Skip to content

Conversation

parseplatformorg
Copy link
Contributor

@parseplatformorg parseplatformorg commented Aug 29, 2025

snyk-top-banner

Snyk has created this PR to upgrade @aws-sdk/client-s3 from 3.858.0 to 3.863.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 3 versions ahead of your current version.

  • The recommended version was released 22 days ago.

Release notes
Package name: @aws-sdk/client-s3
  • 3.863.0 - 2025-08-07

    3.863.0(2025-08-07)

    Chores
    • core/protocols: generate idempotencyTokens in ShapeSerializers (#7247) (35c2bf28)
    Documentation Changes
    • client-batch: This feature allows customers to use AWS Batch with Linux with ARM64 CPU Architecture with Fargate Spot compute support. (4f027296)
    • client-gameliftstreams: Adds Proton 9.0-2 to the list of runtime environment options available when creating an Amazon GameLift Streams application (fee76f44)
    New Features
    • client-codebuild: AWS CodeBuild now supports comment-based pull request control. (14bb0367)
    • client-guardduty: Added support for VPC owner account ID associated with DNS request in the GuardDuty finding. (79364bdb)
    • client-glue: AWS Glue Data Catalog now supports Iceberg Optimization settings at the Catalog level, and supports new options to control the optimization job run rate. (5451046b)
    • client-cloudfront: Added new viewer security policy, TLSv1.3_2025, for CloudFront. (100ddffa)
    Tests
    • bundlers: add e2e test for bundler tree-shaking (#7245) (7312c1b3)

    For list of updated packages, view updated-packages.md in assets-3.863.0.zip

  • 3.862.0 - 2025-08-06

    3.862.0(2025-08-06)

    Chores
    • codegen: sync for CborCodec idempotencyToken (#7246) (25b3eb16)
    Documentation Changes
    • client-appstream: Added support for G6 instances (2fb0a994)
    New Features
    • clients: update client endpoints as of 2025-08-06 (7bd2ce78)
    • client-budgets: Adds support for billing views. Billing views let you control access to cost and usage data through an AWS resource, streamlining the process of sharing cost and usage data across account boundaries. With this release, you can now create and view budgets based on billing views. (360bf1cf)
    • client-ec2: Mark Elastic Inference Accelerators and Elastic Graphics Processor parameters as deprecated on the RunInstances and LaunchTemplate APIs. (aa76eb44)
    • client-qbusiness: Amazon Q Business now supports the GetDocumentContent() API that enables customers to securely access the source documents through clickable citation links at query time (aabc7a59)
    • client-opensearchserverless: Features: add Index APIs in OpenSearchServerless to support managed semantic enrichment (9b2c5e66)

    For list of updated packages, view updated-packages.md in assets-3.862.0.zip

  • 3.859.0 - 2025-08-01

    3.859.0(2025-08-01)

    Chores
    • codegen: sync for omitting protocols files from schema-serde (#7242) (b25304f1)
    Documentation Changes
    • client-sns: Amazon SNS support for Amazon SQS fair queues (749eb139)
    • client-acm-pca: Doc-only update to add more information to GetCertificate action. (0309a7ef)
    New Features
    • clients: update client endpoints as of 2025-08-01 (3c53767b)
    • client-aiops: This release includes fix for InvestigationGroup timestamp conversion issue. (ec627aee)
    • client-pcs: Add support for IPv6 Networking for Clusters. (e8774c17)
    • client-observabilityadmin: CloudWatch Observability Admin adds the ability to enable telemetry on AWS resources such as Amazon VPCs (Flow Logs) in customers AWS Accounts and Organizations. The release introduces new APIs to manage telemetry rules, which define telemetry settings to be applied on AWS resources. (39e204f9)
    • client-securityhub: Release new resource detail type CodeRepository (fb750f9a)
    • client-lightsail: This release adds support for the Asia Pacific (Jakarta) (ap-southeast-3) Region. (32d73d71)
    • client-auditmanager: Added a note to Framework APIs (CreateAssessmentFramework, GetAssessmentFramework, UpdateAssessmentFramework) clarifying that the Controls object returns a partial response when called through Framework APIs. Added documentation that the Framework's controlSources parameter is no longer supported. (dbff0ec3)
    • client-arc-region-switch: This is the initial SDK release for Region switch (6cc73c6a)
    Tests
    • token-providers: add integ test for fromEnvSigningName (#7241) (08c6c214)

    For list of updated packages, view updated-packages.md in assets-3.859.0.zip

  • 3.858.0 - 2025-07-31

    3.858.0(2025-07-31)

    Documentation Changes
    • client-elastic-load-balancing-v2: This release enables secondary IP addresses for Network Load Balancers. (0a12a4ec)
    • update PR template (#7240) (205fd3ca)
    New Features
    • clients: update client endpoints as of 2025-07-31 (38d91b61)
    • client-sesv2: This release introduces support for Multi-tenant management (41eae73b)
    • client-entityresolution: Add support for creating advanced rule-based matching workflows in AWS Entity Resolution. (f36fbb40)
    • client-quicksight: Added Impala connector support (1af8f7e6)
    • client-customer-profiles: The release updates standard profile with 2 new fields that supports account-level engagement. Updated APIs include CreateProfile, UpdateProfile, MergeProfiles, SearchProfiles, BatchGetProfile, GetSegmentMembership, CreateSegmentDefinition, CreateSegmentEstimate. (04e0957b)
    • client-glue: Added support for Route node, S3 Iceberg sources/targets, catalog Iceberg sources, DynamoDB ELT connector, AutoDataQuality evaluation, enhanced PII detection with redaction, Kinesis fan-out support, and new R-series worker types. (3cf6f20a)
    • client-workspaces-web: Added ability to log session activity on a portal to an S3 bucket. (1d75d430)
    • client-ec2: Added support for the force option for the EC2 instance terminate command. This feature enables customers to recover resources associated with an instance stuck in the shutting-down state as a result of rare issues caused by a frozen operating system or an underlying hardware problem. (d8adec80)
    • client-inspector2: Extend usage to include agentless hours and add CODE_REPOSITORY to aggregation resource type (91553bb9)
    • client-opensearch: Granular access control support for NEO-SAML with IAMFederation for AOS data source (026ef659)
    • client-s3-control: Add Tags field to CreateAccessPoint (4e13ff31)
    • client-iot: This release allows AWS IoT Core users to use their own AWS KMS keys for data protection (c65f9eec)
    Bug Fixes
    Tests
    • core: config file and defaults mode integ tests (#7239) (0ae45069)

    For list of updated packages, view updated-packages.md in assets-3.858.0.zip

from @aws-sdk/client-s3 GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Summary by CodeRabbit

  • Chores
    • Upgraded AWS S3 client library to version 3.863.0 to incorporate the latest fixes and improvements.
    • Enhances stability and compatibility for S3-related operations; no changes to user workflows.
    • No impact on public APIs or integrations; existing behavior remains consistent.

Snyk has created this PR to upgrade @aws-sdk/client-s3 from 3.858.0 to 3.863.0.

See this package in npm:
@aws-sdk/client-s3

See this project in Snyk:
https://app.snyk.io/org/acinader/project/3364151b-9c9a-4458-9afd-809dc5309438?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant bot changed the title [Snyk] Upgrade @aws-sdk/client-s3 from 3.858.0 to 3.863.0 refactor: Upgrade @aws-sdk/client-s3 from 3.858.0 to 3.863.0 Aug 29, 2025
Copy link

🚀 Thanks for opening this pull request!

Copy link

coderabbitai bot commented Aug 29, 2025

📝 Walkthrough

Walkthrough

Updated the dependency "@aws-sdk/client-s3" in package.json from version 3.858.0 to 3.863.0. No other files or dependencies were changed.

Changes

Cohort / File(s) Summary
Dependency version bump
package.json
Bumped @aws-sdk/client-s3 from 3.858.0 to 3.863.0; no other changes.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

Tip

🔌 Remote MCP (Model Context Protocol) integration is now available!

Pro plan users can now connect to remote MCP servers from the Integrations page. Connect with popular remote MCPs such as Notion and Linear to add more context to your reviews and chats.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbit in a new review comment at the desired location with your query.
  • PR comments: Tag @coderabbit in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbit gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbit read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

CodeRabbit Commands (Invoked using PR/Issue comments)

Type @coderabbit help to get the list of available commands.

Other keywords and placeholders

  • Add @coderabbit ignore or @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbit summary or @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbit or @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Status, Documentation and Community

  • Visit our Status Page to check the current availability of CodeRabbit.
  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@parseplatformorg
Copy link
Contributor Author

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

Copy link

codecov bot commented Aug 29, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.19%. Comparing base (38db0b7) to head (09c6145).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #342   +/-   ##
=======================================
  Coverage   97.19%   97.19%           
=======================================
  Files           2        2           
  Lines         214      214           
=======================================
  Hits          208      208           
  Misses          6        6           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
package.json (2)

22-24: Optional: align AWS SDK v3 patch train to reduce churn.

If you want to minimize duplicate installs across consumers, consider aligning both direct deps to the same latest patch (e.g., bump client-s3 to match the presigner train) or move to caret ranges for patch updates if that matches your versioning policy.


22-24: AWS SDK v3 graph is deduplicated—no duplicate transitive packages. npm ls shows a single @aws-sdk/types@3.862.0 and @smithy/types@4.3.2 across both packages. Update your smoke‐test to import from the installed @aws-sdk/credential-provider-node (or add @aws-sdk/credential-providers) so the runtime check can run.

📜 Review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • MCP integration is disabled by default for public repositories
  • Jira integration is disabled by default for public repositories
  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 38db0b7 and 09c6145.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json (1 hunks)
🔇 Additional comments (1)
package.json (1)

22-24: LGTM: patch bump of @aws-sdk/client-s3 looks safe.

No code paths changed here; this should be a non-breaking update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants