Skip to content

chore(deps): npm: bump the all-npm group across 4 directories with 40 updates - #716

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/all-npm-9cb530530c
Open

chore(deps): npm: bump the all-npm group across 4 directories with 40 updates#716
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/all-npm-9cb530530c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-npm group with 37 updates in the / directory:

Package From To
@astrojs/check 0.9.9 0.9.10
knip 6.23.0 6.29.0
@aws-sdk/client-bedrock-agentcore 3.1081.0 3.1097.0
@aws-sdk/client-bedrock-runtime 3.1081.0 3.1097.0
@aws-sdk/client-dynamodb 3.1078.0 3.1097.0
@aws-sdk/client-ecs 3.1081.0 3.1097.0
@aws-sdk/client-lambda 3.1081.0 3.1097.0
@aws-sdk/client-s3 3.1081.0 3.1097.0
@aws-sdk/client-secrets-manager 3.1078.0 3.1097.0
@aws-sdk/lib-dynamodb 3.1078.0 3.1097.0
@aws-sdk/s3-presigned-post 3.1081.0 3.1097.0
@aws-sdk/s3-request-presigner 3.1081.0 3.1097.0
@aws/durable-execution-sdk-js 2.1.0 2.2.0
@smithy/protocol-http 5.5.6 5.5.15
aws-cdk-lib 2.261.0 2.262.1
cdk-nag 2.38.2 3.0.1
constructs 10.6.0 10.7.1
ws 8.21.0 8.21.1
@aws-cdk/integ-runner 2.202.1 2.203.2
@cdklabs/eslint-plugin 2.0.13 2.0.16
@types/node 26.1.0 26.1.2
@typescript-eslint/eslint-plugin 8.63.0 8.65.0
@typescript-eslint/parser 8.63.0 8.65.0
aws-cdk 2.1129.0 2.1133.0
eslint 10.6.0 10.8.0
eslint-plugin-jest 29.15.4 29.16.0
eslint-plugin-jsdoc 63.0.12 63.3.2
ts-jest 29.4.11 29.4.12
typescript 6.0.3 7.0.2
@aws-sdk/client-bedrock 3.1078.0 3.1097.0
@aws-sdk/client-bedrock-agentcore-control 3.1078.0 3.1097.0
@aws-sdk/client-cloudformation 3.1078.0 3.1097.0
@aws-sdk/client-cognito-identity-provider 3.1078.0 3.1097.0
commander 14.0.3 15.0.0
@astrojs/starlight 0.41.3 0.41.5
astro 7.1.3 7.1.5
markdown-link-check 3.14.2 3.15.0

Bumps the all-npm group with 4 updates in the /cdk directory: cdk-nag, js-yaml, @aws-cdk/integ-runner and typescript.
Bumps the all-npm group with 9 updates in the /cli directory:

Package From To
@aws-sdk/client-dynamodb 3.1078.0 3.1097.0
@aws-sdk/client-secrets-manager 3.1078.0 3.1097.0
@aws-sdk/lib-dynamodb 3.1078.0 3.1097.0
typescript 6.0.3 7.0.2
@aws-sdk/client-bedrock 3.1078.0 3.1097.0
@aws-sdk/client-bedrock-agentcore-control 3.1078.0 3.1097.0
@aws-sdk/client-cloudformation 3.1078.0 3.1097.0
@aws-sdk/client-cognito-identity-provider 3.1078.0 3.1097.0
commander 14.0.3 15.0.0

Bumps the all-npm group with 2 updates in the /docs directory: typescript and astro.

Updates @astrojs/check from 0.9.9 to 0.9.10

Release notes

Sourced from @​astrojs/check's releases.

@​astrojs/check@​0.9.10

Patch Changes

Changelog

Sourced from @​astrojs/check's changelog.

0.9.10

Patch Changes

Commits

Updates knip from 6.23.0 to 6.29.0

Release notes

Sourced from knip's releases.

Release 6.29.0

  • fix(glob): do not follow symbolic links in async glob (#1900) (b7d5ce2f545d91953a97733aa1567e8728b20644) - thanks @​mogelbrod!
  • Add built-in compiler for tsrx (db05e0142a41fad2ad45d62ba5106e0d97c92b45)
  • Fix -u shortcut for --duration (932b9262af275d209923a5efab1b6f23067bb006)

Release 6.28.0

  • Update oxc-resolver (resolve #1889) (1444f6aaf04d42ad07ee0b88da4dfae0e116043a)
  • Keep entry-exported members public (resolve #1890) (94967c13a589a7e83408b1495c31323ac126fcab)
  • Don't un-ignore sibling paths on unrelated gitignore negations (resolve #1891) (5c026ba50c1e89804fc5094a52dc4c4c37d92bc2)
  • Memoize the gitignore shadowed-pattern check (a5fa3b0ebb7f84c107dba1c1ca9a9b73995f668f)
  • Ignore nested files under a gitignore dir/* pattern (404a53e3e49fa7c1f51b60bcb30ea50450f75aab)
  • Track types referenced by JSDoc imports (resolve #1888) (6ae48aadbe03952690c8608e6df42bd039cf6624)
  • Update oxc-parser (02ca17a72c3f0afa7df32297d2dd2f5463ac6e00)
  • feat: markdownlint-cli2 (#1887) (323b96f55b38b53f5e4648d72fecd968fae35147) - thanks @​Zamiell!
  • Update rolldown snapshot (009e509dee6a5013fd3937abb4ec81684601b023)
  • Resolve $GITHUB_ACTION_PATH in GHA composite actions (ead489f066733f701acfe5b81eac0a6c813fb5c5)
  • Don't report node: specifiers as unlisted dependencies (1a7114f0a159fe82328041e11fc61c5c1730cc01)
  • Discover tsdown CLI entries (0d47a45bfc518a7bf73a4b4878aeab236d6f9791)
  • Discover Convex function modules (e01f21c44773186e7ad74e7badf9fc81b82edfb5)
  • Ignore common system binaries (cd003065fda5422550a412bba07ebbb1f9bae126)
  • Add OpenClaw plugin (73a2d7dd45f65ea312fde38cb4fa4f5a4fc34bf2)
  • Discover Tailwind CLI input stylesheet (resolve #1551) (9ae5feed922ecb7e8c436545e9b45125bd73b457)
  • Discover Angular global stylesheets from angular.json (fb9e0488f6f21284714d0651fcf1dd2de02d425a)
  • Hint when project patterns exclude a compiled extension (74de516d3d73839536fc2a43c2c0ec38a6299631)
  • Ignore common global binaries (a99a206015fe414a4de12016cc62499910afaf6f)
  • Run multiple preprocessors in sequence (844358367e9d1939bbf47f8dcb97d810741f56c1)
  • fix(nuxt): resolve nuxt module paths (#1896) (3c8594f5ffc641b00575b6d7455990db1277ac75) - thanks @​danielroe!
  • Report unused re-exports when ignoreExportsUsedInFile is set (#1895) (a113a5f4eedc81ef56b00a3e488cc94febefede5) - thanks @​mlm20!
  • Pass -w to pnpm add in sentry ecosystem test (ea8c8ac6fe9519f00ca6a61131b345f5de521704)
  • Update sentry snapshot (b75768d544d9f869ebce8f8c6dd8490f3db87023)
  • Record all traversed dirs in glob cache (resolve #1897) (81be1d436eae15518df764cbcb443899e11a9569)
  • Invalidate glob cache when .gitignore changes (baff301f2dceda97bf8bf73809d811cc44c72c8c)
  • Improve Nuxt and Nitro plugin resolution (86ffab7bcdd095631d6b0b17254e8acd6b5022bc)
  • fix: don't treat [-]-c[heck] as config flag for prettier (#1902) (b7266ee8240a9b8686e91a44a4706d3605d094c4) - thanks @​davidkna-sap!
  • Use Entra ID to publish VS Code extension (4236253482f884d92cfde2ccf85c7fb9aca17f7e)
  • Remove obsolete trust policy exclusions (630d5f9835f4303ec9aa7d090ad40a177808c4fb)
  • Update dependencies (810147b5aa21bb57ad103fd19ba92844e42cd84c)
  • Migrate from typescript/native-preview to typescript (140a25a577a64273a7a77f2ff2c8f224118ac298)

Release 6.27.0

  • Add Temporal plugin (98191a04aad0572bead191b101bfecef75067b0c)
  • Handle -d alias for react-email dir argument (53d1fec3213db8d6a84dfa7a82050b122782e065)
  • Expand pnpm script references with forwarded arguments (33e9799df39450033061b9c4c07daf22f5d15721)
  • Treat path-shaped script tokens as file references, extend known global binaries (d9508c282ab81351beda4b2f859435b49f142c51)
  • Mark tsdown neverBundle dependencies as referenced (5fd863ba12e68842f91ab1a94e7e30d1e571da92)
  • Support TanStack Start in tanstack-router plugin (bd63cd8af88dac03a98aa17f1add322f7bdf4a94)
  • Mark vite ssr.external dependencies as referenced (91de938032062cb667bced0eadef9e67d1e20b1f)
  • Expand bun, npm, and yarn script references with forwarded arguments (b5a31767a83e2cec3fb20c3b146d94c0412a4fd6)
  • Add Latitude as sponsor (42676759cad5fb10ac96fd7c0457037e906f4b68)
  • Regenerate plugin list in docs (1d2cdffb4d4151f848c44e066eff43e9efbf44fe)

... (truncated)

Commits
  • d9a6fe0 Release knip@6.29.0
  • 932b926 Fix -u shortcut for --duration
  • db05e01 Add built-in compiler for tsrx
  • b7d5ce2 fix(glob): do not follow symbolic links in async glob (#1900)
  • fc16b38 Release knip@6.28.0
  • 140a25a Migrate from typescript/native-preview to typescript
  • 810147b Update dependencies
  • b7266ee fix: don't treat [-]-c[heck] as config flag for prettier (#1902)
  • 86ffab7 Improve Nuxt and Nitro plugin resolution
  • baff301 Invalidate glob cache when .gitignore changes
  • Additional commits viewable in compare view

Updates @aws-sdk/client-bedrock-agentcore from 3.1081.0 to 3.1097.0

Release notes

Sourced from @​aws-sdk/client-bedrock-agentcore's releases.

v3.1097.0

3.1097.0(2026-07-28)

Chores
Documentation Changes
  • client-connect: Documentation updates for SearchRules, AssociateRoutingProfileQueues, CreateRoutingProfile, AssociateContactWithUser CreateTaskTemplate, and UpdateTaskTemplate (c87ac126)
  • client-datasync: Adds Enhanced mode support for EFS and FSx Lustre locations without an agent, and for HDFS (TDE), Azure Blob, and object storage locations with an agent. HDFS Enhanced mode supports multiple NameNodes for High Availability. Enhanced mode agents can now be deployed on Microsoft Hyper-V. (5ef349f0)
New Features
  • client-trustedadvisor: Adds ListRecommendationsForResource API and four CheckSummary fields (resourceArnQueryable, awsResourceTypes, checkGranularity, recommendationId) to retrieve recommendations for a given resource ARN. (16e67f16)
  • client-rolesanywhere: Increases certificate string length for trust anchor source data to support new adjustable trust anchor limits. (20c913fd)
  • client-bedrock-agentcore-control: AgentCore Identity now supports Private Key JWT client authentication for OAuth 2.0 credential providers. Agents can authenticate to identity provider token endpoints with a JWT client assertion signed by a customer-managed AWS KMS asymmetric key, eliminating the need for client secrets. (fa2b1a0a)

For list of updated packages, view updated-packages.md in assets-3.1097.0.zip

v3.1096.0

3.1096.0(2026-07-27)

New Features
  • clients: update client endpoints as of 2026-07-27 (24e536ee)
  • client-bcm-data-exports: With this release, customers can configure their data exports to deliver CSV reports in ZIP compressed format. (bf6df63c)
  • client-glue: Adds BatchGetDataQualityRulesetEvaluationRun API to retrieve multiple runs in one call, ObservationScope and ObservationMode parameters for anomaly detection, writing evaluation results to Data Catalog tables, and custom log group paths for recommendation runs. (70d8b71e)
  • client-sagemaker: This release adds LoRA adapters, training plans, and new instance types to SageMaker inference optimization. CreateAIRecommendationJob accepts optional AdapterSource and CreateOptimizationJob accepts optional TrainingPlanArns and the ml.g7e and ml.p6-b200 families. (587c6437)
  • client-account: This release adds support for the GetPrimaryEmailUpdateStatus API operation, which allows customers to retrieve the current status of a primary email address update request for an AWS account. The operation returns status information including whether the update is pending, completed, or failed. (d633065c)
  • client-quicksight: Added new Governance fields to Custom Permissions API to support Deny By Default functionality. (730d4716)
  • client-cleanrooms: This release adds support for the CR.8X worker type for SQL (32 vCPU) (4c532188)
  • client-emr-containers: With this launch, you can now set concurrent job limits on a virtual cluster, giving you fine-grained control over how many job runs execute at once and how many can wait in queue. (b6c745a4)
  • client-securityagent: AWS Security Agent adds a new task hours field that reflects the active work done for a task. (6419f793)
  • client-partnercentral-account: Adds optional headquarters location to StartProfileUpdateTask, letting partners record their headquarters as an ISO 3166 country and subdivision code on their profile. When headquarters is provided, both the country and subdivision codes are required. (db69aaa7)
  • client-cleanroomsml: This release adds support for the CR.8X worker type for SQL (32 vCPU) (bcabd86a)
Bug Fixes
  • core/protocols: handle JSON exponent notation in jsonReviver (#8226) (c3b27fd3)

For list of updated packages, view updated-packages.md in assets-3.1096.0.zip

v3.1095.0

... (truncated)

Changelog

Sourced from @​aws-sdk/client-bedrock-agentcore's changelog.

3.1097.0 (2026-07-28)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

3.1096.0 (2026-07-27)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

3.1095.0 (2026-07-24)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

3.1094.0 (2026-07-23)

Features

  • client-bedrock-agentcore: Adds support for the Bring Your Own Storage(BYOS) feature in AgentCore Browser and Code Interpreter. Enables mounting S3Files and EFS File Systems via Access points. (a689531)

3.1093.0 (2026-07-22)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

3.1092.0 (2026-07-21)

Note: Version bump only for package @​aws-sdk/client-bedrock-agentcore

... (truncated)

Commits
  • b24cb22 Publish v3.1097.0
  • 1b94f0b Publish v3.1096.0
  • 753d651 Publish v3.1095.0
  • bb564e5 chore(codegen): sync for CBOR large map deser, event-streams exceptions, endp...
  • c379112 Publish v3.1094.0
  • a689531 feat(client-bedrock-agentcore): Adds support for the Bring Your Own Storage(B...
  • 0f79b6a Publish v3.1093.0
  • 80f0df5 Publish v3.1092.0
  • a1269f7 Publish v3.1091.0
  • 4cf22ef feat(client-bedrock-agentcore): Add W3C trace context headers (traceparent, t...
  • Additional commits viewable in compare view

Updates @aws-sdk/client-bedrock-runtime from 3.1081.0 to 3.1097.0

Release notes

Sourced from @​aws-sdk/client-bedrock-runtime's releases.

v3.1097.0

3.1097.0(2026-07-28)

Chores
Documentation Changes
  • client-connect: Documentation updates for SearchRules, AssociateRoutingProfileQueues, CreateRoutingProfile, AssociateContactWithUser CreateTaskTemplate, and UpdateTaskTemplate (c87ac126)
  • client-datasync: Adds Enhanced mode support for EFS and FSx Lustre locations without an agent, and for HDFS (TDE), Azure Blob, and object storage locations with an agent. HDFS Enhanced mode supports multiple NameNodes for High Availability. Enhanced mode agents can now be deployed on Microsoft Hyper-V. (5ef349f0)
New Features
  • client-trustedadvisor: Adds ListRecommendationsForResource API and four CheckSummary fields (resourceArnQueryable, awsResourceTypes, checkGranularity, recommendationId) to retrieve recommendations for a given resource ARN. (16e67f16)
  • client-rolesanywhere: Increases certificate string length for trust anchor source data to support new adjustable trust anchor limits. (20c913fd)
  • client-bedrock-agentcore-control: AgentCore Identity now supports Private Key JWT client authentication for OAuth 2.0 credential providers. Agents can authenticate to identity provider token endpoints with a JWT client assertion signed by a customer-managed AWS KMS asymmetric key, eliminating the need for client secrets. (fa2b1a0a)

For list of updated packages, view updated-packages.md in assets-3.1097.0.zip

v3.1096.0

3.1096.0(2026-07-27)

New Features
  • clients: update client endpoints as of 2026-07-27 (24e536ee)
  • client-bcm-data-exports: With this release, customers can configure their data exports to deliver CSV reports in ZIP compressed format. (bf6df63c)
  • client-glue: Adds BatchGetDataQualityRulesetEvaluationRun API to retrieve multiple runs in one call, ObservationScope and ObservationMode parameters for anomaly detection, writing evaluation results to Data Catalog tables, and custom log group paths for recommendation runs. (70d8b71e)
  • client-sagemaker: This release adds LoRA adapters, training plans, and new instance types to SageMaker inference optimization. CreateAIRecommendationJob accepts optional AdapterSource and CreateOptimizationJob accepts optional TrainingPlanArns and the ml.g7e and ml.p6-b200 families. (587c6437)
  • client-account: This release adds support for the GetPrimaryEmailUpdateStatus API operation, which allows customers to retrieve the current status of a primary email address update request for an AWS account. The operation returns status information including whether the update is pending, completed, or failed. (d633065c)
  • client-quicksight: Added new Governance fields to Custom Permissions API to support Deny By Default functionality. (730d4716)
  • client-cleanrooms: This release adds support for the CR.8X worker type for SQL (32 vCPU) (4c532188)
  • client-emr-containers: With this launch, you can now set concurrent job limits on a virtual cluster, giving you fine-grained control over how many job runs execute at once and how many can wait in queue. (b6c745a4)
  • client-securityagent: AWS Security Agent adds a new task hours field that reflects the active work done for a task. (6419f793)
  • client-partnercentral-account: Adds optional headquarters location to StartProfileUpdateTask, letting partners record their headquarters as an ISO 3166 country and subdivision code on their profile. When headquarters is provided, both the country and subdivision codes are required. (db69aaa7)
  • client-cleanroomsml: This release adds support for the CR.8X worker type for SQL (32 vCPU) (bcabd86a)
Bug Fixes
  • core/protocols: handle JSON exponent notation in jsonReviver (#8226) (c3b27fd3)

For list of updated packages, view updated-packages.md in assets-3.1096.0.zip

v3.1095.0

... (truncated)

Changelog

Sourced from @​aws-sdk/client-bedrock-runtime's changelog.

3.1097.0 (2026-07-28)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1096.0 (2026-07-27)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1095.0 (2026-07-24)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1094.0 (2026-07-23)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1093.0 (2026-07-22)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1092.0 (2026-07-21)

Note: Version bump only for package @​aws-sdk/client-bedrock-runtime

3.1091.0 (2026-07-20)

... (truncated)

Commits

Updates @aws-sdk/client-dynamodb from 3.1078.0 to 3.1097.0

Release notes

Sourced from @​aws-sdk/client-dynamodb's releases.

v3.1097.0

3.1097.0(2026-07-28)

Chores
Documentation Changes
  • client-connect: Documentation updates for SearchRules, AssociateRoutingProfileQueues, CreateRoutingProfile, AssociateContactWithUser CreateTaskTemplate, and UpdateTaskTemplate (c87ac126)
  • client-datasync: Adds Enhanced mode support for EFS and FSx Lustre locations without an agent, and for HDFS (TDE), Azure Blob, and object storage locations with an agent. HDFS Enhanced mode supports multiple NameNodes for High Availability. Enhanced mode agents can now be deployed on Microsoft Hyper-V. (5ef349f0)
New Features
  • client-trustedadvisor: Adds ListRecommendationsForResource API and four CheckSummary fields (resourceArnQueryable, awsResourceTypes, checkGranularity, recommendationId) to retrieve recommendations for a given resource ARN. (16e67f16)
  • client-rolesanywhere: Increases certificate string length for trust anchor source data to support new adjustable trust anchor limits. (20c913fd)
  • client-bedrock-agentcore-control: AgentCore Identity now supports Private Key JWT client authentication for OAuth 2.0 credential providers. Agents can authenticate to identity provider token endpoints with a JWT client assertion signed by a customer-managed AWS KMS asymmetric key, eliminating the need for client secrets. (fa2b1a0a)

For list of updated packages, view updated-packages.md in assets-3.1097.0.zip

v3.1096.0

3.1096.0(2026-07-27)

New Features
  • clients: update client endpoints as of 2026-07-27 (24e536ee)
  • client-bcm-data-exports: With this release, customers can configure their data exports to deliver CSV reports in ZIP compressed format. (bf6df63c)
  • client-glue: Adds BatchGetDataQualityRulesetEvaluationRun API to retrieve multiple runs in one call, ObservationScope and ObservationMode parameters for anomaly detection, writing evaluation results to Data Catalog tables, and custom log group paths for recommendation runs. (70d8b71e)
  • client-sagemaker: This release adds LoRA adapters, training plans, and new instance types to SageMaker inference optimization. CreateAIRecommendationJob accepts optional AdapterSource and CreateOptimizationJob accepts optional TrainingPlanArns and the ml.g7e and ml.p6-b200 families. (587c6437)
  • client-account: This release adds support for the GetPrimaryEmailUpdateStatus API operation, which allows customers to retrieve the current status of a primary email address update request for an AWS account. The operation returns status information including whether the update is pending, completed, or failed. (d633065c)
  • client-quicksight: Added new Governance fields to Custom Permissions API to support Deny By Default functionality. (730d4716)
  • client-cleanrooms: This release adds support for the CR.8X worker type for SQL (32 vCPU) (4c532188)
  • client-emr-containers: With this launch, you can now set concurrent job limits on a virtual cluster, giving you fine-grained control over how many job runs execute at once and how many can wait in queue. (b6c745a4)
  • client-securityagent: AWS Security Agent adds a new task hours field that reflects the active work done for a task. (6419f793)
  • client-partnercentral-account: Adds optional headquarters location to StartProfileUpdateTask, letting partners record their headquarters as an ISO 3166 country and subdivision code on their profile. When headquarters is provided, both the country and subdivision codes are required. (db69aaa7)
  • client-cleanroomsml: This release adds support for the CR.8X worker type for SQL (32 vCPU) (bcabd86a)
Bug Fixes
  • core/protocols: handle JSON exponent notation in jsonReviver (#8226) (c3b27fd3)

For list of updated packages, view updated-packages.md in assets-3.1096.0.zip

v3.1095.0

... (truncated)

Changelog

Sourced from @​aws-sdk/client-dynamodb's changelog.

3.1097.0 (2026-07-28)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1096.0 (2026-07-27)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1095.0 (2026-07-24)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1094.0 (2026-07-23)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1093.0 (2026-07-22)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1092.0 (2026-07-21)

Note: Version bump only for package @​aws-sdk/client-dynamodb

3.1091.0 (2026-07-20)

... (truncated)

Commits

Updates @aws-sdk/client-ecs from 3.1081.0 to 3.1097.0

Release notes

Sourced from @​aws-sdk/client-ecs's releases.

v3.1097.0

3.1097.0(2026-07-28)

Chores
Documentation Changes
  • client-connect: Documentation updates for SearchRules, AssociateRoutingProfileQueues, CreateRoutingProfile, AssociateContactWithUser CreateTaskTemplate, and UpdateTaskTemplate (c87ac126)
  • client-datasync: Adds Enhanced mode support for EFS and FSx Lustre locations without an agent, and for HDFS (TDE), Azure Blob, and object storage locations with an agent. HDFS Enhanced mode supports multiple NameNodes for High Availability. Enhanced mode agents can now be deployed on Microsoft Hyper-V. (5ef349f0)
New Features
  • client-trustedadvisor: Adds ListRecommendationsForResource API and four CheckSummary fields (resourceArnQueryable, awsResourceTypes, checkGranularity, recommendationId) to retrieve recommendations for a given resource ARN. (16e67f16)
  • client-rolesanywhere: Increases certificate string length for trust anchor source data to support new adjustable trust anchor limits. (20c913fd)
  • client-bedrock-agentcore-control: AgentCore Identity now supports Private Key JWT client authentication for OAuth 2.0 credential providers. Agents can authenticate to identity provider token endpoints with a JWT client assertion signed by a customer-managed AWS KMS asymmetric key, eliminating the need for client secrets. (fa2b1a0a)

For list of updated packages, view updated-packages.md in assets-3.1097.0.zip

v3.1096.0

3.1096.0(2026-07-27)

New Features
  • clients: update client endpoints as of 2026-07-27 (24e536ee)
  • client-bcm-data-exports: With this release, customers can configure their data exports to deliver CSV reports in ZIP compressed format. (bf6df63c)
  • client-glue: Adds BatchGetDataQualityRulesetEvaluationRun API to retrieve multiple runs in one call, ObservationScope and ObservationMode parameters for anomaly detection, writing evaluation results to Data Catalog tables, and custom log group paths for recommendation runs. (70d8b71e)
  • client-sagemaker: This release adds LoRA adapters, training plans, and new instance types to SageMaker inference optimization. CreateAIRecommendationJob accepts optional AdapterSource and CreateOptimizationJob accepts optional TrainingPlanArns and the ml.g7e and ml.p6-b200 families. (587c6437)
  • client-account: This release adds support for the GetPrimaryEmailUpdateStatus API operation, which allows customers to retrieve the current status of a primary email address update request for an AWS account. The operation returns status information including whether the update is pending, completed, or failed. (d633065c)
  • client-quicksight: Added new Governance fields to Custom Permissions API to support Deny By Default functionality. (730d4716)
  • client-cleanrooms: This release adds support for the CR.8X worker type for SQL (32 vCPU) (4c532188)
  • client-emr-containers: With this launch, you can now set concurrent job limits on a virtual cluster, giving you fine-grained control over how many job runs execute at once and how many can wait in queue. (b6c745a4)
  • client-securityagent: AWS Security Agent adds a new task hours field that reflects the active work done for a task. (6419f793)
  • client-partnercentral-account: Adds optional headquarters location to StartProfileUpdateTask, letting partners record their headquarters as an ISO 3166 country and subdivision code on their profile. When headquarters is provided, both the country and subdivision codes are required. (db69aaa7)
  • client-cleanroomsml: This release adds support for the CR.8X worker type for SQL (32 vCPU) (bcabd86a)
Bug Fixes
  • core/protocols: handle JSON exponent notation in jsonReviver (#8226) (c3b27fd3)

For list of updated packages, view updated-packages.md in assets-3.1096.0.zip

v3.1095.0

... (truncated)

Changelog

Sourced from @​aws-sdk/client-ecs's changelog.

3.1097.0 (2026-07-28)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1096.0 (2026-07-27)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1095.0 (2026-07-24)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1094.0 (2026-07-23)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1093.0 (2026-07-22)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1092.0 (2026-07-21)

Note: Version bump only for package @​aws-sdk/client-ecs

3.1091.0 (2026-07-20)

... (truncated)

Commits

Updates @aws-sdk/client-lambda from 3.1081.0 to 3.1097.0

Release notes

Sourced from @​aws-sdk/client-lambda's releases.

v3.1097.0

3.1097.0(2026-07-28)

Chores
Documentation Changes
  • client-connect: Documentation updates for SearchRules, AssociateRoutingProfileQueues, CreateRoutingProfile, AssociateContactWithUser CreateTaskTemplate, and UpdateTaskTemplate (c87ac126)
  • client-datasync: Adds Enhanced mode support for EFS and FSx Lustre locations without an agent, and for HDFS (TDE), Azure Blob, and object storage locations with an agent. HDFS Enhanced mode supports multiple NameNodes for High Availability. Enhanced mode agents can now be deployed on Microsoft Hyper-V. (5ef349f0)
New Features
  • client-trustedadvisor: Adds ListRecommendationsForResource API and four CheckSummary fields (resourceArnQueryable, awsResourceTypes, checkGranularity, recommendationId) to retrieve recommendations for a given resource ARN. (16e67f16)
  • client-rolesanywhere: Increases certificate string length for trust anchor source data to support new adjustable trust anchor limits. (20c913fd)
  • client-bedrock-agentcore-control: AgentCore Identity now supports Private Key JWT client authentication for OAuth 2.0 credential providers. Agents can authenticate to identity provider token endpoints with a JWT client assertion signed by a customer-managed AWS KMS asymmetric key, eliminating the need for client secrets. (fa2b1a0a)

For list of updated packages, view updated-packages.md in assets-3.1097.0.zip

v3.1096.0

3.1096.0(2026-07-27)

New Features
  • clients: update client endpoints as of 2026-07-27 (24e536ee)
  • client-bcm-data-exports: With this release, customers can configure their data exports to deliver CSV reports in ZIP compressed format. (bf6df63c)
  • client-glue: Adds BatchGetDataQualityRulesetEvaluationRun API to retrieve multiple runs in one call, ObservationScope and ObservationMode parameters for anomaly detection, writing evaluation results to Data Catalog tables, and custom log group paths for recommendation runs. (70d8b71e)
  • client-sagemaker: This release adds LoRA adapters, training plans, and new instance types to SageMaker inference optimization. CreateAIRecommendationJob accepts optional AdapterSource and CreateOptimizationJob accepts optional TrainingPlanArns and the ml.g7e and ml.p6-b200 families. (587c6437)
  • client-account: This release adds support for the GetPrimaryEmailUpdateStatus API operation, which allows customers to retrieve the current status of a primary email address update request for an AWS account. The operation returns status information including whether the update is pending, completed, or failed. (d633065c)
  • client-quicksight: Added new Governance fields to Custom Permissions API to support Deny By Default functionality. (730d4716)
  • client-cleanrooms: This release adds support for the CR.8X worker type for SQL (32 vCPU) (4c532188)
  • client-emr-containers: With this launch, you can now set concurrent job limits on a virtual cluster, giving you fine-grained control over how many job runs execute at once and how many can wait in queue. (b6c745a4)
  • client-securityagent: AWS Security Agent adds a new task hours field that reflects the active work done for a task. (6419f793)
  • client-partnercentral-account: Adds optional headquarters location to StartProfileUpdateTask, letting partners record their headquarters as an ISO 3166 country and subdivision code on their profile. When headquarters is provided, both the country and subdivision codes are required. (db69aaa7)
  • client-cleanroomsml: This release adds support for the CR.8X worker type for SQL (32 vCPU) (bcabd86a)
Bug Fixes
  • core/protocols: handle JSON exponent notation in jsonReviver (#8226) (c3b27fd3)

For list of updated packages, view updated-packages.md in assets-3.1096.0.zip

v3.1095.0

... (truncated)

Changelog

Sourced from @​aws-sdk/client-lambda's changelog.

Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 4, 2026
@dependabot
dependabot Bot requested review from a team as code owners August 4, 2026 20:16
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 4, 2026
@scottschreckengaust

Copy link
Copy Markdown
Contributor

@dependabot recreate

… updates

Bumps the all-npm group with 37 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@astrojs/check](https://github.com/withastro/astro/tree/HEAD/packages/language-tools/astro-check) | `0.9.9` | `0.9.10` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.23.0` | `6.29.0` |
| [@aws-sdk/client-bedrock-agentcore](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-agentcore) | `3.1081.0` | `3.1097.0` |
| [@aws-sdk/client-bedrock-runtime](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-runtime) | `3.1081.0` | `3.1097.0` |
| [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/client-ecs](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ecs) | `3.1081.0` | `3.1097.0` |
| [@aws-sdk/client-lambda](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-lambda) | `3.1081.0` | `3.1097.0` |
| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1081.0` | `3.1097.0` |
| [@aws-sdk/client-secrets-manager](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-secrets-manager) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/s3-presigned-post](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-presigned-post) | `3.1081.0` | `3.1097.0` |
| [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) | `3.1081.0` | `3.1097.0` |
| [@aws/durable-execution-sdk-js](https://github.com/aws/aws-durable-execution-sdk-js/tree/HEAD/packages/aws-durable-execution-sdk-js) | `2.1.0` | `2.2.0` |
| [@smithy/protocol-http](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/protocol-http) | `5.5.6` | `5.5.15` |
| [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) | `2.261.0` | `2.262.1` |
| [cdk-nag](https://github.com/cdklabs/cdk-nag) | `2.38.2` | `3.0.1` |
| [constructs](https://github.com/aws/constructs) | `10.6.0` | `10.7.1` |
| [ws](https://github.com/websockets/ws) | `8.21.0` | `8.21.1` |
| [@aws-cdk/integ-runner](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/@aws-cdk/integ-runner) | `2.202.1` | `2.203.2` |
| [@cdklabs/eslint-plugin](https://github.com/cdklabs/eslint-rules) | `2.0.13` | `2.0.16` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.0` | `26.1.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.63.0` | `8.65.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.63.0` | `8.65.0` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1129.0` | `2.1133.0` |
| [eslint](https://github.com/eslint/eslint) | `10.6.0` | `10.8.0` |
| [eslint-plugin-jest](https://github.com/jest-community/eslint-plugin-jest) | `29.15.4` | `29.16.0` |
| [eslint-plugin-jsdoc](https://github.com/gajus/eslint-plugin-jsdoc) | `63.0.12` | `63.3.2` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.11` | `29.4.12` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
| [@aws-sdk/client-bedrock](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/client-bedrock-agentcore-control](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-agentcore-control) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/client-cloudformation](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cloudformation) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/client-cognito-identity-provider](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cognito-identity-provider) | `3.1078.0` | `3.1097.0` |
| [commander](https://github.com/tj/commander.js) | `14.0.3` | `15.0.0` |
| [@astrojs/starlight](https://github.com/withastro/starlight/tree/HEAD/packages/starlight) | `0.41.3` | `0.41.5` |
| [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `7.1.3` | `7.1.5` |
| [markdown-link-check](https://github.com/tcort/markdown-link-check) | `3.14.2` | `3.15.0` |

Bumps the all-npm group with 4 updates in the /cdk directory: [cdk-nag](https://github.com/cdklabs/cdk-nag), [js-yaml](https://github.com/nodeca/js-yaml), [@aws-cdk/integ-runner](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/@aws-cdk/integ-runner) and [typescript](https://github.com/microsoft/TypeScript).
Bumps the all-npm group with 9 updates in the /cli directory:

| Package | From | To |
| --- | --- | --- |
| [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/client-secrets-manager](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-secrets-manager) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1078.0` | `3.1097.0` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
| [@aws-sdk/client-bedrock](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/client-bedrock-agentcore-control](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-agentcore-control) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/client-cloudformation](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cloudformation) | `3.1078.0` | `3.1097.0` |
| [@aws-sdk/client-cognito-identity-provider](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cognito-identity-provider) | `3.1078.0` | `3.1097.0` |
| [commander](https://github.com/tj/commander.js) | `14.0.3` | `15.0.0` |

Bumps the all-npm group with 2 updates in the /docs directory: [typescript](https://github.com/microsoft/TypeScript) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro).


Updates `@astrojs/check` from 0.9.9 to 0.9.10
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/language-tools/astro-check/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/check@0.9.10/packages/language-tools/astro-check)

Updates `knip` from 6.23.0 to 6.29.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.29.0/packages/knip)

Updates `@aws-sdk/client-bedrock-agentcore` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock-agentcore)

Updates `@aws-sdk/client-bedrock-runtime` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-runtime/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock-runtime)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-dynamodb)

Updates `@aws-sdk/client-ecs` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecs/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-ecs)

Updates `@aws-sdk/client-lambda` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-lambda)

Updates `@aws-sdk/client-s3` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-s3)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-secrets-manager)

Updates `@aws-sdk/credential-provider-node` from 3.972.64 to 3.972.78
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-node/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-node)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/lib/lib-dynamodb)

Updates `@aws-sdk/s3-presigned-post` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-presigned-post/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/packages/s3-presigned-post)

Updates `@aws-sdk/s3-request-presigner` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/packages/s3-request-presigner)

Updates `@aws/durable-execution-sdk-js` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/aws/aws-durable-execution-sdk-js/releases)
- [Changelog](https://github.com/aws/aws-durable-execution-sdk-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-durable-execution-sdk-js/commits/HEAD/packages/aws-durable-execution-sdk-js)

Updates `@smithy/protocol-http` from 5.5.6 to 5.5.15
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/protocol-http/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/protocol-http@5.5.15/packages/protocol-http)

Updates `@smithy/signature-v4` from 5.6.2 to 5.6.12
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/signature-v4/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/signature-v4@5.6.12/packages/signature-v4)

Updates `aws-cdk-lib` from 2.261.0 to 2.262.1
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.262.1/packages/aws-cdk-lib)

Updates `cdk-nag` from 2.38.2 to 3.0.1
- [Release notes](https://github.com/cdklabs/cdk-nag/releases)
- [Commits](https://github.com/cdklabs/cdk-nag/compare/v2.38.2...v3.0.1)

Updates `constructs` from 10.6.0 to 10.7.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.7.1)

Updates `js-yaml` from 4.3.0 to 4.3.1
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...5.2.2)

Updates `ws` from 8.21.0 to 8.21.1
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](https://github.com/websockets/ws/compare/8.21.0...8.21.1)

Updates `@aws-cdk/integ-runner` from 2.202.1 to 2.203.2
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/integ-runner@v2.203.2/packages/@aws-cdk/integ-runner)

Updates `@cdklabs/eslint-plugin` from 2.0.13 to 2.0.16
- [Release notes](https://github.com/cdklabs/eslint-rules/releases)
- [Commits](https://github.com/cdklabs/eslint-rules/compare/v2.0.13...v2.0.16)

Updates `@types/node` from 26.1.0 to 26.1.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.65.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.63.0 to 8.65.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/parser)

Updates `aws-cdk` from 2.1129.0 to 2.1133.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1133.0/packages/aws-cdk)

Updates `eslint` from 10.6.0 to 10.8.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.8.0)

Updates `eslint-plugin-jest` from 29.15.4 to 29.16.0
- [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases)
- [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jest-community/eslint-plugin-jest/compare/v29.15.4...v29.16.0)

Updates `eslint-plugin-jsdoc` from 63.0.12 to 63.3.2
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v63.0.12...v63.3.2)

Updates `ts-jest` from 29.4.11 to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.4.11...v29.4.12)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

Updates `@aws-sdk/client-bedrock` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock)

Updates `@aws-sdk/client-bedrock-agentcore-control` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock-agentcore-control)

Updates `@aws-sdk/client-cloudformation` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cloudformation/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-cloudformation)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-cognito-identity-provider)

Updates `commander` from 14.0.3 to 15.0.0
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tj/commander.js/compare/v14.0.3...v15.0.0)

Updates `@astrojs/starlight` from 0.41.3 to 0.41.5
- [Release notes](https://github.com/withastro/starlight/releases)
- [Changelog](https://github.com/withastro/starlight/blob/main/packages/starlight/CHANGELOG.md)
- [Commits](https://github.com/withastro/starlight/commits/@astrojs/starlight@0.41.5/packages/starlight)

Updates `astro` from 7.1.3 to 7.1.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.1.5/packages/astro)

Updates `markdown-link-check` from 3.14.2 to 3.15.0
- [Release notes](https://github.com/tcort/markdown-link-check/releases)
- [Changelog](https://github.com/tcort/markdown-link-check/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tcort/markdown-link-check/compare/v3.14.2...v3.15.0)

Updates `@aws-sdk/client-bedrock-agentcore` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock-agentcore)

Updates `@aws-sdk/client-bedrock-runtime` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-runtime/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock-runtime)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-dynamodb)

Updates `@aws-sdk/client-ecs` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ecs/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-ecs)

Updates `@aws-sdk/client-lambda` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-lambda)

Updates `@aws-sdk/client-s3` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-s3)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-secrets-manager)

Updates `@aws-sdk/credential-provider-node` from 3.972.64 to 3.972.78
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-node/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-node)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/lib/lib-dynamodb)

Updates `@aws-sdk/s3-presigned-post` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-presigned-post/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/packages/s3-presigned-post)

Updates `@aws-sdk/s3-request-presigner` from 3.1081.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/packages/s3-request-presigner)

Updates `@aws/durable-execution-sdk-js` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/aws/aws-durable-execution-sdk-js/releases)
- [Changelog](https://github.com/aws/aws-durable-execution-sdk-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-durable-execution-sdk-js/commits/HEAD/packages/aws-durable-execution-sdk-js)

Updates `@smithy/protocol-http` from 5.5.6 to 5.5.15
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/protocol-http/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/protocol-http@5.5.15/packages/protocol-http)

Updates `@smithy/signature-v4` from 5.6.2 to 5.6.12
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/signature-v4/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/signature-v4@5.6.12/packages/signature-v4)

Updates `aws-cdk-lib` from 2.261.0 to 2.262.1
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.262.1/packages/aws-cdk-lib)

Updates `cdk-nag` from 2.38.2 to 3.0.1
- [Release notes](https://github.com/cdklabs/cdk-nag/releases)
- [Commits](https://github.com/cdklabs/cdk-nag/compare/v2.38.2...v3.0.1)

Updates `constructs` from 10.6.0 to 10.7.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.7.1)

Updates `js-yaml` from 4.3.0 to 4.3.1
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...5.2.2)

Updates `ws` from 8.21.0 to 8.21.1
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](https://github.com/websockets/ws/compare/8.21.0...8.21.1)

Updates `@aws-cdk/integ-runner` from 2.202.1 to 2.203.2
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/integ-runner@v2.203.2/packages/@aws-cdk/integ-runner)

Updates `@cdklabs/eslint-plugin` from 2.0.13 to 2.0.16
- [Release notes](https://github.com/cdklabs/eslint-rules/releases)
- [Commits](https://github.com/cdklabs/eslint-rules/compare/v2.0.13...v2.0.16)

Updates `@types/node` from 26.1.0 to 26.1.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.65.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.63.0 to 8.65.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/parser)

Updates `aws-cdk` from 2.1129.0 to 2.1133.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1133.0/packages/aws-cdk)

Updates `eslint` from 10.6.0 to 10.8.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.8.0)

Updates `eslint-plugin-jest` from 29.15.4 to 29.16.0
- [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases)
- [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jest-community/eslint-plugin-jest/compare/v29.15.4...v29.16.0)

Updates `eslint-plugin-jsdoc` from 63.0.12 to 63.3.2
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v63.0.12...v63.3.2)

Updates `ts-jest` from 29.4.11 to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.4.11...v29.4.12)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

Updates `@aws-sdk/client-bedrock` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock)

Updates `@aws-sdk/client-bedrock-agentcore-control` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock-agentcore-control)

Updates `@aws-sdk/client-cloudformation` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cloudformation/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-cloudformation)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-cognito-identity-provider)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/lib/lib-dynamodb)

Updates `commander` from 14.0.3 to 15.0.0
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tj/commander.js/compare/v14.0.3...v15.0.0)

Updates `@types/node` from 26.1.0 to 26.1.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.65.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.63.0 to 8.65.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/parser)

Updates `eslint` from 10.6.0 to 10.8.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.8.0)

Updates `eslint-plugin-jest` from 29.15.4 to 29.16.0
- [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases)
- [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jest-community/eslint-plugin-jest/compare/v29.15.4...v29.16.0)

Updates `eslint-plugin-jsdoc` from 63.0.12 to 63.3.2
- [Release notes](https://github.com/gajus/eslint-plugin-jsdoc/releases)
- [Commits](https://github.com/gajus/eslint-plugin-jsdoc/compare/v63.0.12...v63.3.2)

Updates `ts-jest` from 29.4.11 to 29.4.12
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/kulshekhar/ts-jest/compare/v29.4.11...v29.4.12)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

Updates `@astrojs/check` from 0.9.9 to 0.9.10
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/language-tools/astro-check/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/check@0.9.10/packages/language-tools/astro-check)

Updates `@astrojs/starlight` from 0.41.3 to 0.41.5
- [Release notes](https://github.com/withastro/starlight/releases)
- [Changelog](https://github.com/withastro/starlight/blob/main/packages/starlight/CHANGELOG.md)
- [Commits](https://github.com/withastro/starlight/commits/@astrojs/starlight@0.41.5/packages/starlight)

Updates `astro` from 7.1.3 to 7.1.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.1.5/packages/astro)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

Updates `markdown-link-check` from 3.14.2 to 3.15.0
- [Release notes](https://github.com/tcort/markdown-link-check/releases)
- [Changelog](https://github.com/tcort/markdown-link-check/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tcort/markdown-link-check/compare/v3.14.2...v3.15.0)

Updates `cdk-nag` from 2.38.2 to 3.0.1
- [Release notes](https://github.com/cdklabs/cdk-nag/releases)
- [Commits](https://github.com/cdklabs/cdk-nag/compare/v2.38.2...v3.0.1)

Updates `js-yaml` from 4.3.1 to 5.2.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...5.2.2)

Updates `@aws-cdk/integ-runner` from 2.202.1 to 2.203.2
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/integ-runner@v2.203.2/packages/@aws-cdk/integ-runner)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

Updates `@aws-cdk/integ-runner` from 2.202.1 to 2.203.2
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/@aws-cdk/integ-runner@v2.203.2/packages/@aws-cdk/integ-runner)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/lib/lib-dynamodb)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

Updates `@aws-sdk/client-bedrock` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock)

Updates `@aws-sdk/client-bedrock-agentcore-control` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock-agentcore-control)

Updates `@aws-sdk/client-cloudformation` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cloudformation/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-cloudformation)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-cognito-identity-provider)

Updates `commander` from 14.0.3 to 15.0.0
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tj/commander.js/compare/v14.0.3...v15.0.0)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/lib/lib-dynamodb)

Updates `@aws-sdk/client-bedrock` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock)

Updates `@aws-sdk/client-bedrock-agentcore-control` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-agentcore-control/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-bedrock-agentcore-control)

Updates `@aws-sdk/client-cloudformation` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cloudformation/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-cloudformation)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-cognito-identity-provider)

Updates `@aws-sdk/client-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1078.0 to 3.1097.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1097.0/lib/lib-dynamodb)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

Updates `astro` from 7.1.3 to 7.1.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.1.5/packages/astro)

Updates `astro` from 7.1.3 to 7.1.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.1.5/packages/astro)

---
updated-dependencies:
- dependency-name: "@astrojs/check"
  dependency-version: 0.9.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@astrojs/check"
  dependency-version: 0.9.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@astrojs/starlight"
  dependency-version: 0.41.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@astrojs/starlight"
  dependency-version: 0.41.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@aws-cdk/integ-runner"
  dependency-version: 2.203.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-cdk/integ-runner"
  dependency-version: 2.203.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-cdk/integ-runner"
  dependency-version: 2.203.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-cdk/integ-runner"
  dependency-version: 2.203.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore-control"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore-control"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore-control"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-agentcore-control"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-runtime"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-bedrock-runtime"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cloudformation"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cloudformation"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cloudformation"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cloudformation"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-ecs"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-ecs"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-lambda"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-lambda"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/credential-provider-node"
  dependency-version: 3.972.77
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@aws-sdk/credential-provider-node"
  dependency-version: 3.972.77
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/s3-presigned-post"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/s3-presigned-post"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.1097.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws/durable-execution-sdk-js"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@aws/durable-execution-sdk-js"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@cdklabs/eslint-plugin"
  dependency-version: 2.0.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@cdklabs/eslint-plugin"
  dependency-version: 2.0.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@smithy/protocol-http"
  dependency-version: 5.5.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@smithy/protocol-http"
  dependency-version: 5.5.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@smithy/signature-v4"
  dependency-version: 5.6.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@smithy/signature-v4"
  dependency-version: 5.6.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@types/node"
  dependency-version: 26.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@types/node"
  dependency-version: 26.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@types/node"
  dependency-version: 26.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.65.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.65.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.65.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.65.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.65.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.65.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: astro
  dependency-version: 7.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: astro
  dependency-version: 7.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: astro
  dependency-version: 7.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: astro
  dependency-version: 7.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: aws-cdk
  dependency-version: 2.1133.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: aws-cdk
  dependency-version: 2.1133.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: aws-cdk-lib
  dependency-version: 2.262.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: aws-cdk-lib
  dependency-version: 2.262.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: cdk-nag
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: cdk-nag
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: cdk-nag
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: commander
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: commander
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: commander
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: constructs
  dependency-version: 10.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: constructs
  dependency-version: 10.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint
  dependency-version: 10.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint
  dependency-version: 10.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint
  dependency-version: 10.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jest
  dependency-version: 29.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jest
  dependency-version: 29.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jest
  dependency-version: 29.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 63.3.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 63.3.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: eslint-plugin-jsdoc
  dependency-version: 63.3.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: js-yaml
  dependency-version: 5.2.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: knip
  dependency-version: 6.29.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: markdown-link-check
  dependency-version: 3.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: markdown-link-check
  dependency-version: 3.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-npm
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: ts-jest
  dependency-version: 29.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-npm
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/all-npm-9cb530530c branch from 4bbcbd3 to 2b08dcd Compare August 4, 2026 23:02

@scottschreckengaust scottschreckengaust left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1. Verdict

Request changes. This is not a routine dependency bump — four major-version upgrades are hiding inside the all-npm group, and at least two of them are multi-day migration projects that this PR does not perform. The build (agentcore) check is already red, and the root cause is one of them: TypeScript 7 removed the compiler API from the package's main export, which breaks scripts/check-types-sync.ts (a required drift-prevention gate). Separately, the manifests and yarn.lock have diverged — three packages are keyed in the lockfile at ranges that appear in no package.json, which guarantees a self-mutation on the next yarn install.

I would not land any part of this as-is. Recommended split: (a) a safe-bump PR containing the AWS SDK 3.1078/3.1081→3.1097 fleet, @smithy/protocol-http, aws-cdk-lib, constructs, ws, astro, starlight, knip, @astrojs/check, eslint plugins, ts-jest, markdown-link-check, @aws/durable-execution-sdk-js; (b) a tracked, issue-backed epic per major (typescript@7, cdk-nag@3, js-yaml@5, commander@15).


2. Vision alignment

Dependency hygiene directly serves bounded blast radius and the control-plane-reliability tenet, and keeping the SDK fleet current is genuinely valuable. But two specifics cut against the tenets as written:

  • cdk-nag 2→3 is a security-guardrail change, not a version bump. cdk-nag is the repo's synth-time security-policy engine (cdk/src/main.ts:32). v3 changes how packs are registered (IAspectIPolicyValidationPlugin). Registering it the old way in v3 does not error loudly — it silently stops evaluating. Trading a guardrail away by accident is precisely the undocumented-tenet-trade the review process treats as blocking.
  • No ADR / backing issue for the majors. typescript@7 (the native port) and cdk-nag@3 are architectural toolchain decisions with repo-wide blast radius. Per ADR-003 these deserve their own approved issues with acceptance criteria, not a group bump.

Governance itself is clear: app/dependabot is exempt from the backing-issue gate and the branch-naming convention (dependabot/npm_and_yarn/all-npm-9cb530530c). Not raising either. Cedar parity is also clean — see §4.


3. Blocking issues

B1 — typescript 6→7 breaks scripts/check-types-sync.ts; this is the live CI failure

cdk/package.json:67, cli/package.json:36, docs/package.json:25

TypeScript 7 is the native (Go) port, and it no longer ships the JS compiler API on the package main entry. From the published typescript@7.0.2 manifest:

"exports": { ".": "./lib/version.cjs", "./unstable/ast": "./dist/ast/index.js", ... }

and lib/version.cjs in its entirety:

const { version } = require("../package.json");
exports.version = version;
exports.versionMajorMinor = "7.0";

So import * as ts from 'typescript' (scripts/check-types-sync.ts:47) now resolves to an object with exactly two properties. ts.ScriptTarget is undefined, and line 175 dies:

TypeError: Cannot read properties of undefined (reading 'Latest')
    at parseFile (scripts/check-types-sync.ts:175:76)

That is verbatim the failure in run 30958631395. check:types-sync is in the drift-prevention DAG (mise.toml:118) which build depends on, so mise run build cannot pass on this branch. The script uses 44 ts.* compiler-API references, so this is not a one-line fix.

Fix: revert typescript to ^6.0.3 in all three manifests. Migrating to TS 7 requires porting scripts/check-types-sync.ts to the typescript/unstable/ast API (or pinning a separate typescript@6 devDependency just for that script) under its own approved issue.

B2 — TS 7 silently violates the declared peer ranges of the type-aware lint and docs toolchain

cdk/package.json:67, cli/package.json:36, docs/package.json:25

Registry-verified peer declarations of packages this PR keeps or bumps:

Package Declares typescript TS 7.0.2 satisfies?
@typescript-eslint/parser@8.65.0 >=4.8.4 <6.1.0 no
@typescript-eslint/eslint-plugin@8.65.0 >=4.8.4 <6.1.0 no
@astrojs/check@0.9.10 ^5.0.0 || ^6.0.0 no
ts-jest@29.4.12 >=4.3 <7 no

Yarn v1 only warns on peer mismatch, so install succeeds and nothing goes red at this layer. That is what makes it dangerous: the repo's type-aware ESLint rules (@typescript-eslint/no-unused-vars, no-magic-numbers, no-shadowcli/eslint.config.mjs:160-192) and astro check would run against a compiler none of them support. Silent degradation of the lint gate, not a loud failure.

Fix: as B1 — hold at ^6.0.3 until the whole toolchain declares TS 7 support.

B3 — cdk-nag 2→3 is an engine rewrite; the repo has not migrated, and the failure mode is partly silent

cdk/package.json:36

cdk-nag@3.0.0 is explicitly breaking — from its own MIGRATION.md (I unpacked the 3.0.1 tarball to confirm): "cdk-nag v3 rewrites the core engine from an IAspect to an IPolicyValidationPlugin." Two concrete breaks in this repo:

  1. NagSuppressions is deleted. v3's lib/index.d.ts re-exports only nag-logger, nag-pack, nag-rules, the packs, and rules. NagSuppressions appears nowhere in any lib/**/*.d.ts — the only suppression-adjacent export left is WriteNagSuppressionsToCloudFormationAspect. Its MIGRATION.md "Removed APIs" table lists NagSuppressionsValidations.of(construct).acknowledge(...).

    This repo has 21 import { NagSuppressions } from 'cdk-nag' sites and 50 NagSuppressions.add* call sites across 22 files under cdk/src and cdk/test, and zero uses of Validations. //cdk:compile (tsc --build) will hard-fail with ~50+ errors. CI has not surfaced this yet only because check:types-sync (B1) fails first in the parallel DAG.

  2. Pack registration silently no-ops. cdk/src/main.ts:32 is Aspects.of(app).add(new AwsSolutionsChecks());. v3 requires Validations.of(app).addPlugins(new AwsSolutionsChecks(app));. Adding an IPolicyValidationPlugin to Aspects is not a type error in every arrangement and does not throw at synth — cdk-nag simply stops evaluating. Worst case this compiles, all nag assertions pass vacuously, and the repo ships with its security-rule engine disabled. Note v3 also raises the aws-cdk-lib floor to 2.257.0 (satisfied) and drops the INagLogger/NagReportLogger/suppressionIgnoreCondition surface.

Fix: revert to cdk-nag: ^2.38.2. File a dedicated approved issue for the v3 migration covering: all 50 suppression call sites → Validations.of(x).acknowledge({id, reason}) (note: no bulk-array form in v3, so each existing multi-entry addResourceSuppressions([...]) fans out into N calls), main.ts registration, and re-verification that every previously-suppressed rule is still acknowledged — with writeSuppressionsToCloudFormation: true if the v2 cdk_nag template-metadata audit trail must be preserved.

B4 — js-yaml 4→5 in cdk/package.json is overridden by a root resolutions floor: the manifest now describes a tree that is not installed

cdk/package.json:38

This one is self-inconsistent inside the PR:

  • cdk/package.json:38 (changed here) declares "js-yaml": "^5.2.2".
  • Root package.json:31 (unchanged by this PR) pins "resolutions": { "js-yaml": "^4.2.0" }.
  • yarn.lock:5959 therefore collapses every descriptor into one v4 entry: js-yaml@^3.13.1, js-yaml@^4.1.1, js-yaml@^4.2.0, js-yaml@^4.3.0: version "4.3.1". There is no js-yaml@5.x entry anywhere in the lockfile (grep js-yaml-5 yarn.lock → empty).

So the manifest advertises v5 while the resolved tree is 4.3.1, and cdk/package.json:38's ^5.2.2 descriptor is not even represented in the lock. That is a manifest/lock divergence of exactly the kind the repo's drift guards exist to catch, and it makes the declared dependency actively misleading to the next reader. Note also @types/js-yaml stays at ^4.0.9 (cdk/package.json:50), so if the resolution were ever lifted, the typings would be a major behind the runtime.

For the record, the runtime risk if v5 did land is real but narrower than the version jump implies: v5's .d.ts is a rewritten tag/AST-oriented surface, but load/dump survive, so the two consumers (cdk/test/handlers/shared/workflows.test.ts:160,180,244,278 and cdk/test/bootstrap/bootstrap-template.test.ts:29, both yaml.load(...)) would probably still work. The blocker is the incoherence, not the call sites.

Fix: revert cdk/package.json:38 to ^4.1.1 (or ^4.2.0 to match the resolution floor). If v5 is genuinely wanted, it must move together with the root resolutions pin, @types/js-yaml, and a re-lock, in its own PR.

B5 — commander 15 raises the Node floor above the repo's own declared engines

cli/package.json:46

commander@15.0.0 declares engines.node: ">=22.12.0" (14.0.3 declared >=20). Every manifest in this repo declares "node": ">= 20.x <= 24.x" (package.json:8, cdk/package.json:71, cli/package.json:10, docs/package.json:29). CI and mise pin Node 22 so CI won't catch it, but the manifests still advertise Node 20 as supported, and cli is the user-facing artifact (bin: { bgagent: ... }). A contributor or user on Node 20.x or 22.0–22.11 gets an unsupported-engine tree.

Fix: either hold commander at ^14.0.3, or bump commander and narrow engines.node to ">= 22.12.0 <= 24.x" across all four manifests in the same PR (the latter is a deliberate support-matrix decision that wants an issue).

B6 — yarn.lock descriptors were rewritten without the matching manifests: guaranteed self-mutation

yarn.lock

Dependabot updated lockfile descriptors for three packages whose package.json ranges it left alone:

Package yarn.lock key (this PR) Declared in a manifest?
aws-cdk-lib aws-cdk-lib@^2.262.1 (line 3685) no — cdk/package.json:34 says ^2.260.0
constructs constructs@^10.7.1 (line 4068) no — cdk/package.json:37 says ^10.6.0
ws ws@^8.21.1 (line 9014) no — cdk/package.json:41 says ^8.21.0

These are the only lock keys for each package, so the ranges the manifests actually request (^2.260.0, ^10.6.0, ^8.21.0) are unsatisfied by the lockfile. The next yarn install --check-files (mise.toml:44) must re-resolve and rewrite yarn.lock, which trips the "Find mutations" step at .github/workflows/build.yml:350-354 and fails the build even after B1–B5 are fixed.

This is the "lockfiles regenerated consistently" check failing. The resolved versions are fine and OSV-clean — it's the descriptor/manifest mismatch that's broken.

Fix: after reverting the four majors, re-run the bump so manifests and lock agree (bump cdk/package.json to ^2.262.1 / ^10.7.1 / ^8.21.1, or let the lock re-resolve against the existing ranges — either is fine as long as they match). @dependabot recreate was already requested on 2026-08-04; it needs to run after the majors are excluded, or it will reproduce the same state.


4. Non-blocking suggestions / nits

  • Supply-chain checks came back clean — worth stating explicitly. I OSV-queried every suspicious bumped version (astro@7.1.5, typescript@7.0.2, commander@15.0.0, cdk-nag@3.0.1, knip@6.29.0, js-yaml@5.2.2): zero advisories, no malware. In particular astro@7.1.5 is clean, and MAL-2026-10726 was scoped to the poisoned astro@7.1.0 tarball specifically (remediated in #636) — 7.1.5 is not affected. The "a fixed version can itself be poisoned" lesson held; no concern here.
  • Cedar parity correctly untouched. The diff contains no cedar hunks. @cedar-policy/cedar-wasm stays at 4.8.2 and cedarpy at 4.8.4 — the .github/dependabot.yml ignore rules (npm major/minor/patch on @cedar-policy/cedar-wasm, uv on cedarpy) did their job. No action.
  • integrations/jira-forge-app correctly untouched (#712). No root resolutions entry moved in this PR, so there is nothing to mirror into that project's overrides, and check:transitive-pin-sync compares resolved floors that are unchanged. The #712 hazard does not apply here. Flagging only so the next reviewer doesn't re-derive it.
  • Newer versions exist for several bumpsastro 7.1.6, cdk-nag 3.0.2, knip 6.31.0, js-yaml 5.2.3. All moot given the recommended reverts; just don't be surprised when the recreated PR picks different numbers.
  • Consider ignore entries for the recurring majors. Given that typescript and cdk-nag majors will keep getting proposed and keep breaking the build, adding update-types: [version-update:semver-major] ignores for them in .github/dependabot.yml (alongside the existing Cedar precedent) would stop the group bump from being blocked by migrations nobody has scheduled. This is arguably the durable fix and relates to open issue #104 (automated toolchain version monitoring).
  • The group-of-40 shape is the meta-problem. all-npm with patterns: ["*"] across 4 directories means one unmigrated major poisons 36 perfectly good bumps — including the entire AWS SDK security-relevant fleet. Splitting the group by update-types (patch/minor auto-grouped; majors individual) would let the safe 90% flow weekly and surface each major as its own reviewable PR.

5. Documentation

Nothing required, nothing missing — for the PR as scoped. It touches only dependency manifests and yarn.lock: no docs/guides/, docs/design/, or CONTRIBUTING.md edits, so the Starlight mirror under docs/src/content/docs/ needs no regeneration (mise //docs:sync not applicable). No behavior, contract, env var, or command changed. No AGENTS.md/README impact.

Documentation that the majors would require, and which is absent:

  • cdk-nag v3 changes the documented suppression idiom repo-wide. Any migration must update docs/design/ prose and cdk/AGENTS.md guidance that references NagSuppressions, and almost certainly warrants an ADR under docs/decisions/ (it is a security-guardrail architecture change, per the review process's "undocumented tenet trades are blocking").
  • commander@15 + a Node-floor bump changes the supported runtime matrix, which is user-facing and documented in the guides.

Issue tracking: no issue exists for any of the four majors. Per ADR-003 and the process's Stage 4 issue-tracking requirement, typescript@7 and cdk-nag@3 each need a filed, approved, priority-labelled issue before implementation. Dependabot itself is exempt from the gate; the migration work is not.


6. Tests & CI

CI status (head 2b08dcd):

Check Status
build (agentcore) FAIL (2m57s) — check:types-sync TypeError, see B1
Dead-code detection (advisory) pass
Secrets, deps, and workflow scan pass
Validate PR title pass
CodeQL skipping

The red check is caused by this PR — not a newly-published CVE on main and not infrastructure flake. I scoped it: the security scan is green, and the failure is a deterministic TypeError in scripts/check-types-sync.ts:175 traceable to the typescript 6→7 entry-point change. No need to look further.

Note the build failed fast, at 2m57s, in the drift-prevention lane//cdk:compile and the jest suites had not finished. So the ~50 NagSuppressions compile errors from B3 are latent, not yet observed in CI. Fixing only B1 will move the failure, not clear it. Expect at least two more red rounds if these are fixed one at a time.

Test coverage: no tests added or changed, and for a pure dependency bump that is correct — no new behavior to cover. But it also means nothing in the test suite defends the invariants these bumps break, which is the real gap:

  • No test asserts cdk-nag is actually registered and evaluating. B3's silent-no-op mode would pass a green suite. A test asserting the AwsSolutions pack produces ≥1 finding on a deliberately non-compliant fixture construct would catch it.
  • No check asserts manifest↔lockfile descriptor agreement (B6). check:transitive-pin-sync covers the jira-forge-app floor case only. A guard that every package.json range appears as a satisfied yarn.lock descriptor would have caught B6 locally.

CDK bootstrap synth-coverage: not applicable. No constructs, stacks, or handlers changed; no new CloudFormation resource types introduced. cdk/src/bootstrap/policies/*.ts, resource-action-map.ts, BOOTSTRAP_VERSION, and the DEPLOYMENT_ROLES.md golden baseline all correctly untouched (ADR-002 / #350 not engaged). Caveat: a real cdk-nag@3 migration edits ~22 files under cdk/src/, so the bootstrap coverage question would re-open in that PR.

Test-performance (#366): not applicable — no CDK test files touched, so no risk of re-enabling aws:cdk:bundling-stacks or per-test new App().

Base freshness: base is 3a5b4cb6; current origin/main is df1ebac6 (one commit ahead — #345, the SDK-UA attribution work). I diffed 3a5b4cb6..df1ebac6 against yarn.lock and all four package.json files: no overlap, so no merge conflict. A rebase is still needed once the manifests are corrected. #345 introduced the attributed-client factory, which this PR does not touch — the SDK 3.1097 bump is orthogonal to it and does not affect AWS_SDK_UA_APP_ID handling.


7. Review agents run

I must be straight about this rather than imply coverage I didn't get: the subagent-dispatch tool was not available in this session. I attempted to load it repeatedly (select:Agent, select:Task, and keyword searches for the toolkit) and it is not exposed among the deferred tools here, so the pr-review-toolkit:* agents were not invocable. I did locate their definitions on disk (/local/home/scoschre/.claude/plugins/cache/claude-plugins-official/pr-review-toolkit/unknown/agents/) and applied their review lenses by hand against the diff and full worktree. Treat this section as a disclosure of a tooling gap, not as a claim of agent coverage.

Agent Status Note
code-reviewer Not invocable — lens applied manually Only arguably in-scope agent. Manual pass produced B1–B6 with registry/tarball verification.
silent-failure-hunter Out of scope Zero error-handling code in the diff (manifests + lockfile only). Its concern still surfaced manually — B2 and B3's no-op registration are silent-degradation findings.
type-design-analyzer Out of scope No new or changed types; no .ts source touched.
comment-analyzer Out of scope No comments added or changed (JSON manifests + lockfile).
pr-test-analyzer Out of scope No test files touched. Coverage gaps assessed manually in §6.
/security-review Out of scope as a skill No IAM, Cedar, network, secrets, or input-gateway change. Supply-chain review done directly instead: OSV queries on all six suspicious versions, plus tarball inspection of cdk-nag@3.0.1, typescript@7.0.2, js-yaml@5.2.2, commander@15.0.0. B3 is nonetheless a security-guardrail regression.

Verification I did run (all read-only, no worktree mutation): npm registry metadata for exports/engines/peerDependencies on every major; npm pack + tarball inspection of cdk-nag@3.0.1 (lib/index.d.ts, lib/nag-pack.d.ts, MIGRATION.md), typescript@7.0.2 (lib/version.cjs, bin/tsc), js-yaml@5.2.2 (dist/js-yaml.d.ts); OSV advisory queries; yarn.lock descriptor/resolution cross-check against all four manifests; call-site counts via grep over cdk/src and cdk/test; CI log retrieval for the failing job.


8. Human heuristics

  • Proportionality — concern. The change is under-proportioned to its own blast radius: 40 updates across 4 directories in one PR, with four majors (typescript 6→7, cdk-nag 2→3, js-yaml 4→5, commander 14→15) carrying migrations that are not performed. cdk-nag@3 alone is ~50 call-site edits across 22 files plus an ADR. A mechanical bump PR is the wrong container for that work; the all-npm patterns: ["*"] group (.github/dependabot.yml) is what collapses them together.
  • Coherence — concern. The PR contradicts itself in two places. cdk/package.json:38 declares js-yaml: ^5.2.2 while root package.json:31 resolutions forces ^4.2.0 and yarn.lock:5959 installs 4.3.1 (B4). And yarn.lock keys aws-cdk-lib@^2.262.1 / constructs@^10.7.1 / ws@^8.21.1 against manifests still declaring ^2.260.0 / ^10.6.0 / ^8.21.0 (B6). A manifest that describes a tree which is not installed is incoherent regardless of whether anything is currently red.
  • Clarity — concern. The failure modes are disproportionately quiet: yarn v1 only warns on the four broken typescript peer ranges (B2); a v3 NagPack added via Aspects stops evaluating without throwing (B3); the js-yaml v5 declaration is silently overridden by resolutions (B4). The one loud failure (B1) fails fast in the drift lane and therefore masks the ~50 latent NagSuppressions compile errors behind it. A reader who fixes only the visible error will reasonably believe they are done.
  • Appropriateness — concern. Not maintainable as a single unit, and this is verified against real published artifacts rather than assumption: I unpacked the tarballs and read typescript@7.0.2's lib/version.cjs, cdk-nag@3.0.1's lib/index.d.ts and MIGRATION.md, and js-yaml@5.2.2's .d.ts. The 36 non-major bumps — notably the AWS SDK 3.1097 fleet — are appropriate, valuable, and being held hostage by the four majors. Split them.

Comment thread cdk/package.json
"aws-cdk-lib": "^2.260.0",
"aws-jwt-verify": "^5.2.1",
"cdk-nag": "^2.38.2",
"cdk-nag": "^3.0.1",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking (B3). cdk-nag 3.0.0 is an engine rewrite (IAspect -> IPolicyValidationPlugin), and this repo has not migrated.

Two concrete breaks, both verified against the published 3.0.1 tarball:

  1. NagSuppressions no longer exists. v3's lib/index.d.ts exports only nag-logger, nag-pack, nag-rules, the packs, and rules; NagSuppressions appears in no lib/**/*.d.ts. Its own MIGRATION.md lists it under "Removed APIs" -> Validations.of(construct).acknowledge(...). This repo has 21 import { NagSuppressions } from 'cdk-nag' sites and 50 NagSuppressions.add* calls across 22 files, and zero uses of Validations. //cdk:compile will fail with ~50+ errors — currently latent only because check:types-sync (B1) fails first.

  2. Registration silently no-ops. cdk/src/main.ts:32 uses Aspects.of(app).add(new AwsSolutionsChecks()). v3 requires Validations.of(app).addPlugins(new AwsSolutionsChecks(app)). The old form does not throw at synth — cdk-nag just stops evaluating, so the repo could ship with its security-rule engine silently disabled.

Also note v3 has no bulk-array suppression form, so each existing addResourceSuppressions([...]) fans out into N acknowledge() calls.

Suggested fix: revert to "cdk-nag": "^2.38.2" and file a dedicated approved issue for the v3 migration (all 50 call sites, main.ts registration, re-verification that every previously-suppressed rule is still acknowledged, plus writeSuppressionsToCloudFormation: true if the v2 cdk_nag template-metadata audit trail must be preserved).

Comment thread cdk/package.json
"cdk-nag": "^3.0.1",
"constructs": "^10.6.0",
"js-yaml": "^4.1.1",
"js-yaml": "^5.2.2",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking (B4). This declaration is overridden and does not describe the installed tree.

  • here: "js-yaml": "^5.2.2"
  • root package.json:31 (unchanged by this PR): "resolutions": { "js-yaml": "^4.2.0" }
  • yarn.lock:5959 collapses everything into one v4 entry: js-yaml@^3.13.1, js-yaml@^4.1.1, js-yaml@^4.2.0, js-yaml@^4.3.0: version "4.3.1"

There is no js-yaml@5.x entry anywhere in the lockfile (grep js-yaml-5 yarn.lock is empty). So the manifest advertises v5 while 4.3.1 is installed, and this ^5.2.2 descriptor is not represented in the lock at all — actively misleading to the next reader, and liable to flip on any re-lock.

Separately, @types/js-yaml stays at ^4.0.9 (line 50), so if the resolution were ever lifted the typings would be a major behind the runtime.

FWIW the runtime risk is narrower than the major implies: v5's .d.ts is a rewritten tag/AST surface but load/dump survive, so the only consumers (cdk/test/handlers/shared/workflows.test.ts:160,180,244,278 and cdk/test/bootstrap/bootstrap-template.test.ts:29, all yaml.load) would likely still work. The blocker is the incoherence.

Suggested fix: revert to "^4.1.1" (or "^4.2.0" to match the resolution floor). A real v5 move must bump the root resolutions pin, @types/js-yaml, and the lockfile together in its own PR.

Comment thread cdk/package.json
"ts-jest": "^29.4.11",
"ts-node": "^10.9.2",
"typescript": "^6.0.3"
"typescript": "^7.0.2"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking (B1) — this is the live build (agentcore) failure.

TypeScript 7 is the native (Go) port and no longer ships the JS compiler API on the package main entry. From the published typescript@7.0.2 manifest, exports["."] is ./lib/version.cjs, whose entire contents are:

const { version } = require("../package.json");
exports.version = version;
exports.versionMajorMinor = "7.0";

So import * as ts from 'typescript' (scripts/check-types-sync.ts:47) yields an object with two properties, ts.ScriptTarget is undefined, and line 175 throws:

TypeError: Cannot read properties of undefined (reading 'Latest')
    at parseFile (scripts/check-types-sync.ts:175:76)

That is verbatim the CI failure. check:types-sync is in the drift-prevention DAG (mise.toml:118) that build depends on, so mise run build cannot pass. The script makes 44 ts.* compiler-API references — not a one-line fix.

Also (B2): TS 7.0.2 satisfies none of the declared peer ranges of the surrounding toolchain — @typescript-eslint/parser@8.65.0 and eslint-plugin@8.65.0 want >=4.8.4 <6.1.0, ts-jest@29.4.12 wants >=4.3 <7, @astrojs/check@0.9.10 wants ^5.0.0 || ^6.0.0. Yarn v1 only warns, so the type-aware ESLint rules would silently run against an unsupported compiler.

Suggested fix: revert to "^6.0.3" here and in cli/package.json:36 + docs/package.json:25. TS 7 needs its own approved issue (port the script to typescript/unstable/ast, or pin a separate typescript@6 just for it).

Comment thread cli/package.json
"@aws-sdk/client-dynamodb": "3.1097.0",
"@aws-sdk/client-secrets-manager": "3.1097.0",
"@aws-sdk/lib-dynamodb": "3.1097.0",
"commander": "^15.0.0"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking (B5). commander@15.0.0 declares engines.node: ">=22.12.0" (14.0.3 declared >=20), but every manifest in this repo declares "node": ">= 20.x <= 24.x" (package.json:8, cdk/package.json:71, cli/package.json:10, docs/package.json:29).

CI and mise pin Node 22 so this won't go red there — but the manifests still advertise Node 20 as supported, and cli is the user-facing artifact (bin: { bgagent: ... }). Anyone on Node 20.x, or 22.0–22.11, gets an unsupported-engine tree.

Suggested fix: hold at "^14.0.3", or bump commander and narrow engines.node to ">= 22.12.0 <= 24.x" across all four manifests in this same PR. The latter is a deliberate support-matrix change and deserves its own issue.

Comment thread docs/package.json
"@astrojs/check": "^0.9.9",
"@astrojs/starlight": "^0.41.2",
"astro": "7.1.3",
"astro": "7.1.5",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit (non-blocking) — this bump is fine and I want to say so explicitly, since astro is the one package here with a poisoned-release history.

I OSV-queried astro@7.1.5: clean, no advisories, no malware. MAL-2026-10726 was scoped to the poisoned astro@7.1.0 tarball specifically (remediated in #636); 7.1.5 is unaffected. @astrojs/starlight@0.41.5 also declares astro: ^7.0.2, which 7.1.5 satisfies.

Only note: 7.1.6 is now latest. Moot given the reverts the majors require — just don't be surprised if a recreated PR lands a different number.

@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant