Skip to content

Conversation

@parseplatformorg
Copy link
Contributor

@parseplatformorg parseplatformorg commented May 29, 2025

snyk-top-banner

Snyk has created this PR to upgrade @aws-sdk/client-s3 from 3.779.0 to 3.806.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 11 versions ahead of your current version.

  • The recommended version was released 21 days ago.

Release notes
Package name: @aws-sdk/client-s3
  • 3.806.0 - 2025-05-08

    3.806.0(2025-05-08)

    Chores
    • deps: pass signing name to env credential provider (#7064) (801cece8)
    • clients: populate logger in loaderConfig (#7061) (48bdda33)
    Documentation Changes
    • client-guardduty: Updated description of a data structure. (c9ce9447)
    • client-cloudfront: Doc-only update for CloudFront. These changes include customer-reported issues. (5a23f2f5)
    New Features
    • clients: update client endpoints as of 2025-05-08 (ece09fe8)
    • client-sso-admin: Update PutPermissionBoundaryToPermissionSet API's managedPolicyArn pattern to allow valid ARN only. Update ApplicationName to allow white spaces. (bc0de81a)
    • client-ec2: Launching the feature to support ENA queues offering flexibility to support multiple queues per Enhanced Network Interface (ENI) (b9b5b6ce)
    • client-glue: This new release supports customizable RefreshInterval for all Saas ZETL integrations from 15 minutes to 6 days. (d6e00491)
    • client-codepipeline: Add support for Secrets Manager and Plaintext environment variable types in Commands action (753bf4e0)
    Bug Fixes
    • codegen: allow overwriting protocol priority order (#7066) (dc4edaa0)
    Tests
    • client-s3: integration for config 'authSchemePreference' (#7063) (49c6f99d)

    For list of updated packages, view updated-packages.md in assets-3.806.0.zip

  • 3.804.0 - 2025-05-06

    3.804.0(2025-05-06)

    Chores
    New Features
    • clients: update client endpoints as of 2025-05-06 (c5846edd)
    • client-timestream-write: Add dualstack endpoints support. (22b258a0)
    • client-service-catalog: ServiceCatalog's APIs (DeleteServiceAction, DisassociateServiceActionFromProvisioningArtifact, AssociateServiceActionWithProvisioningArtifact) now throw InvalidParametersException when IdempotencyToken is invalid. (bb75d640)
    • client-ec2: This release adds support for Amazon EBS Provisioned Rate for Volume Initialization, which lets you specify a volume initialization rate to ensure that your EBS volumes are initialized in a predictable amount of time. (03ae3280)
    • client-timestream-query: Add dualstack endpoints support and correct us-gov-west-1 FIPS endpoint. (9ff8904c)

    For list of updated packages, view updated-packages.md in assets-3.804.0.zip

  • 3.803.0 - 2025-05-05

    3.803.0(2025-05-05)

    Chores
    Documentation Changes
    • client-ecs: Add support to roll back an In_Progress ECS Service Deployment (28c0e82d)
    New Features
    • clients: update client endpoints as of 2025-05-05 (ba7c2bf2)
    • client-device-farm: Add an optional parameter to the GetDevicePoolCompatibility API to pass in project information to check device pool compatibility. (4c93f9a6)
    • client-ec2: This update introduces API operations to manage and create local gateway VIF and VIF groups. It also includes API operations to describe Outpost LAGs and service link VIFs. (0332513e)
    • client-datazone: This release adds a new authorization policy to control the usage of custom AssetType when creating an Asset. Customer can now add new grant(s) of policyType USE_ASSET_TYPE for custom AssetTypes to apply authorization policy to projects members and domain unit owners. (c23b2fb7)
    • client-mediaconvert: This release adds an optional sidecar per-frame video quality metrics report and an ALL_PCM option for audio selectors. It also changes the data type for Probe API response fields related to video and audio bitrate from integer to double. (c8dc7731)
    Tests
    • signature-v4-multi-region: long-lived resources for cfkvs sigv4a e2e test (#7050) (b66091ba)

    For list of updated packages, view updated-packages.md in assets-3.803.0.zip

  • 3.802.0 - 2025-05-02

    3.802.0(2025-05-02)

    Chores
    Documentation Changes
    • client-directory-service: Doc only update - fixed typos. (b15810ac)
    New Features
    • clients: update client endpoints as of 2025-05-02 (bdc8944d)
    • client-kinesis: Marking ResourceARN as required for Amazon Kinesis Data Streams APIs TagResource, UntagResource, and ListTagsForResource. (9edf14f4)
    • client-bedrock-data-automation: Added support for Custom output and blueprints for AUDIO data types. (2591cbd2)

    For list of updated packages, view updated-packages.md in assets-3.802.0.zip

  • 3.800.0 - 2025-04-30

    3.800.0(2025-04-30)

    New Features
    • clients: update client endpoints as of 2025-04-30 (b45461a5)
    • client-bedrock-agent: Features: Add inline code node to prompt flow (7bc9fdef)
    • client-mailmanager: Introducing new RuleSet rule PublishToSns action, which allows customers to publish email notifications to an Amazon SNS topic. New PublishToSns action enables customers to easily integrate their email workflows via Amazon SNS, allowing them to notify other systems about important email events. (7606fc03)
    • client-bedrock-agent-runtime: Support for Custom Orchestration within InlineAgents (a4195f7a)
    • client-bedrock: You can now specify a cross region inference profile as a teacher model for the CreateModelCustomizationJob API. Additionally, the GetModelCustomizationJob API has been enhanced to return the sub-task statuses of a customization job within the StatusDetails response field. (1325ef07)
    • client-ec2: Launch of cost distribution feature for IPAM owners to distribute costs to internal teams. (69fe6453)
    • client-deadline: Adds support for tag management on workers and tag inheritance from fleets to their associated workers. (7283ff56)
    • client-ecr: Adds dualstack support for Amazon Elastic Container Registry (Amazon ECR). (e2fb477e)
    • client-cleanrooms: This release adds support for ProtectedQuery results to be delivered to more than one collaboration member via the new distribute output configuration in StartProtectedQuery. (f6a809d8)
    • client-cloudwatch-logs: CloudWatch Logs supports "DELIVERY" log class. This log class is used only for delivering AWS Lambda logs to Amazon S3 or Amazon Data Firehose. (e89084d3)
    • client-ecr-public: Adds dualstack support for Amazon Elastic Container Registry Public (Amazon ECR Public). (2a08ba6a)
    Tests
    • signature-v4-multi-region: use long-lived resources for sigv4a events test (#7039) (2bd6ec20)

    For list of updated packages, view updated-packages.md in assets-3.800.0.zip

  • 3.799.0 - 2025-04-29

    3.799.0(2025-04-29)

    Chores
    • clients: populate default values for auth scheme preference (#7038) (093005b6)
    • core: add Auth Scheme Preference config selector (#7037) (594c19cf)
    New Features
    • clients: update client endpoints as of 2025-04-29 (b8fecfa9)
    • client-kinesis: Amazon KDS now supports tagging and attribute-based access control (ABAC) for enhanced fan-out consumers. (942b6932)
    • client-sagemaker: Introduced support for P5en instance types on SageMaker Studio for JupyterLab and CodeEditor applications. (219315ab)
    • client-ssm-guiconnect: This release adds API support for the connection recording GUI Connect feature of AWS Systems Manager (e5810670)
    • client-connectcases: Introduces CustomEntity as part of the UserUnion data type. This field is used to indicate the entity who is performing the API action. (9ee87df4)
    • client-qbusiness: Add support for anonymous user access for Q Business applications (6197c7b9)
    • client-pinpoint-sms-voice-v2: AWS End User Messaging has added MONITOR and FILTER functionality to SMS Protect. (73c2247e)
    • client-sagemaker-metrics: SageMaker Metrics Service now supports FIPS endpoint in all US and Canada Commercial regions. (08cb9ed3)
    • client-ssm: This release adds support for just-In-time node access in AWS Systems Manager. Just-in-time node access enables customers to move towards zero standing privileges by requiring operators to request access and obtain approval before remotely connecting to nodes managed by the SSM Agent. (ac4a855e)

    For list of updated packages, view updated-packages.md in assets-3.799.0.zip

  • 3.798.0 - 2025-04-28

    3.798.0(2025-04-28)

    Chores
    • deps: resolve auth schemes based on the preference list (#7036) (d01fbaab)
    Documentation Changes
    • client-dynamodb: Doc only update for GSI descriptions. (f6404915)
    New Features
    • clients: update client endpoints as of 2025-04-28 (1deb7c6f)
    • client-cloudfront: Add distribution tenant, connection group, and multi-tenant distribution APIs to the CloudFront SDK. (fcac15c6)
    • client-acm: Add support for file-based HTTP domain control validation, available through Amazon CloudFront. (3d9e3195)
    • client-imagebuilder: Add integration with SSM Parameter Store to Image Builder. (d20379b6)
    • client-bedrock-runtime: This release adds native h2 support for the bedrock runtime API, the support is only limited to SDKs that support h2 requests natively. (3c9a8946)
    • signature-v4-multi-region: add support for sigv4a package (#6267) (ecbba9f6)

    For list of updated packages, view updated-packages.md in assets-3.798.0.zip

  • 3.797.0 - 2025-04-25
  • 3.796.0 - 2025-04-24
  • 3.787.0 - 2025-04-10
  • 3.782.0 - 2025-04-03
  • 3.779.0 - 2025-03-31
from @aws-sdk/client-s3 GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Summary by CodeRabbit

  • Chores
    • Updated the "@aws-sdk/client-s3" dependency to the latest version to ensure improved stability and compatibility.

Snyk has created this PR to upgrade @aws-sdk/client-s3 from 3.779.0 to 3.806.0.

See this package in npm:
@aws-sdk/client-s3

See this project in Snyk:
https://app.snyk.io/org/acinader/project/3364151b-9c9a-4458-9afd-809dc5309438?utm_source=github&utm_medium=referral&page=upgrade-pr
@parse-github-assistant
Copy link

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant bot changed the title [Snyk] Upgrade @aws-sdk/client-s3 from 3.779.0 to 3.806.0 refactor: Upgrade @aws-sdk/client-s3 from 3.779.0 to 3.806.0 May 29, 2025
@parse-github-assistant
Copy link

🚀 Thanks for opening this pull request!

@coderabbitai
Copy link

coderabbitai bot commented May 29, 2025

📝 Walkthrough

Walkthrough

The dependency "@aws-sdk/client-s3" was updated from version 3.779.0 to 3.806.0 in the package.json file. No other dependencies or parts of the file were changed.

Changes

File Change Summary
package.json Bumped "@aws-sdk/client-s3" from 3.779.0 to 3.806.0

Sequence Diagram(s)

No sequence diagram generated as the change is limited to a dependency version update.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@parseplatformorg
Copy link
Contributor Author

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

@codecov
Copy link

codecov bot commented May 29, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 97.18%. Comparing base (f98893a) to head (a84170a).
Report is 7 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #262   +/-   ##
=======================================
  Coverage   97.18%   97.18%           
=======================================
  Files           2        2           
  Lines         213      213           
=======================================
  Hits          207      207           
  Misses          6        6           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
package.json (1)

22-22: Ensure lockfile regeneration and version alignment.

Please regenerate and commit the lockfile (package-lock.json/yarn.lock) after this bump, and run the full test suite to verify compatibility with @aws-sdk/[email protected]. Also consider aligning @aws-sdk/s3-request-presigner to 3.806.0 to avoid mismatched AWS SDK versions:

-    "@aws-sdk/s3-request-presigner": "3.787.0"
+    "@aws-sdk/s3-request-presigner": "3.806.0"
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between f98893a and a84170a.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json (1 hunks)

@mtrezza mtrezza merged commit c6272b4 into master May 29, 2025
10 checks passed
@mtrezza mtrezza deleted the snyk-upgrade-b68ee3f3c3ee9db3c5389793865274d4 branch May 29, 2025 20:29
@parseplatformorg
Copy link
Contributor Author

🎉 This change has been released in version 4.1.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants