Skip to content

[Snyk] Upgrade @aws-sdk/lib-storage from 3.1045.0 to 3.1108.0 - #2004

Open
macpro-snyk-service-account wants to merge 1 commit into
mainfrom
snyk-upgrade-b1900844e310a0423768910fd76228ef
Open

[Snyk] Upgrade @aws-sdk/lib-storage from 3.1045.0 to 3.1108.0#2004
macpro-snyk-service-account wants to merge 1 commit into
mainfrom
snyk-upgrade-b1900844e310a0423768910fd76228ef

Conversation

@macpro-snyk-service-account

Copy link
Copy Markdown
Collaborator

snyk-top-banner

Snyk has created this PR to upgrade @aws-sdk/lib-storage from 3.1045.0 to 3.1108.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 63 versions ahead of your current version.

  • The recommended version was released 21 days ago.

Breaking Change Risk

Merge Risk: Low

Notice: This assessment is enhanced by AI.

Release notes
Package name: @aws-sdk/lib-storage
  • 3.1108.0 - 2026-08-11

    3.1108.0(2026-08-11)

    Chores
    Documentation Changes
    • client-textract: Amazon A2I entered maintenance mode in July 2026 and now rejects StartHumanLoop requests from accounts that it does not recognize as existing customers. This update adds a corresponding note to the HumanLoopConfig parameter documentation so that the API Reference and SDK docs explain this behavior. (c1efbb87)
    • client-organizations: Documentation update for AWS Organizations that clarifies valid input values for the HandshakePartyType parameter in the InviteAccountToOrganization. API ORGANIZATION is valid in responses only. valid input values are ACCOUNT and EMAIL (389ab808)
    • client-clouddirectory: Added an end-of-support notice to Amazon Cloud Directory public CLI reference documentation. (afdd9b1f)
    New Features
    • clients: update client endpoints as of 2026-08-11 (60a8bce4)
    • client-cleanrooms: Adds support for exporting redacted query execution logs in AWS Clean Rooms (dc4ece15)
    • client-account-access: Adds SDK support for AWS IAM account access manager, a feature that enables mapping of IAM roles to the users and groups in AWS IAM Identity Center. (536036b2)
    • client-connect: Seven new APIs for managing custom metrics, including create, describe, update, and delete. Using Custom Metrics, customers of Amazon Connect Customer can tailor analytics dashboards to their needs by applying custom thresholds, filters, and calculations to one or more out of the box measurements. (97209f36)
    • client-bedrock-agentcore: Adding online eval arn as input for recommendation API (a0d8503e)
    • client-eks: This feature would give customers the ability to selectively tune certain configurations of Kubernetes control plane components in an Amazon EKS cluster. (6d5d1413)
    • client-datazone: GetSubscriptionGrant now returns materialized asset scope name for mapping Lake Formation data cell filters or Redshift views to subscription grants. (95ff8a96)
    Bug Fixes
    • lib-transfer-manager: optimize worker HTTP connections and file I/O (#8256) (3ea6bc4b)

    For list of updated packages, view updated-packages.md in assets-3.1108.0.zip

  • 3.1107.0 - 2026-08-10

    3.1107.0(2026-08-10)

    Chores
    • codegen:
      • sync for omit staticContextParams on ClientInputEndpointParameters (#8258) (2b7601ed)
      • smithy-aws-typescript-codegen 0.52.0 (#8255) (2e4482a6)
    New Features
    • client-connect: Added Malay language option to use AI to automatically fill evaluation forms in Malay (6f82fc3a)
    • client-sagemaker: Added PREFIX AWARE routing strategy and PrefixAwareRoutingConfig to CreateEndpointConfig. Configure PrefixLength and ConcurrencyThreshold to route requests that share the same prompt prefix to the same instance. (c0ce67e2)
    • client-medialive: Added VirtualSourceAddress to multicast output destinations for MediaLive Anywhere channels. Specifies the source IP address for outbound multicast packets when downstream networks enforce source-IP filtering. (dc24c644)
    • client-elementalinference: Added support for the SearchFixtures API and DataSourceConfiguration, enabling customers to map fixture event data onto clipping outputs for improved feature accuracy. (8a63a39d)
    • client-sagemaker-runtime: Added the PrefixAwareId header to InvokeEndpoint and InvokeEndpointWithResponseStream. This optional parameter serves as a routing hint for endpoints configured with prefix-aware routing, differentiating routing decisions for requests that share the same prompt prefix. (8345d8ef)

    For list of updated packages, view updated-packages.md in assets-3.1107.0.zip

  • 3.1106.0 - 2026-08-07

    3.1106.0(2026-08-07)

    New Features
    • clients: update client endpoints as of 2026-08-07 (c5d05426)
    • client-amplify: Increased the maximum allowed length of the oauthToken parameter in the CreateApp and UpdateApp APIs to support longer OAuth tokens issued by third-party Git providers. (b239e292)
    • client-healthlake: Adds provenanceEnabled to StartFHIRImportJob (18ac6efe)
    • client-securityagent: Added enableEmailMfa input field on Actor to enable email-based MFA during penetration tests. When enabled, a server-generated mfaForwardingAddress is returned. Set up a forwarding rule in your email provider to forward MFA emails to this address so the agent can complete email-based MFA login flows (e21d3919)
    • client-mediapackagev2: StreamNameOutputMode - a new optional field on MediaPackageV2 OriginEndpoints that lets customers choose whether egress manifests use numeric stream indices (default) or encoder-assigned stream names from the input (7f49cb06)
    • client-sagemaker: Amazon SageMaker adds maintenance lifecycle statuses for Notebook Instances (6ce0f884)
    • client-ec2: This release adds support for BGP route protection in Amazon VPC IP Address Manager (IPAM), including route discovery, RPKI route protection findings, and delegated RPKI (Internet Registry Associations, routing policy registrations, and ROA management) for BYOIP prefixes. (62f281df)
    • client-mediatailor: Added support for inserting ads via the VAST Ad Buffet standard. You can now configure MediaTailor to insert ads in sequence order using the AdSequencingMode setting in your playback configuration. Standalone ads are used as fallbacks when a sequenced ad is unavailable. (7bebb1e5)
    • client-connect: Supports updating the task template associated with in-progress task contacts using the new UpdateContactTaskTemplate API. This enables supervisors and developers to dynamically reassign task templates without creating a new task. (24f40416)

    For list of updated packages, view updated-packages.md in assets-3.1106.0.zip

  • 3.1105.0 - 2026-08-06

    3.1105.0(2026-08-06)

    Chores
    • lib-dynamodb: add error msg and fallback when incompatible client is supplied (#8231) (e663d41f)
    New Features
    • clients: update client endpoints as of 2026-08-06 (e4f7b32f)
    • client-cloudwatch-logs: This release adds index category support to the CloudWatch Logs DescribeFieldIndexes API. Customers can filter and identify DEFAULT, CUSTOM, AUTO, and INACTIVE field indexes. (e17fff6f)
    • client-socialmessaging: Add support for WhatsApp Conversions APIs. (5c29a869)
    • client-gamelift: Adds support for C8a, C8i, C9g, M8a, M8i, and M9g EC2 instance type families for managed EC2 and container fleets. Also adds explicit anchors on most string regexes. (30dfd63a)
    • client-securityhub: Security Hub is adding a new public API, ListFreeTrialStatusesV2 to describe the free trial statuses of the Security Hub service and its opt-in features. (e44b3582)
    • client-bedrock-agentcore-control: Add support for Gateway rate limits and Runtime instances in Amazon Bedrock AgentCore. Customers can now configure rate limits scoped to control request rates, token consumption rates, and active connection rates. Customers can now create capacity providers to launch runtimes on their EC2 instances. (865d21ef)
    • client-device-farm: Adds support for service generated insights across runs, jobs, and tests. (6c601b71)
    • client-sagemaker: Releases new Model Customization SequenceLength parameter for Training and g7 instance types for Training and Processing. (14bd2ac7)
    • client-agent-registry-control: Agent Registry's Public Preview release (a137863d)
    • client-backup: AWS Backup now lets you create read-only access points for Amazon S3 recovery points, enabling you to access backup data using S3 APIs without initiating a restore. (636228a9)
    • client-mediatailor: AWS Elemental MediaTailor now supports concurrent function execution. The new Concurrent Executor function type runs multiple independent child functions in parallel within a single lifecycle hook, reducing pipeline latency to the duration of the slowest call instead of the sum of all calls. (1cf61475)
    • client-marketplace-agreement: GetAgreementTerms now returns a new term variant in AcceptedTerm, netPaymentTerm, with a paymentDuePeriod field (example "P30D"). (50b0d6d5)
    • client-agent-registry: Agent Registry's Public Preview release (632ae479)
    • client-kafka: MSK Clusters can now deliver authorizer logs alongside broker logs to the destinations defined by you (b7e31937)
    • client-bedrock-agentcore: Add support for capacity provider sessions in Amazon Bedrock AgentCore. Customers can now delete an active session running on a runtime instance launched through their capacity provider. (bd301533)
    • client-auto-scaling: EC2 Auto Scaling now supports being managed by other AWS services via the operator field. (f5d54fce)
    • client-ec2: Adds a new optional IncludeLocalZones parameter to the Spot Placement Score API that defaults to false. When set to true, the Spot Placement Score API will consider the relevant Local Zones with Spot capacity when computing the Spot Placement Score. (43673842)
    • client-marketplace-discovery: GetOfferTerms now returns netPaymentTerm in offerTerms, specifying payment due period after invoice date. The paymentDuePeriod field uses ISO 8601 duration format (e.g., "P30D" for net 30 days). This is a backward-compatible addition. See API documentation for full structure and examples. (f4fd7ae7)
    • client-s3: AWS Backup now lets you create read-only access points for Amazon S3 recovery points, enabling you to access backup data using S3 APIs without initiating a restore. (faf65602)

    For list of updated packages, view updated-packages.md in assets-3.1105.0.zip

  • 3.1104.0 - 2026-08-05

    3.1104.0(2026-08-05)

    New Features
    • client-deadline: AWS Deadline Cloud now reports persistent volume costs alongside compute and license costs. Customers can view per-fleet storage costs in Usage Explorer by selecting the Usage Type grouping, helping them better understand the costs of their infrastructure. (f6649b9d)
    • client-bedrock-agentcore-control: Adding support for fine-grained access control for AgentCore Memory through managed AgentCore Gateway HTTP Connectors. (448fc0f7)
    • client-glue: Added the PutDataCatalogExportConfiguration to export Glue Data Catalog metadata to systems tables stored in S3 Tables. (31c69446)
    • client-acm-pca: Private Certificate Authority service now supports RSASSA-PSS signing algorithm. (203b57d1)
    • client-ecs: New enum values added for Agent Connectivity issues (13e0f989)

    For list of updated packages, view updated-packages.md in assets-3.1104.0.zip

  • 3.1103.0 - 2026-08-04

    3.1103.0(2026-08-04)

    Chores
    Documentation Changes
    • client-dsql: UpdateCluster now checks the RemovePeerCluster permission on the specific cluster being removed, not a wildcard and docs now clarify how to set kmsEncryptionKey so the cluster uses the AWS-owned key. (473c65ca)
    • client-organizations: Improved accuracy of CloudTrail event documentation for AWS Organizations membership operations. (263633e3)
    New Features
    • client-iam: Updating endpoint generation logic (4f3cb1da)
    • client-partnercentral-selling: Partners can now create leads with only 5 required fields and free-text values for all other fields, reducing import friction. Engagement invitations now include enrichment data (propensity scores, lead readiness) directly in the response. (108bdedc)
    • client-workspaces: Added ClientExperiencePolicy to ClientProperties object for ModifyClientProperties and DescribeClientProperties APIs. (c05ebd0e)
    • client-connect: Amazon Connect Customer now supports up to 50 attachments per email, increased from the previous limit of 10. The individual maximum attachment size limit of 20 MB and the total email size limit of 25 MB still hold true. (a0b556cb)
    • client-ec2: Amazon EC2 now supports Application Status Checks, a new status check that monitors your application's health through configurable HTTP(S) paths and ports, so you can detect and automatically respond to application-level impairments. (b66fadca)
    • client-inspector2: Adding Azure SBOM export capability. (c8824ff2)
    • client-sso-admin: AWS IAM Identity Center now lets you create organization-level instances without enabling multi-account permissions. You can enable multi-account permissions during instance creation or later via console or API, which then provisions the necessary service-linked roles. (97c52b6c)
    • client-dynamodb: Vector indexes are a type of index in Amazon DynamoDB that enable similarity search on vector embedding stored in your table items. Vector indexes use approximate nearest neighbor search to find items whose vectors are most similar to a query vector that you provide. (3b4460cb)
    Bug Fixes

    For list of updated packages, view updated-packages.md in assets-3.1103.0.zip

  • 3.1102.0 - 2026-08-03

    3.1102.0(2026-08-03)

    Chores
    • scripts: add api-extractor.json validation for packages with public annotations (#8242) (77c1c5c0)
    • core/protocols: switch to v2 JSON codecs (#8234) (54c1c236)
    Documentation Changes
    • client-wafv2: Updated descriptions for number of PreParseTextTransformations allowed per rule statement (b2440c3b)
    • checksums: populate readme with package overview (#8243) (353e67dd)
    New Features
    • client-direct-connect: Added route visibility support for AWS Direct Connect, allowing customers to call ListVirtualInterfaceRoutes to view the BGP routes including AS path and BGP communities advertised over their virtual interfaces. (12675348)
    • client-mediaconvert: Updates Kantar server URL validation to accept Fifty5Blue domain. Adds support for output to S3 Glacier Instant Retrieval. (01860cb3)
    • client-network-firewall: This launch allows customers to use Network Firewall as an explicit Proxy and protect their workloads against threat of data exfiltration. (46a686e2)
    • client-eks-auth: Added eksNodeName, instanceId, and zone optional parameters to the AssumeRoleForPodIdentity API. (bbb99c9a)
    • client-observabilityadmin: Launch CMK support for Telemetry Enablement Organization and Account Rules. (d6dcfbd3)
    • client-timestream-influxdb: This release adds support for customer-managed backup restore, and encryption of new DbInstances and DbClusters using customer-managed KMS keys. (8eb57639)
    Bug Fixes
    • credential-provider-login: always read token from disk (#8216) (5caf21f6)
    • core/protocols: document and number serialization fixes (#8245) (71d43842)

    For list of updated packages, view updated-packages.md in assets-3.1102.0.zip

  • 3.1101.0 - 2026-07-31

    3.1101.0(2026-07-31)

    New Features
    • client-resiliencehubv2: Adding support for new testing capability in AWS Resilience Hub. (105876ce)
    • client-cloudwatch-logs: Amazon CloudWatch Logs now lets you create and update lookup tables directly from CloudWatch Logs query results by passing a queryId, and configure a lookup table as a scheduled query destination so it refreshes automatically with the latest query results on each run. (6f5f75a0)
    • client-network-firewall: Doc Updates for Container Attributes (82107b32)
    • client-billing: Adds GetEnterpriseSupportChargeSummary, GetEnterpriseSupportContractDetails, and ListEnterpriseSupportLinkedAccountCharges. These APIs provide first-time programmatic access to billing data for Enterprise Support usage previously only available upon request through AWS Concierge or Support. (643d01c5)
    • client-quicksight: Adding TopicV2 management APIs, adding possibility to use Topics in Analysis (087bb505)
    • client-connectcampaignsv2: Launching feature for abandonment rate pacing control for outbound campaigns. (fbb8c225)
    • client-amp: Amazon Managed Service for Prometheus adds support for an Amazon OpenSearch Service exporter for managed collectors. (d9c634a8)
    • client-elementalinference: AWS Elemental Inference now supports graphic composition on cropped video outputs, enabling branded graphics and other visual elements to be overlaid as part of the inference workflow. (b9116f87)
    • client-rds: Adds StorageOperationStatus and StorageOperationPercentProgress to DescribeDBInstances, letting you monitor RDS storage initialization and optimization progress. (842d1779)
    • client-datazone: Adding support for enhanced Git experience in Sagemaker Unified Studio. (e5fcea3c)
    • client-transcribe-streaming: This release adds a new optional TranscriptFormat parameter to the Amazon Transcribe streaming API, letting customers select spoken or written form for numeric and formatted output. (5808fd5c)
    • client-bedrock-runtime: Added support for mid-conversation tool changes in the Amazon Bedrock Converse and ConverseStream APIs (8f29d856)
    • client-cloudformation: Adding enum for sensitive property to DriftIgnoredReason (ce2fa95d)
    • client-marketplace-catalog: This release enhances the ListEntities API to support TargetAgreementId, TargetAgreementIntent, and CreatedBySource filters for the Offer entity type. (550b6cf0)
    • client-outposts: Adds the "EKS" value to the AWSServiceName enum and marks the Address field as sensitive. (65dd1932)

    For list of updated packages, view updated-packages.md in assets-3.1101.0.zip

  • 3.1100.0 - 2026-07-31

    3.1100.0(2026-07-31)

    Chores
    • add packages-internal to root tsconfig inclusion (#8240) (a0f3fb58)
    New Features
    • clients: update client endpoints as of 2026-07-31 (30d44c7e)
    • client-bcm-pricing-calculator: Removing Smithy RPC v2 CBOR support that was added in previous SDK release. (edce242c)
    • client-bcm-recommended-actions: Removing Smithy RPC v2 CBOR support that was added in previous SDK release. (7bed97ab)
    Bug Fixes
    • core/protocols: v2 JSON codec updates and JsonBytesStringAdapter (#8238) (a1001f4b)
    Tests

    For list of updated packages, view updated-packages.md in assets-3.1100.0.zip

  • 3.1099.0 - 2026-07-30

    3.1099.0(2026-07-30)

    Chores
    New Features
    • clients: update client endpoints as of 2026-07-30 (e93ec43a)
    • client-pricing-plan-manager: Adds support for Public PricingPlanManager SDK (f5af47b6)
    • client-securityagent: Adds support for providing a branch override when configured integrated repositories (0f5a2dd0)
    • client-iam: Improved IAM Policy Simulator accuracy. Simulator now evaluates SCP conditions and resource scoping, returns explicitDeny for explicit SCP denials, and reports accurate cross-account decisions. (d8cd86e4)
    • client-network-firewall: Adds UPDATING field to Container Association Status (65a8fd3f)
    • client-kafka: Amazon MSK Express brokers now support streaming tables for Apache Iceberg, continuously materializing Apache Kafka topics as Iceberg tables in Amazon S3 Tables. Express brokers also now support data delivery to Amazon S3 general purpose buckets. (16236255)
    • client-lambda: Add Python3.15 (python3.15) and NodeJs 26 (nodejs26.x) support to AWS Lambda (e9cf5069)
    • client-sagemaker: Adds support for g7 family instance types for SageMaker Studio JupyterLab and CodeEditor apps for IAD (us-east-1), PDX (us-west-2), CMH (us-east-2). (5e4ec9ce)
    • client-bedrock-agentcore-control: Adds support for configuring models through the OpenResponses API for custom evaluators. CreateEvaluator and UpdateEvaluator now accept an OpenResponses model configuration for LLM-as-a-Judge evaluations. (9cfbf372)

    For list of updated packages, view updated-packages.md in assets-3.1099.0.zip

  • 3.1098.0 - 2026-07-29
  • 3.1097.0 - 2026-07-28
  • 3.1096.0 - 2026-07-27
  • 3.1095.0 - 2026-07-24
  • 3.1094.0 - 2026-07-23
  • 3.1093.0 - 2026-07-22
  • 3.1092.0 - 2026-07-21
  • 3.1091.0 - 2026-07-20
  • 3.1090.0 - 2026-07-17
  • 3.1089.0 - 2026-07-16
  • 3.1088.0 - 2026-07-15
  • 3.1087.0 - 2026-07-14
  • 3.1086.0 - 2026-07-13
  • 3.1085.0 - 2026-07-10
  • 3.1084.0 - 2026-07-09
  • 3.1083.0 - 2026-07-08
  • 3.1082.0 - 2026-07-08
  • 3.1081.0 - 2026-07-07
  • 3.1080.0 - 2026-07-06
  • 3.1079.0 - 2026-07-02
  • 3.1078.0 - 2026-07-01
  • 3.1077.0 - 2026-06-30
  • 3.1076.0 - 2026-06-29
  • 3.1075.0 - 2026-06-23
  • 3.1074.0 - 2026-06-22
  • 3.1073.0 - 2026-06-19
  • 3.1072.0 - 2026-06-18
  • 3.1071.0 - 2026-06-17
  • 3.1070.0 - 2026-06-16
  • 3.1069.0 - 2026-06-15
  • 3.1068.0 - 2026-06-12
  • 3.1067.0 - 2026-06-11
  • 3.1066.0 - 2026-06-10
  • 3.1065.0 - 2026-06-09
  • 3.1064.0 - 2026-06-08
  • 3.1063.0 - 2026-06-05
  • 3.1062.0 - 2026-06-04
  • 3.1061.0 - 2026-06-03
  • 3.1060.0 - 2026-06-03
  • 3.1059.0 - 2026-06-02
  • 3.1058.0 - 2026-06-01
  • 3.1057.0 - 2026-05-29
  • 3.1056.0 - 2026-05-28
  • 3.1055.0 - 2026-05-27
  • 3.1054.0 - 2026-05-26
  • 3.1053.0 - 2026-05-22
  • 3.1052.0 - 2026-05-21
  • 3.1051.0 - 2026-05-20
  • 3.1050.0 - 2026-05-19
  • 3.1049.0 - 2026-05-18
  • 3.1048.0 - 2026-05-15
  • 3.1047.0 - 2026-05-14
  • 3.1046.0 - 2026-05-14
  • 3.1045.0 - 2026-05-07
from @aws-sdk/lib-storage GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade @aws-sdk/lib-storage from 3.1045.0 to 3.1108.0.

See this package in npm:
@aws-sdk/lib-storage

See this project in Snyk:
https://app.snyk.io/org/macpro-macpro/project/d1f8f5ab-b938-4566-b8b4-7da03a27789e?utm_source=github&utm_medium=referral&page=upgrade-pr
@macpro-snyk-service-account

Copy link
Copy Markdown
Collaborator Author

Merge Risk: Low

This is a minor version upgrade for the AWS SDK for JavaScript v3's lib-storage package. The changes between versions 3.1045.0 and 3.1108.0 consist of routine updates, bug fixes, and dependency bumps. No breaking changes are documented for this version range. The upgrade is considered safe and does not require any code modifications.

Source: AWS SDK for JavaScript v3 Releases

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@macpro-snyk-service-account

macpro-snyk-service-account commented Sep 2, 2026

Copy link
Copy Markdown
Collaborator Author

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

Status Category Percentage Covered / Total
🔴 Lines 88.68% (🎯 90%)
⬆️ +0.07%
10354 / 11675
🔴 Statements 88.35% (🎯 90%)
⬆️ +0.08%
11051 / 12508
🟢 Functions 86.15% (🎯 85%)
⬆️ +0.10%
2625 / 3047
🔴 Branches 77.45% (🎯 80%)
⬆️ +0.01%
6470 / 8353
File CoverageNo changed files found.
Generated in workflow #4966 for commit 89de184 by the Vitest Coverage Report Action

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants