Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 22, 2025

Note

Mend has cancelled the proposed renaming of the Renovate GitHub app being renamed to mend[bot].

This notice will be removed on 2025-10-07.


This PR contains the following updates:

Package Type Update Change Age Confidence
actions/cache action digest 0400d5f -> 0057852
actions/stale action digest 3a9db7e -> 5f858e3
aws (source) required_provider minor 6.13.0 -> 6.15.0 age confidence
boto3 patch == 1.40.30 -> ==1.40.45 age confidence
botocore patch == 1.40.30 -> ==1.40.46 age confidence
checkmarx/kics container patch v2.1.13-debian -> v2.1.14-debian age confidence
github/codeql-action action patch v3.30.3 -> v3.30.6 age confidence
oxsecurity/megalinter action major v8.8.0 -> v9.0.1 age confidence
terraform-linters/setup-tflint action major v5 -> v6 age confidence
terraform-linters/tflint-ruleset-aws plugin minor 0.42.0 -> 0.43.0 age confidence

Release Notes

hashicorp/terraform-provider-aws (aws)

v6.15.0

Compare Source

BREAKING CHANGES:

  • resource/aws_ecs_service: Fix behavior when updating capacity_provider_strategy to avoid ECS service recreation after recent AWS changes (#​43533)

FEATURES:

  • New Action: aws_codebuild_start_build (#​44444)
  • New Action: aws_events_put_events (#​44487)
  • New Action: aws_sfn_start_execution (#​44464)
  • New Data Source: aws_appconfig_application (#​44168)
  • New Data Source: aws_odb_db_node (#​43792)
  • New Data Source: aws_odb_db_nodes (#​43792)
  • New Data Source: aws_odb_db_server (#​43792)
  • New Data Source: aws_odb_db_servers (#​43792)
  • New Data Source: aws_odb_db_system_shapes (#​43825)
  • New Data Source: aws_odb_gi_versions (#​43825)
  • New Resource: aws_lakeformation_lf_tag_expression (#​43883)

ENHANCEMENTS:

  • data-source/aws_dms_endpoint: Add mysql_settings attribute (#​44516)
  • data-source/aws_ec2_instance_type_offering: Add location attribute (#​44328)
  • data-source/aws_rds_proxy: Add default_auth_scheme attribute (#​44309)
  • resource/aws_cleanrooms_configured_table: Add resource identity support (#​44435)
  • resource/aws_cloudfront_distribution: Add ip_address_type argument to origin.custom_origin_config block (#​44463)
  • resource/aws_connect_instance: Add resource identity support (#​44346)
  • resource/aws_connect_phone_number: Add resource identity support (#​44365)
  • resource/aws_dms_endpoint: Add mysql_settings configuration block (#​44516)
  • resource/aws_dsql_cluster: Adds attribute force_destroy. (#​44406)
  • resource/aws_ebs_volume: Update throughput maximum validation from 1000 to 2000 MiB/s for gp3 volumes (#​44514)
  • resource/aws_ecs_capacity_provider: Add cluster and managed_instances_provider arguments (#​44509)
  • resource/aws_ecs_capacity_provider: Make auto_scaling_group_provider optional (#​44509)
  • resource/aws_iam_service_specific_credential: Add support for Bedrock API keys with credential_age_days, service_credential_alias, service_credential_secret, create_date, and expiration_date attributes (#​44299)
  • resource/aws_networkfirewall_logging_configuration: Add enable_monitoring_dashboard argument (#​44515)
  • resource/aws_opensearch_domain: Add aiml_options argument (#​44417)
  • resource/aws_pinpointsmsvoicev2_phone_number: Update two_way_channel_arn argument to accept connect.[region].amazonaws.com in addition to ARNs (#​44372)
  • resource/aws_rds_proxy: Add default_auth_scheme argument (#​44309)
  • resource/aws_rds_proxy: Make auth configuration block optional (#​44309)
  • resource/aws_route53recoverycontrolconfig_cluster: Add network_type argument (#​44377)
  • resource/aws_route53recoverycontrolconfig_cluster: Add tagging support (#​44473)
  • resource/aws_route53recoverycontrolconfig_control_panel: Add tagging support (#​44473)
  • resource/aws_route53recoverycontrolconfig_safety_rule: Add tagging support (#​44473)
  • resource/aws_s3control_bucket: Add resource identity support (#​44379)
  • resource/aws_sfn_activity: Add arn argument (#​44408)
  • resource/aws_sfn_activity: Add resource identity support (#​44408)
  • resource/aws_sfn_alias: Add resource identity support (#​44408)
  • resource/aws_ssmcontacts_contact_channel: Add resource identity support (#​44369)

BUG FIXES:

  • data-source/aws_lb: Fix Invalid address to set: []string{"secondary_ips_auto_assigned_per_subnet"} errors (#​44485)
  • data-source/aws_networkfirewall_firewall_policy: Fix failure to retrieve multiple firewall_policy.stateful_rule_group_reference attributes (#​44482)
  • data-source/aws_servicequotas_service_quota: Fixed a panic that occurred when a non-existing quota_name was provided (#​44449)
  • resource/aws_bedrock_provisioned_model_throughput: Fix AttributeName("arn") still remains in the path: could not find attribute or block "arn" in schema errors when upgrading from a pre-v6.0.0 provider version (#​44434)
  • resource/aws_chatbot_slack_channel_configuration: Force resource replacement when configuration_name is modified (#​43996)
  • resource/aws_cloudwatch_event_rule: Do not retry on LimitExceededException (#​44489)
  • resource/aws_cloudwatch_log_resource_policy: Do not retry on LimitExceededException (#​44522)
  • resource/aws_default_vpc: Correctly set ipv6_cidr_block when the VPC has multiple associated IPv6 CIDRs (#​44362)
  • resource/aws_dms_endpoint: Ensure that postgres_settings are updated (#​44389)
  • resource/aws_dsql_cluster: Prevents error when optional attribute deletion_protection_enabled not set. (#​44406)
  • resource/aws_eks_cluster: Change compute_config, kubernetes_network_config.elastic_load_balancing, and storage_config. to Optional and Computed, allowing EKS Auto Mode settings to be enabled, disabled, and removed from configuration (#​44334)
  • resource/aws_elastic_beanstalk_configuration_template: Fix inconsistent final plan error in some cases with setting elements. (#​44461)
  • resource/aws_elastic_beanstalk_environment: Fix inconsistent final plan error in some cases with setting elements. (#​44461)
  • resource/aws_elasticache_cluster: Fix provider produced unexpected value for cache_usage_limits argument. (#​43841)
  • resource/aws_fsx_lustre_file_system: Fixed to update metadata_configuration first to allow simultaneous increase of metadata_configuration.iops and storage_capacity (#​44456)
  • resource/aws_instance: Fix interface conversion: interface {} is nil, not map[string]interface {} panics when capacity_reservation_target is empty (#​44459)
  • resource/aws_kinesisanalyticsv2_application: Ensure that configured application_configuration.run_configuration values are respected during update (#​43490)
  • resource/aws_odb_cloud_autonomous_vm_cluster : Fixed planmodifier for computed attribute. (#​44401)
  • resource/aws_odb_cloud_vm_cluster : Fixed planmodifier for computed attribute. Fixed planmodifier from display_name attribute. (#​44401)
  • resource/aws_odb_cloud_vm_cluster : Fixed planmodifier for data_storage_size_in_tbs. Marked it mandatory. Fixed gi-version issue during creation (#​44498)
  • resource/aws_odb_network_peering_connection : Fixed planmodifier for computed attribute. (#​44401)
  • resource/aws_rds_cluster: Fixes error when setting database_insights_mode with global_cluster_identifier. (#​44404)
  • resource/aws_route53_health_check: Fix child_health_threshold to properly accept explicitly specified zero value (#​44006)
  • resource/aws_s3_bucket_lifecycle_configuration: Allows unsetting noncurrent_version_expiration.newer_noncurrent_versions and noncurrent_version_transition.newer_noncurrent_versions. (#​44442)
  • resource/aws_s3_bucket_lifecycle_configuration: Do not warn if no filter element is set (#​43590)
  • resource/aws_vpc: Correctly set ipv6_cidr_block when the VPC has multiple associated IPv6 CIDRs (#​44362)

v6.14.1

Compare Source

NOTES:

  • provider: This release contains both internal provider fixes and a Terraform Plugin SDK V2 update related to a regression which may impact resources that support resource identity (#​44375)

BUG FIXES:

  • provider: Fix Missing Resource Identity After Update errors for non-refreshed and failed updates (#​44375)
  • provider: Fix Unexpected Identity Change errors when fully-null identity values in state are updated to valid values (#​44375)

v6.14.0

Compare Source

FEATURES:

  • New Action: aws_cloudfront_create_invalidation (#​43955)
  • New Action: aws_ec2_stop_instance (#​43700)
  • New Action: aws_lambda_invoke (#​43972)
  • New Action: aws_ses_send_email (#​44214)
  • New Action: aws_sns_publish (#​44232)
  • New Data Source: aws_billing_views (#​44272)
  • New Data Source: aws_odb_cloud_autonomous_vm_cluster (#​43809)
  • New Data Source: aws_odb_cloud_exadata_infrastructure (#​43650)
  • New Data Source: aws_odb_cloud_vm_cluster (#​43790)
  • New Data Source: aws_odb_network (#​43715)
  • New Data Source: aws_odb_network_peering_connection (#​43757)
  • New Resource: aws_controltower_baseline (#​42397)
  • New Resource: aws_odb_cloud_autonomous_vm_cluster (#​43809)
  • New Resource: aws_odb_cloud_exadata_infrastructure (#​43650)
  • New Resource: aws_odb_cloud_vm_cluster (#​43790)
  • New Resource: aws_odb_network (#​43715)
  • New Resource: aws_odb_network_peering_connection (#​43757)

ENHANCEMENTS:

  • resource/aws_batch_job_queue: Adds List support (#​43960)
  • resource/aws_cloudwatch_log_group: Adds List support (#​44129)
  • resource/aws_ecs_service: Add deployment_configuration.lifecycle_hook.hook_details argument (#​44289)
  • resource/aws_iam_role: Adds List support (#​44129)
  • resource/aws_instance: Adds List support (#​44129)
  • resource/aws_rds_global_cluster: Remove provider-side conflict between source_db_cluster_identifier and engine arguments (#​44252)
  • resource/aws_scheduler_schedule: Add action_after_completion argument (#​44264)
  • resource/aws_sfn_state_machine: Add resource identity support (#​44286)

BUG FIXES:

  • resource/aws_elasticache_user_group: Ignore InvalidParameterValue: User xxx is not a member of user group xxx errors during group modification (#​43520)
  • resource/aws_sagemaker_endpoint_configuration: Fix panic when empty async_inference_config.output_config.notification_config block is specified (#​44310)
boto/boto3 (boto3)

v1.40.45

Compare Source

=======

  • api-change:cleanrooms: [botocore] Added support for reading data sources across regions, and results delivery to allowedlisted regions.
  • api-change:medialive: [botocore] AWS Elemental MediaLive enables Mediapackage V2 users to configure ID3, KLV, Nielsen ID3, and Segment Length related parameters through the Mediapackage output group.
  • api-change:payment-cryptography-data: [botocore] Added a new API - translateKeyMaterial; allows keys wrapped by ECDH derived keys to be rewrapped under a static AES keyblock without first importing the key into the service.
  • api-change:qconnect: [botocore] Updated Amazon Q in Connect APIs to support Email Contact Recommendations.

v1.40.44

Compare Source

=======

  • api-change:cloudformation: [botocore] Add new warning type 'EXCLUDED_RESOURCES'
  • api-change:connectcases: [botocore] New Search All Related Items API enables searching related items across cases
  • api-change:dynamodb: [botocore] Add support for dual-stack account endpoint generation
  • api-change:endpoint-rules: [botocore] Update endpoint-rules client to latest version
  • api-change:guardduty: [botocore] Updated descriptions for the Location parameter in CreateTrustedEntitySet and CreateThreatEntitySet.
  • api-change:synthetics: [botocore] Adds support to configure canaries with pre-configured blueprint code on supported runtime versions. This behavior can be controlled via the new BlueprintTypes property exposed in the CreateCanary and UpdateCanary APIs.

v1.40.43

Compare Source

=======

  • api-change:chime-sdk-meetings: [botocore] Add support to receive dual stack MediaPlacement URLs in Chime Meetings SDK
  • api-change:cleanrooms: [botocore] This release introduces data access budgets to control how many times a table can be used for queries and jobs in a collaboration.
  • api-change:cleanroomsml: [botocore] This release introduces data access budgets to view how many times an input channel can be used for ML jobs in a collaboration.
  • api-change:dms: [botocore] This is a doc-only update, revising text for kms-key-arns.
  • api-change:ecs: [botocore] This is a documentation only Amazon ECS release that adds additional information for health checks.
  • api-change:pcs: [botocore] Added the UpdateCluster API action to modify cluster configurations, and Slurm custom settings for queues.

v1.40.42

Compare Source

=======

  • api-change:application-signals: [botocore] Amazon CloudWatch Application Signals is introducing the Application Map to give users a more comprehensive view of their service health. Users will now be able to group services, track their latest deployments, and view automated audit findings concerning service performance.
  • api-change:bedrock-agentcore-control: [botocore] Tagging support for AgentCore Gateway
  • api-change:chime-sdk-voice: [botocore] Added support for IPv4-only and dual-stack network configurations for VoiceConnector and CreateVoiceConnector API.
  • api-change:connectcases: [botocore] This release adds support for two new related item types: ConnectCase for linking Amazon Connect cases and Custom for user-defined related items with configurable fields.
  • api-change:customer-profiles: [botocore] This release introduces ListProfileHistoryRecords and GetProfileHistoryRecord APIs for comprehensive profile history tracking with complete audit trails of creation, updates, merges, deletions, and data ingestion events.
  • api-change:datasync: [botocore] Added support for FIPS VPC endpoints in FIPS-enabled AWS Regions.
  • api-change:datazone: [botocore] This release adds support for creation of EMR on EKS Connections in Amazon DataZone.
  • api-change:ds: [botocore] AWS Directory service now supports IPv6-native and dual-stack configurations for AWS Managed Microsoft AD, AD Connector, and Simple AD (dual-stack only). Additionally, AWS Managed Microsoft AD Standard Edition directories can be upgraded to Enterprise Edition directories through a single API call.
  • api-change:ecs: [botocore] This release adds support for Managed Instances on Amazon ECS.
  • api-change:fsx: [botocore] Add Dual-Stack support for Amazon FSx for NetApp ONTAP and Windows File Server
  • api-change:mediatailor: [botocore] Adding TPS Traffic Shaping to Prefetch Schedules
  • api-change:quicksight: [botocore] added warnings to a few CLI pages
  • api-change:rds: [botocore] Enhanced RDS error handling: Added DBProxyEndpointNotFoundFault, DBShardGroupNotFoundFault, KMSKeyNotAccessibleFault for snapshots/restores/backups, NetworkTypeNotSupported, StorageTypeNotSupportedFault for restores, and granular state validation faults. Changed DBInstanceNotReadyFault to HTTP 400.
  • api-change:transfer: [botocore] Add support for updating server identity provider type

v1.40.41

Compare Source

=======

  • api-change:bedrock: [botocore] Release for fixing GetFoundationModel API behavior. Imported and custom models have their own exclusive API and GetFM should not accept those ARNS as input
  • api-change:bedrock-runtime: [botocore] New stop reason for Converse and ConverseStream
  • api-change:imagebuilder: [botocore] This release introduces several new features and improvements to enhance pipeline management, logging, and resource configuration.
  • api-change:vpc-lattice: [botocore] Adds support for specifying the number of IPv4 addresses in each ENI for the resource gateway for VPC Lattice.

v1.40.40

Compare Source

=======

  • api-change:bedrock-agent-runtime: [botocore] This release enhances the information provided through Flow Traces. New information includes source/next node tracking, execution chains for complex nodes, dependency action (operation) details, and dependency traces.
  • api-change:bedrock-data-automation: [botocore] Added support for configurable Speaker Labeling and Channel Labeling features for Audio modality.
  • api-change:billing: [botocore] Add ability to combine custom billing views to create new consolidated views.
  • api-change:ce: [botocore] Support for payer account dimension and billing view health status.
  • api-change:connect: [botocore] Adds supports for manual contact picking (WorkList) operations on Routing Profiles, Agent Management and SearchContacts APIs.
  • api-change:dynamodbstreams: [botocore] Added support for IPv6 compatible endpoints for DynamoDB Streams.
  • api-change:ec2: [botocore] This release includes documentation updates for Amazon EBS General Purpose SSD (gp3) volumes with larger size and higher IOPS and throughput.
  • api-change:endpoint-rules: [botocore] Update endpoint-rules client to latest version
  • api-change:redshift: [botocore] Support tagging and tag propagation to IAM Identity Center for Redshift Idc Applications

v1.40.39

Compare Source

=======

  • api-change:glue: [botocore] Update GetConnection(s) API to return KmsKeyArn & Add 63 missing connection types
  • api-change:lightsail: [botocore] Attribute HTTP binding update for Get/Delete operations
  • api-change:network-firewall: [botocore] Network Firewall now introduces Reject and Alert action support for stateful domain list rule groups, providing customers with more granular control over their network traffic.

v1.40.38

Compare Source

=======

  • api-change:appstream: [botocore] G6f instance support for AppStream 2.0
  • api-change:cloudwatch: [botocore] Fix default dualstack FIPS endpoints in AWS GovCloud(US) regions
  • api-change:dax: [botocore] This release adds support for IPv6-only, DUAL_STACK DAX instances
  • api-change:endpoint-rules: [botocore] Update endpoint-rules client to latest version
  • api-change:kms: [botocore] Documentation only updates for KMS.
  • api-change:neptune: [botocore] Doc-only update to address customer use.

v1.40.37

Compare Source

=======

  • api-change:cleanrooms: [botocore] Added support for running incremental ID mapping for rule-based workflows.
  • api-change:ec2: [botocore] Add Amazon EC2 R8gn instance types
  • api-change:entityresolution: [botocore] Support incremental id mapping workflow for AWS Entity Resolution
  • api-change:ssm: [botocore] Added Dualstack support to GetDeployablePatchSnapshotForInstance
  • api-change:sso-admin: [botocore] Add support for encryption at rest with Customer Managed KMS Key in AWS IAM Identity Center
  • api-change:sso-oidc: [botocore] This release includes exception definition and documentation updates.

v1.40.36

Compare Source

=======

  • api-change:batch: [botocore] Starting in JAN 2026, AWS Batch will change the default AMI for new Amazon ECS compute environments from Amazon Linux 2 to Amazon Linux 2023. We recommend migrating AWS Batch Amazon ECS compute environments to Amazon Linux 2023 to maintain optimal performance and security.
  • api-change:eks: [botocore] Adds support for RepairConfig overrides and configurations in EKS Managed Node Groups.
  • api-change:imagebuilder: [botocore] Version ARNs are no longer required for the EC2 Image Builder list-image-build-version, list-component-build-version, and list-workflow-build-version APIs. Calling these APIs without the ARN returns all build versions for the given resource type in the requesting account.

v1.40.35

Compare Source

=======

  • api-change:bedrock-agentcore-control: [botocore] Add tagging and VPC support to AgentCore Runtime, Code Interpreter, and Browser resources. Add support for configuring request headers in Runtime. Fix AgentCore Runtime shape names.
  • api-change:config: [botocore] Add UNKNOWN state to RemediationExecutionState and add IN_PROGRESS/EXITED/UNKNOWN states to RemediationExecutionStepState.
  • api-change:connect: [botocore] This release adds a persistent connection field to UserPhoneConfig that maintains agent's softphone media connection for faster call connections.
  • api-change:kendra-ranking: [botocore] Model whitespace change - no client difference
  • api-change:license-manager-user-subscriptions: [botocore] Added support for cross-account Active Directories.
  • api-change:medialive: [botocore] Add MinBitrate for QVBR mode under H264/H265/AV1 output codec. Add GopBReference, GopNumBFrames, SubGopLength fields under H265 output codec.
  • api-change:sms-voice: [botocore] Updated the sms-voice client to the latest version. Note: this client is maintained only for backwards compatibility and should not be used for new development. We recommend using the pinpoint-sms-voice client for full support and ongoing updates.
  • api-change:sqs: [botocore] Update invalid character handling documentation for SQS SendMessage API

v1.40.34

Compare Source

=======

  • api-change:bedrock: [botocore] Release includes an increase to the maximum policy build document size, an update to DeleteAutomatedReasoningPolicyBuildWorkflow to add ResourceInUseException, and corrections to UpdateAutomatedReasoningPolicyTestCaseRequest.
  • api-change:budgets: [botocore] Added BillingViewHealthStatus Exception which is thrown when a Budget is created or updated with a Billing View that is not in the HEALTHY status
  • api-change:chime-sdk-messaging: [botocore] Amazon Chime SDK Messaging GetMessagingSessionEndpoint API now returns dual-stack WebSocket endpoints supporting IPv4/IPv6.
  • api-change:ec2: [botocore] Allowed AMIs adds support for four new parameters - marketplaceProductCodes, deprecationTimeCondition, creationDateCondition and imageNames

v1.40.33

Compare Source

=======

  • api-change:ec2: [botocore] Add mac-m4.metal and mac-m4pro.metal instance types.
  • api-change:network-firewall: [botocore] Network Firewall now prevents TLS handshakes with the target server until after the Server Name Indication (SNI) has been seen and verified. The monitoring dashboard now provides deeper insights into PrivateLink endpoint candidates and offers filters based on IP addresses and protocol.
  • api-change:pcs: [botocore] Add support for Amazon EC2 Capacity Blocks for ML

v1.40.32

Compare Source

=======

  • api-change:budgets: [botocore] Add support for custom time periods in budget configuration
  • api-change:ivs-realtime: [botocore] IVS now offers customers the ability to control the positioning of participants in both grid and PiP layouts based on custom attribute values in participant tokens.
  • api-change:logs: [botocore] Cloudwatch Logs added support for 2 new API parameters in metric and subscription filter APIs to filter log events based on system field values and emit system field values as dimensions and send them to customer destination as additional metadata.
  • api-change:osis: [botocore] Adds support for cross-account ingestion for push-based sources. This includes resource policies for sharing pipelines across accounts and features for managing pipeline endpoints which enable accessing pipelines across different VPCs, including VPCs in other accounts.

v1.40.31

Compare Source

=======

  • api-change:ce: [botocore] Added endpoint support for eusc-de-east-1 region.
  • api-change:medical-imaging: [botocore] Added support for OpenID Connect (OIDC) custom authorizer
  • api-change:observabilityadmin: [botocore] CloudWatch Observability Admin adds the ability to enable telemetry centralization in customers' Organizations. The release introduces new APIs to manage centralization rules, which define settings to replicate telemetry data to a central destination in the customers' Organization.
  • api-change:s3control: [botocore] Introduce three new encryption filters: EncryptionType (SSE-S3, SSE-KMS, DSSE-KMS, SSE-C, NOT-SSE), KmsKeyArn (for SSE-KMS and DSSE-KMS), and BucketKeyEnabled (for SSE-KMS).
  • api-change:sms: [botocore] The sms client has been removed following the deprecation of the service.
boto/botocore (botocore)

v1.40.46

Compare Source

=======

  • api-change:backup: Adds optional MaxScheduledRunsPreview input to GetBackupPlan API to provide a preview of up to 10 next scheduled backup plan runs in the GetBackupPlan response.
  • api-change:bedrock-agentcore: Add support for batch memory management, agent card retrieval and session termination
  • api-change:bedrock-agentcore-control: Add support for VM lifecycle configuration parameters and A2A protocol
  • api-change:glue: Adds labeling for DataQualityRuleResult for GetDataQualityResult and PublishDataQualityResult APIs
  • api-change:mediaconnect: Enabling Tag-on-Create for AWS Elemental MediaConnect flow-based resource types
  • api-change:memorydb: Support for DescribeMultiRegionParameterGroups and DescribeMultiRegionParameters API.
  • api-change:quicksight: Documentation improvements for QuickSight API documentation to clarify that delete operation APIs are global.
  • api-change:rds: Documentation updates to the CreateDBClusterMessage$PubliclyAccessible and CreateDBInstanceMessage$PubliclyAccessible properties.
  • api-change:resource-explorer-2: Add new AWS Resource Explorer APIs

v1.40.45

Compare Source

=======

  • api-change:cleanrooms: Added support for reading data sources across regions, and results delivery to allowedlisted regions.
  • api-change:medialive: AWS Elemental MediaLive enables Mediapackage V2 users to configure ID3, KLV, Nielsen ID3, and Segment Length related parameters through the Mediapackage output group.
  • api-change:payment-cryptography-data: Added a new API - translateKeyMaterial; allows keys wrapped by ECDH derived keys to be rewrapped under a static AES keyblock without first importing the key into the service.
  • api-change:qconnect: Updated Amazon Q in Connect APIs to support Email Contact Recommendations.

v1.40.44

Compare Source

=======

  • api-change:cloudformation: Add new warning type 'EXCLUDED_RESOURCES'
  • api-change:connectcases: New Search All Related Items API enables searching related items across cases
  • api-change:dynamodb: Add support for dual-stack account endpoint generation
  • api-change:endpoint-rules: Update endpoint-rules client to latest version
  • api-change:guardduty: Updated descriptions for the Location parameter in CreateTrustedEntitySet and CreateThreatEntitySet.
  • api-change:synthetics: Adds support to configure canaries with pre-configured blueprint code on supported runtime versions. This behavior can be controlled via the new BlueprintTypes property exposed in the CreateCanary and UpdateCanary APIs.

v1.40.43

Compare Source

=======

  • api-change:chime-sdk-meetings: Add support to receive dual stack MediaPlacement URLs in Chime Meetings SDK
  • api-change:cleanrooms: This release introduces data access budgets to control how many times a table can be used for queries and jobs in a collaboration.
  • api-change:cleanroomsml: This release introduces data access budgets to view how many times an input channel can be used for ML jobs in a collaboration.
  • api-change:dms: This is a doc-only update, revising text for kms-key-arns.
  • api-change:ecs: This is a documentation only Amazon ECS release that adds additional information for health checks.
  • api-change:pcs: Added the UpdateCluster API action to modify cluster configurations, and Slurm custom settings for queues.

v1.40.42

Compare Source

=======

  • api-change:application-signals: Amazon CloudWatch Application Signals is introducing the Application Map to give users a more comprehensive view of their service health. Users will now be able to group services, track their latest deployments, and view automated audit findings concerning service performance.
  • api-change:bedrock-agentcore-control: Tagging support for AgentCore Gateway
  • api-change:chime-sdk-voice: Added support for IPv4-only and dual-stack network configurations for VoiceConnector and CreateVoiceConnector API.
  • api-change:connectcases: This release adds support for two new related item types: ConnectCase for linking Amazon Connect cases and Custom for user-defined related items with configurable fields.
  • api-change:customer-profiles: This release introduces ListProfileHistoryRecords and GetProfileHistoryRecord APIs for comprehensive profile history tracking with complete audit trails of creation, updates, merges, deletions, and data ingestion events.
  • api-change:datasync: Added support for FIPS VPC endpoints in FIPS-enabled AWS Regions.
  • api-change:datazone: This release adds support for creation of EMR on EKS Connections in Amazon DataZone.
  • api-change:ds: AWS Directory service now supports IPv6-native and dual-stack configurations for AWS Managed Microsoft AD, AD Connector, and Simple AD (dual-stack only). Additionally, AWS Managed Microsoft AD Standard Edition directories can be upgraded to Enterprise Edition directories through a single API call.
  • api-change:ecs: This release adds support for Managed Instances on Amazon ECS.
  • api-change:fsx: Add Dual-Stack support for Amazon FSx for NetApp ONTAP and Windows File Server
  • api-change:mediatailor: Adding TPS Traffic Shaping to Prefetch Schedules
  • api-change:quicksight: added warnings to a few CLI pages
  • api-change:rds: Enhanced RDS error handling: Added DBProxyEndpointNotFoundFault, DBShardGroupNotFoundFault, KMSKeyNotAccessibleFault for snapshots/restores/backups, NetworkTypeNotSupported, StorageTypeNotSupportedFault for restores, and granular state validation faults. Changed DBInstanceNotReadyFault to HTTP 400.
  • api-change:transfer: Add support for updating server identity provider type

v1.40.41

Compare Source

=======

  • api-change:bedrock: Release for fixing GetFoundationModel API behavior. Imported and custom models have their own exclusive API and GetFM should not accept those ARNS as input
  • api-change:bedrock-runtime: New stop reason for Converse and ConverseStream
  • api-change:imagebuilder: This release introduces several new features and improvements to enhance pipeline management, logging, and resource configuration.
  • api-change:vpc-lattice: Adds support for specifying the number of IPv4 addresses in each ENI for the resource gateway for VPC Lattice.

v1.40.40

Compare Source

=======

  • api-change:bedrock-agent-runtime: This release enhances the information provided through Flow Traces. New information includes source/next node tracking, execution chains for complex nodes, dependency action (operation) details, and dependency traces.
  • api-change:bedrock-data-automation: Added support for configurable Speaker Labeling and Channel Labeling features for Audio modality.
  • api-change:billing: Add ability to combine custom billing views to create new consolidated views.
  • api-change:ce: Support for payer account dimension and billing view health status.
  • api-change:connect: Adds supports for manual contact picking (WorkList) operations on Routing Profiles, Agent Management and SearchContacts APIs.
  • api-change:dynamodbstreams: Added support for IPv6 compatible endpoints for DynamoDB Streams.
  • api-change:ec2: This release includes documentation updates for Amazon EBS General Purpose SSD (gp3) volumes with larger size and higher IOPS and throughput.
  • api-change:endpoint-rules: Update endpoint-rules client to latest version
  • api-change:redshift: Support tagging and tag propagation to IAM Identity Center for Redshift Idc Applications

v1.40.39

Compare Source

=======

  • api-change:glue: Update GetConnection(s) API to return KmsKeyArn & Add 63 missing connection types
  • api-change:lightsail: Attribute HTTP binding update for Get/Delete operations
  • api-change:network-firewall: Network Firewall now introduces Reject and Alert action support for stateful domain list rule groups, providing customers with more granular control over their network traffic.

v1.40.38

Compare Source

=======

  • api-change:appstream: G6f instance support for AppStream 2.0
  • api-change:cloudwatch: Fix default dualstack FIPS endpoints in AWS GovCloud(US) regions
  • api-change:dax: This release adds support for IPv6-only, DUAL_STACK DAX instances
  • api-change:endpoint-rules: Update endpoint-rules client to latest version
  • api-change:kms: Documentation only updates for KMS.
  • api-change:neptune: Doc-only update to address customer use.

v1.40.37

Compare Source

=======

  • api-change:cleanrooms: Added support for running incremental ID mapping for rule-based workflows.
  • api-change:ec2: Add Amazon EC2 R8gn instance types
  • api-change:entityresolution: Support incremental id mapping workflow for AWS Entity Resolution
  • api-change:ssm: Added Dualstack support to GetDeployablePatchSnapshotForInstance
  • api-change:sso-admin: Add support for encryption at rest with Customer Managed KMS Key in AWS IAM Identity Center
  • api-change:sso-oidc: This release includes exception definition and documentation updates.

v1.40.36

Compare Source

=======

  • api-change:batch: Starting in JAN 2026, AWS Batch will change the default AMI for new Amazon ECS compute environments from Amazon Linux 2 to Amazon Linux 2023. We recommend migrating AWS Batch Amazon ECS compute environments to Amazon Linux 2023 to maintain optimal performance and security.
  • api-change:eks: Adds support for RepairConfig overrides and configurations in EKS Managed Node Groups.
  • api-change:imagebuilder: Version ARNs are no longer required for the EC2 Image Builder list-image-build-version, list-component-build-version, and list-workflow-build-version APIs. Calling these APIs without the ARN returns all build versions for the given resource type in the requesting account.

v1.40.35

Compare Source

=======

  • api-change:bedrock-agentcore-control: Add tagging and VPC support to AgentCore Runtime, Code Interpreter, and Browser resources. Add support for configuring request headers in Runtime. Fix AgentCore Runtime shape names.
  • api-change:config: Add UNKNOWN state to RemediationExecutionState and add IN_PROGRESS/EXITED/UNKNOWN states to RemediationExecutionStepState.
  • api-change:connect: This release adds a persistent connection field to UserPhoneConfig that maintains agent's softphone media connection for faster call connections.
  • api-change:kendra-ranking: Model whitespace change - no client difference
  • api-change:license-manager-user-subscriptions: Added support for cross-account Active Directories.
  • api-change:medialive: Add MinBitrate for QVBR mode under H264/H265/AV1 output codec. Add GopBReference, GopNumBFrames, SubGopLength fields under H265 output codec.
  • api-change:sms-voice: Updated the sms-voice client to the latest version. Note: this client is maintained only for backwards compatibility and should not be used for new development. We recommend using the pinpoint-sms-voice client for full support and ongoing updates.
  • api-change:sqs: Update invalid character handling documentation for SQS SendMessage API

v1.40.34

Compare Source

=======

  • api-change:bedrock: Release includes an increase to the maximum policy build document size, an update to DeleteAutomatedReasoningPolicyBuildWorkflow to add ResourceInUseException, and corrections to UpdateAutomatedReasoningPolicyTestCaseRequest.
  • api-change:budgets: Added BillingViewHealthStatus Exception which is thrown when a Budget is created or updated with a Billing View that is not in the HEALTHY status
  • api-change:chime-sdk-messaging: Amazon Chime SDK Messaging GetMessagingSessionEndpoint API now returns dual-stack WebSocket endpoints supporting IPv4/IPv6.
  • api-change:ec2: Allowed AMIs adds support for four new parameters - marketplaceProductCodes, deprecationTimeCondition, creationDateCondition and imageNames

v1.40.33

Compare Source

=======

  • api-change:ec2: Add mac-m4.metal and mac-m4pro.metal instance types.
  • api-change:network-firewall: Network Firewall now prevents TLS handshakes with the target server until after the Server Name Indication (SNI) has been seen and verified. The monitoring dashboard now provides deeper insights into PrivateLink endpoint candidates and offers filters based on IP addresses and protocol.
  • api-change:pcs: Add support for Amazon EC2 Capacity Blocks for ML

v1.40.32

Compare Source

=======

  • api-change:budgets: Add support for custom time periods in budget configuration
  • api-change:ivs-realtime: IVS now offers customers the ability to control the positioning of participants in both grid and PiP layouts based on custom attribute values in participant tokens.
  • api-change:logs: Cloudwatch Logs added support for 2 new API parameters in metric and subscription filter APIs to filter log events based on system field values and emit system field values as dimensions and send them to customer destination as additional metadata.
  • api-change:osis: Adds support for cross-account ingestion for push-based sources. This includes resource policies for sharing pipelines across accounts and features for managing pipeline endpoints which enable accessing pipelines across different VPCs, including VPCs in other accounts.

v1.40.31

Compare Source

=======

  • api-change:ce: Added endpoint support for eusc-de-east-1 region.
  • api-change:medical-imaging: Added support for OpenID Connect (OIDC) custom authorizer
  • api-change:observabilityadmin: CloudWatch Observability Admin adds the ability to enable telemetry centralization in customers' Organizations. The release introduces new APIs to manage centralization rules, which define settings to replicate telemetry data to a central destination in the customers' Organization.
  • api-change:s3control: Introduce three new encryption filters: EncryptionType (SSE-S3, SSE-KMS, DSSE-KMS, SSE-C, NOT-SSE), KmsKeyArn (for SSE-KMS and DSSE-KMS), and BucketKeyEnabled (for SSE-KMS).
  • api-change:sms: The sms client has been removed following the deprecation of the service.
Checkmarx/kics (checkmarx/kics)

v2.1.14

Compare Source

What's Changed


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested review from npalm and kayman-mk as code owners September 22, 2025 00:27
Copy link
Contributor

Hey @renovate[bot]! 👋

Thank you for your contribution to the project. Please refer to the contribution rules for a quick overview of the process.

Make sure that this PR clearly explains:

  • the problem being solved
  • the best way a reviewer and you can test your changes

With submitting this PR you confirm that you hold the rights of the code added and agree that it will published under this LICENSE.

The following ChatOps commands are supported:

  • /help: notifies a maintainer to help you out

Simply add a comment with the command in the first line. If you need to pass more information, separate it with a blank line from the command.

This message was generated automatically. You are welcome to improve it.

kayman-mk
kayman-mk previously approved these changes Sep 22, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

Copy link
Contributor

github-actions bot commented Sep 22, 2025

MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 4 0 0 0.31s
✅ COPYPASTE jscpd yes no no 1.81s
✅ REPOSITORY dustilock yes no no 0.48s
✅ REPOSITORY gitleaks yes no no 1.68s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 25.66s
✅ REPOSITORY secretlint yes no no 0.63s
✅ REPOSITORY syft yes no no 1.06s
✅ REPOSITORY trivy-sbom yes no no 0.13s
✅ REPOSITORY trufflehog yes no no 3.86s
✅ SPELL cspell 5 0 0 2.88s
✅ YAML prettier 4 2 0 0 0.47s
✅ YAML v8r 4 0 0 3.38s
✅ YAML yamllint 4 0 0 0.48s

See detailed reports in MegaLinter artifacts
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

kayman-mk
kayman-mk previously approved these changes Sep 22, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Sep 22, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Sep 23, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Sep 23, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Sep 24, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Sep 24, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Sep 25, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Sep 25, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Sep 30, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Oct 1, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Oct 2, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Oct 2, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Oct 3, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Oct 3, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Oct 3, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Oct 3, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

kayman-mk
kayman-mk previously approved these changes Oct 4, 2025
Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

Copy link
Collaborator

@kayman-mk kayman-mk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Renovate PR by organization

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant