce99212b2d"><code>b94cadf</code></a>
feat(client-ec2): AWS Site-to-Site VPN now supports VPN Concentrator, a
new f...</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.934.0/clients/client-ec2">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/client-ssm` from 3.933.0 to 3.934.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-ssm</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.934.0</h2>
<h4>3.934.0(2025-11-18)</h4>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2025-11-18
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0f98925410ab7b21c1c92bd6a507e3b571f1b337">0f989254</a>)</li>
<li><strong>client-connect:</strong> This release added support for ring
timer configuration for campaign calls. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ae3d76000b552fa56dad59d65f3241b0404c32df">ae3d7600</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> CloudWatch Logs updates:
Added capability to setup a recurring schedule for log insights queries.
Logs introduced Scheduled Queries (managed through
Create/Update/Get/Delete/List/History Scheduled Query APIs). For more
information, see CloudWatch Logs API documentation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/467947d43202b1e0ee40288e3482aa6a1b7db760">467947d4</a>)</li>
<li><strong>client-wafv2:</strong> AssociateWebACL, UpdateWebACL and
PutLoggingConfiguration will now throw
WAFFeatureNotIncludedInPricingPlanException when the request contains a
feature that is not included in the CloudFront pricing plan of the
WebACL. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6da7a3dbfa7d5d5f824e1ee6e8a3e414ee6ed10b">6da7a3db</a>)</li>
<li><strong>client-storage-gateway:</strong> Adds support for European
Sovereign Cloud ARNs in Storage Gateway API parameters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/c7dd6fd72f0c688fbd0030167104dd9bdc8a8bf5">c7dd6fd7</a>)</li>
<li><strong>client-cloudformation:</strong> New CloudFormation
DescribeEvents API with operation ID tracking and failure filtering
capabilities to quickly identify root causes of deployment failures.
Also, a DeploymentMode parameter for the CreateChangeSet API that
enables creation of drift-aware change sets for safe drift management.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/04624df229903dcdcb0058cab7f2600c430f3adb">04624df2</a>)</li>
<li><strong>client-kafka:</strong> Amazon MSK adds three new APIs,
ListTopics, DescribeTopic, and DescribeTopicPartitions for viewing Kafka
topics in your MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/12ad701d38579bc63130dd7b0cbb054ed69f6f3d">12ad701d</a>)</li>
<li><strong>client-backup:</strong> AWS Backup now supports a low-cost
warm storage tier for Amazon S3 backup data. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0b0c9b8f6a3e9719499db5a0cdaf0b9b31b70ed1">0b0c9b8f</a>)</li>
<li><strong>client-iam:</strong> Added the AssociateDelegationRequest,
GetDelegationRequest, AcceptDelegationRequest, RejectDelegatonRequest,
ListDelegationRequests, UpdateDelegationRequest, SendDelegationToken and
GetHumanReadableSummary APIs for the IAM temporary delegation feature.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b200679b040a3e3158a2cb4773360fab5cf4bbd8">b200679b</a>)</li>
<li><strong>client-resource-groups-tagging-api:</strong> Add support for
new ListRequiredTags API used to retrieve the required tags specified in
a customer's effective tag policy. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa50551511be7be35117b486ddfc84126623be3b">fa505515</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
Concentrator, a new feature that enables customers to connect multiple
low-bandwidth sites connections through a single attachment, simplifying
multi-site connectivity for distributed enterprises. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b94cadfd704fa2cc3df6d60075aae1ce99212b2d">b94cadfd</a>)</li>
<li><strong>client-bedrock-runtime:</strong> Amazon Bedrock Runtime
Service Tier Support Launch (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ea418df5de064d09ca66470f7452fc6d41c0caf4">ea418df5</a>)</li>
<li><strong>client-auto-scaling:</strong> This release adds the new
LaunchInstances API, which can launch instances synchronously in an
AutoScaling group. The API also returns instances info and launch error
back immediately. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5d96b6881d2b6ace315029f471dca7cd058aa643">5d96b688</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>core/protocols:</strong> add json rpc perf baseline (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7505">#7505</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/114920c68764e2ea9d3a6b8a00851cf132db8dad">114920c6</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.934.0.zip</strong></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ssm/CHANGELOG.md"><code>@​aws-sdk/client-ssm</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.933.0...v3.934.0">3.934.0</a>
(2025-11-18)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-ssm</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/3b6a4d9a2d9e26564506d833431c43ae0de335c6"><code>3b6a4d9</code></a>
Publish v3.934.0</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.934.0/clients/client-ssm">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/client-sqs` from 3.933.0 to 3.934.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-sqs</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.934.0</h2>
<h4>3.934.0(2025-11-18)</h4>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2025-11-18
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0f98925410ab7b21c1c92bd6a507e3b571f1b337">0f989254</a>)</li>
<li><strong>client-connect:</strong> This release added support for ring
timer configuration for campaign calls. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ae3d76000b552fa56dad59d65f3241b0404c32df">ae3d7600</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> CloudWatch Logs updates:
Added capability to setup a recurring schedule for log insights queries.
Logs introduced Scheduled Queries (managed through
Create/Update/Get/Delete/List/History Scheduled Query APIs). For more
information, see CloudWatch Logs API documentation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/467947d43202b1e0ee40288e3482aa6a1b7db760">467947d4</a>)</li>
<li><strong>client-wafv2:</strong> AssociateWebACL, UpdateWebACL and
PutLoggingConfiguration will now throw
WAFFeatureNotIncludedInPricingPlanException when the request contains a
feature that is not included in the CloudFront pricing plan of the
WebACL. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6da7a3dbfa7d5d5f824e1ee6e8a3e414ee6ed10b">6da7a3db</a>)</li>
<li><strong>client-storage-gateway:</strong> Adds support for European
Sovereign Cloud ARNs in Storage Gateway API parameters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/c7dd6fd72f0c688fbd0030167104dd9bdc8a8bf5">c7dd6fd7</a>)</li>
<li><strong>client-cloudformation:</strong> New CloudFormation
DescribeEvents API with operation ID tracking and failure filtering
capabilities to quickly identify root causes of deployment failures.
Also, a DeploymentMode parameter for the CreateChangeSet API that
enables creation of drift-aware change sets for safe drift management.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/04624df229903dcdcb0058cab7f2600c430f3adb">04624df2</a>)</li>
<li><strong>client-kafka:</strong> Amazon MSK adds three new APIs,
ListTopics, DescribeTopic, and DescribeTopicPartitions for viewing Kafka
topics in your MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/12ad701d38579bc63130dd7b0cbb054ed69f6f3d">12ad701d</a>)</li>
<li><strong>client-backup:</strong> AWS Backup now supports a low-cost
warm storage tier for Amazon S3 backup data. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0b0c9b8f6a3e9719499db5a0cdaf0b9b31b70ed1">0b0c9b8f</a>)</li>
<li><strong>client-iam:</strong> Added the AssociateDelegationRequest,
GetDelegationRequest, AcceptDelegationRequest, RejectDelegatonRequest,
ListDelegationRequests, UpdateDelegationRequest, SendDelegationToken and
GetHumanReadableSummary APIs for the IAM temporary delegation feature.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b200679b040a3e3158a2cb4773360fab5cf4bbd8">b200679b</a>)</li>
<li><strong>client-resource-groups-tagging-api:</strong> Add support for
new ListRequiredTags API used to retrieve the required tags specified in
a customer's effective tag policy. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa50551511be7be35117b486ddfc84126623be3b">fa505515</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
Concentrator, a new feature that enables customers to connect multiple
low-bandwidth sites connections through a single attachment, simplifying
multi-site connectivity for distributed enterprises. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b94cadfd704fa2cc3df6d60075aae1ce99212b2d">b94cadfd</a>)</li>
<li><strong>client-bedrock-runtime:</strong> Amazon Bedrock Runtime
Service Tier Support Launch (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ea418df5de064d09ca66470f7452fc6d41c0caf4">ea418df5</a>)</li>
<li><strong>client-auto-scaling:</strong> This release adds the new
LaunchInstances API, which can launch instances synchronously in an
AutoScaling group. The API also returns instances info and launch error
back immediately. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5d96b6881d2b6ace315029f471dca7cd058aa643">5d96b688</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>core/protocols:</strong> add json rpc perf baseline (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7505">#7505</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/114920c68764e2ea9d3a6b8a00851cf132db8dad">114920c6</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.934.0.zip</strong></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sqs/CHANGELOG.md"><code>@​aws-sdk/client-sqs</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.933.0...v3.934.0">3.934.0</a>
(2025-11-18)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-sqs</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/3b6a4d9a2d9e26564506d833431c43ae0de335c6"><code>3b6a4d9</code></a>
Publish v3.934.0</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.934.0/clients/client-sqs">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/client-s3` from 3.933.0 to 3.934.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-s3</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.934.0</h2>
<h4>3.934.0(2025-11-18)</h4>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2025-11-18
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0f98925410ab7b21c1c92bd6a507e3b571f1b337">0f989254</a>)</li>
<li><strong>client-connect:</strong> This release added support for ring
timer configuration for campaign calls. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ae3d76000b552fa56dad59d65f3241b0404c32df">ae3d7600</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> CloudWatch Logs updates:
Added capability to setup a recurring schedule for log insights queries.
Logs introduced Scheduled Queries (managed through
Create/Update/Get/Delete/List/History Scheduled Query APIs). For more
information, see CloudWatch Logs API documentation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/467947d43202b1e0ee40288e3482aa6a1b7db760">467947d4</a>)</li>
<li><strong>client-wafv2:</strong> AssociateWebACL, UpdateWebACL and
PutLoggingConfiguration will now throw
WAFFeatureNotIncludedInPricingPlanException when the request contains a
feature that is not included in the CloudFront pricing plan of the
WebACL. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6da7a3dbfa7d5d5f824e1ee6e8a3e414ee6ed10b">6da7a3db</a>)</li>
<li><strong>client-storage-gateway:</strong> Adds support for European
Sovereign Cloud ARNs in Storage Gateway API parameters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/c7dd6fd72f0c688fbd0030167104dd9bdc8a8bf5">c7dd6fd7</a>)</li>
<li><strong>client-cloudformation:</strong> New CloudFormation
DescribeEvents API with operation ID tracking and failure filtering
capabilities to quickly identify root causes of deployment failures.
Also, a DeploymentMode parameter for the CreateChangeSet API that
enables creation of drift-aware change sets for safe drift management.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/04624df229903dcdcb0058cab7f2600c430f3adb">04624df2</a>)</li>
<li><strong>client-kafka:</strong> Amazon MSK adds three new APIs,
ListTopics, DescribeTopic, and DescribeTopicPartitions for viewing Kafka
topics in your MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/12ad701d38579bc63130dd7b0cbb054ed69f6f3d">12ad701d</a>)</li>
<li><strong>client-backup:</strong> AWS Backup now supports a low-cost
warm storage tier for Amazon S3 backup data. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0b0c9b8f6a3e9719499db5a0cdaf0b9b31b70ed1">0b0c9b8f</a>)</li>
<li><strong>client-iam:</strong> Added the AssociateDelegationRequest,
GetDelegationRequest, AcceptDelegationRequest, RejectDelegatonRequest,
ListDelegationRequests, UpdateDelegationRequest, SendDelegationToken and
GetHumanReadableSummary APIs for the IAM temporary delegation feature.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b200679b040a3e3158a2cb4773360fab5cf4bbd8">b200679b</a>)</li>
<li><strong>client-resource-groups-tagging-api:</strong> Add support for
new ListRequiredTags API used to retrieve the required tags specified in
a customer's effective tag policy. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa50551511be7be35117b486ddfc84126623be3b">fa505515</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
Concentrator, a new feature that enables customers to connect multiple
low-bandwidth sites connections through a single attachment, simplifying
multi-site connectivity for distributed enterprises. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b94cadfd704fa2cc3df6d60075aae1ce99212b2d">b94cadfd</a>)</li>
<li><strong>client-bedrock-runtime:</strong> Amazon Bedrock Runtime
Service Tier Support Launch (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ea418df5de064d09ca66470f7452fc6d41c0caf4">ea418df5</a>)</li>
<li><strong>client-auto-scaling:</strong> This release adds the new
LaunchInstances API, which can launch instances synchronously in an
AutoScaling group. The API also returns instances info and launch error
back immediately. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5d96b6881d2b6ace315029f471dca7cd058aa643">5d96b688</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>core/protocols:</strong> add json rpc perf baseline (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7505">#7505</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/114920c68764e2ea9d3a6b8a00851cf132db8dad">114920c6</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.934.0.zip</strong></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md"><code>@​aws-sdk/client-s3</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.933.0...v3.934.0">3.934.0</a>
(2025-11-18)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/3b6a4d9a2d9e26564506d833431c43ae0de335c6"><code>3b6a4d9</code></a>
Publish v3.934.0</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.934.0/clients/client-s3">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/lib-storage` from 3.933.0 to 3.934.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/lib-storage</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.934.0</h2>
<h4>3.934.0(2025-11-18)</h4>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2025-11-18
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0f98925410ab7b21c1c92bd6a507e3b571f1b337">0f989254</a>)</li>
<li><strong>client-connect:</strong> This release added support for ring
timer configuration for campaign calls. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ae3d76000b552fa56dad59d65f3241b0404c32df">ae3d7600</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> CloudWatch Logs updates:
Added capability to setup a recurring schedule for log insights queries.
Logs introduced Scheduled Queries (managed through
Create/Update/Get/Delete/List/History Scheduled Query APIs). For more
information, see CloudWatch Logs API documentation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/467947d43202b1e0ee40288e3482aa6a1b7db760">467947d4</a>)</li>
<li><strong>client-wafv2:</strong> AssociateWebACL, UpdateWebACL and
PutLoggingConfiguration will now throw
WAFFeatureNotIncludedInPricingPlanException when the request contains a
feature that is not included in the CloudFront pricing plan of the
WebACL. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6da7a3dbfa7d5d5f824e1ee6e8a3e414ee6ed10b">6da7a3db</a>)</li>
<li><strong>client-storage-gateway:</strong> Adds support for European
Sovereign Cloud ARNs in Storage Gateway API parameters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/c7dd6fd72f0c688fbd0030167104dd9bdc8a8bf5">c7dd6fd7</a>)</li>
<li><strong>client-cloudformation:</strong> New CloudFormation
DescribeEvents API with operation ID tracking and failure filtering
capabilities to quickly identify root causes of deployment failures.
Also, a DeploymentMode parameter for the CreateChangeSet API that
enables creation of drift-aware change sets for safe drift management.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/04624df229903dcdcb0058cab7f2600c430f3adb">04624df2</a>)</li>
<li><strong>client-kafka:</strong> Amazon MSK adds three new APIs,
ListTopics, DescribeTopic, and DescribeTopicPartitions for viewing Kafka
topics in your MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/12ad701d38579bc63130dd7b0cbb054ed69f6f3d">12ad701d</a>)</li>
<li><strong>client-backup:</strong> AWS Backup now supports a low-cost
warm storage tier for Amazon S3 backup data. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0b0c9b8f6a3e9719499db5a0cdaf0b9b31b70ed1">0b0c9b8f</a>)</li>
<li><strong>client-iam:</strong> Added the AssociateDelegationRequest,
GetDelegationRequest, AcceptDelegationRequest, RejectDelegatonRequest,
ListDelegationRequests, UpdateDelegationRequest, SendDelegationToken and
GetHumanReadableSummary APIs for the IAM temporary delegation feature.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b200679b040a3e3158a2cb4773360fab5cf4bbd8">b200679b</a>)</li>
<li><strong>client-resource-groups-tagging-api:</strong> Add support for
new ListRequiredTags API used to retrieve the required tags specified in
a customer's effective tag policy. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa50551511be7be35117b486ddfc84126623be3b">fa505515</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
Concentrator, a new feature that enables customers to connect multiple
low-bandwidth sites connections through a single attachment, simplifying
multi-site connectivity for distributed enterprises. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b94cadfd704fa2cc3df6d60075aae1ce99212b2d">b94cadfd</a>)</li>
<li><strong>client-bedrock-runtime:</strong> Amazon Bedrock Runtime
Service Tier Support Launch (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ea418df5de064d09ca66470f7452fc6d41c0caf4">ea418df5</a>)</li>
<li><strong>client-auto-scaling:</strong> This release adds the new
LaunchInstances API, which can launch instances synchronously in an
AutoScaling group. The API also returns instances info and launch error
back immediately. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5d96b6881d2b6ace315029f471dca7cd058aa643">5d96b688</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>core/protocols:</strong> add json rpc perf baseline (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7505">#7505</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/114920c68764e2ea9d3a6b8a00851cf132db8dad">114920c6</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.934.0.zip</strong></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-storage/CHANGELOG.md"><code>@​aws-sdk/lib-storage</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.933.0...v3.934.0">3.934.0</a>
(2025-11-18)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/lib-storage</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/3b6a4d9a2d9e26564506d833431c43ae0de335c6"><code>3b6a4d9</code></a>
Publish v3.934.0</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.934.0/lib/lib-storage">compare
view</a></li>
</ul>
</details>
<br />

Updates `@aws-sdk/client-eventbridge` from 3.933.0 to 3.934.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases"><code>@​aws-sdk/client-eventbridge</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v3.934.0</h2>
<h4>3.934.0(2025-11-18)</h4>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2025-11-18
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0f98925410ab7b21c1c92bd6a507e3b571f1b337">0f989254</a>)</li>
<li><strong>client-connect:</strong> This release added support for ring
timer configuration for campaign calls. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ae3d76000b552fa56dad59d65f3241b0404c32df">ae3d7600</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> CloudWatch Logs updates:
Added capability to setup a recurring schedule for log insights queries.
Logs introduced Scheduled Queries (managed through
Create/Update/Get/Delete/List/History Scheduled Query APIs). For more
information, see CloudWatch Logs API documentation. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/467947d43202b1e0ee40288e3482aa6a1b7db760">467947d4</a>)</li>
<li><strong>client-wafv2:</strong> AssociateWebACL, UpdateWebACL and
PutLoggingConfiguration will now throw
WAFFeatureNotIncludedInPricingPlanException when the request contains a
feature that is not included in the CloudFront pricing plan of the
WebACL. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/6da7a3dbfa7d5d5f824e1ee6e8a3e414ee6ed10b">6da7a3db</a>)</li>
<li><strong>client-storage-gateway:</strong> Adds support for European
Sovereign Cloud ARNs in Storage Gateway API parameters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/c7dd6fd72f0c688fbd0030167104dd9bdc8a8bf5">c7dd6fd7</a>)</li>
<li><strong>client-cloudformation:</strong> New CloudFormation
DescribeEvents API with operation ID tracking and failure filtering
capabilities to quickly identify root causes of deployment failures.
Also, a DeploymentMode parameter for the CreateChangeSet API that
enables creation of drift-aware change sets for safe drift management.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/04624df229903dcdcb0058cab7f2600c430f3adb">04624df2</a>)</li>
<li><strong>client-kafka:</strong> Amazon MSK adds three new APIs,
ListTopics, DescribeTopic, and DescribeTopicPartitions for viewing Kafka
topics in your MSK clusters. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/12ad701d38579bc63130dd7b0cbb054ed69f6f3d">12ad701d</a>)</li>
<li><strong>client-backup:</strong> AWS Backup now supports a low-cost
warm storage tier for Amazon S3 backup data. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0b0c9b8f6a3e9719499db5a0cdaf0b9b31b70ed1">0b0c9b8f</a>)</li>
<li><strong>client-iam:</strong> Added the AssociateDelegationRequest,
GetDelegationRequest, AcceptDelegationRequest, RejectDelegatonRequest,
ListDelegationRequests, UpdateDelegationRequest, SendDelegationToken and
GetHumanReadableSummary APIs for the IAM temporary delegation feature.
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b200679b040a3e3158a2cb4773360fab5cf4bbd8">b200679b</a>)</li>
<li><strong>client-resource-groups-tagging-api:</strong> Add support for
new ListRequiredTags API used to retrieve the required tags specified in
a customer's effective tag policy. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/fa50551511be7be35117b486ddfc84126623be3b">fa505515</a>)</li>
<li><strong>client-ec2:</strong> AWS Site-to-Site VPN now supports VPN
Concentrator, a new feature that enables customers to connect multiple
low-bandwidth sites connections through a single attachment, simplifying
multi-site connectivity for distributed enterprises. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b94cadfd704fa2cc3df6d60075aae1ce99212b2d">b94cadfd</a>)</li>
<li><strong>client-bedrock-runtime:</strong> Amazon Bedrock Runtime
Service Tier Support Launch (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ea418df5de064d09ca66470f7452fc6d41c0caf4">ea418df5</a>)</li>
<li><strong>client-auto-scaling:</strong> This release adds the new
LaunchInstances API, which can launch instances synchronously in an
AutoScaling group. The API also returns instances info and launch error
back immediately. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5d96b6881d2b6ace315029f471dca7cd058aa643">5d96b688</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>core/protocols:</strong> add json rpc perf baseline (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7505">#7505</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/114920c68764e2ea9d3a6b8a00851cf132db8dad">114920c6</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.934.0.zip</strong></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-eventbridge/CHANGELOG.md"><code>@​aws-sdk/client-eventbridge</code>'s
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.933.0...v3.934.0">3.934.0</a>
(2025-11-18)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-eventbridge</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/3b6a4d9a2d9e26564506d833431c43ae0de335c6"><code>3b6a4d9</code></a>
Publish v3.934.0</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.934.0/clients/client-eventbridge">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…te group (#4908)

Bumps the vite group in /lambdas with 1 update:
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).

Updates `vitest` from 4.0.8 to 4.0.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitest-dev/vitest/releases">vitest's
releases</a>.</em></p>
<blockquote>
<h2>v4.0.10</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Remove <code>onCancel</code> when worker is terminated  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/9033">vitest-dev/vitest#9033</a>
<a href="https://github.com/vitest-dev/vitest/commit/6d7f0a99e"><!-- raw
HTML omitted -->(6d7f0)<!-- raw HTML omitted --></a></li>
<li><strong>browser</strong>:
<ul>
<li>Don't scale the iframe if UI is disabled  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/9018">vitest-dev/vitest#9018</a>
<a href="https://github.com/vitest-dev/vitest/commit/5406e8ea4"><!-- raw
HTML omitted -->(5406e)<!-- raw HTML omitted --></a></li>
<li>Handle dependency stack traces with external source maps. Resolves:
<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9003">#9003</a>
 -  by <a href="https://github.com/iclectic"><code>@​iclectic</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9016">vitest-dev/vitest#9016</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9003">vitest-dev/vitest#9003</a>
<a href="https://github.com/vitest-dev/vitest/commit/57ae547de"><!-- raw
HTML omitted -->(57ae5)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>bun</strong>:
<ul>
<li>Parsing of stack trace for bun runtime  -  by <a
href="https://github.com/nazarhussain"><code>@​nazarhussain</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9032">vitest-dev/vitest#9032</a>
<a href="https://github.com/vitest-dev/vitest/commit/f3ec6fcb0"><!-- raw
HTML omitted -->(f3ec6)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>core</strong>:
<ul>
<li>Prevent starting new run when cancelling  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8991">vitest-dev/vitest#8991</a>
<a href="https://github.com/vitest-dev/vitest/commit/eb98dd8fd"><!-- raw
HTML omitted -->(eb98d)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>pool</strong>:
<ul>
<li>Prevent writing to closed worker  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> and
<a href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9023">vitest-dev/vitest#9023</a>
<a href="https://github.com/vitest-dev/vitest/commit/042c60c80"><!-- raw
HTML omitted -->(042c6)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>reporters</strong>:
<ul>
<li>Report correct test run duration at the end  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8969">vitest-dev/vitest#8969</a>
<a href="https://github.com/vitest-dev/vitest/commit/bc3a6921e"><!-- raw
HTML omitted -->(bc3a6)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>ui</strong>:
<ul>
<li>Use execution time from ws reporter (<code>onFinished</code>)  -  by
<a href="https://github.com/userquin"><code>@​userquin</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8975">vitest-dev/vitest#8975</a>
<a href="https://github.com/vitest-dev/vitest/commit/f56dc0cc4"><!-- raw
HTML omitted -->(f56dc)<!-- raw HTML omitted --></a></li>
</ul>
</li>
</ul>
<h5>    <a
href="https://github.com/vitest-dev/vitest/compare/v4.0.9...v4.0.10">View
changes on GitHub</a></h5>
<h2>v4.0.9</h2>
<h3>   🚀 Experimental Features</h3>
<ul>
<li><strong>expect</strong>: Add Set support to toBeOneOf  -  by <a
href="https://github.com/tim-we"><code>@​tim-we</code></a> and <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8906">vitest-dev/vitest#8906</a>
<a href="https://github.com/vitest-dev/vitest/commit/a415d0375"><!-- raw
HTML omitted -->(a415d)<!-- raw HTML omitted --></a></li>
</ul>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li><strong>browser</strong>: Add favicon icons to the browser mode ui
 -  by <a href="https://github.com/userquin"><code>@​userquin</code></a>
in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/8972">vitest-dev/vitest#8972</a>
<a href="https://github.com/vitest-dev/vitest/commit/353ee5bbc"><!-- raw
HTML omitted -->(353ee)<!-- raw HTML omitted --></a></li>
<li><strong>forks</strong>: Increase worker start timeout  -  by <a
href="https://github.com/AriPerkkio"><code>@​AriPerkkio</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/9027">vitest-dev/vitest#9027</a>
<a href="https://github.com/vitest-dev/vitest/commit/5e750f4ba"><!-- raw
HTML omitted -->(5e750)<!-- raw HTML omitted --></a></li>
<li><strong>jsdom</strong>: Cloned request is an instance of
<code>Request</code>  -  by <a
href="https://github.com/sheremet-va"><code>@​sheremet-va</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8985">vitest-dev/vitest#8985</a>
<a href="https://github.com/vitest-dev/vitest/commit/506a9fd0f"><!-- raw
HTML omitted -->(506a9)<!-- raw HTML omitted --></a></li>
<li><strong>ui</strong>: Collect file/suite/test duration correctly  - 
by <a href="https://github.com/userquin"><code>@​userquin</code></a> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/8976">vitest-dev/vitest#8976</a>
<a href="https://github.com/vitest-dev/vitest/commit/8016da886"><!-- raw
HTML omitted -->(8016d)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/vitest-dev/vitest/compare/v4.0.8...v4.0.9">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitest-dev/vitest/commit/259a3d1b563ecafa51ced4641218545dab635be7"><code>259a3d1</code></a>
chore: release v4.0.10</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/bc3a6921e2782a55a192802891feee84f50ec283"><code>bc3a692</code></a>
fix(reporters): report correct test run duration at the end (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8969">#8969</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/f3ec6fcb0abc4bc44b6511423a24587dfbbad47a"><code>f3ec6fc</code></a>
fix(bun): parsing of stack trace for bun runtime (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9032">#9032</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/042c60c80ab20f0e6c5b759b875f51602a4dc621"><code>042c60c</code></a>
fix(pool): prevent writing to closed worker (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9023">#9023</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/80f2bb6d8992aa54f1c5992c4269c3e117263487"><code>80f2bb6</code></a>
chore(deps): update all non-major dependencies (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9037">#9037</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/eb98dd8fd29e5e0b1f5c8741b7744fdb7a99f9a2"><code>eb98dd8</code></a>
fix(core): prevent starting new run when cancelling (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8991">#8991</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/f509d2ab9f2c88aca48113d775297fd1eabac063"><code>f509d2a</code></a>
chore(deps): update dependency <code>@​types/node</code> to v24 (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9038">#9038</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/44dca5fb432ef9213a0d44a2794f9a404fcc4f03"><code>44dca5f</code></a>
chore: print a better error when browser orchestrator fails to run a
test (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8">#8</a>...</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/f56dc0cc4c2c0e61bada9500208de6e56d4b434e"><code>f56dc0c</code></a>
fix(ui): use execution time from ws reporter (<code>onFinished</code>)
(<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8975">#8975</a>)</li>
<li><a
href="https://github.com/vitest-dev/vitest/commit/7c9edffb055546390379c7c97ad7cff70e1d6891"><code>7c9edff</code></a>
refactor(forks): simplify IPC channel serialization (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/8999">#8999</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vitest-dev/vitest/commits/v4.0.10/packages/vitest">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=vitest&package-manager=npm_and_yarn&previous-version=4.0.8&new-version=4.0.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
🤖 I have created a release *beep* *boop*
---


##
[6.10.0](v6.9.1...v6.10.0)
(2025-11-24)


### Features

* **runner-binaries-syncer:** add s3_tags variable for additional S3
bucket tagging
([#4832](#4832))
([8db1f60](8db1f60))


### Bug Fixes

* **lambda:** bump the aws group in /lambdas with 6 updates
([#4906](#4906))
([afd62b6](afd62b6))
* **runners:** support for AMIs with parentheses in the name
([#4856](#4856))
([2904a10](2904a10))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: runners-releaser[bot] <194412594+runners-releaser[bot]@users.noreply.github.com>
Co-authored-by: github-aws-runners-pr|bot <github-aws-runners-pr[bot]@users.noreply.github.com>
… /lambdas (#4909)

Bumps
[aws-sdk-client-mock-vitest](https://github.com/stschulte/aws-sdk-client-mock-vitest)
from 6.2.1 to 7.0.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/releases">aws-sdk-client-mock-vitest's
releases</a>.</em></p>
<blockquote>
<h2>Release v7.0.1</h2>
<h3>Changed</h3>
<ul>
<li>small internal changes and updated dependencies</li>
</ul>
<h2>Release v7.0.0</h2>
<h3>Changed</h3>
<ul>
<li>Support <code>@vitest/expect</code> version <code>4</code>. You
should upgrade to this version when
using <code>vitest</code> <code>4</code>. Otherwise you should keep at
<code>aws-sdk-client-mock-vitest</code>
version <code>6.2.1</code>. This version also drops support for Node 18,
since vitest <code>4</code>
<a href="https://redirect.github.com/vitest-dev/vitest/pull/8608">does
not support it anymore</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/blob/main/CHANGELOG.md">aws-sdk-client-mock-vitest's
changelog</a>.</em></p>
<blockquote>
<h2>[7.0.1] - 2025-11-06</h2>
<h3>Changed</h3>
<ul>
<li>small internal changes and updated dependencies</li>
</ul>
<h2>[7.0.0] - 2025-11-01</h2>
<h3>Changed</h3>
<ul>
<li>Support <code>@vitest/expect</code> version <code>4</code>. You
should upgrade to this version when
using <code>vitest</code> <code>4</code>. Otherwise you should keep at
<code>aws-sdk-client-mock-vitest</code>
version <code>6.2.1</code>. This version also drops support for Node 18,
since vitest <code>4</code>
<a href="https://redirect.github.com/vitest-dev/vitest/pull/8608">does
not support it anymore</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/5b21a4b0a0df0c41ef9446fa58fc2230bd2c34ab"><code>5b21a4b</code></a>
Prepare 7.0.1 Release</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/8d0c7b71dc7895557d117c3728a98c23f21b7678"><code>8d0c7b7</code></a>
Merge pull request <a
href="https://redirect.github.com/stschulte/aws-sdk-client-mock-vitest/issues/21">#21</a>
from stschulte/simplify-format-calls</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/ddcdd8b82e6a2a34c60c4d83553cb7ada3344d4d"><code>ddcdd8b</code></a>
maint: Update dependencies</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/74f5cf8bddfa0a87380f8d8098c8ad06171fd60e"><code>74f5cf8</code></a>
Simplify formatCalls by extracting indent function</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/eede967b9abb7aa5a1966287637d3835beaa777b"><code>eede967</code></a>
Prepare 7.0.0 Release</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/a7532cae92be70608e80c591a57ce6c6cb6ea3bc"><code>a7532ca</code></a>
Merge pull request <a
href="https://redirect.github.com/stschulte/aws-sdk-client-mock-vitest/issues/20">#20</a>
from stschulte/vitest-4-support</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/e07830007722bfc587b2dfc2a43d4000ff0d1d81"><code>e078300</code></a>
maint: Revert to eslint 3.38.0</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/c2e5e00e227da2c18f3266d9e181e30ff3f57870"><code>c2e5e00</code></a>
Add vitest peerDependency</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/f6e45859fd67c0504504230b1ffd73bd91ce84fb"><code>f6e4585</code></a>
Update vitest extending matchers</li>
<li><a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/commit/1c8843d7989971056cb2f91748aac79f0a5f1f19"><code>1c8843d</code></a>
Add information about dropped node 18 support</li>
<li>Additional commits viewable in <a
href="https://github.com/stschulte/aws-sdk-client-mock-vitest/compare/v6.2.1...v7.0.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aws-sdk-client-mock-vitest&package-manager=npm_and_yarn&previous-version=6.2.1&new-version=7.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the nx group in /lambdas with 3 updates:
[@nx/eslint](https://github.com/nrwl/nx/tree/HEAD/packages/eslint),
[@nx/js](https://github.com/nrwl/nx/tree/HEAD/packages/js) and
[@nx/vite](https://github.com/nrwl/nx/tree/HEAD/packages/vite).

Updates `@nx/eslint` from 22.0.3 to 22.0.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nrwl/nx/releases"><code>@​nx/eslint</code>'s
releases</a>.</em></p>
<blockquote>
<h2>22.0.4 (2025-11-17)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>core:</strong> pull nx init from latest before executing (<a
href="https://redirect.github.com/nrwl/nx/pull/33446">#33446</a>)</li>
<li><strong>docker:</strong> add skipDefaultTag option to build target
(<a href="https://redirect.github.com/nrwl/nx/pull/33477">#33477</a>, <a
href="https://redirect.github.com/nrwl/nx/pull/33506">#33506</a>)</li>
<li><strong>maven:</strong> add option to prefix all maven targets (<a
href="https://redirect.github.com/nrwl/nx/pull/33420">#33420</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>core:</strong> resolve lockfile cache regression with keyMap
state (<a
href="https://redirect.github.com/nrwl/nx/pull/33448">#33448</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33256">#33256</a>)</li>
<li><strong>core:</strong> optimize batch task scheduling to prevent
redundant traversals (<a
href="https://redirect.github.com/nrwl/nx/pull/33455">#33455</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33366">#33366</a>)</li>
<li><strong>core:</strong> capture stderr in nx add command for better
error messages (<a
href="https://redirect.github.com/nrwl/nx/pull/33462">#33462</a>)</li>
<li><strong>core:</strong> include require paths when resolving
specified plugins (<a
href="https://redirect.github.com/nrwl/nx/pull/33495">#33495</a>)</li>
<li><strong>core:</strong> prevent hanging between command end and
process exit (<a
href="https://redirect.github.com/nrwl/nx/pull/33500">#33500</a>)</li>
<li><strong>gradle:</strong> bump gradle migration version (<a
href="https://redirect.github.com/nrwl/nx/pull/33479">#33479</a>)</li>
<li><strong>graph:</strong> add nx:build-native dependency to typecheck
target (<a
href="https://redirect.github.com/nrwl/nx/pull/33428">#33428</a>)</li>
<li><strong>js:</strong> improve typescript plugin performance (<a
href="https://redirect.github.com/nrwl/nx/pull/33425">#33425</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33076">#33076</a>)</li>
<li><strong>maven:</strong> skip maven plugin computation on
vercel/netlify (<a
href="https://redirect.github.com/nrwl/nx/pull/33486">#33486</a>)</li>
<li><strong>misc:</strong> handle ERR_USE_AFTER_CLOSE gracefully in nx
init and create-nx-workspace (<a
href="https://redirect.github.com/nrwl/nx/pull/33469">#33469</a>)</li>
<li><strong>release:</strong> changelog renderer should render commit
title with breaking changes (<a
href="https://redirect.github.com/nrwl/nx/pull/33439">#33439</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Claude</li>
<li>Colum Ferry <a
href="https://github.com/Coly010"><code>@​Coly010</code></a></li>
<li>Craigory Coppola <a
href="https://github.com/AgentEnder"><code>@​AgentEnder</code></a></li>
<li>FrozenPandaz <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Jack Hsu <a
href="https://github.com/jaysoo"><code>@​jaysoo</code></a></li>
<li>Jason Jean <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Leosvel Pérez Espinosa <a
href="https://github.com/leosvelperez"><code>@​leosvelperez</code></a></li>
<li>Louie Weng <a
href="https://github.com/lourw"><code>@​lourw</code></a></li>
<li>MaxKless <a
href="https://github.com/MaxKless"><code>@​MaxKless</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/nrwl/nx/commits/22.0.4/packages/eslint">compare
view</a></li>
</ul>
</details>
<br />

Updates `@nx/js` from 22.0.3 to 22.0.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nrwl/nx/releases"><code>@​nx/js</code>'s
releases</a>.</em></p>
<blockquote>
<h2>22.0.4 (2025-11-17)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>core:</strong> pull nx init from latest before executing (<a
href="https://redirect.github.com/nrwl/nx/pull/33446">#33446</a>)</li>
<li><strong>docker:</strong> add skipDefaultTag option to build target
(<a href="https://redirect.github.com/nrwl/nx/pull/33477">#33477</a>, <a
href="https://redirect.github.com/nrwl/nx/pull/33506">#33506</a>)</li>
<li><strong>maven:</strong> add option to prefix all maven targets (<a
href="https://redirect.github.com/nrwl/nx/pull/33420">#33420</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>core:</strong> resolve lockfile cache regression with keyMap
state (<a
href="https://redirect.github.com/nrwl/nx/pull/33448">#33448</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33256">#33256</a>)</li>
<li><strong>core:</strong> optimize batch task scheduling to prevent
redundant traversals (<a
href="https://redirect.github.com/nrwl/nx/pull/33455">#33455</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33366">#33366</a>)</li>
<li><strong>core:</strong> capture stderr in nx add command for better
error messages (<a
href="https://redirect.github.com/nrwl/nx/pull/33462">#33462</a>)</li>
<li><strong>core:</strong> include require paths when resolving
specified plugins (<a
href="https://redirect.github.com/nrwl/nx/pull/33495">#33495</a>)</li>
<li><strong>core:</strong> prevent hanging between command end and
process exit (<a
href="https://redirect.github.com/nrwl/nx/pull/33500">#33500</a>)</li>
<li><strong>gradle:</strong> bump gradle migration version (<a
href="https://redirect.github.com/nrwl/nx/pull/33479">#33479</a>)</li>
<li><strong>graph:</strong> add nx:build-native dependency to typecheck
target (<a
href="https://redirect.github.com/nrwl/nx/pull/33428">#33428</a>)</li>
<li><strong>js:</strong> improve typescript plugin performance (<a
href="https://redirect.github.com/nrwl/nx/pull/33425">#33425</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33076">#33076</a>)</li>
<li><strong>maven:</strong> skip maven plugin computation on
vercel/netlify (<a
href="https://redirect.github.com/nrwl/nx/pull/33486">#33486</a>)</li>
<li><strong>misc:</strong> handle ERR_USE_AFTER_CLOSE gracefully in nx
init and create-nx-workspace (<a
href="https://redirect.github.com/nrwl/nx/pull/33469">#33469</a>)</li>
<li><strong>release:</strong> changelog renderer should render commit
title with breaking changes (<a
href="https://redirect.github.com/nrwl/nx/pull/33439">#33439</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Claude</li>
<li>Colum Ferry <a
href="https://github.com/Coly010"><code>@​Coly010</code></a></li>
<li>Craigory Coppola <a
href="https://github.com/AgentEnder"><code>@​AgentEnder</code></a></li>
<li>FrozenPandaz <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Jack Hsu <a
href="https://github.com/jaysoo"><code>@​jaysoo</code></a></li>
<li>Jason Jean <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Leosvel Pérez Espinosa <a
href="https://github.com/leosvelperez"><code>@​leosvelperez</code></a></li>
<li>Louie Weng <a
href="https://github.com/lourw"><code>@​lourw</code></a></li>
<li>MaxKless <a
href="https://github.com/MaxKless"><code>@​MaxKless</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nrwl/nx/commit/b0d3e04250231ae5cd0fcb7c72d3b2f0be763345"><code>b0d3e04</code></a>
fix(js): improve typescript plugin performance (<a
href="https://github.com/nrwl/nx/tree/HEAD/packages/js/issues/33425">#33425</a>)</li>
<li>See full diff in <a
href="https://github.com/nrwl/nx/commits/22.0.4/packages/js">compare
view</a></li>
</ul>
</details>
<br />

Updates `@nx/vite` from 22.0.3 to 22.0.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/nrwl/nx/releases"><code>@​nx/vite</code>'s
releases</a>.</em></p>
<blockquote>
<h2>22.0.4 (2025-11-17)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>core:</strong> pull nx init from latest before executing (<a
href="https://redirect.github.com/nrwl/nx/pull/33446">#33446</a>)</li>
<li><strong>docker:</strong> add skipDefaultTag option to build target
(<a href="https://redirect.github.com/nrwl/nx/pull/33477">#33477</a>, <a
href="https://redirect.github.com/nrwl/nx/pull/33506">#33506</a>)</li>
<li><strong>maven:</strong> add option to prefix all maven targets (<a
href="https://redirect.github.com/nrwl/nx/pull/33420">#33420</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>core:</strong> resolve lockfile cache regression with keyMap
state (<a
href="https://redirect.github.com/nrwl/nx/pull/33448">#33448</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33256">#33256</a>)</li>
<li><strong>core:</strong> optimize batch task scheduling to prevent
redundant traversals (<a
href="https://redirect.github.com/nrwl/nx/pull/33455">#33455</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33366">#33366</a>)</li>
<li><strong>core:</strong> capture stderr in nx add command for better
error messages (<a
href="https://redirect.github.com/nrwl/nx/pull/33462">#33462</a>)</li>
<li><strong>core:</strong> include require paths when resolving
specified plugins (<a
href="https://redirect.github.com/nrwl/nx/pull/33495">#33495</a>)</li>
<li><strong>core:</strong> prevent hanging between command end and
process exit (<a
href="https://redirect.github.com/nrwl/nx/pull/33500">#33500</a>)</li>
<li><strong>gradle:</strong> bump gradle migration version (<a
href="https://redirect.github.com/nrwl/nx/pull/33479">#33479</a>)</li>
<li><strong>graph:</strong> add nx:build-native dependency to typecheck
target (<a
href="https://redirect.github.com/nrwl/nx/pull/33428">#33428</a>)</li>
<li><strong>js:</strong> improve typescript plugin performance (<a
href="https://redirect.github.com/nrwl/nx/pull/33425">#33425</a>, <a
href="https://redirect.github.com/nrwl/nx/issues/33076">#33076</a>)</li>
<li><strong>maven:</strong> skip maven plugin computation on
vercel/netlify (<a
href="https://redirect.github.com/nrwl/nx/pull/33486">#33486</a>)</li>
<li><strong>misc:</strong> handle ERR_USE_AFTER_CLOSE gracefully in nx
init and create-nx-workspace (<a
href="https://redirect.github.com/nrwl/nx/pull/33469">#33469</a>)</li>
<li><strong>release:</strong> changelog renderer should render commit
title with breaking changes (<a
href="https://redirect.github.com/nrwl/nx/pull/33439">#33439</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Claude</li>
<li>Colum Ferry <a
href="https://github.com/Coly010"><code>@​Coly010</code></a></li>
<li>Craigory Coppola <a
href="https://github.com/AgentEnder"><code>@​AgentEnder</code></a></li>
<li>FrozenPandaz <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Jack Hsu <a
href="https://github.com/jaysoo"><code>@​jaysoo</code></a></li>
<li>Jason Jean <a
href="https://github.com/FrozenPandaz"><code>@​FrozenPandaz</code></a></li>
<li>Leosvel Pérez Espinosa <a
href="https://github.com/leosvelperez"><code>@​leosvelperez</code></a></li>
<li>Louie Weng <a
href="https://github.com/lourw"><code>@​lourw</code></a></li>
<li>MaxKless <a
href="https://github.com/MaxKless"><code>@​MaxKless</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/nrwl/nx/commits/22.0.4/packages/vite">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….47.0 in /lambdas (#4910)

Bumps
[@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin)
from 8.46.0 to 8.47.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/typescript-eslint/typescript-eslint/releases"><code>@​typescript-eslint/eslint-plugin</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v8.47.0</h2>
<h2>8.47.0 (2025-11-17)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-unused-private-class-members]
new extension rule (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/10913">#10913</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Brad Zacher <a
href="https://github.com/bradzacher"><code>@​bradzacher</code></a></li>
</ul>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>v8.46.4</h2>
<h2>8.46.4 (2025-11-10)</h2>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-deprecated] fix double-report on
computed literal identifiers (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11006">#11006</a>,
<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/issues/10958">#10958</a>)</li>
<li><strong>eslint-plugin:</strong> handle override modifier in
promise-function-async fixer (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11730">#11730</a>)</li>
<li><strong>parser:</strong> error when both <code>projectService</code>
and <code>project</code> are set (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11333">#11333</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Evgeny Stepanovych <a
href="https://github.com/undsoft"><code>@​undsoft</code></a></li>
<li>Kentaro Suzuki <a
href="https://github.com/sushichan044"><code>@​sushichan044</code></a></li>
<li>Maria Solano <a
href="https://github.com/MariaSolOs"><code>@​MariaSolOs</code></a></li>
</ul>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>v8.46.3</h2>
<h2>8.46.3 (2025-11-03)</h2>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-misused-promises] expand union
type to retrieve target property (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11706">#11706</a>)</li>
<li><strong>eslint-plugin:</strong> [no-duplicate-enum-values] support
signed numbers (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11722">#11722</a>,
<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11723">#11723</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Evgeny Stepanovych <a
href="https://github.com/undsoft"><code>@​undsoft</code></a></li>
<li>tao</li>
</ul>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>v8.46.2</h2>
<h2>8.46.2 (2025-10-20)</h2>
<h3>🩹 Fixes</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md"><code>@​typescript-eslint/eslint-plugin</code>'s
changelog</a>.</em></p>
<blockquote>
<h2>8.47.0 (2025-11-17)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-unused-private-class-members]
new extension rule (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/10913">#10913</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Brad Zacher <a
href="https://github.com/bradzacher"><code>@​bradzacher</code></a></li>
</ul>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>8.46.4 (2025-11-10)</h2>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>parser:</strong> error when both <code>projectService</code>
and <code>project</code> are set (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11333">#11333</a>)</li>
<li><strong>eslint-plugin:</strong> handle override modifier in
promise-function-async fixer (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11730">#11730</a>)</li>
<li><strong>eslint-plugin:</strong> [no-deprecated] fix double-report on
computed literal identifiers (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11006">#11006</a>,
<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/issues/10958">#10958</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Evgeny Stepanovych <a
href="https://github.com/undsoft"><code>@​undsoft</code></a></li>
<li>Kentaro Suzuki <a
href="https://github.com/sushichan044"><code>@​sushichan044</code></a></li>
<li>Maria Solano <a
href="https://github.com/MariaSolOs"><code>@​MariaSolOs</code></a></li>
</ul>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>8.46.3 (2025-11-03)</h2>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-duplicate-enum-values] support
signed numbers (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11722">#11722</a>,
<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11723">#11723</a>)</li>
<li><strong>eslint-plugin:</strong> [no-misused-promises] expand union
type to retrieve target property (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11706">#11706</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Evgeny Stepanovych <a
href="https://github.com/undsoft"><code>@​undsoft</code></a></li>
<li>tao</li>
</ul>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>8.46.2 (2025-10-20)</h2>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>eslint-plugin:</strong> [prefer-optional-chain] skip
optional chaining when it could change the result (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/11702">#11702</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/28cf8032c2492bb3c55dd7dd145249f2246034ad"><code>28cf803</code></a>
chore(release): publish 8.47.0</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/6c6db249bde934b6d617eff6f70d105bae5b9c50"><code>6c6db24</code></a>
feat(eslint-plugin): [no-unused-private-class-members] new extension
rule (<a
href="https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/1">#1</a>...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/843f144797c0a94272cdb002c00c5639cf0797c6"><code>843f144</code></a>
chore(release): publish 8.46.4</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/997e0c005d2d80a726249cafb7cbdf4ec287aea3"><code>997e0c0</code></a>
fix(parser): error when both <code>projectService</code> and
<code>project</code> are set (<a
href="https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/11333">#11333</a>)</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/7c6944e74b29a3310515a9de9333e20116165b58"><code>7c6944e</code></a>
chore: fix typos (<a
href="https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/11744">#11744</a>)</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/189a7f76fc85661e0bebdedebd24a60c255e920d"><code>189a7f7</code></a>
fix(eslint-plugin): handle override modifier in promise-function-async
fixer ...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/c779f3cd80c41ecfc279fd9c66651314b97d843e"><code>c779f3c</code></a>
fix(eslint-plugin): [no-deprecated] fix double-report on computed
literal ide...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/ea2ee6b65a2f14dd2c3fc8d12be969cbeaef80a8"><code>ea2ee6b</code></a>
chore(eslint-plugin): use correct type for return type of
<code>createValidator</code> (...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/d9f3497dfb72e90fd7dc977c77d41b0eb9df4909"><code>d9f3497</code></a>
chore(release): publish 8.46.3</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/26a9f9485faa45d269fd701b5fb8b11c97d75144"><code>26a9f94</code></a>
fix(eslint-plugin): [no-duplicate-enum-values] support signed numbers
(<a
href="https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/11722">#11722</a>...</li>
<li>Additional commits viewable in <a
href="https://github.com/typescript-eslint/typescript-eslint/commits/v8.47.0/packages/eslint-plugin">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@typescript-eslint/eslint-plugin&package-manager=npm_and_yarn&previous-version=8.46.0&new-version=8.47.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [body-parser](https://github.com/expressjs/body-parser) from 2.2.0
to 2.2.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/body-parser/releases">body-parser's
releases</a>.</em></p>
<blockquote>
<h2>v2.2.1</h2>
<h2>Important: Security</h2>
<ul>
<li>Security fix for <a
href="https://www.cve.org/CVERecord?id=CVE-2025-13466">CVE-2025-13466</a>
(<a
href="https://github.com/expressjs/body-parser/security/advisories/GHSA-wqch-xfxh-vrr4">GHSA-wqch-xfxh-vrr4</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>ci: add dependabot by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/593">expressjs/body-parser#593</a></li>
<li>ci: use full SHAs for github action versions by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/594">expressjs/body-parser#594</a></li>
<li>deps: type-is@^2.0.1 by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/599">expressjs/body-parser#599</a></li>
<li>build(deps): bump actions/setup-node from 4.3.0 to 4.4.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/609">expressjs/body-parser#609</a></li>
<li>build(deps): bump github/codeql-action from 3.28.13 to 3.28.15 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/610">expressjs/body-parser#610</a></li>
<li>build(deps-dev): bump eslint-plugin-promise from 6.1.1 to 6.6.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/611">expressjs/body-parser#611</a></li>
<li>build(deps-dev): bump eslint-plugin-import from 2.27.5 to 2.31.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/613">expressjs/body-parser#613</a></li>
<li>build(deps-dev): bump eslint-plugin-markdown from 3.0.0 to 3.0.1 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/612">expressjs/body-parser#612</a></li>
<li>ci: add codeql github workflows scanning by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/614">expressjs/body-parser#614</a></li>
<li>ci: update CodeQL config to ignore the test directory by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/615">expressjs/body-parser#615</a></li>
<li>build(deps): bump actions/download-artifact from 4.2.1 to 4.3.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/620">expressjs/body-parser#620</a></li>
<li>build(deps): bump github/codeql-action from 3.28.15 to 3.28.16 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/619">expressjs/body-parser#619</a></li>
<li>chore(deps): unpin devDependencies by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/616">expressjs/body-parser#616</a></li>
<li>ci: add node.js 24 to test matrix by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/621">expressjs/body-parser#621</a></li>
<li>build(deps): bump github/codeql-action from 3.28.16 to 3.28.18 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/623">expressjs/body-parser#623</a></li>
<li>build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/624">expressjs/body-parser#624</a></li>
<li>chore: add funding to package.json by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/617">expressjs/body-parser#617</a></li>
<li>build(deps): bump github/codeql-action from 3.28.18 to 3.29.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/625">expressjs/body-parser#625</a></li>
<li>build(deps): bump github/codeql-action from 3.29.2 to 3.29.5 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/630">expressjs/body-parser#630</a></li>
<li>refactor: move common request validation to read function by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/600">expressjs/body-parser#600</a></li>
<li>deps: bump iconv-lite by <a
href="https://github.com/bjohansebas"><code>@​bjohansebas</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/631">expressjs/body-parser#631</a></li>
<li>doc: pull beta changelog forward into 2.0.0 by <a
href="https://github.com/jonchurch"><code>@​jonchurch</code></a> in <a
href="https://redirect.github.com/expressjs/body-parser/pull/629">expressjs/body-parser#629</a></li>
<li>refactor: optimize raw and text parsers with shared passthrough
function by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/634">expressjs/body-parser#634</a></li>
<li>build(deps): bump actions/checkout from 4.2.2 to 5.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/640">expressjs/body-parser#640</a></li>
<li>build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/639">expressjs/body-parser#639</a></li>
<li>build(deps): bump actions/setup-node from 4.4.0 to 5.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/636">expressjs/body-parser#636</a></li>
<li>build(deps): bump actions/download-artifact from 4.3.0 to 5.0.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/637">expressjs/body-parser#637</a></li>
<li>build(deps): bump github/codeql-action from 3.29.7 to 3.30.5 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/638">expressjs/body-parser#638</a></li>
<li>deps: raw-body@^3.0.1 by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/641">expressjs/body-parser#641</a></li>
<li>deps: debug@^4.4.3 by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/642">expressjs/body-parser#642</a></li>
<li>docs: add iconv-lite 0.7.0 changes to history entry by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/645">expressjs/body-parser#645</a></li>
<li>ci: add node.js 25 to test matrix by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/650">expressjs/body-parser#650</a></li>
<li>perf: move read options outside parser middlewares by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/648">expressjs/body-parser#648</a></li>
<li>test(json): add RFC 7159 whitespace edge cases by <a
href="https://github.com/Ayoub-Mabrouk"><code>@​Ayoub-Mabrouk</code></a>
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/653">expressjs/body-parser#653</a></li>
<li>test: add test for urlencoded invalid defaultCharset by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/643">expressjs/body-parser#643</a></li>
<li>build(deps): bump actions/download-artifact from 5.0.0 to 6.0.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/657">expressjs/body-parser#657</a></li>
<li>build(deps): bump github/codeql-action from 3.30.5 to 4.31.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/656">expressjs/body-parser#656</a></li>
<li>build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/655">expressjs/body-parser#655</a></li>
<li>build(deps): bump actions/setup-node from 5.0.0 to 6.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/654">expressjs/body-parser#654</a></li>
<li>ci: also test on first supported node.js version by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/646">expressjs/body-parser#646</a></li>
<li>chore: switch badges from badgen.net to shields.io by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/661">expressjs/body-parser#661</a></li>
<li>Remove history.md from being packaged on publish by <a
href="https://github.com/bjohansebas"><code>@​bjohansebas</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/660">expressjs/body-parser#660</a></li>
<li>Release: 2.2.1 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/659">expressjs/body-parser#659</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/body-parser/blob/master/HISTORY.md">body-parser's
changelog</a>.</em></p>
<blockquote>
<h1>2.2.1 / 2025-11-24</h1>
<ul>
<li>Security fix for <a
href="https://github.com/expressjs/body-parser/security/advisories/GHSA-wqch-xfxh-vrr4">GHSA-wqch-xfxh-vrr4</a></li>
<li>deps:
<ul>
<li>type-is@^2.0.1</li>
<li>iconv-lite@^0.7.0
<ul>
<li>Handle split surrogate pairs when encoding UTF-8</li>
<li>Avoid false positives in <code>encodingExists</code> by using
prototype-less objects</li>
</ul>
</li>
<li>raw-body@^3.0.1</li>
<li>debug@^4.4.3</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/expressjs/body-parser/commit/d96b63da8d7445de317736471633bac83ec76cbb"><code>d96b63d</code></a>
2.2.1 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/659">#659</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/b204886a6744b0b6d297cd0e849d75de836f3b63"><code>b204886</code></a>
sec: security patch for CVE-2025-13466</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/e20e3512e085c1162e8ffe36ac65c705a8017251"><code>e20e351</code></a>
feat: remove <code>history.md</code> from being packaged on publish (<a
href="https://redirect.github.com/expressjs/body-parser/issues/660">#660</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/0d7ce71c84fa3dd80930188c85f8b2862c1f32a5"><code>0d7ce71</code></a>
docs: switch badges from badgen.net to shields.io (<a
href="https://redirect.github.com/expressjs/body-parser/issues/661">#661</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/168afff3470302aa28050a8ae6681fa1fdaf71a2"><code>168afff</code></a>
ci: also test on first supported node.js version (<a
href="https://redirect.github.com/expressjs/body-parser/issues/646">#646</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/e539a7121d106539379b3192705a06bac48c6d1c"><code>e539a71</code></a>
build(deps): bump actions/setup-node from 5.0.0 to 6.0.0 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/654">#654</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/939161277a70c1b082f7169f7dc64abf35ff5ce9"><code>9391612</code></a>
build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/655">#655</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/57baafb3bb04c115967a5f8ce9b8be2f96ea0b03"><code>57baafb</code></a>
build(deps): bump github/codeql-action from 3.30.5 to 4.31.2 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/656">#656</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/a6a088e088dfe226b4a4f8e1290352db5e26aab4"><code>a6a088e</code></a>
build(deps): bump actions/download-artifact from 5.0.0 to 6.0.0 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/657">#657</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/10a114d55d5d9be979eaa06a37e65c0df713ae33"><code>10a114d</code></a>
test: add test for urlencoded invalid defaultCharset (<a
href="https://redirect.github.com/expressjs/body-parser/issues/643">#643</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/expressjs/body-parser/compare/v2.2.0...v2.2.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=body-parser&package-manager=npm_and_yarn&previous-version=2.2.0&new-version=2.2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github-aws-runners/terraform-aws-github-runner/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
vegardx and others added 30 commits July 21, 2026 15:38
### Problem

`JSON.parse(body)` runs in the record loop at the top of
`scaleUpHandler`, outside the `try`/`catch` further down. An unparseable
message body therefore throws straight out of the handler.

Lambda treats a thrown exception as a complete batch failure, so
**nothing is deleted and the entire batch returns to the queue** after
the visibility timeout. The body is malformed deterministically, so
every redelivery reproduces the same `SyntaxError`. `scaleUp` is never
reached, which means valid messages batched alongside the malformed one
are never processed either — they are blocked as collateral damage.

Two things make it worse:

- `ReportBatchItemFailures` [disables Lambda's scale-down of message
polling when invocations
fail](https://docs.aws.amazon.com/lambda/latest/dg/services-sqs-errorhandling.html),
so the usual concurrency backoff does not apply.
- `redrive_build_queue` defaults to `enabled = false`, so there is no
`maxReceiveCount` cap. The only backstop is
`job_queue_retention_in_seconds`, default 24h.

Verified empirically against `main`: a batch of two valid records plus
one malformed one rejects with `SyntaxError` and `scaleUp` is called
zero times.

### Change

Parse each record defensively. A malformed body is logged and reported
as an individual batch item failure; the rest of the batch proceeds to
`scaleUp` as normal.

The malformed message then exhausts `maxReceiveCount` on its own rather
than taking the batch with it. It cannot be acknowledged and discarded
through the partial-failure mechanism — reporting it is the only way to
single it out — so with the default configuration it expires by
retention rather than moving to a DLQ. Operators who want these captured
should enable `redrive_build_queue`.

### Tests

Four tests covering: the invocation no longer fails, only the malformed
message is reported, valid messages still reach `scaleUp`, and malformed
and rejected messages combine correctly. All four fail against the
current implementation.

### Note on scope

This is distinct from #5129. That PR addresses the `catch` block, where
a non-`ScaleError` returns an empty `batchItemFailures` — which AWS
treats as complete success, so the batch is **deleted**. Opposite
failure mode, different path, and worth keeping separate. I originally
conflated the two in a comment on #5129 and have corrected it there.

Touches the same file as #5129, so whichever lands second will need a
trivial rebase.
Adds `docs/rate-limits-and-tuning.md` documenting:

- GitHub API primary rate limits (`core` 5,000/hr,
`actions_runner_registration` 10,000/hr)
- Secondary rate limits (900 points/min per endpoint, 100 concurrent
requests)
- Point cost table (GET=1, POST=5) with source link
- Maximum runner creation rate per App (~166–180/min) with derivation
- AWS SSM Parameter Store 40 TPS shared limit and higher-throughput mode
- EC2 CreateFleet undocumented rate limit
- Service Quotas to raise (vCPU defaults are 5)
- `batch_size` tradeoffs with concrete examples
- Monitoring recommendations

Also adds a cross-reference from `docs/configuration.md` where rate
limits are mentioned but never explained.

All numbers verified against GitHub's official docs source
(`github/docs` repo) and AWS documentation.
## Problem

When `enable_job_queued_check = true` (default), the `isJobQueued` call
has no error handling. If `getJobForWorkflowRun` throws (404, rate
limit, 502), the error propagates up through `scaleUp` and hits the
generic catch in `scaleUpHandler` — causing the batch to fail.

This is especially problematic in combination with the race condition
described in #5026: when SQS delivers messages in multiple batches due
to concurrency limits, GitHub API errors during the second batch cause
jobs to be silently dropped.

## Fix

Wrap the `isJobQueued` check in a try/catch. On any error, assume the
job is still queued (fail-open) and log a warning. The worst case is
creating a runner for a job that has already been handled — the runner
will self-terminate when no job is available.

```typescript
if (enableJobQueuedCheck) {
  let jobQueued = true;
  try {
    jobQueued = await isJobQueued(githubInstallationClient, message);
  } catch (e) {
    messageLogger.warn('isJobQueued check failed, assuming job is still queued (fail-open)', { error: e });
  }
  if (!jobQueued) {
    messageLogger.info('No runner will be created, job is not queued.');
    continue;
  }
}
```

## Changes

- `lambdas/functions/control-plane/src/scale-runners/scale-up.ts` —
try/catch around isJobQueued
- `lambdas/functions/control-plane/src/scale-runners/scale-up.test.ts` —
test: API error → runner still created

## Risk

Low — fail-open is strictly more resilient than fail-closed for job
dispatch. The extra runner (if the job was already handled)
self-terminates with no work.

Fixes #5026

---------

Co-authored-by: Ederson Brilhante <contato@edersonbrilhante.com.br>
…#5136)

## Problem

Two resilience gaps that compound under burst load:

1. **Octokit throttle plugin never retries** — `onRateLimit` and
`onSecondaryRateLimit` callbacks log a warning but don't return `true`,
so `@octokit/plugin-throttling` throws immediately instead of retrying
after the `retryAfter` delay.

2. **SSM client uses default retry** (`standard`, 3 attempts, ~3s
budget) — under burst with multiple concurrent Lambdas writing JIT
configs via PutParameter, SSM's ~40 TPS limit is easily exceeded and
`ThrottlingException` propagates up, failing the entire batch.

## Fix

### Octokit throttle callbacks return `true` with caps

```typescript
onRateLimit: (retryAfter, options) => {
  logger.warn(`...retrying after ${retryAfter}s`);
  return options.request.retryCount < 2; // retry up to 2x on primary rate limit
},
onSecondaryRateLimit: (retryAfter, options) => {
  logger.warn(`...retrying after ${retryAfter}s`);
  return options.request.retryCount < 1; // retry once on secondary/abuse limit
},
```

### SSM adaptive retry with maxAttempts=10

```typescript
const SSM_CLIENT_CONFIG = {
  region: process.env.AWS_REGION,
  maxAttempts: 10,
  retryMode: 'adaptive' as const,
};
```

`adaptive` mode adds client-side rate-sensing — when the SDK sees
ThrottlingException it slows further calls to match the observed budget.
10 attempts gives ~30s of retry budget, which is safe because runners
take ~30-50s to boot before reading their JIT config.

## Changes

- `lambdas/functions/control-plane/src/github/auth.ts` — throttle
callbacks return `true` with retry caps
- `lambdas/libs/aws-ssm-util/src/index.ts` — shared SSM client config
with adaptive retry

## Impact

| Scenario | Before | After |
|---|---|---|
| GitHub rate limit during scale-up | Request fails immediately |
Retries 1-2x with backoff |
| SSM throttle during JIT config write | ThrottlingException after ~3s |
Adaptive backoff for ~30s |
| Burst of 100 jobs, batch_size=10 | SSM throttle → orphaned instances |
Retry absorbs throttle |

Fixes #5135
Refs: #5024, #5037
Bumps [body-parser](https://github.com/expressjs/body-parser) from 2.2.1
to 2.3.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/body-parser/releases">body-parser's
releases</a>.</em></p>
<blockquote>
<h2>v2.3.0</h2>
<h2>Important: Security</h2>
<ul>
<li>Security fix for <a
href="https://www.cve.org/CVERecord?id=CVE-2025-13466">CVE-2026-12590</a>
(<a
href="https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6">GHSA-v422-hmwv-36x6</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/681">expressjs/body-parser#681</a></li>
<li>build(deps): bump actions/checkout from 5.0.0 to 6.0.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/682">expressjs/body-parser#682</a></li>
<li>build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/683">expressjs/body-parser#683</a></li>
<li>build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/685">expressjs/body-parser#685</a></li>
<li>build(deps): bump github/codeql-action from 4.31.2 to 4.31.9 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/684">expressjs/body-parser#684</a></li>
<li>perf(urlencoded): move empty-body guard to avoid extra function
closure by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/647">expressjs/body-parser#647</a></li>
<li>Improve ESM compatibility by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/697">expressjs/body-parser#697</a></li>
<li>docs: add recommendations for configuring payload limits by <a
href="https://github.com/bjohansebas"><code>@​bjohansebas</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/699">expressjs/body-parser#699</a></li>
<li>build(deps): bump actions/setup-node from 6.1.0 to 6.2.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/701">expressjs/body-parser#701</a></li>
<li>build(deps): bump github/codeql-action from 4.31.10 to 4.32.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/702">expressjs/body-parser#702</a></li>
<li>build(deps): bump actions/checkout from 6.0.1 to 6.0.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/700">expressjs/body-parser#700</a></li>
<li>chore: add explicit type commonjs to package.json by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/711">expressjs/body-parser#711</a></li>
<li>deps: update dependencies to latest versions by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/708">expressjs/body-parser#708</a></li>
<li>build(deps): bump actions/download-artifact from 7.0.0 to 8.0.0 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/712">expressjs/body-parser#712</a></li>
<li>build(deps): bump github/codeql-action from 4.32.0 to 4.32.4 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/713">expressjs/body-parser#713</a></li>
<li>build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/714">expressjs/body-parser#714</a></li>
<li>fix: improve limit option validation by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/698">expressjs/body-parser#698</a></li>
<li>build(deps): bump github/codeql-action from 4.32.4 to 4.35.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/719">expressjs/body-parser#719</a></li>
<li>build(deps): bump actions/setup-node from 6.2.0 to 6.3.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/718">expressjs/body-parser#718</a></li>
<li>build(deps): bump actions/download-artifact from 8.0.0 to 8.0.1 by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/717">expressjs/body-parser#717</a></li>
<li>perf: eliminate conditional check in json strict mode hot path by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/651">expressjs/body-parser#651</a></li>
<li>ci: add node.js 26 to text matrix by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/726">expressjs/body-parser#726</a></li>
<li>build(deps): bump actions/setup-node from 6.3.0 to 6.4.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/725">expressjs/body-parser#725</a></li>
<li>build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/724">expressjs/body-parser#724</a></li>
<li>build(deps): bump github/codeql-action from 4.35.1 to 4.35.3 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/723">expressjs/body-parser#723</a></li>
<li>Upgrade &quot;content-type&quot; by <a
href="https://github.com/blakeembrey"><code>@​blakeembrey</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/728">expressjs/body-parser#728</a></li>
<li>refactor: switch to const/let and enable eslint no-var rule by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/729">expressjs/body-parser#729</a></li>
<li>Update outdated reference to MDN docs by <a
href="https://github.com/krzysdz"><code>@​krzysdz</code></a> in <a
href="https://redirect.github.com/expressjs/body-parser/pull/730">expressjs/body-parser#730</a></li>
<li>build(deps): bump github/codeql-action from 4.35.3 to 4.36.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/731">expressjs/body-parser#731</a></li>
<li>build(deps): bump actions/checkout from 6.0.2 to 6.0.3 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/732">expressjs/body-parser#732</a></li>
<li>chore: updated deps to latest by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/733">expressjs/body-parser#733</a></li>
<li>2.3.0 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/body-parser/pull/735">expressjs/body-parser#735</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/krzysdz"><code>@​krzysdz</code></a> made
their first contribution in <a
href="https://redirect.github.com/expressjs/body-parser/pull/730">expressjs/body-parser#730</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0">https://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0</a></p>
<h2>v2.2.2</h2>
<h2>What's Changed</h2>
<ul>
<li>docs: update README links by <a
href="https://github.com/efekrskl"><code>@​efekrskl</code></a> in <a
href="https://redirect.github.com/expressjs/body-parser/pull/673">expressjs/body-parser#673</a></li>
<li>docs: release notes for the v1.20.4 release by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/674">expressjs/body-parser#674</a></li>
<li>docs: update URL-encoded parser description to include ISO-8859-1
encoding support by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/679">expressjs/body-parser#679</a></li>
<li>docs: use standard jsdoc tags everywhere by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/body-parser/pull/677">expressjs/body-parser#677</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/body-parser/blob/master/HISTORY.md">body-parser's
changelog</a>.</em></p>
<blockquote>
<h1>2.3.0 / 2026-06-15</h1>
<ul>
<li>Security fix for <a
href="https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6">GHSA-v422-hmwv-36x6</a></li>
<li>fix: use static exports instead of lazy getters to improve ESM
compatibility</li>
<li>feat: add subpath exports for individual parsers</li>
<li>fix: improve <code>limit</code> option validation (<a
href="https://redirect.github.com/expressjs/body-parser/issues/698">#698</a>)
<ul>
<li>Invalid <code>limit</code> values (e.g. unparseable strings or
<code>NaN</code>) now throw instead of being silently ignored, which
previously disabled size limit enforcement</li>
<li><code>null</code> and <code>undefined</code> fall back to the
default 100kb limit</li>
</ul>
</li>
<li>deps:
<ul>
<li>content-type@^2.0.0</li>
<li>http-errors@^2.0.1</li>
<li>iconv-lite^0.7.2</li>
<li>qs@^6.15.2</li>
<li>raw-body@^3.0.2</li>
<li>type-is@^2.1.0</li>
</ul>
</li>
</ul>
<h1>2.2.2 / 2026-01-07</h1>
<ul>
<li>deps: qs@^6.14.1</li>
<li>refactor(json): simplify strict mode error string construction</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/expressjs/body-parser/commit/d0f2ace6c74769da7d19b8661b9a01c01bdb0bf7"><code>d0f2ace</code></a>
2.3.0 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/735">#735</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/7d03f2f9d561dafd1576b137713353c95253512c"><code>7d03f2f</code></a>
chore: updated deps to latest (<a
href="https://redirect.github.com/expressjs/body-parser/issues/733">#733</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/8024ba7a813e6647ed63832d209a2abb8531267a"><code>8024ba7</code></a>
build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/732">#732</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/32b4ed4639281f04563adcd41d724ab06c9105d4"><code>32b4ed4</code></a>
build(deps): bump github/codeql-action from 4.35.3 to 4.36.1 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/731">#731</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/ff0f6b907106ec5a1b81c80f5a552d921c1bc9a5"><code>ff0f6b9</code></a>
docs: update outdated reference to MDN docs (<a
href="https://redirect.github.com/expressjs/body-parser/issues/730">#730</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/14d001a9c90abc05891d895ad3e9cf0a65b7b34a"><code>14d001a</code></a>
refactor: switch to const/let and enable eslint no-var rule (<a
href="https://redirect.github.com/expressjs/body-parser/issues/729">#729</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/37f36a27528e65d7216f2c31c7039d3458c72147"><code>37f36a2</code></a>
deps: update content-type and type-is (<a
href="https://redirect.github.com/expressjs/body-parser/issues/728">#728</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/e1c244bf55fb00a6de4be882b4ed9fc20807d864"><code>e1c244b</code></a>
build(deps): bump github/codeql-action from 4.35.1 to 4.35.3 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/723">#723</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/e01087f52192e20e2d0f8726d4f28a8d49d06c87"><code>e01087f</code></a>
build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/724">#724</a>)</li>
<li><a
href="https://github.com/expressjs/body-parser/commit/a7698d30280a3e931ea8841396e5d0ac5414e429"><code>a7698d3</code></a>
build(deps): bump actions/setup-node from 6.3.0 to 6.4.0 (<a
href="https://redirect.github.com/expressjs/body-parser/issues/725">#725</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/expressjs/body-parser/compare/v2.2.1...v2.3.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=body-parser&package-manager=npm_and_yarn&previous-version=2.2.1&new-version=2.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github-aws-runners/terraform-aws-github-runner/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.14.2 to
3.15.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md">js-yaml's
changelog</a>.</em></p>
<blockquote>
<h2>4.3.0, 3.15.0 - 2026-06-27</h2>
<h3>Security</h3>
<ul>
<li>Backported <code>maxTotalMergeKeys</code> option.</li>
</ul>
<h2>[5.2.0] - 2026-06-26</h2>
<h3>Added</h3>
<ul>
<li>Added <code>maxTotalMergeKeys</code> (10000) loader option to limit
the total number of
keys processed by YAML merge (<code>&lt;&lt;</code>) across one
<code>load()</code> / <code>loadAll()</code> call.</li>
<li>Added <code>maxAliases</code> (-1) loader option to limit the number
of YAML aliases per
document.</li>
</ul>
<h3>Removed</h3>
<ul>
<li><code>maxMergeSeqLength</code> replaced with
<code>maxTotalMergeKeys</code> for limiting YAML merge
processing.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Round-trip of integers with exponential form (&gt;=
<code>1e21</code>)</li>
</ul>
<h2>[5.1.0] - 2026-06-23</h2>
<h3>Added</h3>
<ul>
<li>Collection tags can finalize an incrementally populated carrier into
a
different result value.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>[breaking] <code>quoteStyle</code> now selects the preferred quote
style; use the
restored <code>forceQuotes</code> option to force quoting non-key
strings.</li>
</ul>
<h2>[5.0.0] - 2026-06-20</h2>
<h3>Added</h3>
<ul>
<li>Added named exports for schemas, tags, parser events and AST
utilities.</li>
<li>Reworked <code>JSON_SCHEMA</code> and <code>CORE_SCHEMA</code> with
spec-compliant scalar resolution
rules, and added <code>YAML11_SCHEMA</code>.</li>
<li>Added <code>realMapTag</code> for lossless mappings with non-string
and complex keys.
Object-based mappings now reject complex keys instead of stringifying
them.</li>
<li>Added <code>dump()</code> <code>transform</code> option for changing
the generated AST before
rendering.</li>
<li>Added <code>dump()</code> options <code>seqInlineFirst</code>,
<code>flowBracketPadding</code>,
<code>flowSkipCommaSpace</code>, <code>flowSkipColonSpace</code>,
<code>quoteFlowKeys</code>, <code>quoteStyle</code> and
<code>tagBeforeAnchor</code>.</li>
<li>Added formal data layers (events and AST) for modular data
pipelines.
<ul>
<li>Added low-level parser (to events), presenter and visitor APIs.</li>
</ul>
</li>
<li>Added the <a href="https://github.com/yaml/yaml-test-suite">YAML
Test Suite</a> to the
test set.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>See the <a
href="https://github.com/nodeca/js-yaml/blob/master/docs/migrate_v4_to_v5.md">migration
guide</a> for upgrade notes.</li>
<li>Rewritten in TypeScript and reorganized the public API around flat
named
exports.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodeca/js-yaml/commit/c34b6c40027a769eb0d67958ae615268a1d55f54"><code>c34b6c4</code></a>
3.15.0 released</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/21e13d363f33501c7ee6ca988b88c29084999f72"><code>21e13d3</code></a>
dist rebuild</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/4165c62630d64fe4f25fb0d03139c7e137b24b1c"><code>4165c62</code></a>
Add v3-legacy tag for publish</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/d8ff750b0130e4e4b4062fb0dbd32027e41d4c51"><code>d8ff750</code></a>
Add package lock</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7"><code>24f13e7</code></a>
Added <code>maxTotalMergeKeys</code> (10000) loader option (v5
backport)</li>
<li>See full diff in <a
href="https://github.com/nodeca/js-yaml/compare/3.14.2...3.15.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=js-yaml&package-manager=npm_and_yarn&previous-version=3.14.2&new-version=3.15.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github-aws-runners/terraform-aws-github-runner/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [axios](https://github.com/axios/axios) from 1.17.0 to 1.18.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/releases">axios's
releases</a>.</em></p>
<blockquote>
<h2>v1.18.0 — June 13, 2026</h2>
<p>This release hardens redirect and URL handling, improves the
validateStatus configuration semantics, and includes updates to
documentation, dependencies, and release metadata.</p>
<h2>🔒 Security Fixes</h2>
<ul>
<li>
<p><strong>Redirect Header Safety:</strong> Added Node HTTP adapter
support for stripping caller-specified sensitive headers on cross-origin
redirects, helping prevent custom auth headers such as API keys from
leaking to another origin. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10892">#10892</a></strong>)</p>
</li>
<li>
<p><strong>URL And Request Hardening:</strong> Rejects malformed
<code>http:</code> and <code>https:</code> URLs that omit
<code>//</code> with <code>ERR_INVALID_URL</code>, while tightening
prototype-pollution-safe config reads, stream size limits, FormData
depth handling, data URL sizing, and local <code>NO_PROXY</code>
matching. (<strong><a
href="https://redirect.github.com/axios/axios/issues/11000">#11000</a></strong>)</p>
</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li><strong>Status Validation:</strong> Added
<code>transitional.validateStatusUndefinedResolves</code> so
applications can opt in to treating <code>validateStatus:
undefined</code> like the option was omitted, while
<code>validateStatus: null</code> remains the explicit way to accept
every status. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10899">#10899</a></strong>)</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>
<p><strong>Documentation:</strong> Published the v1.17.0 release notes,
fixed a changelog typo, clarified the package update PR policy, and
marked the <code>proxy</code> request config as Node.js-only in the
advanced docs. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10984">#10984</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10988">#10988</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10992">#10992</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10995">#10995</a></strong>)</p>
</li>
<li>
<p><strong>Dependencies:</strong> Bumped <code>@babel/core</code>,
<code>@babel/preset-env</code>, <code>@commitlint/cli</code>,
<code>@commitlint/config-conventional</code>,
<code>@rollup/plugin-babel</code>, <code>@rollup/plugin-commonjs</code>,
<code>@vitest/browser</code>, <code>@vitest/browser-playwright</code>,
<code>eslint</code>, <code>lint-staged</code>, <code>rollup</code>,
<code>vitest</code>, and <code>actions/checkout</code>. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10989">#10989</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10996">#10996</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10997">#10997</a></strong>)</p>
</li>
<li>
<p><strong>Release Metadata:</strong> Prepared the 1.18.0 release by
updating package metadata and the runtime <code>VERSION</code> value.
(<strong><a
href="https://redirect.github.com/axios/axios/issues/11003">#11003</a></strong>)</p>
</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve axios:</p>
<ul>
<li><strong><a
href="https://github.com/drori12"><code>@​drori12</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10984">#10984</a></strong>)</li>
<li><strong><a
href="https://github.com/eyupcanakman"><code>@​eyupcanakman</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10899">#10899</a></strong>)</li>
<li><strong><a
href="https://github.com/Adi-Beker"><code>@​Adi-Beker</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10995">#10995</a></strong>)</li>
</ul>
<p><a
href="https://github.com/axios/axios/compare/v1.17.0...v1.18.0">Full
Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md">axios's
changelog</a>.</em></p>
<blockquote>
<h2>v1.18.0 — June 13, 2026</h2>
<p>This release hardens redirect and URL handling, improves the
validateStatus configuration semantics, and includes updates to
documentation, dependencies, and release metadata.</p>
<h2>🔒 Security Fixes</h2>
<ul>
<li>
<p><strong>Redirect Header Safety:</strong> Added Node HTTP adapter
support for stripping caller-specified sensitive headers on cross-origin
redirects, helping prevent custom auth headers such as API keys from
leaking to another origin. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10892">#10892</a></strong>)</p>
</li>
<li>
<p><strong>URL And Request Hardening:</strong> Rejects malformed
<code>http:</code> and <code>https:</code> URLs that omit
<code>//</code> with <code>ERR_INVALID_URL</code>, while tightening
prototype-pollution-safe config reads, stream size limits, FormData
depth handling, data URL sizing, and local <code>NO_PROXY</code>
matching. (<strong><a
href="https://redirect.github.com/axios/axios/issues/11000">#11000</a></strong>)</p>
</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li><strong>Status Validation:</strong> Added
<code>transitional.validateStatusUndefinedResolves</code> so
applications can opt in to treating <code>validateStatus:
undefined</code> like the option was omitted, while
<code>validateStatus: null</code> remains the explicit way to accept
every status. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10899">#10899</a></strong>)</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>
<p><strong>Documentation:</strong> Published the v1.17.0 release notes,
fixed a changelog typo, clarified the package update PR policy, and
marked the <code>proxy</code> request config as Node.js-only in the
advanced docs. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10984">#10984</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10988">#10988</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10992">#10992</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10995">#10995</a></strong>)</p>
</li>
<li>
<p><strong>Dependencies:</strong> Bumped <code>@babel/core</code>,
<code>@babel/preset-env</code>, <code>@commitlint/cli</code>,
<code>@commitlint/config-conventional</code>,
<code>@rollup/plugin-babel</code>, <code>@rollup/plugin-commonjs</code>,
<code>@vitest/browser</code>, <code>@vitest/browser-playwright</code>,
<code>eslint</code>, <code>lint-staged</code>, <code>rollup</code>,
<code>vitest</code>, and <code>actions/checkout</code>. (<strong><a
href="https://redirect.github.com/axios/axios/issues/10989">#10989</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10996">#10996</a></strong>,
<strong><a
href="https://redirect.github.com/axios/axios/issues/10997">#10997</a></strong>)</p>
</li>
<li>
<p><strong>Release Metadata:</strong> Prepared the 1.18.0 release by
updating package metadata and the runtime <code>VERSION</code> value.
(<strong><a
href="https://redirect.github.com/axios/axios/issues/11003">#11003</a></strong>)</p>
</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve axios:</p>
<ul>
<li><strong><a
href="https://github.com/drori12"><code>@​drori12</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10984">#10984</a></strong>)</li>
<li><strong><a
href="https://github.com/eyupcanakman"><code>@​eyupcanakman</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10899">#10899</a></strong>)</li>
<li><strong><a
href="https://github.com/Adi-Beker"><code>@​Adi-Beker</code></a></strong>
(<strong><a
href="https://redirect.github.com/axios/axios/issues/10995">#10995</a></strong>)</li>
</ul>
<p><a
href="https://github.com/axios/axios/compare/v1.17.0...v1.18.0">Full
Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/axios/axios/commit/2d06f96e8602c2db13b65a26340ee4a1bbc0b61f"><code>2d06f96</code></a>
chore(release): prepare release 1.18.0 (<a
href="https://redirect.github.com/axios/axios/issues/11003">#11003</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2"><code>32fc489</code></a>
fix: malformed http urls (<a
href="https://redirect.github.com/axios/axios/issues/11000">#11000</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/b40ce498abfa10d90b873b4fd08f520afa5d2545"><code>b40ce49</code></a>
chore(deps-dev): bump the development_dependencies group with 10 updates
(<a
href="https://redirect.github.com/axios/axios/issues/10">#10</a>...</li>
<li><a
href="https://github.com/axios/axios/commit/fe964f960ecb52c3e1155b0daf7be77541956b01"><code>fe964f9</code></a>
docs: mark proxy config as Node.js only (<a
href="https://redirect.github.com/axios/axios/issues/10995">#10995</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/5f229d2d1f018d1db3dab6bbe034dbf3f9041b99"><code>5f229d2</code></a>
chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the
github-actions ...</li>
<li><a
href="https://github.com/axios/axios/commit/fae9d4e7db6a858c407c75e607a071c533c5c4f6"><code>fae9d4e</code></a>
docs: clarify package update PR policy (<a
href="https://redirect.github.com/axios/axios/issues/10992">#10992</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/28ab2ced820e55192806c53472ab3eb0cbb68dc2"><code>28ab2ce</code></a>
chore(deps-dev): bump the development_dependencies group with 2 updates
(<a
href="https://redirect.github.com/axios/axios/issues/10989">#10989</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b"><code>a8e4f13</code></a>
fix(core): keep default validateStatus when request passes undefined (<a
href="https://redirect.github.com/axios/axios/issues/10899">#10899</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/614f4552a17de757d4171ad7c3bd38c9c1025fd8"><code>614f455</code></a>
docs: publish v1.17.0 release notes (<a
href="https://redirect.github.com/axios/axios/issues/10988">#10988</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/6bb12c191f5380fad321322fb90216ae0dc36985"><code>6bb12c1</code></a>
fix: custom auth headers not stripped on cross-origin redirects (<a
href="https://redirect.github.com/axios/axios/issues/10892">#10892</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/axios/axios/compare/v1.17.0...v1.18.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=axios&package-manager=npm_and_yarn&previous-version=1.17.0&new-version=1.18.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github-aws-runners/terraform-aws-github-runner/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Description

Treat malformed SQS message bodies as permanent, non-retryable failures.
The scale-up handler logs and acknowledges malformed records so they do
not block valid messages in the same batch or repeatedly return to the
queue.

Document the SQS event source mapping contract near `batchItemFailures`
and update the focused handler tests for the new behavior.

## Test Plan

1. Send a scale-up SQS batch containing one valid message and one
malformed JSON body.
2. Confirm the valid message is passed to `scaleUp`.
3. Confirm the malformed message is logged but omitted from
`batchItemFailures`.
4. Confirm a message rejected by `scaleUp` is still returned in
`batchItemFailures`.
5. Run `yarn vitest run functions/control-plane/src/lambda.test.ts
--config functions/control-plane/vitest.config.ts --reporter=dot`.

## Related Issues

None.
## Description

Refactors the existing EC2 runner implementation behind
provider-specific boundaries while preserving EC2 as the only
supported/default runner provider in this PR.

This prepares the codebase for future AWS runner providers without
adding MicroVM support yet:

- renames the control-plane AWS runner implementation to EC2-specific
files (`ec2-runners.ts`, `ec2-runners.d.ts`)
- adds provider interfaces and registries for scale-up, scale-down, and
pool flows
- moves EC2-specific scale-up, scale-down, pool, runner creation, and
dynamic-label logic into EC2 modules while keeping orchestration code
provider-neutral
- extracts shared GitHub runner/JIT config flow and scale-runner types
- decouples webhook dynamic-label dispatch through AWS/provider helpers
and keeps the EC2 label policy implementation behind the EC2 provider
- renames dynamic label policy configuration from
`ec2_dynamic_labels_policy` / `ec2DynamicLabelsPolicy` to
`aws_dynamic_labels_policy` / `awsDynamicLabelsPolicy`
- wires Terraform defaults so scale-up and pool payloads carry the EC2
provider type where needed, while `idle_config` remains provider-neutral
- updates configuration docs and generated module README tables
- keeps the existing test file layout to reduce review noise

## Test Plan

Replace your config to use aws_dynamic_labels_policy and run apply.
Everything should work as today

## Related Issues

N/A

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to
8.5.22.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/releases">postcss's
releases</a>.</em></p>
<blockquote>
<h2>8.5.22</h2>
<ul>
<li>Fixed custom property losing semicolon before a comment (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
</ul>
<h2>8.5.21</h2>
<ul>
<li>Fixed childless at-rule losing semicolon before comment (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed docs (by <a
href="https://github.com/isker"><code>@​isker</code></a>).</li>
</ul>
<h2>8.5.20</h2>
<ul>
<li>Fixed missing space if <code>AtRule#params</code> is set after (by
<a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed mixing AST error on warnings (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.19</h2>
<ul>
<li>Fixed cleaning <code>before</code> for new nodes inserted to
<code>Root</code> (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.18</h2>
<ul>
<li>Restricted loading previous source maps file to the
<code>opts.from</code> folder for security reasons (use <code>unsafeMap:
true</code> to disable the check).</li>
</ul>
<h2>8.5.17</h2>
<ul>
<li>Fixed <code>Maximum call stack size exceeded</code> error.</li>
<li>Fixed Prototype hijacking for <code>postcss.fromJSON()</code>.</li>
<li>Fixed <code>Input#origin()</code> for unmapped end position (by <a
href="https://github.com/chatman-media"><code>@​chatman-media</code></a>).</li>
</ul>
<h2>8.5.16</h2>
<ul>
<li>Fixed <code>Input#origin()</code> position (by <a
href="https://github.com/mizdra"><code>@​mizdra</code></a>).</li>
<li>Fixed <code>raws</code> after rehydrating a JSON AST (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed putting parent-less node in <code>nodes</code> of new node (by
<a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
<li>Fixed computing <code>offset</code> in <code>positionBy()</code> (by
<a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
<li>Fixed <code>rangeBy()</code> on <code>index: 0</code> (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md">postcss's
changelog</a>.</em></p>
<blockquote>
<h2>8.5.22</h2>
<ul>
<li>Fixed custom property losing semicolon before a comment (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
</ul>
<h2>8.5.21</h2>
<ul>
<li>Fixed childless at-rule losing semicolon before comment (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed docs (by <a
href="https://github.com/isker"><code>@​isker</code></a>).</li>
</ul>
<h2>8.5.20</h2>
<ul>
<li>Fixed missing space if <code>AtRule#params</code> is set after (by
<a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed mixing AST error on warnings (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.19</h2>
<ul>
<li>Fixed cleaning <code>before</code> for new nodes inserted to
<code>Root</code> (by <a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.18</h2>
<ul>
<li>Restricted loading previous source maps file to the
<code>opts.from</code> folder for security reasons (use <code>unsafeMap:
true</code> to disable the check).</li>
</ul>
<h2>8.5.17</h2>
<ul>
<li>Fixed <code>Maximum call stack size exceeded</code> error.</li>
<li>Fixed Prototype hijacking for <code>postcss.fromJSON()</code>.</li>
<li>Fixed <code>Input#origin()</code> for unmapped end position (by <a
href="https://github.com/chatman-media"><code>@​chatman-media</code></a>).</li>
</ul>
<h2>8.5.16</h2>
<ul>
<li>Fixed <code>Input#origin()</code> position (by <a
href="https://github.com/mizdra"><code>@​mizdra</code></a>).</li>
<li>Fixed <code>raws</code> after rehydrating a JSON AST (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
<li>Fixed putting parent-less node in <code>nodes</code> of new node (by
<a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a>).</li>
<li>Fixed computing <code>offset</code> in <code>positionBy()</code> (by
<a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
<li>Fixed <code>rangeBy()</code> on <code>index: 0</code> (by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352"><code>a3e48c4</code></a>
Release 8.5.22 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618"><code>f49d691</code></a>
Fix custom property losing its semicolon before a comment (<a
href="https://redirect.github.com/postcss/postcss/issues/2117">#2117</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e"><code>28e0daf</code></a>
Release 8.5.21 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9"><code>3d2b4e4</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/postcss/commit/d197327e82e1a7d6dd9272effa3e4bfa91fdd20e"><code>d197327</code></a>
Fix childless at-rule losing its semicolon before a comment (<a
href="https://redirect.github.com/postcss/postcss/issues/2115">#2115</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/0e360b749aa17a5a89baccf9c8e5db3c2978c21e"><code>0e360b7</code></a>
Fix mismatched JSDoc comments on Position (<a
href="https://redirect.github.com/postcss/postcss/issues/2114">#2114</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/c4ac725d5920916d35be44002b49b7f66f8b1dc8"><code>c4ac725</code></a>
Release 8.5.20 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/c30586d7863d0563e2f2707bd89461636e37f6f6"><code>c30586d</code></a>
Fix missing space when AtRule#params is set after parsing (<a
href="https://redirect.github.com/postcss/postcss/issues/2113">#2113</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/5bfc3b9e7463936fdd4898f92dd43c358bfdef62"><code>5bfc3b9</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/postcss/commit/24733fdbfe9abe4a949eb0a10e53db8c87fc9277"><code>24733fd</code></a>
Move back to latest 11 pnpm</li>
<li>Additional commits viewable in <a
href="https://github.com/postcss/postcss/compare/8.5.15...8.5.22">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for postcss since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=postcss&package-manager=npm_and_yarn&previous-version=8.5.15&new-version=8.5.22)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github-aws-runners/terraform-aws-github-runner/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Description

Refactor runner creation to return structured partial-success results
instead of throwing `ScaleError`.

- Return created instance IDs with `retryableErrorCount` and
`nonRetryableErrorCount`.
- Preserve successfully created EC2 instances when Fleet or
dedicated-host requests only partially succeed.
- Classify configured scale errors, transient AWS errors, network
failures, throttling, and server failures as retryable.
- Treat unclassified AWS errors as non-retryable.
- Propagate the result contract through EC2, pool, and scale-up
providers.
- Convert unexpected provider exceptions into retryable result counts.
- Treat GitHub runner registration failures as retryable and terminate
the affected EC2 instances.
- Retry only the corresponding number of SQS messages.
- Remove the obsolete `ScaleError` implementation and handler logic.
- Skip unsupported event types without retrying them.

## Test Plan
TBD

## Related Issues

None.
## Description

Align test-file ownership with the runner-provider module layout
introduced in #5203 and requested in #5230.

This PR only renames or relocates existing tests. Provider-neutral tests
remain beside the shared orchestration modules, while EC2-specific tests
move beside their EC2 implementations.

I plan to create following PR to reduced some duplicated tests. I didn't
change in this PR to prevent a hard review

### Test cases moved or renamed

- Renamed `control-plane/src/aws/runners.test.ts` to
`ec2-runners.test.ts`.
- Renamed `webhook/src/runners/dynamic-labels-policy.test.ts` to
`ec2-dynamic-labels-policy.test.ts`.
- Moved 19 existing `canRunJob` test declarations from
`dispatch.test.ts` to `labels.test.ts`.
- Moved four existing AWS dynamic-label test declarations from
`dispatch.test.ts` to `aws-dynamic-labels.test.ts`.
- Moved three existing EC2 dynamic-label test declarations from
`dispatch.test.ts` to `ec2-dynamic-labels.test.ts`; 18 dispatch
integration tests remain in `dispatch.test.ts`.
- Moved four existing EC2 pool-size test declarations from
`pool.test.ts` to `ec2-pool.test.ts`; 17 provider-neutral pool tests
remain in `pool.test.ts`.
- Moved 20 existing EC2 scale-down test declarations from
`scale-down.test.ts` to `ec2-scale-down.test.ts`; four provider-neutral
eviction-order tests remain in `scale-down.test.ts`.
- Moved 251 existing EC2 scale-up test declarations from
`scale-up.test.ts` to `ec2-scale-up.test.ts`; the provider-selection
test remains in `scale-up.test.ts`.

### Test cases created

None.

### Duplicated test cases merged

None.

### Test cases deleted

None. The test titles and coverage from `origin/main` are preserved.

## Test Plan

- Renamed EC2 suites: 85 tests passed.
- Webhook runner suites: 44 tests passed.
- Pool suites: 21 tests passed.
- Scale-down suites: 130 tests passed.
- Scale-up suites: 254 tests passed.
- ESLint passed for every affected test file.
- `git diff --check` passed.
- Repository pre-commit hooks passed for all five commits.

## Related Issues

Closes #5230
🤖 I have created a release *beep* *boop*
---


##
[7.10.1](v7.10.0...v7.10.1)
(2026-07-31)


### Bug Fixes

* **control-plane:** discard malformed SQS messages
([#5219](#5219))
([8ca5816](8ca5816))
* enable Octokit throttle retry and SSM adaptive retry under burst
([#5136](#5136))
([cbdd916](cbdd916)),
closes
[#5135](#5135)
* **lambda:** bump axios from 1.17.0 to 1.18.0 in /lambdas
([#5211](#5211))
([67bfdf8](67bfdf8))
* **lambda:** bump js-yaml from 3.14.2 to 3.15.0 in /lambdas
([#5212](#5212))
([facea4e](facea4e))
* **lambda:** bump postcss from 8.5.15 to 8.5.22 in /lambdas
([#5231](#5231))
([8ee045d](8ee045d))
* **lambda:** fail-open isJobQueued — assume queued on API errors
([#5130](#5130))
([8fa06ee](8fa06ee))
* **scale-up:** return partial runner creation results
([#5220](#5220))
([9045340](9045340))
* stop a malformed SQS body from poisoning the whole batch
([#5215](#5215))
([69e06b1](69e06b1))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: runners-releaser[bot] <194412594+runners-releaser[bot]@users.noreply.github.com>
…ity (#5238)

## Description

Powertools v2 Logger reads the `LOG_LEVEL` environment variable without
calling `.toUpperCase()`, and the internal `LogLevelThreshold` map only
has uppercase keys (`DEBUG`, `INFO`, `WARN`, `ERROR`). When a lowercase
value like `debug` is passed, it fails validation silently and defaults
to `INFO`.

This wraps all `LOG_LEVEL` assignments with Terraform's `upper()`
function, ensuring the Lambda always receives an uppercase value
regardless of how the Terraform variable is cased.

**Files changed (9):**
- `modules/runners/scale-up.tf`
- `modules/runners/scale-down.tf`
- `modules/runners/ssm-housekeeper.tf`
- `modules/runners/pool/main.tf`
- `modules/webhook/eventbridge/webhook.tf`
- `modules/webhook/eventbridge/dispatcher.tf`
- `modules/webhook/direct/webhook.tf`
- `modules/ami-housekeeper/main.tf`
- `modules/runner-binaries-syncer/runner-binaries-syncer.tf`

## Test Plan

- Deployed to a staging environment with `log_level = "debug"` and
verified Lambdas receive `LOG_LEVEL=DEBUG`
- Confirmed debug-level log output appears in CloudWatch after the fix
(previously defaulted to INFO silently)
- Ran `terraform validate` successfully

## Related Issues

N/A — discovered during debugging of silent log level failures after
upgrading to `@aws-lambda-powertools/logger` v2.31.0

Signed-off-by: Brend Smits <brend.smits@philips.com>
## Description

Introduce a shared runner-provider plugin framework so a provider is
enabled once and its webhook, scale-up, scale-down, pool, and
runner-resource capabilities are available through one registry facade.

- Move the EC2 provider implementation into the shared
`runner-providers` library.
- Add a single provider configuration and capability registry for
webhook and control-plane consumers.
- Add reusable scale-up, scale-down, and pool contract tests that run
for every enabled provider lane.
- Add a provider skeleton that documents the interfaces required to
implement another lane.

This reduces the number of control-plane and webhook locations that must
be changed when adding a runner provider.

## Follow-up work

Some tests still need to move to the control-plane package instead of
remaining with the EC2 plugin. The affected files contain groups of
tests, so this cleanup requires moving individual test cases rather than
relocating an entire block or file. It will be handled in a follow-up PR
to keep this refactor reviewable.

This is why some EC2 provider tests currently import from
`../../../../../../functions/control-plane`. Those dependencies should
be removed in the follow-up PR.

## Test Plan

- Ran the `runner-providers:test` Nx target.
- Ran the `control-plane:test` Nx target.
- Ran Prettier checks for the runner-provider library.
- Ran ESLint for the runner-provider library.

## Related Issues

Follow-up: #5236.
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.22 to
8.5.24.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/releases">postcss's
releases</a>.</em></p>
<blockquote>
<h2>8.5.24</h2>
<ul>
<li>Preserve the BOM after the processing (by <a
href="https://github.com/hdimer"><code>@​hdimer</code></a>).</li>
</ul>
<h2>8.5.23</h2>
<ul>
<li>Do not load source map without <code>opts.from</code> for security
reasons.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md">postcss's
changelog</a>.</em></p>
<blockquote>
<h2>8.5.24</h2>
<ul>
<li>Preserve the BOM after the processing (by <a
href="https://github.com/hdimer"><code>@​hdimer</code></a>).</li>
</ul>
<h2>8.5.23</h2>
<ul>
<li>Do not load source map without <code>opts.from</code> for security
reasons.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/postcss/postcss/commit/0ebe8ad591621ab4e48311da47a76974617571f9"><code>0ebe8ad</code></a>
Release 8.5.24 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/73218c64245be53e25d58150e0cc7e984f1d162d"><code>73218c6</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/postcss/commit/9a114f62b0deb37be859102f93b414b49385805a"><code>9a114f6</code></a>
Preserve the BOM when stringifying (<a
href="https://redirect.github.com/postcss/postcss/issues/2119">#2119</a>)</li>
<li><a
href="https://github.com/postcss/postcss/commit/90692619125cb9424f5eafd8c64bc76b2da23db1"><code>9069261</code></a>
Fix types check</li>
<li><a
href="https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd"><code>eb9e1fe</code></a>
Release 8.5.23 version</li>
<li><a
href="https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84"><code>9d19c78</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8"><code>7beca13</code></a>
Does no load source map file without opts.from</li>
<li><a
href="https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930"><code>decea51</code></a>
Typo</li>
<li><a
href="https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae"><code>c18e30d</code></a>
Update EM banner</li>
<li><a
href="https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc"><code>98a39ad</code></a>
Update EM banner</li>
<li>See full diff in <a
href="https://github.com/postcss/postcss/compare/8.5.22...8.5.24">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=postcss&package-manager=npm_and_yarn&previous-version=8.5.22&new-version=8.5.24)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/github-aws-runners/terraform-aws-github-runner/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…r actual spot interruption events (#5245)

## Problem

Since v7.10.0 (#5055), the `SpotInterruptionWarning` CloudWatch metric
is inflated by 100-350x because it's emitted for **all** instance
shutdowns — not just actual spot interruption warnings.

The `instance-termination` EventBridge rule added in #5055 sends `EC2
Instance State-change Notification` (state: `shutting-down`) events to
the same `interruptionWarning` Lambda handler. The handler emits
`SpotInterruptionWarning` unconditionally for all events passing the tag
filter, without checking the event's `detail-type`.

### Impact in production

| Period | Lambda Invocations/day | SpotInterruptionWarning Sum/day |
|--------|----------------------|-------------------------------|
| Before (normal) | 116-272 | 9-44 |
| After v7.10.0 | 54,787-93,945 | 7,672-16,446 |

## Fix

Gate metric emission on the event's `detail-type`. Only emit
`SpotInterruptionWarning` when the event is an actual `EC2 Spot Instance
Interruption Warning`. Runner deregistration still triggers for all
event types as intended by #5055.

```typescript
const isSpotInterruption = event['detail-type'] === 'EC2 Spot Instance Interruption Warning';
const metricName = isSpotInterruption && config.createSpotWarningMetric ? 'SpotInterruptionWarning' : undefined;
```

## Testing

Added a test case for `EC2 Instance State-change Notification` events
verifying:
- Metric is **not** emitted (metricName is `undefined`)
- Runner deregistration **is** still called

Fixes #5244

---------

Signed-off-by: Brend Smits <brend.smits@philips.com>
🤖 I have created a release *beep* *boop*
---


##
[7.10.2](v7.10.1...v7.10.2)
(2026-08-10)


### Bug Fixes

* **lambda:** bump postcss from 8.5.22 to 8.5.24 in /lambdas
([#5241](#5241))
([17cd322](17cd322))
* **termination-watcher:** only emit SpotInterruptionWarning metric for
actual spot interruption events
([#5245](#5245))
([7480fd5](7480fd5))
* wrap LOG_LEVEL env var with upper() for Powertools v2 compatibility
([#5238](#5238))
([2394f84](2394f84))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: runners-releaser[bot] <194412594+runners-releaser[bot]@users.noreply.github.com>
…ests (#5246)

## Description

- Move generic scale-up and scale-down orchestration tests from the EC2
provider package into the control-plane package.
- Test orchestration through the runner-provider interfaces and
registry.
- Keep EC2 resource operations and dynamic configuration coverage beside
the EC2 provider.
- Remove direct EC2 provider test imports and mocks of control-plane
modules.

Production behavior is unchanged.

## Test Plan

- `cd lambdas && yarn test` (all 8 projects passed)
- Focused control-plane suites: 226 tests passed
- Focused EC2 provider suites: 158 tests passed
- ESLint and Prettier checks passed for control-plane and
runner-providers
- Exact test-title inventory: 276 before and after, with no additions or
removals
- `git diff --check`

## Related Issues

Closes #5236

Follow-up to #5234
## Description

- Define the provider-neutral `RunnerType`, `RunnerInfo`,
`ListRunnerFilters`, and `CreateRunnerResult` contracts in
runner-provider core.
- Use one `RunnerInfo` shape across control-plane and EC2, with `id`,
`githubRunnerId`, and required `owner` and `type` fields.
- Keep EC2-specific inputs and the EC2 status-filter extension in
`runners.d.ts`.
- Consolidate control-plane type re-exports in `scale-runners/types.ts`
and remove the redundant scale-up and scale-down provider type shims.
- Update the existing tests in place without adding or removing test
cases.

### Compatibility note

This PR intentionally normalizes the exported `listEC2Runners` result
fields from `instanceId`/`runnerId` to `id`/`githubRunnerId` and removes
the legacy core type aliases. This differs from the compatibility
approach initially described in #5247 and is included explicitly for
review.

## Test Plan

- `cd lambdas && NX_DAEMON=false yarn test` (all 8 projects passed)
- Control-plane suite: 14 test files / 326 tests passed
- Runner-provider suite: 10 test files / 270 tests passed
- Focused scale-down contract, EC2 listing, and pool tests passed after
the final type tightening
- ESLint and Prettier passed for control-plane and runner-providers
- Exact test-title inventory: 276 before and after, with no additions or
removals
- `git diff --check`

Local TypeScript build validation remains blocked by the installed
`@aws-sdk/client-ec2` declarations missing exports used throughout the
existing EC2 sources; the same environment issue affects untouched code.

## Related Issues

Closes #5247

Stacked on #5246
## Description

- Rename the scale-up provider hook from `prepareGroup` to
`resolveLabelsForRunners`.
- Replace `PreparedScaleUpRunnerGroup` with `RunnerLabelResolution`,
containing the resolved `runnerLabels` and provider-specific `state`.
- Update control-plane orchestration, the EC2 provider, the provider
template, registry expectations, and existing tests in place.
- Preserve runtime behavior while making the plugin contract explicit:
message labels are resolved into runner labels and state used for runner
lookup and creation.

## Test Plan

- Control-plane suite: 14 test files / 326 tests passed
- Runner-provider suite: 10 test files / 270 tests passed
- ESLint and Prettier passed for all changed files
- Exact test-title inventory: 276 before and after, with no additions or
removals
- `git diff --check`

Local TypeScript build validation remains blocked by the installed
`@aws-sdk/client-ec2` declarations missing exports used throughout the
existing EC2 sources; the same environment issue affects untouched code.

## Related Issues

Stacked on #5248
## Description

- Rename the Lambda provider workspace, imports, exported types,
registries, templates, and contract-test helpers from runner-provider
terminology to compute-provider terminology.
- Rename `runnerProvider` to `computeProvider` and
`RUNNER_PROVIDER_TYPE` to `COMPUTE_PROVIDER_TYPE`.
- Update Terraform wiring, tests, the lockfile, and generated module
documentation.
- Preserve migration behavior: webhook configurations without
`computeProvider` and control-plane deployments without
`COMPUTE_PROVIDER_TYPE` default to EC2.
- Keep runtime behavior otherwise unchanged; EC2 remains the only
supported compute provider.

This intentionally changes the internal workspace package/import API and
the direct `modules/webhook` matcher object shape. Custom consumers of
the old package path, matcher field, or environment variable must
migrate.

This standalone draft is based on `refactor-runner-label-resolution`.

## Test Plan

- Ran `yarn install --frozen-lockfile`.
- Ran formatting and lint checks for compute-providers, webhook, and
control-plane.
- Ran the affected workspace test suites: 685 tests passed.
- Ran the focused scale-up suite after adding the EC2 migration fallback
regression: 109 tests passed.
- Built the webhook and control-plane Lambda bundles.
- Ran `terraform validate` for the webhook and runners modules.
- Ran the runners Terraform test: 1 passed, 0 failed.
- Confirmed the changed Terraform files pass formatting and tflint.
- Confirmed `modules/webhook/README.md` is current with terraform-docs
v0.20.0.
- Confirmed no stale runner-provider references remain.
- Confirmed `git diff --check`.

## Related Issues

N/A
## Description

Supersedes #5038 by @thomasnemer, whose branch lives in an org-owned
fork that maintainers cannot push to. This PR rebases that work onto
current `main` (porting it to the compute-provider architecture
introduced in #5234/#5267) and addresses the review feedback on #5038.
All of Thomas's work is preserved with co-authorship.

From the original PR:

- New `additional_github_apps` variable (optional, no breaking changes)
accepts extra GitHub Apps with `id`, `key_base64`, and optionally
`installation_id` (direct values or SSM references).
- The control-plane lambdas (scale-up, scale-down, pool, job-retry)
select one app per invocation and thread the selection through the JWT →
installation token → API call chain, spreading load across N × 15,000
req/hour rate-limit buckets.
- Installation ID resolution: pre-configured `installation_id` wins, the
primary app reuses the webhook payload's id, API lookup is the fallback.

Changes on top of #5038:

- **Ported to the compute-provider layout**: the `appIndex` selection
lives in the orchestrators (`scale-up.ts`, `pool.ts`, `scale-down.ts`)
and flows to providers via `CreateGitHubRunnerConfig.appIndex`, so
provider interfaces are unchanged.
- **Restored the 404 stale-installation fallback** ([review
feedback](#5038 (review))):
when installation auth fails with 404 (app uninstalled/reinstalled while
messages were in flight), the flow re-resolves the installation via the
API and retries once with the same app. This now also covers stale
pre-configured installation ids, and has regression tests in
`octokit.test.ts`.
- Updated env wiring for the `COMPUTE_PROVIDER_TYPE` era and regenerated
module docs.

## Test Plan

- `vitest`: control-plane 348 passed, compute-providers 270 passed,
webhook 89 passed.
- New regression tests: stale-payload 404 retry, same-id rethrow,
non-404 rethrow.
- ESLint and Prettier clean on all touched packages.
- `terraform fmt -check -recursive`, `terraform validate` (root,
runners, multi-runner, ssm), `terraform test` in `modules/runners` (1
passed).
- READMEs regenerated with terraform-docs.

## Related Issues

Closes #5037. Supersedes #5038.

Co-authored with @thomasnemer.

---------

Co-authored-by: Thomas Nemer <thomas.nemer@doctolib.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
🤖 I have created a release *beep* *boop*
---


##
[7.11.0](v7.10.2...v7.11.0)
(2026-08-14)


### Features

* **github-app:** allow several github apps to be used
([#5269](#5269))
([82cb0fd](82cb0fd))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: runners-releaser[bot] <194412594+runners-releaser[bot]@users.noreply.github.com>
Bumps [axios](https://github.com/axios/axios) from 1.18.0 to 1.18.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/releases">axios's
releases</a>.</em></p>
<blockquote>
<h2>v1.18.1 — June 21, 2026</h2>
<p>This release focuses on Node HTTP adapter fixes, safer AxiosError
serialisation, runtime/type correctness fixes, documentation updates,
and dependency maintenance.</p>
<h2>🐛 Bug Fixes</h2>
<ul>
<li>AxiosError Serialisation: Made AxiosError#cause non-enumerable to
prevent circular JSON serialisation failures when errors include nested
causes. (<a
href="https://redirect.github.com/axios/axios/issues/10913">#10913</a>)</li>
<li>Node HTTP Adapter: Guarded socket.setKeepAlive for proxy agent
streams, accepted path-only URLs when socketPath is configured, deferred
environment proxy handling to Node, and explicitly passed maxBodyLength
through to follow-redirects. (<a
href="https://redirect.github.com/axios/axios/issues/10917">#10917</a>,
<a
href="https://redirect.github.com/axios/axios/issues/10930">#10930</a>,
<a
href="https://redirect.github.com/axios/axios/issues/10942">#10942</a>,
<a
href="https://redirect.github.com/axios/axios/issues/10993">#10993</a>)</li>
<li>Runtime and Type Correctness: Fixed several runtime crashes, type
definition mismatches, and incorrect error handling paths. (<a
href="https://redirect.github.com/axios/axios/issues/10959">#10959</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11021">#11021</a>)</li>
<li>AxiosURLSearchParams: Switched the encoder callback to an arrow
function so <code>encoder.call(this)</code> receives the
<code>AxiosURLSearchParams</code> instance correctly. (<a
href="https://redirect.github.com/axios/axios/issues/11019">#11019</a>)</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>
<p>Documentation: Documented sensitive headers and status transition
behaviour, prepared cleaned-up docs, added Deno install instructions,
and clarified that request data is request-specific (<a
href="https://redirect.github.com/axios/axios/issues/11007">#11007</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11010">#11010</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11023">#11023</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11025">#11025</a>)</p>
</li>
<li>
<p>Dependencies: Bumped vite, rollup, form-data, js-yaml, and multer
across the root project, docs, smoke tests, and module test workspaces.
(<a
href="https://redirect.github.com/axios/axios/issues/11011">#11011</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11012">#11012</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11013">#11013</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11014">#11014</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11015">#11015</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11016">#11016</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11017">#11017</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11026">#11026</a>)</p>
</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve axios:</p>
<ul>
<li><a
href="https://github.com/webdevelopersrinu"><code>@​webdevelopersrinu</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/10913">#10913</a>)</li>
<li><a href="https://github.com/sijie-Z"><code>@​sijie-Z</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/10993">#10993</a>)</li>
<li><a
href="https://github.com/bartlomieju"><code>@​bartlomieju</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11023">#11023</a>)</li>
<li><a href="https://github.com/JSap0914"><code>@​JSap0914</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11019">#11019</a>)</li>
</ul>
<p><a
href="https://github.com/axios/axios/compare/v1.18.0...v1.18.1">Full
Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md">axios's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v1.19.0 — July 22, 2026</h2>
<p>This release raises the form-data security floor, adds configuration
and type-system capabilities, and fixes NO_PROXY matching, interceptor
errors, progress reporting, and serialization edge cases.</p>
<h2>🔒 Security Fixes</h2>
<ul>
<li>Multipart Form Data: Raised the form-data dependency floor to
^4.0.6, preventing fresh installations from resolving versions affected
by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a
href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>).
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
</ul>
<h2>🚀 New Features</h2>
<ul>
<li>Configuration Extensibility: Preserved own-enumerable symbol-keyed
fields through mergeConfig and added a generic params type across public
TypeScript declarations, responses, errors,
adapters, and serializers. (<a
href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11081">#11081</a>)</li>
<li>Header Parameter Parsing: Added the opt-in
AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP
parameter parsing while preserving legacy parsing behavior. (<a
href="https://redirect.github.com/axios/axios/issues/11051">#11051</a>)</li>
<li>HTTP Status Codes: Added the missing Cloudflare 520
WebServerReturnsAnUnknownError status and matching ESM/CJS declarations.
(<a
href="https://redirect.github.com/axios/axios/issues/11067">#11067</a>)</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li>
<p>Form Data Conversion: Limited formDataToJSON path splitting to dot
and bracket notation, preserving literal punctuation in keys, and
removed browser-facing Buffer.from usage from toFormData to avoid
unnecessary polyfills. (<a
href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11018">#11018</a>)</p>
</li>
<li>
<p>Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal
forms during NO_PROXY matching and honored * entries within comma- or
space-separated bypass lists. (<a
href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11053">#11053</a>)</p>
</li>
<li>
<p>Cancellation: Propagated already-aborted input signals immediately
when composing abort signals. (<a
href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</p>
</li>
<li>
<p>Header Handling: Preserved empty first values for duplicate singleton
headers and made AxiosHeaders#getSetCookie() consistently return arrays
for present values. (<a
href="https://redirect.github.com/axios/axios/issues/11036">#11036</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11037">#11037</a>)</p>
</li>
<li>
<p>URL Handling: Included normalized, safely redacted offending URLs in
malformed-protocol errors and removed repeated trailing slashes when
combining base URLs. (<a
href="https://redirect.github.com/axios/axios/issues/11008">#11008</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11038">#11038</a>)</p>
</li>
<li>
<p>Progress Events: Clamped malformed negative progress values to zero
and ensured final Node.js download progress events are delivered before
streamed responses close. (<a
href="https://redirect.github.com/axios/axios/issues/11039">#11039</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11040">#11040</a>)</p>
</li>
<li>
<p>Error and JSON Serialization: Serialized Set values as arrays in
JSON-compatible snapshots and synthesized useful AxiosError messages
from otherwise-empty AggregateError instances. (<a
href="https://redirect.github.com/axios/axios/issues/11044">#11044</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11059">#11059</a>)</p>
</li>
<li>
<p>Content-Length Enforcement: Corrected base64 data: URL size
estimation so maxContentLength is enforced consistently by the HTTP and
Fetch adapters. (<a
href="https://redirect.github.com/axios/axios/issues/11061">#11061</a>)</p>
</li>
<li>
<p>Synchronous Interceptors: Prevented requests from being dispatched
after synchronous request interceptors fail unless their paired
rejection handler resolves successfully. (<a
href="https://redirect.github.com/axios/axios/issues/11071">#11071</a>)</p>
</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>Dependencies: Updated development and test tooling, the docs
fixture's Axios version, and GitHub Actions integrations including
Checkout, Setup Node, Setup Deno, and Zizmor. (<a
href="https://redirect.github.com/axios/axios/issues/11031">#11031</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11055">#11055</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11056">#11056</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11058">#11058</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11079">#11079</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11080">#11080</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11088">#11088</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11089">#11089</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11090">#11090</a>)</li>
<li>Build Outputs: Limited sourcemap generation to published minified
bundles, removing broken map references from non-minified builds. (<a
href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li>
<li>Form Data Internals: Centralized FormData header handling and made
the Node.js adapter tolerate getHeaders() returning undefined under the
content-only policy. (<a
href="https://redirect.github.com/axios/axios/issues/11062">#11062</a>)</li>
<li>Developer Experience: Ignored common local AI-tooling directories
and fixed a constant-reassignment crash when the development sandbox
serves its root path. (<a
href="https://redirect.github.com/axios/axios/issues/11032">#11032</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11073">#11073</a>)</li>
<li>Documentation: Updated sponsor information, clarified that baseURL
is not a path-security boundary, scoped provenance claims to attested
releases, and corrected the configuration-defaults documentation. (<a
href="https://redirect.github.com/axios/axios/issues/11041">#11041</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11068">#11068</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11076">#11076</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11078">#11078</a>)</li>
<li>Publishing: Simplified v1 publishing to use the npm version bundled
with Node.js 26 and updated package metadata for the 1.19.0 release. (<a
href="https://redirect.github.com/axios/axios/issues/11083">#11083</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11095">#11095</a>)</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve Axios:</p>
<ul>
<li><a
href="https://github.com/afonsojramos"><code>@​afonsojramos</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
<li><a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>)</li>
<li><a
href="https://github.com/yassertawfik4"><code>@​yassertawfik4</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11024">#11024</a>)</li>
<li><a
href="https://github.com/AnandSundar"><code>@​AnandSundar</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>)</li>
<li><a
href="https://github.com/lin-hongkuan"><code>@​lin-hongkuan</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</li>
<li><a
href="https://github.com/Wali007-lab"><code>@​Wali007-lab</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li>
<li><a href="https://github.com/magicdawn"><code>@​magicdawn</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/axios/axios/commit/a209bfb1e5dcbce3cecbf4bd955339d006358887"><code>a209bfb</code></a>
chore(release): prepare release 1.18.1 (<a
href="https://redirect.github.com/axios/axios/issues/11027">#11027</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/fa6a55ef99235074d2c11d80a1064ef02850d598"><code>fa6a55e</code></a>
chore(deps-dev): bump multer from 2.1.1 to 2.2.0 (<a
href="https://redirect.github.com/axios/axios/issues/11026">#11026</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/40e7be8a78dd43caaeb2313cc4be3f8e714be91d"><code>40e7be8</code></a>
docs: clarifies that request data is request-specific in axios (<a
href="https://redirect.github.com/axios/axios/issues/11025">#11025</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/a446b39b19c8b570214a4158520c5ddd5b020366"><code>a446b39</code></a>
fix(AxiosURLSearchParams): use arrow function so encoder.call(this)
receives ...</li>
<li><a
href="https://github.com/axios/axios/commit/cf1306a42d97960b635c894c83658f2692e53585"><code>cf1306a</code></a>
docs: add Deno to install instructions (<a
href="https://redirect.github.com/axios/axios/issues/11023">#11023</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/b32880af48017457a1203ab2e63720902d3b71b3"><code>b32880a</code></a>
fix: incorrect use of error (<a
href="https://redirect.github.com/axios/axios/issues/11021">#11021</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/1792eda11aff8fe0f8c8a6e5ae6ff305740a6460"><code>1792eda</code></a>
fix: ensure maxBodyLength is explicitly passed to follow-redirects (<a
href="https://redirect.github.com/axios/axios/issues/10993">#10993</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/30499d6af0961ec38619792013a534d1933b08a9"><code>30499d6</code></a>
fix: various runtime crashes and type definition mismatches (<a
href="https://redirect.github.com/axios/axios/issues/10959">#10959</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/20ce9c412ebd88823d1a4a47000cb133a8f79440"><code>20ce9c4</code></a>
fix(http): defer env proxy handling to Node (<a
href="https://redirect.github.com/axios/axios/issues/10942">#10942</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/e64bcf9c5af231d6f37d8389b1e57ded314fff86"><code>e64bcf9</code></a>
chore(deps): merge branch 'v1.x' into tests/module/cjs (<a
href="https://redirect.github.com/axios/axios/issues/11014">#11014</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/axios/axios/compare/v1.18.0...v1.18.1">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.15.0 to
3.15.1.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/nodeca/js-yaml/blob/3.15.1/CHANGELOG.md">js-yaml's
changelog</a>.</em></p>
<blockquote>
<h2>3.15.1 - 2026-07-31</h2>
<h3>Security</h3>
<ul>
<li>[backport] Remove quadratic complexity from <code>!!omap</code>
duplicate key detection.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodeca/js-yaml/commit/ab85ae2c622bc6d8cdbceccafe9f9b7df80463ed"><code>ab85ae2</code></a>
3.15.1 released</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/30a5e7647a4454f7bac969bfbbe7eac9921a4279"><code>30a5e76</code></a>
dist rebuild</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/22a8071ef032117bc6249c330b240ac3aa2d3ded"><code>22a8071</code></a>
Backport quadratic complexity fix for !!omap</li>
<li>See full diff in <a
href="https://github.com/nodeca/js-yaml/compare/3.15.0...3.15.1">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to
3.1.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fastify/fast-uri/releases">fast-uri's
releases</a>.</em></p>
<blockquote>
<h2>v3.1.5</h2>
<h2>⚠️ Security Warning</h2>
<p>Fix for <a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7">https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7</a></p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5">https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5</a></p>
<h2>v3.1.4</h2>
<h2>⚠️ Security Release</h2>
<p>Fix for <a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx">https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx</a></p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4">https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4</a></p>
<h2>v3.1.3</h2>
<h2>⚠️ Security Release</h2>
<ul>
<li>Fixes: <a
href="https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6">https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3">https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/fastify/fast-uri/commit/5e179cbb4636d5f773ed21126e5bd3068e87e94e"><code>5e179cb</code></a>
Bumped v3.1.5</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/2cad02d6ed428a720499bb7a3c3d6c3d41f10f5a"><code>2cad02d</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/6aeece669e4166b2446a89f17c07a3b15dfb7ed4"><code>6aeece6</code></a>
Bumped v3.1.4</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/2d50fbabc80e4d0884fe0f6a98fe118ce6faa353"><code>2d50fba</code></a>
fix: reject literal backslash in URI authority</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/0549fe35b0d482233f3be2816439f3ec803603fa"><code>0549fe3</code></a>
Bumped v3.1.3</li>
<li><a
href="https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05"><code>2a6d357</code></a>
Merge commit from fork</li>
<li>See full diff in <a
href="https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.5">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…kflows/mkdocs in the python-deps group across 1 directory (#5226)

Bumps the python-deps group with 1 update in the
/.github/workflows/mkdocs directory:
[mkdocs-material](https://github.com/squidfunk/mkdocs-material).

Updates `mkdocs-material` from 9.7.6 to 9.7.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/squidfunk/mkdocs-material/releases">mkdocs-material's
releases</a>.</em></p>
<blockquote>
<h2>mkdocs-material-9.7.7</h2>
<blockquote>
<p>[!WARNING]</p>
<p><strong>Material for MkDocs is approaching end of life</strong></p>
<p>Material for MkDocs is scheduled to reach end of life on November 5,
2026. Until then, maintenance is limited to critical bug fixes and
security updates. After this date, the project will remain available on
PyPI and GitHub, but no further maintenance is planned except in
exceptional circumstances.</p>
<p>For users looking for a long-term, actively developed successor,
we're building <a href="https://zensical.org">Zensical</a> – a
next-generation static site generator designed for technical
documentation. If you're planning a new documentation project or
evaluating your long-term options, we invite you to take a look.</p>
<p>Organizations requiring support beyond this date are welcome to get
in touch to discuss available options.</p>
<p><a
href="https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/">Read
the full announcement on our blog</a></p>
</blockquote>
<h2>Changes</h2>
<ul>
<li>Fixed a DOM-based XSS vulnerability in search suggestions</li>
</ul>
<blockquote>
<p>Thanks to <a href="https://github.com/p"><code>@​p</code></a>- for
responsibly reporting this issue.</p>
</blockquote>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG">mkdocs-material's
changelog</a>.</em></p>
<blockquote>
<p>mkdocs-material-9.7.7 (2026-07-17)</p>
<ul>
<li>Fixed DOM-based XSS vulnerability in search suggestions</li>
</ul>
<p>mkdocs-material-9.7.6 (2026-03-19)</p>
<ul>
<li>Automatically disable MkDocs 2.0 warning for forks of MkDocs</li>
</ul>
<p>mkdocs-material-9.7.5 (2026-03-10)</p>
<ul>
<li>Limited version range of mkdocs to &lt;2</li>
<li>Updated MkDocs 2.0 incompatibility warning (clarify relation with
MkDocs)</li>
</ul>
<p>mkdocs-material-9.7.4 (2026-03-03)</p>
<ul>
<li>Hardened social cards plugin by switching to sandboxed
environment</li>
<li>Updated MkDocs 2.0 incompatibility warning</li>
</ul>
<p>mkdocs-material-9.7.3 (2026-02-24)</p>
<ul>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8567">#8567</a>:
Print MkDocs 2.0 incompatibility warning to stderr</li>
</ul>
<p>mkdocs-material-9.7.2 (2026-02-18)</p>
<ul>
<li>Opened up version ranges of optional dependencies for
forward-compatibility</li>
<li>Added warning to 'mkdocs build' about impending MkDocs 2.0
incompatibility</li>
</ul>
<p>mkdocs-material-9.7.1 (2025-12-18)</p>
<ul>
<li>Updated requests to 2.30+ to mitigate CVE in urllib</li>
<li>Fixed privacy plugin not picking up protocol-relative URLs</li>
<li>Fixed <a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8542">#8542</a>:
false positives and negatives captured in privacy plugin</li>
</ul>
<p>mkdocs-material-9.7.0 (2025-11-11)</p>
<p>⚠️ Material for MkDocs is now in maintenance mode</p>
<p>This is the last release of Material for MkDocs that will receive new
features.
Going forward, the Material for MkDocs team focuses on Zensical, a
next-gen
static site generator built from first principles. We will provide
critical
bug fixes and security updates for Material for MkDocs for 12 months at
least.</p>
<p>Read the full announcement on our blog:
<a
href="https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/">https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/</a></p>
<p>This release includes all features that were previously exclusive to
the
Insiders edition. These features are now freely available to
everyone.</p>
<p>Note on deprecated plugins: The projects and typeset plugins are
included in
this release, but must be considered deprecated. Both plugins proved</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/b3e6dd886a974aa8200759ecfd7db28c598a2894"><code>b3e6dd8</code></a>
Prepare 9.7.7 release</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25"><code>52fb6be</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/901e6335cc80b0f12e46a1e34bd85e983dd78a6e"><code>901e633</code></a>
Added <code>SECURITY.md</code> with EOL notice</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/5b36f2ac499a45905e246bc66bbee2858ef6556f"><code>5b36f2a</code></a>
Bump js-yaml from 4.1.1 to 4.2.0 (<a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8598">#8598</a>)</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/2d11e7bc92c59b86d6ac0da2e38044fb4befa6e0"><code>2d11e7b</code></a>
Bump form-data from 3.0.4 to 3.0.5 (<a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8597">#8597</a>)</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/ae05a534a8c8e1c58eb6aa55d460d309bcfce22b"><code>ae05a53</code></a>
Bump esbuild from 0.27.2 to 0.28.1 (<a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8596">#8596</a>)</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/434af93166e5b90b78bba1295ca5a140fc67d0bc"><code>434af93</code></a>
Bump shell-quote from 1.7.3 to 1.8.4 (<a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8593">#8593</a>)</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/4447cdadcbe8bc82570e9f1ae2b970f461b03b68"><code>4447cda</code></a>
Documentation (<a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8590">#8590</a>)</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/8f8d551c9c5296dfc2a5ede35047bfb491d66bc9"><code>8f8d551</code></a>
Updated copyright year (<a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8588">#8588</a>)</li>
<li><a
href="https://github.com/squidfunk/mkdocs-material/commit/08d8514d491782b4ac46673bcfdedb2f6fc85f3d"><code>08d8514</code></a>
Bump fast-uri from 3.0.3 to 3.1.2 (<a
href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8587">#8587</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/squidfunk/mkdocs-material/compare/9.7.6...9.7.7">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#5168)

Bumps
[peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request)
from 8.1.0 to 8.1.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/peter-evans/create-pull-request/releases">peter-evans/create-pull-request's
releases</a>.</em></p>
<blockquote>
<h2>Create Pull Request v8.1.1</h2>
<h2>What's Changed</h2>
<ul>
<li>build(deps-dev): bump the npm group with 2 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4305">peter-evans/create-pull-request#4305</a></li>
<li>build(deps): bump minimatch by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4311">peter-evans/create-pull-request#4311</a></li>
<li>build(deps): bump the github-actions group with 2 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4316">peter-evans/create-pull-request#4316</a></li>
<li>build(deps): bump <code>@​tootallnate/once</code> and
jest-environment-jsdom by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4323">peter-evans/create-pull-request#4323</a></li>
<li>build(deps-dev): bump undici from 6.23.0 to 6.24.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4328">peter-evans/create-pull-request#4328</a></li>
<li>build(deps-dev): bump flatted from 3.3.1 to 3.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4334">peter-evans/create-pull-request#4334</a></li>
<li>build(deps): bump picomatch by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4339">peter-evans/create-pull-request#4339</a></li>
<li>build(deps-dev): bump handlebars from 4.7.8 to 4.7.9 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4344">peter-evans/create-pull-request#4344</a></li>
<li>build(deps-dev): bump the npm group with 3 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4349">peter-evans/create-pull-request#4349</a></li>
<li>fix: retry post-creation API calls on 422 eventual consistency
errors by <a
href="https://github.com/peter-evans"><code>@​peter-evans</code></a> in
<a
href="https://redirect.github.com/peter-evans/create-pull-request/pull/4356">peter-evans/create-pull-request#4356</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/peter-evans/create-pull-request/compare/v8.1.0...v8.1.1">https://github.com/peter-evans/create-pull-request/compare/v8.1.0...v8.1.1</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/5f6978faf089d4d20b00c7766989d076bb2fc7f1"><code>5f6978f</code></a>
fix: retry post-creation API calls on 422 eventual consistency errors
(<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4356">#4356</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/d32e88dac789dcc7906e7d26f69f24116fa9c97d"><code>d32e88d</code></a>
build(deps-dev): bump the npm group with 3 updates (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4349">#4349</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/8170bccad11c0df62542c04dcaefe36d342dfd39"><code>8170bcc</code></a>
build(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4344">#4344</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/00418193b417f888dbf1d993c5c0d31d27fdc7de"><code>0041819</code></a>
build(deps): bump picomatch (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4339">#4339</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/b993918c8536b6d44706130734d5456879762b27"><code>b993918</code></a>
build(deps-dev): bump flatted from 3.3.1 to 3.4.2 (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4334">#4334</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/36d7c8468b48f9c2f8f29e260e82f10d4b90d2bd"><code>36d7c84</code></a>
build(deps-dev): bump undici from 6.23.0 to 6.24.0 (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4328">#4328</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/a45d1fb447fcaf601166e405fd4f335cde1a8aa8"><code>a45d1fb</code></a>
build(deps): bump <code>@​tootallnate/once</code> and
jest-environment-jsdom (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4323">#4323</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/3499eb61835cc0015c0b786e203d74b1e8f55e43"><code>3499eb6</code></a>
build(deps): bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4316">#4316</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/3f3b473b8c148f5a7520efb4d1f9a70eea3d9d1f"><code>3f3b473</code></a>
build(deps): bump minimatch (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4311">#4311</a>)</li>
<li><a
href="https://github.com/peter-evans/create-pull-request/commit/6699836a213cf8b28c4f0408a404a6ac79d4458a"><code>6699836</code></a>
build(deps-dev): bump the npm group with 2 updates (<a
href="https://redirect.github.com/peter-evans/create-pull-request/issues/4305">#4305</a>)</li>
<li>See full diff in <a
href="https://github.com/peter-evans/create-pull-request/compare/c0f553fe549906ede9cf27b5156039d195d2ece0...5f6978faf089d4d20b00c7766989d076bb2fc7f1">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…5272)

[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps the github group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `7.0.0` |
`7.0.1` |
| [actions/setup-node](https://github.com/actions/setup-node) | `6.4.0`
| `7.0.0` |
|
[actions/attest-build-provenance](https://github.com/actions/attest-build-provenance)
| `4.1.1` | `4.2.2` |
| [actions/stale](https://github.com/actions/stale) | `10.4.0` |
`11.0.0` |
| [actions/setup-python](https://github.com/actions/setup-python) |
`6.3.0` | `7.0.0` |


Updates `actions/checkout` from 7.0.0 to 7.0.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/releases">actions/checkout's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v7...v7.0.1">https://github.com/actions/checkout/compare/v7...v7.0.1</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v7.0.1</h2>
<ul>
<li>Skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>Trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>Escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v7.0.0</h2>
<ul>
<li>Block checking out fork PR for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v6.0.3</h2>
<ul>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<h2>v6.0.2</h2>
<ul>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<h2>v6.0.1</h2>
<ul>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
</ul>
<h2>v6.0.0</h2>
<ul>
<li>Persist creds to a separate file by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
<li>Update README to include Node.js 24 support details and requirements
by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
</ul>
<h2>v5.0.1</h2>
<ul>
<li>Port v6 cleanup to v5 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
</ul>
<h2>v5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>v4.3.1</h2>
<ul>
<li>Port v6 cleanup to v4 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
</ul>
<h2>v4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@​motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@​benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1"><code>3d3c42e</code></a>
prep v7.0.1 release (<a
href="https://redirect.github.com/actions/checkout/issues/2531">#2531</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07"><code>2880268</code></a>
escape values passed to --unset (<a
href="https://redirect.github.com/actions/checkout/issues/2530">#2530</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1"><code>12cd223</code></a>
trim only ascii whitespace for branch (<a
href="https://redirect.github.com/actions/checkout/issues/2521">#2521</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541"><code>62661c4</code></a>
skip running unsafe pr check if input is default (<a
href="https://redirect.github.com/actions/checkout/issues/2518">#2518</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f"><code>e8d4307</code></a>
Bump the minor-actions-dependencies group with 2 updates (<a
href="https://redirect.github.com/actions/checkout/issues/2499">#2499</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87"><code>631c942</code></a>
eslint 9 (<a
href="https://redirect.github.com/actions/checkout/issues/2474">#2474</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e"><code>4f1f4ae</code></a>
Bump actions/upload-artifact from 4 to 7 (<a
href="https://redirect.github.com/actions/checkout/issues/2476">#2476</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92"><code>ba09753</code></a>
Bump actions/checkout from 6 to 7 (<a
href="https://redirect.github.com/actions/checkout/issues/2488">#2488</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22"><code>b9e0990</code></a>
Bump docker/login-action from 3.3.0 to 4.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2479">#2479</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2"><code>e8cb398</code></a>
Bump docker/build-push-action from 6.5.0 to 7.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2478">#2478</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/setup-node` from 6.4.0 to 7.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-node/releases">actions/setup-node's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements:</h3>
<ul>
<li>Add cache-primary-key and cache-matched-key as outputs by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1577">actions/setup-node#1577</a></li>
<li>Migrate to ESM and upgrade dependencies by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1574">actions/setup-node#1574</a></li>
</ul>
<h3>Bug fixes:</h3>
<ul>
<li>Remove dummy NODE_AUTH_TOKEN export by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1558">actions/setup-node#1558</a></li>
<li>Only use <code>mirrorToken</code> in <code>getManifest</code> if
it's provided by <a
href="https://github.com/deiga"><code>@​deiga</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
</ul>
<h3>Documentation updates:</h3>
<ul>
<li>Add documentation for publishing to npm with Trusted Publisher
(OIDC) by <a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
<li>docs: Update restore-only cache documentation by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1550">actions/setup-node#1550</a></li>
<li>docs: Update caching recommendations to mitigate cache poisoning
risks by <a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1567">actions/setup-node#1567</a></li>
</ul>
<h3>Dependency update:</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
<li><a href="https://github.com/deiga"><code>@​deiga</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-node/compare/v6...v7.0.0">https://github.com/actions/setup-node/compare/v6...v7.0.0</a></p>
<h2>v6.5.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update <code>@​actions/cache</code> to 5.1.0 and add security
overrides for undici and fast-xml-parser by <a
href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1579">actions/setup-node#1579</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0">https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-node/commit/820762786026740c76f36085b0efc47a31fe5020"><code>8207627</code></a>
Migrate to ESM and upgrade dependencies (<a
href="https://redirect.github.com/actions/setup-node/issues/1574">#1574</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/04be95cf3511ea51ebf9f224ddfb99cc7ab87cd4"><code>04be95c</code></a>
Add cache-primary-key and cache-matched-key as outputs (<a
href="https://redirect.github.com/actions/setup-node/issues/1577">#1577</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/7c2c68d20d402ed6a201ada70a81341941093140"><code>7c2c68d</code></a>
docs: Update caching recommendations to mitigate cache poisoning risks
(<a
href="https://redirect.github.com/actions/setup-node/issues/1567">#1567</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/6a61c0375d66246de94630495909f12cf8dac84d"><code>6a61c03</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/setup-node/issues/1569">#1569</a>
from jasongin/update-actions-cache-5.1.0</li>
<li><a
href="https://github.com/actions/setup-node/commit/30eb73b41ded577900c1ebf968ef95cdf8f7434f"><code>30eb73b</code></a>
Resolve high-severity audit issues</li>
<li><a
href="https://github.com/actions/setup-node/commit/4e1a87a501d0302f99e30e2748568adcb388d09f"><code>4e1a87a</code></a>
Update dist</li>
<li><a
href="https://github.com/actions/setup-node/commit/360237f0c01778d0c17291f75c56d6feae4f7574"><code>360237f</code></a>
Strict equality</li>
<li><a
href="https://github.com/actions/setup-node/commit/4f8aac5beb2f0854bc79651567a18c67eb0b9de3"><code>4f8aac5</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied</li>
<li><a
href="https://github.com/actions/setup-node/commit/f4a67bbeca970f103397d3d2b9462cf787cd2980"><code>f4a67bb</code></a>
Only use <code>mirrorToken</code> in <code>getManifest</code> if it's
provided (<a
href="https://redirect.github.com/actions/setup-node/issues/1548">#1548</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/0355742c943ddb13ca8a6b700f824231caa91e75"><code>0355742</code></a>
Remove dummy NODE_AUTH_TOKEN export (<a
href="https://redirect.github.com/actions/setup-node/issues/1558">#1558</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e...820762786026740c76f36085b0efc47a31fe5020">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/attest-build-provenance` from 4.1.1 to 4.2.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/attest-build-provenance/releases">actions/attest-build-provenance's
releases</a>.</em></p>
<blockquote>
<h2>v4.2.2</h2>
<blockquote>
<p>[!NOTE]
As of version 4, <code>actions/attest-build-provenance</code> is simply
a wrapper on top of <a
href="https://github.com/actions/attest"><code>actions/attest</code></a>.</p>
<p>Existing applications may continue to use the
<code>attest-build-provenance</code> action, but new implementations
should use <code>actions/attest</code> instead.</p>
</blockquote>
<h2>What's Changed</h2>
<ul>
<li>Bump actions/attest from 4.2.0 to 4.2.1 in the actions-minor group
by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/attest-build-provenance/pull/862">actions/attest-build-provenance#862</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/attest-build-provenance/compare/v4.1.1...v4.2.2">https://github.com/actions/attest-build-provenance/compare/v4.1.1...v4.2.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/attest-build-provenance/commit/4d101475d8b20a2381f78447822ac1eab6504dd8"><code>4d10147</code></a>
Bump actions/attest from 4.2.0 to 4.2.1 in the actions-minor group (<a
href="https://redirect.github.com/actions/attest-build-provenance/issues/862">#862</a>)</li>
<li><a
href="https://github.com/actions/attest-build-provenance/commit/e3fe62ef559997059fe8380e7d2b4c909e2d65f4"><code>e3fe62e</code></a>
Bump the actions-minor group with 2 updates (<a
href="https://redirect.github.com/actions/attest-build-provenance/issues/860">#860</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/attest-build-provenance/compare/0f67c3f4856b2e3261c31976d6725780e5e4c373...4d101475d8b20a2381f78447822ac1eab6504dd8">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/stale` from 10.4.0 to 11.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/stale/releases">actions/stale's
releases</a>.</em></p>
<blockquote>
<h2>v11.0.0</h2>
<h2>What's Changed</h2>
<h3>Enhancement</h3>
<ul>
<li>Migrate to ESM and update dependencies by <a
href="https://github-grid.enterprise.slack.com/team/U08CVLQ4JKE"><code>@​chiranjib-swain</code></a>
in <a
href="https://redirect.github.com/actions/stale/pull/1350">actions/stale#1350</a></li>
</ul>
<h3>Dependency Update</h3>
<ul>
<li>Override brace-expansion to 5.0.8 to address 24 high-severity
dependency vulnerabilities by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/stale/pull/1351">actions/stale#1351</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/stale/compare/v10...v11.0.0">https://github.com/actions/stale/compare/v10...v11.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/stale/commit/4391f3da665fdf50b6810c1a66712fb9ba21aa93"><code>4391f3d</code></a>
Fix 24 high severity vulnerabilities by overriding brace-expansion to
5.0.8 (...</li>
<li><a
href="https://github.com/actions/stale/commit/eaf9131fae5eafd0c31a64ebe3a2e183266fec48"><code>eaf9131</code></a>
refactor: update imports to use ES module syntax and improve test
structure (...</li>
<li>See full diff in <a
href="https://github.com/actions/stale/compare/1e223db275d687790206a7acac4d1a11bd6fe629...4391f3da665fdf50b6810c1a66712fb9ba21aa93">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/setup-python` from 6.3.0 to 7.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-python/releases">actions/setup-python's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Migrate to ESM and upgrade dependencies by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-python/pull/1330">actions/setup-python#1330</a></li>
<li>Pin SHA commits and update docs with latest versions by <a
href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
in <a
href="https://redirect.github.com/actions/setup-python/pull/1338">actions/setup-python#1338</a></li>
<li>Remove the pip-install input by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-python/pull/1336">actions/setup-python#1336</a></li>
</ul>
<h3>Bug Fix</h3>
<ul>
<li>Fix to Classify stderr warning messages as warnings instead of
errors in annotations by <a
href="https://github.com/lmvysakh"><code>@​lmvysakh</code></a> in <a
href="https://redirect.github.com/actions/setup-python/pull/1335">actions/setup-python#1335</a></li>
<li>Validate and retry manifest fetch to prevent silent failures by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-python/pull/1332">actions/setup-python#1332</a></li>
</ul>
<h3>Dependency Upgrade</h3>
<ul>
<li>Bump certifi from 2020.6.20 to 2024.7.4 in
/<strong>tests</strong>/data by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/setup-python/pull/1328">actions/setup-python#1328</a></li>
<li>Remove EOL Python versions and Bumps numpy text fixture by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-python/pull/1333">actions/setup-python#1333</a></li>
<li>Upgrade <code>@​actions/cache</code> to 6.2.0 by <a
href="https://github.com/philip-gai"><code>@​philip-gai</code></a> in <a
href="https://redirect.github.com/actions/setup-python/pull/1337">actions/setup-python#1337</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/lmvysakh"><code>@​lmvysakh</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-python/pull/1335">actions/setup-python#1335</a></li>
<li><a
href="https://github.com/philip-gai"><code>@​philip-gai</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-python/pull/1337">actions/setup-python#1337</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-python/compare/v6...v7.0.0">https://github.com/actions/setup-python/compare/v6...v7.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-python/commit/5fda3b95a4ea91299a34e894583c3862153e4b97"><code>5fda3b9</code></a>
Pin SHA commits and update docs with latest versions (<a
href="https://redirect.github.com/actions/setup-python/issues/1338">#1338</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/4ab7e95f05e168b4356aebde89dd84f59c283d8e"><code>4ab7e95</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/setup-python/issues/1337">#1337</a>
from actions/philip-gai/bump-actions-cache-6-2-0</li>
<li><a
href="https://github.com/actions/setup-python/commit/0f3a009f475dbea83c0371cd85d099690fee8c5c"><code>0f3a009</code></a>
Remove the pip-install input (<a
href="https://redirect.github.com/actions/setup-python/issues/1336">#1336</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/f8cf4291c8b8e273ddd26e569454615c7315d932"><code>f8cf429</code></a>
Migrate to ESM and upgrade dependencies (<a
href="https://redirect.github.com/actions/setup-python/issues/1330">#1330</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/54baeea5b34417d10a7479663a23cca53ea209b5"><code>54baeea</code></a>
Validate and retry manifest fetch to prevent silent failures (<a
href="https://redirect.github.com/actions/setup-python/issues/1332">#1332</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/c7092773a316760f4ecfe498e4af668a4dafeac5"><code>c709277</code></a>
Annotation code fix (<a
href="https://redirect.github.com/actions/setup-python/issues/1335">#1335</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/6849080452e69b330395e8a6d23cf90f56d76a1a"><code>6849080</code></a>
remove EOL Python versions and Bumps numpy text fixture (<a
href="https://redirect.github.com/actions/setup-python/issues/1333">#1333</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/0903b469fbf4441aadfe4f4b249dc5b1fba3a73e"><code>0903b46</code></a>
Bump certifi from 2020.6.20 to 2024.7.4 in /<strong>tests</strong>/data
(<a
href="https://redirect.github.com/actions/setup-python/issues/1328">#1328</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-python/compare/ece7cb06caefa5fff74198d8649806c4678c61a1...5fda3b95a4ea91299a34e894583c3862153e4b97">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.