Skip to content

chore(deps): npm: bump the all-npm group across 4 directories with 44 updates - #838

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/all-npm-ad163dcf0a
Open

chore(deps): npm: bump the all-npm group across 4 directories with 44 updates#838
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/all-npm-ad163dcf0a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-npm group with 41 updates in the / directory:

Package From To
knip 6.23.0 6.32.2
@aws-sdk/client-agent-registry-control 3.1116.0 3.1117.0
@aws-sdk/client-bedrock-agentcore 3.1081.0 3.1117.0
@aws-sdk/client-bedrock-runtime 3.1081.0 3.1117.0
@aws-sdk/client-dynamodb 3.1078.0 3.1117.0
@aws-sdk/client-ecs 3.1081.0 3.1117.0
@aws-sdk/client-lambda 3.1081.0 3.1117.0
@aws-sdk/client-lambda-microvms 3.1103.0 3.1117.0
@aws-sdk/client-s3 3.1081.0 3.1117.0
@aws-sdk/client-secrets-manager 3.1078.0 3.1117.0
@aws-sdk/lib-dynamodb 3.1078.0 3.1117.0
@aws-sdk/s3-presigned-post 3.1081.0 3.1117.0
@aws-sdk/s3-request-presigner 3.1081.0 3.1117.0
@aws/durable-execution-sdk-js 2.1.0 2.3.0
@smithy/protocol-http 5.5.6 5.6.2
aws-cdk-lib 2.261.0 2.266.0
cdk-nag 2.38.2 3.0.2
constructs 10.6.0 10.8.1
ws 8.21.0 8.21.3
@aws-cdk/integ-runner 2.202.1 2.204.5
@cdklabs/eslint-plugin 2.0.13 2.0.18
@types/node 26.1.0 26.3.0
@typescript-eslint/eslint-plugin 8.63.0 8.68.0
@typescript-eslint/parser 8.63.0 8.68.0
aws-cdk 2.1129.0 2.1138.0
esbuild 0.28.1 0.28.2
eslint 10.6.0 10.9.1
eslint-plugin-jest 29.15.4 29.16.1
eslint-plugin-jsdoc 63.0.12 64.2.1
ts-jest 29.4.11 29.4.12
typescript 6.0.3 7.0.2
@aws-sdk/client-bedrock 3.1078.0 3.1117.0
@aws-sdk/client-bedrock-agentcore-control 3.1078.0 3.1117.0
@aws-sdk/client-cloudformation 3.1078.0 3.1117.0
@aws-sdk/client-cognito-identity-provider 3.1078.0 3.1117.0
commander 14.0.3 15.0.0
retire 5.4.3 5.7.0
@astrojs/check 0.9.9 0.9.10
@astrojs/starlight 0.41.3 0.41.8
astro 7.1.3 7.2.6
markdown-link-check 3.14.2 3.15.0

Bumps the all-npm group with 5 updates in the /cdk directory:

Package From To
cdk-nag 2.38.2 3.0.2
js-yaml 4.3.2 5.3.0
@aws-cdk/integ-runner 2.202.1 2.204.5
eslint-plugin-jsdoc 63.3.3 64.2.1
typescript 6.0.3 7.0.2

Bumps the all-npm group with 10 updates in the /cli directory:

Package From To
@aws-sdk/client-dynamodb 3.1078.0 3.1117.0
@aws-sdk/client-secrets-manager 3.1078.0 3.1117.0
@aws-sdk/lib-dynamodb 3.1078.0 3.1117.0
eslint-plugin-jsdoc 63.3.3 64.2.1
typescript 6.0.3 7.0.2
@aws-sdk/client-bedrock 3.1078.0 3.1117.0
@aws-sdk/client-bedrock-agentcore-control 3.1078.0 3.1117.0
@aws-sdk/client-cloudformation 3.1078.0 3.1117.0
@aws-sdk/client-cognito-identity-provider 3.1078.0 3.1117.0
commander 14.0.3 15.0.0

Bumps the all-npm group with 2 updates in the /docs directory: typescript and astro.

Updates knip from 6.23.0 to 6.32.2

Release notes

Sourced from knip's releases.

Release 6.32.2

  • Support oxfmt.config.mts (#1933) (795900191dc75eec8d1e717b866bf57e1e2912cc) - thanks @​joealden!
  • Support oxlint.config.mts (#1934) (531e2dc7c1d8bf31babea0068c34391182ec2d50) - thanks @​joealden!
  • Fix Supported lint-staged Configs (#1935) (f9c755e414ed10baa4d01af8ddac6d04cb8d5617) - thanks @​joealden!
  • Update dependencies (95f7c529f918dd9e1a84f92c68d064738977b825)
  • Update sentry snapshot (ea7929fcbd6b323c8bdd9252ac57017feeb29ecf)

Release 6.32.1

  • Handle referenced config files in their own plugin (resolve #1931, close #1932) (982c1d8e28cc62d3cba5ecde6dd8df2740c7c329)
  • Fix type-check against typescript@5.0.4 (2febefe44a8b39f74158916a2bc73933b4c281ae)
  • Update sentry snapshot (0397bddbf809e2b24fe59a4bea8c0258526bb565)

Release 6.32.0

  • fix: attribute wildcard subpath-import aliases as dependency usage (#1918) (4890a2ad5317b9e3f0ab844631ad0f0592802c3e) - thanks @​jsmecham!
  • Add Borp plugin (5eb9ad4cfb2ccb7770eac49f6109459d30590211)
  • Add tsd plugin (bd4ae7041f3fc6aef27b027644f80daefc432aca)
  • Resolve Rollup --config argument as plugin configuration (8111f97981406f4327d5e6a655c13308a9dc4426)
  • Resolve babel-jest configFile from Jest transform options (24794ccecb80fdaecfe4d46a26faff46c30d9015)
  • Add pre-commit plugin (ac726b0918cb931a6d538797e342484812a6752e)
  • Thread script words through resolvers to preserve quoting (89f9ada6ca81229bf8f7293439998acc5f87d457)
  • Resolve entries from Mocha script arguments (353f860f8e32f05f7c87dc5501071befc0e5a293)
  • Detect Node test runner through c8 (fa44be722aa35c6e8b441cd8cd0f4cf644027c22)
  • Update dependencies (non-major) (#1922) (6b1e6f3cbb1749776e3798f46eb2b99cd95ed56a) - thanks @​renovate[bot]!
  • fix(playwright): match config files with .cjs, .cts and .mts extensions (#1919) (1c1073a1817fdb3bcd3dc00eda2b1d858e444156) - thanks @​davidpavlovschi!
  • Restart VS Code language server process (resolve #1923) (d48eac5a2447567a33e835ce3e1648bf3f4ffb2b)
  • Classify built-ins from module specifiers (resolve #1925) (3528c5d0f808b7b2155f69a1f98493ee0e3e06c1)
  • Don't turn absolute-path script tokens into entries (resolve #1928) (e5608e77b434145c8dd5c2c2872bfb90ae622ce7)
  • Update sponsors data (025884bb53eede041732723197ac0415a1a50f71)
  • Update dependencies (d2c0a07c09cea70ab2cae5f97d12da272a6e43e6)

Release 6.31.0

  • feat: Add basic support for Marko 6 and 5 (#1914) (c6b151642701f9b4864ddb5ea8e40580623f59d1) - thanks @​caseycarroll!
  • Use Array.from in Marko compiler (5aadf47a22bdfd43bb8ad4082768e07fe37fc5ca)
  • Update release-it and fix release script flags (6fa9c269c65c0923965924226a5ccf0778842967)
  • Downgrade @​types/vscode to match extension engines range (6d8e9bf5200cf982d0bc801469c4e2be5627e5b8)

Release 6.30.0

  • docs: migrate to Starlight Blog plugin (#1854) (c89e3e3c9) - thanks @​trueberryless!
  • Include workspace dependencies in scoped runs (resolve #1901) (a75309eda)
  • Simplify workspace assembly (b3ac16411)
  • Document export declaration safety (ef98a7682)
  • Read object jsPlugin specifiers from Vite+ config (#1879) (3ea6a92d4) - thanks @​matchai!
  • Compile gitignore negations once (6884cdb20)
  • Cache Node test script detection (d970f67d8)
  • Track only enabled workspace plugins (67d48268a)
  • Skip unsupported Vite config command (545bb2d36)
  • Add SARIF reporter (ce11cf5d4)
  • Track catalog refs in pnpm dlx scripts (resolve #1885, close #1886) (102189a1a)
  • Report unresolved catalog references (b2b86c3e5)
  • Track catalog references across scoped runs (resolve #1905) (f0365bae0)

... (truncated)

Commits

Updates @aws-sdk/client-agent-registry-control from 3.1116.0 to 3.1117.0

Release notes

Sourced from @​aws-sdk/client-agent-registry-control's releases.

v3.1117.0

3.1117.0(2026-08-24)

Documentation Changes
  • client-batch: Doc Update, Add note that UpdatePolicy applies only to EC2 managed compute environments (26c213cf)
New Features
  • client-securityagent: Adding private and self-signed certificate configuration support for penetration tests (42f6ecb8)
  • client-bedrock: Adds support for specifying an inference profile ID or ARN, or an application inference profile ARN as the target model in CreateAdvancedPromptOptimizationJob. (9110f46b)
  • client-connect-contact-lens: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API, enabling customers to retrieve information extracted from real-time contact analysis. (9c5bda85)
  • client-dsql: Corrected the validation pattern on the ServiceName response field in the GetVpcEndpointServiceName API to match the values Amazon Aurora DSQL actually returns. (1b689a9f)
  • client-connect: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API, enabling customers to retrieve information extracted from real-time contact analysis. (775d1ad4)
  • client-launch-wizard: Added accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns for Launch Wizard (721b9f47)
  • client-elementalinference: Added support for the GetFixture API, enabling customers to retrieve the details of a fixture from its fixture ID, and added the access role ARN to the CreateFeed, GetFeed, and UpdateFeed responses. (d4b71834)
  • client-kafka: Amazon MSK Replicator now supports OAuth authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require OAuth for client authentication. This new capability is supported in all AWS Regions where MSK Express brokers are available. (a461b5a0)
  • client-timestream-influxdb: Service-managed parameter groups now only apply optimized defaults to DB Clusters automatically. New field effectiveDbParameterGroupIdentifier surfaces the parameter group actually applied. (8c7f04cd)

For list of updated packages, view updated-packages.md in assets-3.1117.0.zip

Changelog

Sourced from @​aws-sdk/client-agent-registry-control's changelog.

3.1117.0 (2026-08-24)

Note: Version bump only for package @​aws-sdk/client-agent-registry-control

Commits

Updates @aws-sdk/client-bedrock-agentcore from 3.1081.0 to 3.1117.0

Release notes

Sourced from @​aws-sdk/client-bedrock-agentcore's releases.

v3.1117.0

3.1117.0(2026-08-24)

Documentation Changes
  • client-batch: Doc Update, Add note that UpdatePolicy applies only to EC2 managed compute environments (26c213cf)
New Features
  • client-securityagent: Adding private and self-signed certificate configuration support for penetration tests (42f6ecb8)
  • client-bedrock: Adds support for specifying an inference profile ID or ARN, or an application inference profile ARN as the target model in CreateAdvancedPromptOptimizationJob. (9110f46b)
  • client-connect-contact-lens: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API, enabling customers to retrieve information extracted from real-time contact analysis. (9c5bda85)
  • client-dsql: Corrected the validation pattern on the ServiceName response field in the GetVpcEndpointServiceName API to match the values Amazon Aurora DSQL actually returns. (1b689a9f)
  • client-connect: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API, enabling customers to retrieve information extracted from real-time contact analysis. (775d1ad4)
  • client-launch-wizard: Added accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns for Launch Wizard (721b9f47)
  • client-elementalinference: Added support for the GetFixture API, enabling customers to retrieve the details of a fixture from its fixture ID, and added the access role ARN to the CreateFeed, GetFeed, and UpdateFeed responses. (d4b71834)
  • client-kafka: Amazon MSK Replicator now supports OAuth authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require OAuth for client authentication. This new capability is supported in all AWS Regions where MSK Express brokers are available. (a461b5a0)
  • client-timestream-influxdb: Service-managed parameter groups now only apply optimized defaults to DB Clusters automatically. New field effectiveDbParameterGroupIdentifier surfaces the parameter group actually applied. (8c7f04cd)

For list of updated packages, view updated-packages.md in assets-3.1117.0.zip

v3.1116.0

3.1116.0(2026-08-21)

Chores
Documentation Changes
  • client-backup: Updating CLI Docs for Backup Audit Manager List Job Summaries APIs. (98f47ffe)
  • client-wafv2: DataProtectionConfig field Key Documentation Update (a8f1fb90)
New Features
  • client-cloudwatch: Allows customers to specify an initial warm up period to wait for metrics to arrive when creating metric or log alarms (e354f162)
  • client-device-farm: Added support to CreateRemoveAccessSession for selecting a server version on the mobile WebDriver endpoint. (d91e09c8)
  • client-bedrock-agentcore: Increase spans count from 1k to 20k (e83264aa)
  • client-kinesis: Generate account endpoint for Kinesis Data Streams requests when the account ID is available (ed9966e2)
  • client-bedrock-agentcore-control: Update Dataset schema to THIRDPARTYEVALUATIONV1 (f0fe8db3)

For list of updated packages, view updated-packages.md in assets-3.1116.0.zip

... (truncated)

Changelog

Sourced from @​aws-sdk/client-bedrock-agentcore's changelog.

3.1117.0 (2026-08-24)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

3.1116.0 (2026-08-21)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

3.1115.0 (2026-08-20)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

3.1114.0 (2026-08-19)

Features

  • client-bedrock-agentcore: AgentCore Memory now supports Flexible Namespaces and Non-Conversational Payloads in CreateEvent API (a0d8fb6)

3.1113.0 (2026-08-18)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

3.1112.0 (2026-08-17)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

... (truncated)

Commits
  • 78b069a Publish v3.1117.0
  • d760a00 Publish v3.1116.0
  • 8369ada chore(codegen): update to sync with the latest smithy-ts (#8272)
  • efc86fc Publish v3.1115.0
  • 5318b44 Publish v3.1114.0
  • a0d8fb6 feat(client-bedrock-agentcore): AgentCore Memory now supports Flexible Namesp...
  • 73a06d2 Publish v3.1113.0
  • cb4ae76 Publish v3.1112.0
  • c41e9a9 Publish v3.1111.0
  • 7fdf457 feat(client-bedrock-agentcore): Add support for the Machine Payments Protocol...
  • Additional commits viewable in compare view

Updates @aws-sdk/client-bedrock-runtime from 3.1081.0 to 3.1117.0

Release notes

Sourced from @​aws-sdk/client-bedrock-runtime's releases.

v3.1117.0

3.1117.0(2026-08-24)

Documentation Changes
  • client-batch: Doc Update, Add note that UpdatePolicy applies only to EC2 managed compute environments (26c213cf)
New Features
  • client-securityagent: Adding private and self-signed certificate configuration support for penetration tests (42f6ecb8)
  • client-bedrock: Adds support for specifying an inference profile ID or ARN, or an application inference profile ARN as the target model in CreateAdvancedPromptOptimizationJob. (9110f46b)
  • client-connect-contact-lens: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API, enabling customers to retrieve information extracted from real-time contact analysis. (9c5bda85)
  • client-dsql: Corrected the validation pattern on the ServiceName response field in the GetVpcEndpointServiceName API to match the values Amazon Aurora DSQL actually returns. (1b689a9f)
  • client-connect: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API, enabling customers to retrieve information extracted from real-time contact analysis. (775d1ad4)
  • client-launch-wizard: Added accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns for Launch Wizard (721b9f47)
  • client-elementalinference: Added support for the GetFixture API, enabling customers to retrieve the details of a fixture from its fixture ID, and added the access role ARN to the CreateFeed, GetFeed, and UpdateFeed responses. (d4b71834)
  • client-kafka: Amazon MSK Replicator now supports OAuth authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require OAuth for client authentication. This new capability is supported in all AWS Regions where MSK Express brokers are available. (a461b5a0)
  • client-timestream-influxdb: Service-managed parameter groups now only apply optimized defaults to DB Clusters automatically. New field effectiveDbParameterGroupIdentifier surfaces the parameter group actually applied. (8c7f04cd)

For list of updated packages, view updated-packages.md in assets-3.1117.0.zip

v3.1116.0

3.1116.0(2026-08-21)

Chores
Documentation Changes
  • client-backup: Updating CLI Docs for Backup Audit Manager List Job Summaries APIs. (98f47ffe)
  • client-wafv2: DataProtectionConfig field Key Documentation Update (a8f1fb90)
New Features
  • client-cloudwatch: Allows customers to specify an initial warm up period to wait for metrics to arrive when creating metric or log alarms (e354f162)
  • client-device-farm: Added support to CreateRemoveAccessSession for selecting a server version on the mobile WebDriver endpoint. (d91e09c8)
  • client-bedrock-agentcore: Increase spans count from 1k to 20k (e83264aa)
  • client-kinesis: Generate account endpoint for Kinesis Data Streams requests when the account ID is available (ed9966e2)
  • client-bedrock-agentcore-control: Update Dataset schema to THIRDPARTYEVALUATIONV1 (f0fe8db3)

For list of updated packages, view updated-packages.md in assets-3.1116.0.zip

... (truncated)

Changelog

Sourced from @​aws-sdk/client-bedrock-runtime's changelog.

3.1117.0 (2026-08-24)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1116.0 (2026-08-21)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1115.0 (2026-08-20)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1114.0 (2026-08-19)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1113.0 (2026-08-18)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1112.0 (2026-08-17)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1111.0 (2026-08-14)

... (truncated)

Commits

Updates @aws-sdk/client-dynamodb from 3.1078.0 to 3.1117.0

Release notes

Sourced from @​aws-sdk/client-dynamodb's releases.

v3.1117.0

3.1117.0(2026-08-24)

Documentation Changes
  • client-batch: Doc Update, Add note that UpdatePolicy applies only to EC2 managed compute environments (26c213cf)
New Features
  • client-securityagent: Adding private and self-signed certificate configuration support for penetration tests (42f6ecb8)
  • client-bedrock: Adds support for specifying an inference profile ID or ARN, or an application inference profile ARN as the target model in CreateAdvancedPromptOptimizationJob. (9110f46b)
  • client-connect-contact-lens: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API, enabling customers to retrieve information extracted from real-time contact analysis. (9c5bda85)
  • client-dsql: Corrected the validation pattern on the ServiceName response field in the GetVpcEndpointServiceName API to match the values Amazon Aurora DSQL actually returns. (1b689a9f)
  • client-connect: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API, enabling customers to retrieve information extracted from real-time contact analysis. (775d1ad4)
  • client-launch-wizard: Added accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns for Launch Wizard (721b9f47)
  • client-elementalinference: Added support for the GetFixture API, enabling customers to retrieve the details of a fixture from its fixture ID, and added the access role ARN to the CreateFeed, GetFeed, and UpdateFeed responses. (d4b71834)
  • client-kafka: Amazon MSK Replicator now supports OAuth authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require OAuth for client authentication. This new capability is supported in all AWS Regions where MSK Express brokers are available. (a461b5a0)
  • client-timestream-influxdb: Service-managed parameter groups now only apply optimized defaults to DB Clusters automatically. New field effectiveDbParameterGroupIdentifier surfaces the parameter group actually applied. (8c7f04cd)

For list of updated packages, view updated-packages.md in assets-3.1117.0.zip

v3.1116.0

3.1116.0(2026-08-21)

Chores
Documentation Changes
  • client-backup: Updating CLI Docs for Backup Audit Manager List Job Summaries APIs. (98f47ffe)
  • client-wafv2: DataProtectionConfig field Key Documentation Update (a8f1fb90)
New Features
  • client-cloudwatch: Allows customers to specify an initial warm up period to wait for metrics to arrive when creating metric or log alarms (e354f162)
  • client-device-farm: Added support to CreateRemoveAccessSession for selecting a server version on the mobile WebDriver endpoint. (d91e09c8)
  • client-bedrock-agentcore: Increase spans count from 1k to 20k (e83264aa)
  • client-kinesis: Generate account endpoint for Kinesis Data Streams requests when the account ID is available (ed9966e2)
  • client-bedrock-agentcore-control: Update Dataset schema to THIRDPARTYEVALUATIONV1 (f0fe8db3)

For list of updated packages, view updated-packages.md in assets-3.1116.0.zip

... (truncated)

Changelog

Sourced from @​aws-sdk/client-dynamodb's changelog.

3.1117.0 (2026-08-24)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1116.0 (2026-08-21)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1115.0 (2026-08-20)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1114.0 (2026-08-19)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1113.0 (2026-08-18)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1112.0 (2026-08-17)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1111.0 (2026-08-14)

... (truncated)

Commits

Updates @aws-sdk/client-ecs from 3.1081.0 to 3.1117.0

Release notes

Sourced from @​aws-sdk/client-ecs's releases.

v3.1117.0

3.1117.0(2026-08-24)

Documentation Changes
  • client-batch: Doc Update, Add note that UpdatePolicy applies only to EC2 managed compute environments (26c213cf)
New Features
  • client-securityagent: Adding private and self-signed certificate configuration support for penetration tests (42f6ecb8)
  • client-bedrock: Adds support for specifying an inference profile ID or ARN, or an application inference profile ARN as the target model in CreateAdvancedPromptOptimizationJob. (9110f46b)
  • client-connect-contact-lens: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API, enabling customers to retrieve information extracted from real-time contact analysis. (9c5bda85)
  • client-dsql: Corrected the validation pattern on the ServiceName response field in the GetVpcEndpointServiceName API to match the values Amazon Aurora DSQL actually returns. (1b689a9f)
  • client-connect: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API, enabling customers to retrieve information extracted from real-time contact analysis. (775d1ad4)
  • client-launch-wizard: Added accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns for Launch Wizard (721b9f47)
  • client-elementalinference: Added support for the GetFixture API, enabling customers to retrieve the details of a fixture from its fixture ID, and added the access role ARN to the CreateFeed, GetFeed, and UpdateFeed responses. (d4b71834)
  • client-kafka: Amazon MSK Replicator now supports OAuth authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require OAuth for client authentication. This new capability is supported in all AWS Regions where MSK Express brokers are available. (a461b5a0)
  • client-timestream-influxdb: Service-managed parameter groups now only apply optimized defaults to DB Clusters automatically. New field effectiveDbParameterGroupIdentifier surfaces the parameter group actually applied. (8c7f04cd)

For list of updated packages, view updated-packages.md in assets-3.1117.0.zip

v3.1116.0

3.1116.0(2026-08-21)

Chores
Documentation Changes
  • client-backup: Updating CLI Docs for Backup Audit Manager List Job Summaries APIs. (98f47ffe)
  • client-wafv2: DataProtectionConfig field Key Documentation Update (a8f1fb90)
New Features
  • client-cloudwatch: Allows customers to specify an initial warm up period to wait for metrics to arrive when creating metric or log alarms (e354f162)
  • client-device-farm: Added support to CreateRemoveAccessSession for selecting a server version on the mobile WebDriver endpoint. (d91e09c8)
  • client-bedrock-agentcore: Increase spans count from 1k to 20k (e83264aa)
  • client-kinesis: Generate account endpoint for Kinesis Data Streams requests when the account ID is available (ed9966e2)
  • client-bedrock-agentcore-control: Update Dataset schema to THIRDPARTYEVALUATIONV1 (f0fe8db3)

For list of updated packages, view updated-packages.md in assets-3.1116.0.zip

... (truncated)

Changelog

Sourced from @​aws-sdk/client-ecs's changelog.

3.1117.0 (2026-08-24)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1116.0 (2026-08-21)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1115.0 (2026-08-20)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1114.0 (2026-08-19)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1113.0 (2026-08-18)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1112.0 (2026-08-17)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1111.0 (2026-08-14)

... (truncated)

Commits

Updates @aws-sdk/client-lambda from 3.1081.0 to 3.1117.0

Release notes

Sourced from @​aws-sdk/client-lambda's releases.

v3.1117.0

3.1117.0(2026-08-24)

Documentation Changes
  • client-batch: Doc Update, Add note that UpdatePolicy applies only to EC2 managed compute environments (26c213cf)
New Features
  • client-securityagent: Adding private and self-signed certificate configuration support for penetration tests (42f6ecb8)
  • client-bedrock: Adds support for specifying an inference profile ID or ARN, or an application inference profile ARN as the target model in CreateAdvancedPromptOptimizationJob. (9110f46b)
  • client-connect-contact-lens: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API, enabling customers to retrieve information extracted from real-time contact analysis. (9c5bda85)
  • client-dsql: Corrected the validation pattern on the ServiceName response field in the GetVpcEndpointServiceName API to match the values Amazon Aurora DSQL actually returns. (1b689a9f)
  • client-connect: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API, enabling customers to retrieve information extracted from real-time contact analysis. (775d1ad4)
  • client-launch-wizard: Added accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns for Launch Wizard (721b9f47)
  • client-elementalinference: Added support for the GetFixture API, enabling customers to retrieve the details of a fixture from its fixture ID, and added the access role ARN to the CreateFeed, GetFeed, and UpdateFeed responses. (d4b71834)
  • client-kafka: Amazon MSK Replicator now supports OAuth authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require OAuth for client authentication. This new capability is supported in all AWS Regions where MSK Express brokers are available. (a461b5a0)
  • client-timestream-influxdb: Service-managed parameter groups now only apply optimized defaults to DB Clusters automatically. New field effectiveDbParameterGroupIdentifier surfaces the parameter group actually applied. (8c7f04cd)

For list of updated packages, view updated-packages.md in assets-3.1117.0.zip

v3.1116.0

3.1116.0(2026-08-21)

Chores
Documentation Changes
  • client-backup: Updating CLI Docs for Backup Audit Manager List Job Summaries APIs. (98f47ffe)
  • client-wafv2: DataProtectionConfig field Key Documentation Update (a8f1fb90)
New Features
  • client-cloudwatch: Allows customers to specify an initial warm up period to wait for metrics to arrive when creating metric or log alarms (e354f162)
  • client-device-farm: Added support to CreateRemoveAccessSession for selecting a server version on the mobile WebDriver endpoint. (d91e09c8)
  • client-bedrock-agentcore: Increase spans count from 1k to 20k (e83264aa)
  • client-kinesis: Generate account endpoint for Kinesis Data Streams requests when the account ID is available (

… updates

Bumps the all-npm group with 41 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.23.0` | `6.32.2` |
| [@aws-sdk/client-agent-registry-control](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-agent-registry-control) | `3.1116.0` | `3.1117.0` |
| [@aws-sdk/client-bedrock-agentcore](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-agentcore) | `3.1081.0` | `3.1117.0` |
| [@aws-sdk/client-bedrock-runtime](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-runtime) | `3.1081.0` | `3.1117.0` |
| [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/client-ecs](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecs) | `3.1081.0` | `3.1117.0` |
| [@aws-sdk/client-lambda](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-lambda) | `3.1081.0` | `3.1117.0` |
| [@aws-sdk/client-lambda-microvms](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-lambda-microvms) | `3.1103.0` | `3.1117.0` |
| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1081.0` | `3.1117.0` |
| [@aws-sdk/client-secrets-manager](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-secrets-manager) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/s3-presigned-post](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-presigned-post) | `3.1081.0` | `3.1117.0` |
| [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) | `3.1081.0` | `3.1117.0` |
| [@aws/durable-execution-sdk-js](https://github.com/aws/aws-durable-execution-sdk-js/tree/HEAD/packages/aws-durable-execution-sdk-js) | `2.1.0` | `2.3.0` |
| [@smithy/protocol-http](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/protocol-http) | `5.5.6` | `5.6.2` |
| [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) | `2.261.0` | `2.266.0` |
| [cdk-nag](https://github.com/cdklabs/cdk-nag) | `2.38.2` | `3.0.2` |
| [constructs](https://github.com/aws/constructs) | `10.6.0` | `10.8.1` |
| [ws](https://github.com/websockets/ws) | `8.21.0` | `8.21.3` |
| [@aws-cdk/integ-runner](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/@aws-cdk/integ-runner) | `2.202.1` | `2.204.5` |
| [@cdklabs/eslint-plugin](https://github.com/cdklabs/eslint-rules) | `2.0.13` | `2.0.18` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.0` | `26.3.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.63.0` | `8.68.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.63.0` | `8.68.0` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1129.0` | `2.1138.0` |
| [esbuild](https://github.com/evanw/esbuild) | `0.28.1` | `0.28.2` |
| [eslint](https://github.com/eslint/eslint) | `10.6.0` | `10.9.1` |
| [eslint-plugin-jest](https://github.com/jest-community/eslint-plugin-jest) | `29.15.4` | `29.16.1` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc) | `63.0.12` | `64.2.1` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.11` | `29.4.12` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
| [@aws-sdk/client-bedrock](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/client-bedrock-agentcore-control](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-agentcore-control) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/client-cloudformation](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cloudformation) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/client-cognito-identity-provider](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cognito-identity-provider) | `3.1078.0` | `3.1117.0` |
| [commander](https://github.com/tj/commander.js) | `14.0.3` | `15.0.0` |
| [retire](https://github.com/RetireJS/retire.js) | `5.4.3` | `5.7.0` |
| [@astrojs/check](https://github.com/withastro/astro/tree/HEAD/packages/language-tools/astro-check) | `0.9.9` | `0.9.10` |
| [@astrojs/starlight](https://github.com/withastro/starlight/tree/HEAD/packages/starlight) | `0.41.3` | `0.41.8` |
| [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `7.1.3` | `7.2.6` |
| [markdown-link-check](https://github.com/tcort/markdown-link-check) | `3.14.2` | `3.15.0` |

Bumps the all-npm group with 5 updates in the /cdk directory:

| Package | From | To |
| --- | --- | --- |
| [cdk-nag](https://github.com/cdklabs/cdk-nag) | `2.38.2` | `3.0.2` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `4.3.2` | `5.3.0` |
| [@aws-cdk/integ-runner](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/@aws-cdk/integ-runner) | `2.202.1` | `2.204.5` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc) | `63.3.3` | `64.2.1` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |

Bumps the all-npm group with 10 updates in the /cli directory:

| Package | From | To |
| --- | --- | --- |
| [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/client-secrets-manager](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-secrets-manager) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1078.0` | `3.1117.0` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc) | `63.3.3` | `64.2.1` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
| [@aws-sdk/client-bedrock](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/client-bedrock-agentcore-control](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-agentcore-control) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/client-cloudformation](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cloudformation) | `3.1078.0` | `3.1117.0` |
| [@aws-sdk/client-cognito-identity-provider](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cognito-identity-provider) | `3.1078.0` | `3.1117.0` |
| [commander](https://github.com/tj/commander.js) | `14.0.3` | `15.0.0` |

Bumps the all-npm group with 2 updates in the /docs directory: [typescript](https://github.com/microsoft/TypeScript) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro).


Updates `knip` from 6.23.0 to 6.32.2
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.32.2/packages/knip)

Updates `@aws-sdk/client-agent-registry-control` from 3.1116.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-agent-registry-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-agent-registry-control)

Updates `@aws-sdk/client-bedrock-agentcore` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock-agentcore)

Updates `@aws-sdk/client-bedrock-runtime` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-runtime/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock-runtime)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-dynamodb)

Updates `@aws-sdk/client-ecs` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecs/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-ecs)

Updates `@aws-sdk/client-lambda` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-lambda)

Updates `@aws-sdk/client-lambda-microvms` from 3.1103.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda-microvms/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-lambda-microvms)

Updates `@aws-sdk/client-s3` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-s3)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-secrets-manager)

Updates `@aws-sdk/credential-provider-node` from 3.972.64 to 3.972.82
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-node/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-node)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/lib/lib-dynamodb)

Updates `@aws-sdk/s3-presigned-post` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-presigned-post/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/packages/s3-presigned-post)

Updates `@aws-sdk/s3-request-presigner` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/packages/s3-request-presigner)

Updates `@aws/durable-execution-sdk-js` from 2.1.0 to 2.3.0
- [Release notes](https://github.com/aws/aws-durable-execution-sdk-js/releases)
- [Changelog](https://github.com/aws/aws-durable-execution-sdk-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-durable-execution-sdk-js/commits/sdk-2.3.0/packages/aws-durable-execution-sdk-js)

Updates `@smithy/protocol-http` from 5.5.6 to 5.6.2
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/protocol-http/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/protocol-http@5.6.2/packages/protocol-http)

Updates `@smithy/signature-v4` from 5.6.2 to 5.6.12
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/signature-v4/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/signature-v4@5.6.12/packages/signature-v4)

Updates `aws-cdk-lib` from 2.261.0 to 2.266.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.266.0/packages/aws-cdk-lib)

Updates `cdk-nag` from 2.38.2 to 3.0.2
- [Release notes](https://github.com/cdklabs/cdk-nag/releases)
- [Commits](https://github.com/cdklabs/cdk-nag/compare/v2.38.2...v3.0.2)

Updates `constructs` from 10.6.0 to 10.8.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.8.1)

Updates `js-yaml` from 4.3.1 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.2...5.3.0)

Updates `ws` from 8.21.0 to 8.21.3
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](https://github.com/websockets/ws/compare/8.21.0...8.21.3)

Updates `@aws-cdk/integ-runner` from 2.202.1 to 2.204.5
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/integ-runner@v2.204.5/packages/@aws-cdk/integ-runner)

Updates `@cdklabs/eslint-plugin` from 2.0.13 to 2.0.18
- [Release notes](https://github.com/cdklabs/eslint-rules/releases)
- [Commits](https://github.com/cdklabs/eslint-rules/compare/v2.0.13...v2.0.18)

Updates `@types/node` from 26.1.0 to 26.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.68.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.68.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.63.0 to 8.68.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.68.0/packages/parser)

Updates `aws-cdk` from 2.1129.0 to 2.1138.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1138.0/packages/aws-cdk)

Updates `esbuild` from 0.28.1 to 0.28.2
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](https://github.com/evanw/esbuild/compare/v0.28.1...v0.28.2)

Updates `eslint` from 10.6.0 to 10.9.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.9.1)

Updates `eslint-plugin-jest` from 29.15.4 to 29.16.1
- [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases)
- [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jest-community/eslint-plugin-jest/compare/v29.15.4...v29.16.1)

Updates `eslint-plugin-jsdoc` from 63.0.12 to 64.2.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v63.0.12...v64.2.1)

Updates `ts-jest` from 29.4.11 to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.4.11...v29.4.12)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v6.0.3...v7.0.2)

Updates `@aws-sdk/client-bedrock` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock)

Updates `@aws-sdk/client-bedrock-agentcore-control` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock-agentcore-control)

Updates `@aws-sdk/client-cloudformation` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cloudformation/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-cloudformation)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-cognito-identity-provider)

Updates `commander` from 14.0.3 to 15.0.0
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tj/commander.js/compare/v14.0.3...v15.0.0)

Updates `retire` from 5.4.3 to 5.7.0
- [Release notes](https://github.com/RetireJS/retire.js/releases)
- [Commits](https://github.com/RetireJS/retire.js/compare/5.4.3...5.7.0)

Updates `@astrojs/check` from 0.9.9 to 0.9.10
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/language-tools/astro-check/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/check@0.9.10/packages/language-tools/astro-check)

Updates `@astrojs/starlight` from 0.41.3 to 0.41.8
- [Release notes](https://github.com/withastro/starlight/releases)
- [Changelog](https://github.com/withastro/starlight/blob/main/packages/starlight/CHANGELOG.md)
- [Commits](https://github.com/withastro/starlight/commits/@astrojs/starlight@0.41.8/packages/starlight)

Updates `astro` from 7.1.3 to 7.2.6
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.2.6/packages/astro)

Updates `markdown-link-check` from 3.14.2 to 3.15.0
- [Release notes](https://github.com/tcort/markdown-link-check/releases)
- [Changelog](https://github.com/tcort/markdown-link-check/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tcort/markdown-link-check/compare/v3.14.2...v3.15.0)

Updates `@aws-sdk/client-agent-registry-control` from 3.1116.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-agent-registry-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-agent-registry-control)

Updates `@aws-sdk/client-bedrock-agentcore` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock-agentcore)

Updates `@aws-sdk/client-bedrock-runtime` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-runtime/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock-runtime)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-dynamodb)

Updates `@aws-sdk/client-ecs` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecs/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-ecs)

Updates `@aws-sdk/client-lambda` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-lambda)

Updates `@aws-sdk/client-lambda-microvms` from 3.1103.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda-microvms/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-lambda-microvms)

Updates `@aws-sdk/client-s3` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-s3)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-secrets-manager)

Updates `@aws-sdk/credential-provider-node` from 3.972.64 to 3.972.82
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-node/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-node)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/lib/lib-dynamodb)

Updates `@aws-sdk/s3-presigned-post` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-presigned-post/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/packages/s3-presigned-post)

Updates `@aws-sdk/s3-request-presigner` from 3.1081.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/packages/s3-request-presigner)

Updates `@aws/durable-execution-sdk-js` from 2.1.0 to 2.3.0
- [Release notes](https://github.com/aws/aws-durable-execution-sdk-js/releases)
- [Changelog](https://github.com/aws/aws-durable-execution-sdk-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-durable-execution-sdk-js/commits/sdk-2.3.0/packages/aws-durable-execution-sdk-js)

Updates `@smithy/protocol-http` from 5.5.6 to 5.6.2
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/protocol-http/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/protocol-http@5.6.2/packages/protocol-http)

Updates `@smithy/signature-v4` from 5.6.2 to 5.6.12
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/signature-v4/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/signature-v4@5.6.12/packages/signature-v4)

Updates `aws-cdk-lib` from 2.261.0 to 2.266.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.266.0/packages/aws-cdk-lib)

Updates `cdk-nag` from 2.38.2 to 3.0.2
- [Release notes](https://github.com/cdklabs/cdk-nag/releases)
- [Commits](https://github.com/cdklabs/cdk-nag/compare/v2.38.2...v3.0.2)

Updates `constructs` from 10.6.0 to 10.8.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.8.1)

Updates `js-yaml` from 4.3.1 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.2...5.3.0)

Updates `ws` from 8.21.0 to 8.21.3
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](https://github.com/websockets/ws/compare/8.21.0...8.21.3)

Updates `@aws-cdk/integ-runner` from 2.202.1 to 2.204.5
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/integ-runner@v2.204.5/packages/@aws-cdk/integ-runner)

Updates `@cdklabs/eslint-plugin` from 2.0.13 to 2.0.18
- [Release notes](https://github.com/cdklabs/eslint-rules/releases)
- [Commits](https://github.com/cdklabs/eslint-rules/compare/v2.0.13...v2.0.18)

Updates `@types/node` from 26.1.0 to 26.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.68.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.68.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.63.0 to 8.68.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.68.0/packages/parser)

Updates `aws-cdk` from 2.1129.0 to 2.1138.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1138.0/packages/aws-cdk)

Updates `esbuild` from 0.28.1 to 0.28.2
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](https://github.com/evanw/esbuild/compare/v0.28.1...v0.28.2)

Updates `eslint` from 10.6.0 to 10.9.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.9.1)

Updates `eslint-plugin-jest` from 29.15.4 to 29.16.1
- [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases)
- [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jest-community/eslint-plugin-jest/compare/v29.15.4...v29.16.1)

Updates `eslint-plugin-jsdoc` from 63.0.12 to 64.2.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v63.0.12...v64.2.1)

Updates `ts-jest` from 29.4.11 to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.4.11...v29.4.12)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v6.0.3...v7.0.2)

Updates `@aws-sdk/client-bedrock` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock)

Updates `@aws-sdk/client-bedrock-agentcore-control` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock-agentcore-control)

Updates `@aws-sdk/client-cloudformation` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cloudformation/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-cloudformation)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-cognito-identity-provider)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-dynamodb)

Updates `@aws-sdk/client-lambda-microvms` from 3.1103.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda-microvms/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-lambda-microvms)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/lib/lib-dynamodb)

Updates `commander` from 14.0.3 to 15.0.0
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tj/commander.js/compare/v14.0.3...v15.0.0)

Updates `@types/node` from 26.1.0 to 26.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.68.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.68.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.63.0 to 8.68.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.68.0/packages/parser)

Updates `eslint` from 10.6.0 to 10.9.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.9.1)

Updates `eslint-plugin-jest` from 29.15.4 to 29.16.1
- [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases)
- [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jest-community/eslint-plugin-jest/compare/v29.15.4...v29.16.1)

Updates `eslint-plugin-jsdoc` from 63.0.12 to 64.2.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v63.0.12...v64.2.1)

Updates `retire` from 5.4.3 to 5.7.0
- [Release notes](https://github.com/RetireJS/retire.js/releases)
- [Commits](https://github.com/RetireJS/retire.js/compare/5.4.3...5.7.0)

Updates `ts-jest` from 29.4.11 to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.4.11...v29.4.12)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v6.0.3...v7.0.2)

Updates `@astrojs/check` from 0.9.9 to 0.9.10
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/language-tools/astro-check/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/check@0.9.10/packages/language-tools/astro-check)

Updates `@astrojs/starlight` from 0.41.3 to 0.41.8
- [Release notes](https://github.com/withastro/starlight/releases)
- [Changelog](https://github.com/withastro/starlight/blob/main/packages/starlight/CHANGELOG.md)
- [Commits](https://github.com/withastro/starlight/commits/@astrojs/starlight@0.41.8/packages/starlight)

Updates `astro` from 7.1.3 to 7.2.6
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.2.6/packages/astro)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v6.0.3...v7.0.2)

Updates `markdown-link-check` from 3.14.2 to 3.15.0
- [Release notes](https://github.com/tcort/markdown-link-check/releases)
- [Changelog](https://github.com/tcort/markdown-link-check/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tcort/markdown-link-check/compare/v3.14.2...v3.15.0)

Updates `retire` from 5.4.3 to 5.7.0
- [Release notes](https://github.com/RetireJS/retire.js/releases)
- [Commits](https://github.com/RetireJS/retire.js/compare/5.4.3...5.7.0)

Updates `cdk-nag` from 2.38.2 to 3.0.2
- [Release notes](https://github.com/cdklabs/cdk-nag/releases)
- [Commits](https://github.com/cdklabs/cdk-nag/compare/v2.38.2...v3.0.2)

Updates `js-yaml` from 4.3.2 to 5.3.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.2...5.3.0)

Updates `@aws-cdk/integ-runner` from 2.202.1 to 2.204.5
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/integ-runner@v2.204.5/packages/@aws-cdk/integ-runner)

Updates `eslint-plugin-jsdoc` from 63.3.3 to 64.2.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v63.0.12...v64.2.1)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v6.0.3...v7.0.2)

Updates `@aws-cdk/integ-runner` from 2.202.1 to 2.204.5
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/integ-runner@v2.204.5/packages/@aws-cdk/integ-runner)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/lib/lib-dynamodb)

Updates `eslint-plugin-jsdoc` from 63.3.3 to 64.2.1
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v63.0.12...v64.2.1)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v6.0.3...v7.0.2)

Updates `@aws-sdk/client-bedrock` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock)

Updates `@aws-sdk/client-bedrock-agentcore-control` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock-agentcore-control)

Updates `@aws-sdk/client-cloudformation` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cloudformation/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-cloudformation)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-cognito-identity-provider)

Updates `commander` from 14.0.3 to 15.0.0
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tj/commander.js/compare/v14.0.3...v15.0.0)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/lib/lib-dynamodb)

Updates `@aws-sdk/client-bedrock` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock)

Updates `@aws-sdk/client-bedrock-agentcore-control` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-bedrock-agentcore-control)

Updates `@aws-sdk/client-cloudformation` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cloudformation/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-cloudformation)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-cognito-identity-provider)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1117.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1117.0/lib/lib-dynamodb)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v6.0.3...v7.0.2)

Updates `astro` from 7.1.3 to 7.2.6
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.2.6/packages/astro)

Updates `astro` from 7.1.3 to 7.2.6
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.2.6/packages/astro)

---
updated-dependencies:
- dependency-name: knip
  dependency-version: 6.32.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-agent-registry-control"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-runtime"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-ecs"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-lambda"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-lambda-microvms"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/credential-provider-node"
  dependency-version: 3.972.82
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/s3-presigned-post"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws/durable-execution-sdk-js"
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@smithy/protocol-http"
  dependency-version: 5.6.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@smithy/signature-v4"
  dependency-version: 5.6.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: aws-cdk-lib
  dependency-version: 2.266.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: cdk-nag
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: constructs
  dependency-version: 10.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: ws
  dependency-version: 8.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@aws-cdk/integ-runner"
  dependency-version: 2.204.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@cdklabs/eslint-plugin"
  dependency-version: 2.0.18
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@types/node"
  dependency-version: 26.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: aws-cdk
  dependency-version: 2.1138.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: eslint
  dependency-version: 10.9.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jest
  dependency-version: 29.16.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 64.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore-control"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cloudformation"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: commander
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: retire
  dependency-version: 5.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@astrojs/check"
  dependency-version: 0.9.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@astrojs/starlight"
  dependency-version: 0.41.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: astro
  dependency-version: 7.2.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: markdown-link-check
  dependency-version: 3.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-agent-registry-control"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-runtime"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-ecs"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-lambda"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-lambda-microvms"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/credential-provider-node"
  dependency-version: 3.972.82
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/s3-presigned-post"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws/durable-execution-sdk-js"
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@smithy/protocol-http"
  dependency-version: 5.6.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@smithy/signature-v4"
  dependency-version: 5.6.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: aws-cdk-lib
  dependency-version: 2.266.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: cdk-nag
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: constructs
  dependency-version: 10.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: ws
  dependency-version: 8.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@aws-cdk/integ-runner"
  dependency-version: 2.204.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@cdklabs/eslint-plugin"
  dependency-version: 2.0.18
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@types/node"
  dependency-version: 26.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: aws-cdk
  dependency-version: 2.1138.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: eslint
  dependency-version: 10.9.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jest
  dependency-version: 29.16.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 64.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore-control"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cloudformation"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-lambda-microvms"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: commander
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: "@types/node"
  dependency-version: 26.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint
  dependency-version: 10.9.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jest
  dependency-version: 29.16.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 64.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: retire
  dependency-version: 5.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: "@astrojs/check"
  dependency-version: 0.9.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@astrojs/starlight"
  dependency-version: 0.41.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: astro
  dependency-version: 7.2.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: markdown-link-check
  dependency-version: 3.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: retire
  dependency-version: 5.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: cdk-nag
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: js-yaml
  dependency-version: 5.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: "@aws-cdk/integ-runner"
  dependency-version: 2.204.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 64.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: "@aws-cdk/integ-runner"
  dependency-version: 2.204.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 64.2.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore-control"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cloudformation"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: commander
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock"
  dependency-version: 3.1117.0
  dependency-type: direct:production
  update-type: versi...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 1, 2026
@dependabot
dependabot Bot requested review from a team as code owners September 1, 2026 00:11
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 1, 2026

@scottschreckengaust scottschreckengaust left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Principal review — #838 chore(deps): npm: bump the all-npm group across 4 directories with 44 updates

Review commit: 0ee449dc3e94ae751037532538c14b0605b47bf9 (base merge-base 861bc856; PR is behind origin/main 4da0a1fa)

How this was verified. I did not run mise run build, jest, pytest, tsc, or cdk synth — the review worktree has no node_modules/ or agent/.venv/ and installs are out of scope for this pass. Everything below is either (a) static reasoning over the diff, yarn.lock, and the manifests, or (b) quoted from this PR's own CI logs (run 33513574897, job 99874899974). Items I could not verify are labelled unverified.

1. Verdict

Request changes. The PR is CI-red for two independent reasons, both caused by majors smuggled into a grouped patch PR: cdk-nag ^2^3 breaks 27 files in cdk/src (NagSuppressions removed, AwsSolutionsChecks no longer satisfies IAspect), and typescript ^6^7 breaks the check:types-sync drift guard. A third, quieter defect: the declared js-yaml ^5.3.0 bump is silently neutralised by the root resolutions pin, so cdk/package.json now advertises a version that is not installed. Split the majors out; the ~39 routine patch/minor bumps are fine on their own.

2. Vision alignment

Routine dependency hygiene is squarely in support of "the control plane stays reliable and improvable" — keeping the AWS SDK v3 clients, aws-cdk-lib, and astro current is exactly the maintenance the platform needs, and the cooldown: default-days: 7 / grouped-PR setup keeps the churn bounded.

Where it drifts: the all-npm: patterns: ["*"] group in .github/dependabot.yml bundles five semver-majors with 39 patch bumps into one atomic unit. That defeats reviewable outcomes — nobody can approve the SDK patches without also approving a TypeScript-native-port migration. The repo already has the right pattern for this (the @cedar-policy/cedar-wasm / cedarpy ignore stanzas in .github/dependabot.yml, and the standalone tracked issue #169 for the ESLint 9→10 major). No tenet is traded here, so no ADR is needed — but the grouping policy needs the same treatment Cedar got.

3. Blocking issues

B1 — cdk/package.json:40: cdk-nag ^2.38.2^3.0.2 is not API-compatible with this repo (CI-confirmed)

cdk-nag 3.x drops the NagSuppressions export and its AwsSolutionsChecks no longer satisfies aws-cdk-lib 2.x's IAspect. The repo uses both, heavily: 86 NagSuppressions call sites across 47 cdk-nag import sites in cdk/src + cdk/test, plus Aspects.of(app).add(new AwsSolutionsChecks()) at cdk/src/main.ts:66.

From this PR's CI (//cdk:compile, 27 errors):

src/constructs/admission-queue-pickup.ts(28,10): error TS2305: Module '"cdk-nag"' has no exported member 'NagSuppressions'.
... (25 more constructs + src/stacks/agent.ts)
src/main.ts(66,23): error TS2741: Property 'visit' is missing in type 'AwsSolutionsChecks' but required in type 'IAspect'.

Risk. The visit/IAspect mismatch is the tell that cdk-nag 3.x targets a newer CDK aspect API than aws-cdk-lib@^2.266.0 (what the lock resolves) exposes — inference, unverified, but it means this is not a mechanical rename you can sed away. Landing it would take the whole CDK app out of compile, and with it every cdk-nag suppression that documents an accepted security finding.

Suggested fix. Revert this line to "cdk-nag": "^2.38.2" and add a major-version ignore for cdk-nag in .github/dependabot.yml, mirroring the existing Cedar stanza:

    ignore:
      # cdk-nag 3.x targets a newer CDK aspect API and removes `NagSuppressions`.
      # Bump only alongside the aws-cdk-lib major, via a tracked issue.
      - dependency-name: "cdk-nag"
        update-types: ["version-update:semver-major"]

Then file an issue for the cdk-nag 2→3 migration and land it separately.

B2 — cdk/package.json:71, cli/package.json:36, docs/package.json:25: typescript ^6.0.3^7.0.2 breaks the types-sync drift guard (CI-confirmed)

typescript@^7.0.2 resolves to the native/platform-binary distribution (yarn.lock: optionalDependencies: @typescript/typescript-linux-arm64 7.0.2, -darwin-arm64, …). Its JS compiler-API surface differs from TS 6's, and scripts/check-types-sync.ts consumes that API directly:

// scripts/check-types-sync.ts:47,175
import * as ts from 'typescript';
const sourceFile = ts.createSourceFile(filePath, source, ts.ScriptTarget.Latest, true);

From this PR's CI (//:check:types-sync):

TypeError: Cannot read properties of undefined (reading 'Latest')
    at parseFile (scripts/check-types-sync.ts:175:76)

Risk. check:types-sync is the guard that keeps cdk/src/handlers/shared/types.ts and cli/src/types.ts from drifting (mise.toml drift-prevention). It now dies on a TypeError — loudly today (exit 1), but the same API break plausibly hits every other TS-API consumer in the toolchain, none of which got as far as running before the build aborted at 2.1s: ts-jest (^29.4.11, peer range historically typescript >=4.3 <6) drives //cdk:test and //cli:test; typescript-eslint via @cdklabs/eslint-plugin drives //cdk:eslint / //cli:eslint; @astrojs/check + volar-service-typescript drive the docs typecheck. Those three are unverified — the job never reached them — but they are the reason this is a repo-wide toolchain migration, not a version bump.

Suggested fix. Keep ^6.0.3 in all three manifests, add a typescript major ignore to .github/dependabot.yml, and file a tracked issue for the TS 7 migration in the shape of #169 (ESLint 9→10). Note that migration must also fix AGENTS.md:76 (**TypeScript** 6.x) and re-verify ts-jest / typescript-eslint / @astrojs/check peer support before flipping the pin.

B3 — cdk/package.json:42: the js-yaml ^5.3.0 bump is inert, and the manifest now lies

cdk/package.json:42 declares "js-yaml": "^5.3.0", but the root package.json:30 resolutions block pins "js-yaml": "^4.3.1". Yarn v1 resolutions apply tree-wide, including workspace direct dependencies, and the lockfile confirms the outcome — there is no js-yaml@^5.x descriptor anywhere in yarn.lock, only:

js-yaml@^3.13.1, js-yaml@^4.1.1, js-yaml@^4.3.0, js-yaml@^4.3.1:
  version "4.3.2"

(The ^4.1.1 descriptor that survives is requested by @astrojs/internal-helpers, @astrojs/starlight, and xmlbuilder2 — not by cdk/.)

Risk (three-fold).

  1. The manifest is wrong. cdk/package.json advertises js-yaml 5 while 4.3.2 is what installs. Anyone reading the manifest to reason about API surface is misled.
  2. A latent, unreviewed breaking change. The day someone touches that resolution — precisely the kind of lockfile-only OSV re-resolve this repo does routinely (#844, #637) — js-yaml 5's breaking API lands with zero review on cdk/src/handlers/shared/registry/agent-registry-client.ts:45 and cdk/scripts/generate-bootstrap-template.ts:32. The latter generates the committed bootstrap IAM artifacts, so a silent YAML-emit change there is a deploy-role correctness problem, not a cosmetic one.
  3. Type drift. cdk/package.json:54 still pins "@types/js-yaml": "^4.0.9". If v5 ever does land it will almost certainly ship its own types and collide with the @types shim.

Suggested fix. Revert cdk/package.json:42 to ^4.1.1 (or bump it to ^4.3.1 to match the resolution floor and drop the contradiction). If a js-yaml 5 upgrade is genuinely wanted, it needs its own PR that moves the manifest, the root resolutions floor, and @types/js-yaml together, with the two call sites re-verified.

Guard gap this exposes (worth fixing regardless of what you do with B3): nothing in drift-prevention checks that root resolutions don't contradict a workspace direct-dependency range, and mise.toml:44 uses yarn install --check-files rather than --frozen-lockfile, so neither install nor CI notices. scripts/check-transitive-pin-sync.mjs already owns the "resolutions have reach" concern — a sibling assertion ("no workspace dep declares a range disjoint from a root resolutions pin for the same package") would have caught this at mise run drift-prevention.

4. Non-blocking suggestions / nits

  1. cdk/package.json:65 + cli/package.jsoneslint-plugin-jsdoc 63 → 64 (major). Unverified: //cdk:eslint and //cli:eslint had only just started ($ eslint --fix src test) when //cdk:compile aborted the run. A jsdoc-plugin major typically changes rule defaults; with --fix in CI plus the "Fail build on mutation" gate, new autofixes surface as a red build rather than a lint report. Re-run after B1/B2 are resolved.
  2. cli/package.json:47commander 14 → 15 (major). Unverified (//cli:compile///cli:test never completed). ~19 import { Command } from 'commander' sites in cli/src/commands/. Please confirm (a) no removed API is in use and (b) commander 15's engines.node floor is compatible with this repo's "node": ">= 20.x <= 24.x" (root, cdk/, and cli/ all declare it) — a bot bump that raises the Node floor above 20 would break the declared support matrix silently.
  3. docs/package.json:23astro 7.1.3 → 7.2.6. Unverified (docs build never ran; //docs:sync did pass). Related: astro 7.2.6 depends on @astrojs/markdown-satteri, not @astrojs/markdown-remark, so the root resolutions pin "@astrojs/markdown-remark": "7.2.0" is now reachable only via @astrojs/mdx. Worth confirming that pin still does what it was added for rather than lingering as a fossil.
  4. cdk/package.json:48@aws-cdk/integ-runner 2.202.1 → 2.204.5 leaves it ~60 minors behind the aws-cdk-lib@^2.266.0 the lock resolves (and behind @aws-cdk/integ-tests-alpha@2.260.0-alpha.0). Pre-existing skew, not introduced here; flagging only so it doesn't become invisible.
  5. scripts/check-types-sync.ts:175 robustness. A TypeError: Cannot read properties of undefined (reading 'Latest') is a poor diagnostic for "the TypeScript compiler API changed shape." A one-line guard (if (!ts.ScriptTarget) throw new Error('unsupported typescript build: compiler API missing ScriptTarget')) turns a stack trace into an actionable message. Out of this diff's scope, but this PR is the reason it matters.
  6. AGENTS.md:76 still reads **TypeScript** 6.x. Whatever PR eventually lands TS 7 must update it (same for the cdk-nag line if the tech-stack section grows one).
  7. PR is behind origin/main; treat the green deps scan as stale. origin/main is now 4da0a1fa — "re-resolve browserslist to clear two HIGH OSV advisories (#844)". This head's yarn.lock:3946 still carries browserslist 4.28.5 (GHSA-73wf-gq98-2v4g / GHSA-c83g-rgw3-j3cx, 7.5, fixed in 4.28.7); main is on 4.28.8. The "Secrets, deps, and workflow scan" green on this head ran at 13:30, before #844 landed at 19:19, so it is not evidence of a clean lockfile. Since this PR doesn't touch those stanzas a merge shouldn't revert the fix, but per the known merge-queue re-scan behaviour the queue will re-run security:deps against latest main — re-lock on current main rather than relying on the stale green.

5. Supply-chain / provenance checks (all verified, all clean)

Explicitly recording these because they were the highest-value things to get wrong on this PR:

  • Cedar lockstep — clean, N/A. cdk/package.json:35 is still "@cedar-policy/cedar-wasm": "4.8.2"; grep -n cedar over the full diff returns nothing, and agent/ is untouched. The _cedar_parity_pin warning comment at cdk/package.json:7 is intact and the .github/dependabot.yml ignore stanzas for @cedar-policy/cedar-wasm / cedarpy did their job. No parity fixtures needed.
  • Transitive-pin sync (#712) — clean, N/A. The root resolutions block is unchanged by this PR (verified line-by-line: the only root-manifest edit is knip 6.23.0 → 6.32.2 in devDependencies; the resolutions lines appear as diff context only). Nothing to mirror into integrations/jira-forge-app/package.json overrides, which still carries its three pins (brace-expansion, fast-uri, undici) at the root floors. check:transitive-pin-sync is unaffected.
  • Hijacked-release check — no new suspicious packages. @astrojs/markdown-satteri and the @bruits/satteri-* platform binaries look exactly like the shape of an astro-adjacent typosquat (cf. astro 7.1.0 = MAL-2026-10726), so I checked provenance rather than pattern-matching: git show 861bc856:yarn.lock | grep -c satteri38 occurrences already on the merge base. This PR only moves them 0.9.x → 0.10.x as a consequence of the astro bump. Not a new dependency, not a new scope. No other new scopes appear in the lock diff, all additions resolve from registry.yarnpkg.com with integrity hashes, and osv-scanner was green on this head (with the staleness caveat in nit 7).

6. Documentation

  • Nothing required for the routine bumps — no behaviour, contract, env var, or command changed. Correct as-is.
  • Missing, tied to B2: AGENTS.md:76 (**TypeScript** 6.x) contradicts typescript ^7.0.2. Not worth fixing in this PR — fix it in the PR that actually lands TS 7.
  • Starlight mirror — N/A. No edits under docs/guides/, docs/design/, or CONTRIBUTING.md; //docs:sync ran clean in CI (Finished in 136.5ms), so no stale-mirror mutation risk.
  • Issue tracking — gap. No backing issue. For the routine bot bumps that is the established, de-facto-waived pattern in this repo (bot PR, dependencies + javascript labels, no issue), and I am not raising ADR-003 "No PRs without an Issue" as a blocker for those. But the majors are different: cdk-nag 2→3 and TS 6→7 are migrations that each need their own approved, prioritised issue before they can land, exactly as #169 did for ESLint 9→10.

7. Tests & CI

  • build (agentcore): FAIL//cdk:compile (27 errors, B1) and //:check:types-sync (B2). All other checks pass: Analyze (actions/javascript-typescript/python), CodeQL, Dead-code detection (advisory), Secrets, deps, and workflow scan, Validate PR title. mergeStateStatus: BLOCKED.
  • Coverage of the failure surface is thin because the build died at 2.1s. Only //:sync:abca-commands, //docs:sync, //:check:constants-sync, and //:test:jira-forge-app (11/11 pass) completed. //cdk:test, //cli:test, //cdk:eslint, //cli:eslint, and the docs build never reported — so the majors in nits 1–3 are genuinely untested, not merely unmentioned. Don't read "only two tasks failed" as "only two things are broken."
  • No tests added/changed — correct for a dependency PR; the build is the test, and it is red.
  • Bootstrap synth-coverage: N/A. No constructs, stacks, handlers, or new CFN resource types; cdk/src/bootstrap/**, resource-action-map.ts, version.ts, and the generated cdk/bootstrap/policies/*.json are untouched, so ADR-002's same-PR bundle requirement doesn't trigger. Flagging one adjacency: cdk/scripts/generate-bootstrap-template.ts:32 imports js-yaml, so a real js-yaml 5 landing (B3) would need cdk/test/bootstrap/ — including the golden baseline in docs/design/DEPLOYMENT_ROLES.md — re-verified.
  • CDK synth test performance (#366): N/A — no test files changed, so no risk of re-enabling aws:cdk:bundling-stacks or per-test new App().

8. Review agents run

Nested agent dispatch was unavailable for this review. This review ran as a subagent inside a batch fan-out, which cannot spawn further agents, so the pr-review-toolkit agents named in Stage 3 (code-reviewer, silent-failure-hunter, type-design-analyzer, comment-analyzer, pr-test-analyzer) were not invoked. I applied each rubric dimension inline instead, one at a time. To be unambiguous: everything below is rubric-applied-inline, not agent-dispatched.

Dimension Applied inline? Result
code-reviewer (guidelines, style, conventions) Yes Conventional-commit title passes CI; the _cedar_parity_pin convention (cdk/package.json:7) honoured; the dependabot ignore-stanza convention not extended to the new majors → B1/B2 remedies. AGENTS.md:76 tech-stack line goes stale under B2.
silent-failure-hunter (error handling, swallowed failures, plausible defaults) Yes No error-handling code in the diff, but the silent-failure pattern is present at the build level: B3's declared-vs-effective js-yaml divergence is invisible because mise.toml:44 uses yarn install --check-files (not --frozen-lockfile) and no drift-prevention check compares resolutions against workspace ranges. Counter-example worth noting: check:types-sync fails loudly (nit 5 asks only for a better message, not for it to be caught).
type-design-analyzer (new types, encapsulation, invariants) Judged out of scope The diff introduces no types — it is four package.json version-range edits plus a lockfile.
comment-analyzer (comment accuracy vs code) Yes Only comment-bearing artefact touched is cdk/package.json; its _cedar_parity_pin prose remains accurate (cedar-wasm unchanged). Nearest inaccuracy is AGENTS.md:76 under B2.
pr-test-analyzer (failure-path coverage, not just happy path) Yes See §7 — no tests expected for a dep bump, but the build aborted before the suites that would have exercised the remaining majors ran, and the missing resolutions-vs-manifest guard is a concrete coverage gap that would have caught B3 pre-CI.
security-review Skill Not invoked, deliberately The diff touches no IAM, Cedar, network, secrets, or input-validation code — only dependency ranges and a lockfile. The security dimension that does apply here is supply chain, and I did that inline and in depth (§5: cedar lockstep, transitive-pin sync, hijacked-release provenance via merge-base comparison, OSV staleness vs #844).

Human review heuristics (Stage 3, non-automatable):

  • Proportionality — concern. One atomic PR carrying five semver-majors (cdk-nag, typescript ×3 manifests, js-yaml, commander, eslint-plugin-jsdoc) plus ~39 routine patch bumps. The complexity of the review massively exceeds the complexity of the intent ("keep deps current"), and it is a property of .github/dependabot.yml's all-npm: patterns: ["*"] group, not of dependabot.
  • Coherence — concern. cdk/package.json:42 (js-yaml ^5.3.0), package.json:30 (resolutions: js-yaml ^4.3.1), and cdk/package.json:54 (@types/js-yaml ^4.0.9) express three mutually inconsistent beliefs about one dependency in one PR. Same concept, three versions.
  • Clarity — pass, with one caveat. The dependabot body enumerates every bump with from/to and links, which is genuinely good provenance. Caveat: it gives a major (typescript 6 → 7) exactly the same visual weight as a patch (@aws-sdk/client-s3 3.1081.0 → 3.1117.0), which is how a toolchain migration ends up looking routine.
  • Appropriateness — concern. cdk-nag 3 and the TypeScript native port are migrations this team should schedule and own, not inherit from a Saturday bot run. The repo already knows how to do this well: the Cedar ignore stanzas and tracked issue #169 (ESLint 9→10) are the pattern to copy.

Path forward

  1. Split the PR (or let dependabot recreate it) so the ~39 patch/minor bumps land on their own — those look fine and I would approve them.
  2. Add version-update:semver-major ignore entries for cdk-nag and typescript in .github/dependabot.yml, alongside the existing Cedar stanzas.
  3. Revert cdk/package.json:42 js-yaml to match the root resolutions floor.
  4. File tracked, approved issues for cdk-nag 2→3 and TypeScript 6→7 (shape: #169).
  5. Re-lock on current origin/main so the browserslist fix from #844 is in the tree the deps gate scores.

Happy to re-review the split-out patch PR promptly — the routine half of this is unobjectionable and I don't want the majors to hold it hostage.

Comment thread cdk/package.json
"aws-cdk-lib": "^2.260.0",
"aws-jwt-verify": "^5.2.1",
"cdk-nag": "^2.38.2",
"cdk-nag": "^3.0.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking (B1). cdk-nag 3.x is not API-compatible with this repo on aws-cdk-lib 2.x. CI on this head (//cdk:compile) reports 27 errors: Module '"cdk-nag"' has no exported member 'NagSuppressions' across 26 files, plus src/main.ts(66,23): error TS2741: Property 'visit' is missing in type 'AwsSolutionsChecks' but required in type 'IAspect'.

Static scope check: 86 NagSuppressions call sites across 47 cdk-nag imports in cdk/src + cdk/test. The IAspect/visit mismatch suggests cdk-nag 3 targets a newer CDK aspect API (inference, unverified) — so this is not a mechanical rename.

Suggested fix: revert to "cdk-nag": "^2.38.2" and add a major ignore to .github/dependabot.yml mirroring the existing Cedar stanza:

      - dependency-name: "cdk-nag"
        update-types: ["version-update:semver-major"]

Then land the 2→3 migration behind its own tracked issue.

Comment thread cdk/package.json
"cdk-nag": "^3.0.2",
"constructs": "^10.6.0",
"js-yaml": "^4.1.1",
"js-yaml": "^5.3.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking (B3). This bump is inert, and it makes the manifest wrong.

Root package.json:30 resolutions pins "js-yaml": "^4.3.1", and yarn v1 resolutions apply tree-wide including workspace direct deps. yarn.lock on this head contains no js-yaml@^5.x descriptor at all — only js-yaml@^3.13.1, js-yaml@^4.1.1, js-yaml@^4.3.0, js-yaml@^4.3.1: version "4.3.2". (The surviving ^4.1.1 is requested by @astrojs/internal-helpers / @astrojs/starlight / xmlbuilder2, not by cdk/.) So the installed version is 4.3.2 while this line advertises 5.

Three consequences:

  1. The manifest misleads anyone reasoning about js-yaml's API surface here.
  2. The next lockfile-only OSV re-resolve that touches that pin (cf. fix(deps): re-resolve browserslist to clear two HIGH OSV advisories (#845) #844, fix(deps): bump astro to 7.1.3 + re-resolve brace-expansion to clear osv-scanner (#636) #637) silently lands js-yaml 5's breaking API on cdk/src/handlers/shared/registry/agent-registry-client.ts:45 and cdk/scripts/generate-bootstrap-template.ts:32 — the latter generates the committed bootstrap IAM artifacts.
  3. @types/js-yaml two lines below is still ^4.0.9.

Suggested fix: revert to ^4.1.1 (or set ^4.3.1 to match the resolution floor). A genuine v5 upgrade needs its own PR moving the manifest, the root resolutions floor, and @types/js-yaml together.

Comment thread cdk/package.json
"ts-jest": "^29.4.11",
"ts-node": "^10.9.2",
"typescript": "^6.0.3"
"typescript": "^7.0.2"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking (B2) — same for cli/package.json:36 and docs/package.json:25.

typescript@^7.0.2 resolves to the native/platform-binary distribution (yarn.lock optionalDeps: @typescript/typescript-linux-arm64 7.0.2, -darwin-arm64, …), whose JS compiler-API surface differs from TS 6's. CI on this head:

[//:check:types-sync] TypeError: Cannot read properties of undefined (reading 'Latest')
    at parseFile (scripts/check-types-sync.ts:175:76)

That is the drift-prevention guard keeping cdk/src/handlers/shared/types.ts in sync with cli/src/types.ts, and it now dies on ts.ScriptTarget being undefined.

The build aborted at 2.1s, so the other TS-API consumers are unverified but at risk: ts-jest ^29.4.11 (drives //cdk:test / //cli:test; peer range historically >=4.3 <6), typescript-eslint via @cdklabs/eslint-plugin, and @astrojs/check + volar-service-typescript for the docs typecheck.

Suggested fix: keep ^6.0.3 in all three manifests, add a typescript major ignore to .github/dependabot.yml, and file a tracked migration issue in the shape of #169 (ESLint 9→10) — which must also update AGENTS.md:76 (**TypeScript** 6.x).

Comment thread cli/package.json
"commander": "^14.0.3"
"@aws-sdk/client-secrets-manager": "3.1117.0",
"@aws-sdk/lib-dynamodb": "3.1117.0",
"commander": "^15.0.0"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit / unverified. commander 14 → 15 is a major, and //cli:compile + //cli:test never completed on this head (//cdk:compile aborted the run at 2.1s), so nothing exercised it. ~19 import { Command } from 'commander' sites in cli/src/commands/.

Two things to confirm before this lands: (a) no removed/renamed commander API is in use, and (b) commander 15's engines.node floor is compatible with the repo's declared "node": ">= 20.x <= 24.x" (root, cdk/, and cli/). A bot bump that quietly raises the Node floor above 20 breaks the declared support matrix without any test noticing.

Comment thread docs/package.json
"@astrojs/check": "^0.9.9",
"@astrojs/starlight": "^0.41.2",
"astro": "7.1.3",
"astro": "7.2.6",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit / unverified. The docs build never ran on this head (//docs:sync passed, but the Astro build was never reached), so 7.1.3 → 7.2.6 is untested here.

Provenance check done and clean: astro 7.2.6 pulls @astrojs/markdown-satteri / @bruits/satteri-*, which look like the shape of an astro-adjacent typosquat (cf. astro 7.1.0 = MAL-2026-10726) — but git show 861bc856:yarn.lock | grep -c satteri → 38 occurrences already on the merge base. This PR only moves them 0.9.x → 0.10.x. Not a new dependency.

Related follow-up: astro 7.2.6 no longer depends on @astrojs/markdown-remark, so the root resolutions pin "@astrojs/markdown-remark": "7.2.0" is now reachable only via @astrojs/mdx. Worth confirming that pin still serves its original purpose rather than lingering as a fossil.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants