chore: bump AWS SDK from 3.1090.0 to 3.1127.0 #261

Merged
stack72 merged 2 commits from chore/bump-aws-sdk-3.1127.0 into main 2026-09-07 05:35:14 +00:00
Owner

Summary

  • Bump all @aws-sdk/* packages from 3.1090.0 to 3.1127.0 (37 patch releases)
  • Updates codegen source (denoConfigGenerator, libGenerator, enrichments), hand-written extensions (vault/aws-sm, datastore/s3, workflows/s3-bootstrap), benchmarks, test snapshots, and regenerated models (~275 services)
  • Version bumps for vault/aws-sm, datastore/s3, and workflows/s3-bootstrap manifests to 2026.09.06.1 with upgrade entry added to the s3-bootstrap provisioner model

Notes

Nine orphaned model directories (artifact, backupsearch, cognitosync, controlcatalog, partnercentral, savingsplans, states, thinclient, usernotifications) still pin 3.1090.0 — their schemas are no longer in the upstream CloudFormation bundle so the codegen cannot regenerate them.

Test plan

  • deno check passes for vault/aws-sm and datastore/s3
  • Codegen test snapshots updated and passing
  • Second generation run confirms idempotency (0 changes)
  • CI validates all extensions

🤖 Generated with Claude Code

## Summary - Bump all `@aws-sdk/*` packages from `3.1090.0` to `3.1127.0` (37 patch releases) - Updates codegen source (denoConfigGenerator, libGenerator, enrichments), hand-written extensions (vault/aws-sm, datastore/s3, workflows/s3-bootstrap), benchmarks, test snapshots, and regenerated models (~275 services) - Version bumps for vault/aws-sm, datastore/s3, and workflows/s3-bootstrap manifests to `2026.09.06.1` with upgrade entry added to the s3-bootstrap provisioner model ## Notes Nine orphaned model directories (artifact, backupsearch, cognitosync, controlcatalog, partnercentral, savingsplans, states, thinclient, usernotifications) still pin `3.1090.0` — their schemas are no longer in the upstream CloudFormation bundle so the codegen cannot regenerate them. ## Test plan - [x] `deno check` passes for vault/aws-sm and datastore/s3 - [x] Codegen test snapshots updated and passing - [x] Second generation run confirms idempotency (0 changes) - [ ] CI validates all extensions 🤖 Generated with [Claude Code](https://claude.com/claude-code)
chore: bump AWS SDK from 3.1090.0 to 3.1127.0
Some checks failed
CI: Models / Gate: Models (pull_request) Has been cancelled
CI: Reviews / Detect Changes (pull_request) Has been cancelled
CI: Reviews / Claude Code Review (pull_request) Has been cancelled
CI: Reviews / Adversarial Code Review (pull_request) Has been cancelled
CI: Reviews / CI Security Review (pull_request) Has been cancelled
CI: Reviews / Gate: Reviews (pull_request) Has been cancelled
CI: Vaults / vault/1password - check (pull_request) Has been cancelled
CI: Vaults / vault/aws-sm - check (pull_request) Has been cancelled
CI: Vaults / vault/azure-kv - check (pull_request) Has been cancelled
CI: Vaults / vault/gcp-sm - check (pull_request) Has been cancelled
CI: Vaults / vault/1password - fmt (pull_request) Has been cancelled
CI: Vaults / vault/aws-sm - fmt (pull_request) Has been cancelled
CI: Vaults / vault/azure-kv - fmt (pull_request) Has been cancelled
CI: Vaults / vault/gcp-sm - fmt (pull_request) Has been cancelled
CI: Vaults / vault/1password - lint (pull_request) Has been cancelled
CI: Vaults / vault/aws-sm - lint (pull_request) Has been cancelled
CI: Vaults / vault/azure-kv - lint (pull_request) Has been cancelled
CI: Vaults / vault/gcp-sm - lint (pull_request) Has been cancelled
CI: Vaults / vault/1password - test (pull_request) Has been cancelled
CI: Vaults / vault/aws-sm - test (pull_request) Has been cancelled
CI: Vaults / vault/azure-kv - test (pull_request) Has been cancelled
CI: Vaults / vault/gcp-sm - test (pull_request) Has been cancelled
CI: Vaults / vault/1password - lockfile up to date (pull_request) Has been cancelled
CI: Vaults / vault/aws-sm - lockfile up to date (pull_request) Has been cancelled
CI: Vaults / vault/azure-kv - lockfile up to date (pull_request) Has been cancelled
CI: Vaults / vault/gcp-sm - lockfile up to date (pull_request) Has been cancelled
CI: Vaults / Gate: Vaults (pull_request) Has been cancelled
CI / Dependency Audit (pull_request) Has started running
CI / Actions Audit (pull_request) Has been cancelled
CI / Gate: Audit (pull_request) Has been cancelled
d4123bec1b
Update all AWS SDK packages across the repo to 3.1127.0 (37 patch
releases). Covers codegen source, generated models, hand-written
extensions (vault/aws-sm, datastore/s3, workflows/s3-bootstrap),
benchmarks, and test snapshots. Lockfiles regenerated.

Nine orphaned model directories (artifact, backupsearch, cognitosync,
controlcatalog, partnercentral, savingsplans, states, thinclient,
usernotifications) still pin 3.1090.0 — their schemas are no longer
in the upstream CloudFormation bundle so the codegen cannot regenerate
them.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
fix: regenerate datastore/s3 lockfile with all source and test deps
Some checks failed
CI: Models / gcp models - lockfiles up to date (pull_request) Successful in 26s
CI: Models / cloudflare models - sample check (pull_request) Successful in 26s
CI: Models / cloudflare models - lockfiles up to date (pull_request) Successful in 26s
CI: Models / vercel models - sample check (pull_request) Successful in 30s
CI: Models / vercel models - lockfiles up to date (pull_request) Successful in 26s
CI: Models / codegen - check (pull_request) Successful in 25s
CI: Models / codegen - fmt (pull_request) Successful in 22s
CI: Models / codegen - lint (pull_request) Successful in 23s
CI: Models / codegen - lockfile up to date (pull_request) Successful in 22s
CI: Reviews / Detect Changes (pull_request) Successful in 18s
CI: Reviews / CI Security Review (pull_request) Has been skipped
CI / Actions Audit (pull_request) Successful in 23s
CI: Extensions / workflows/gcs-bootstrap - check (pull_request) Successful in 23s
CI: Extensions / workflows/s3-bootstrap - check (pull_request) Successful in 26s
CI: Extensions / workflows/gcs-bootstrap - fmt (pull_request) Successful in 24s
CI: Extensions / workflows/s3-bootstrap - fmt (pull_request) Successful in 25s
CI: Extensions / workflows/gcs-bootstrap - lint (pull_request) Successful in 24s
CI: Extensions / workflows/s3-bootstrap - lint (pull_request) Successful in 25s
CI / Dependency Audit (pull_request) Successful in 2m28s
CI: Extensions / workflows/gcs-bootstrap - test (pull_request) Successful in 26s
CI: Extensions / workflows/s3-bootstrap - test (pull_request) Successful in 34s
CI: Extensions / workflows/gcs-bootstrap - lockfile up to date (pull_request) Successful in 32s
CI: Extensions / workflows/s3-bootstrap - lockfile up to date (pull_request) Successful in 31s
CI: Datastores / Gate: Datastores (pull_request) Successful in 0s
CI: Reviews / Claude Code Review (pull_request) Has started running
CI: Models / Gate: Models (pull_request) Successful in 1s
CI: Reviews / Adversarial Code Review (pull_request) Has started running
CI / Gate: Audit (pull_request) Successful in 0s
CI: Reviews / Gate: Reviews (pull_request) Has been cancelled
CI: Extensions / Gate: Extensions (pull_request) Successful in 1s
187ba086de
The prior lockfile was missing transitive dependencies from inline
npm: specifiers and test imports. Regenerated via deno check over
all source and test entrypoints so deno install --frozen passes.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
stack72 force-pushed chore/bump-aws-sdk-3.1127.0 from 187ba086de
Some checks failed
CI: Models / gcp models - lockfiles up to date (pull_request) Successful in 26s
CI: Models / cloudflare models - sample check (pull_request) Successful in 26s
CI: Models / cloudflare models - lockfiles up to date (pull_request) Successful in 26s
CI: Models / vercel models - sample check (pull_request) Successful in 30s
CI: Models / vercel models - lockfiles up to date (pull_request) Successful in 26s
CI: Models / codegen - check (pull_request) Successful in 25s
CI: Models / codegen - fmt (pull_request) Successful in 22s
CI: Models / codegen - lint (pull_request) Successful in 23s
CI: Models / codegen - lockfile up to date (pull_request) Successful in 22s
CI: Reviews / Detect Changes (pull_request) Successful in 18s
CI: Reviews / CI Security Review (pull_request) Has been skipped
CI / Actions Audit (pull_request) Successful in 23s
CI: Extensions / workflows/gcs-bootstrap - check (pull_request) Successful in 23s
CI: Extensions / workflows/s3-bootstrap - check (pull_request) Successful in 26s
CI: Extensions / workflows/gcs-bootstrap - fmt (pull_request) Successful in 24s
CI: Extensions / workflows/s3-bootstrap - fmt (pull_request) Successful in 25s
CI: Extensions / workflows/gcs-bootstrap - lint (pull_request) Successful in 24s
CI: Extensions / workflows/s3-bootstrap - lint (pull_request) Successful in 25s
CI / Dependency Audit (pull_request) Successful in 2m28s
CI: Extensions / workflows/gcs-bootstrap - test (pull_request) Successful in 26s
CI: Extensions / workflows/s3-bootstrap - test (pull_request) Successful in 34s
CI: Extensions / workflows/gcs-bootstrap - lockfile up to date (pull_request) Successful in 32s
CI: Extensions / workflows/s3-bootstrap - lockfile up to date (pull_request) Successful in 31s
CI: Datastores / Gate: Datastores (pull_request) Successful in 0s
CI: Reviews / Claude Code Review (pull_request) Has started running
CI: Models / Gate: Models (pull_request) Successful in 1s
CI: Reviews / Adversarial Code Review (pull_request) Has started running
CI / Gate: Audit (pull_request) Successful in 0s
CI: Reviews / Gate: Reviews (pull_request) Has been cancelled
CI: Extensions / Gate: Extensions (pull_request) Successful in 1s
to f1c1784b93
Some checks failed
CI: Vaults / vault/azure-kv - lint (pull_request) Successful in 32s
CI: Vaults / vault/gcp-sm - lint (pull_request) Successful in 31s
CI: Vaults / vault/1password - test (pull_request) Successful in 25s
CI: Vaults / vault/aws-sm - test (pull_request) Successful in 35s
CI: Vaults / vault/azure-kv - test (pull_request) Successful in 34s
CI: Vaults / vault/gcp-sm - test (pull_request) Successful in 30s
CI: Vaults / vault/1password - lockfile up to date (pull_request) Successful in 35s
CI: Vaults / vault/aws-sm - lockfile up to date (pull_request) Failing after 37s
CI: Vaults / vault/azure-kv - lockfile up to date (pull_request) Successful in 36s
CI: Vaults / vault/gcp-sm - lockfile up to date (pull_request) Successful in 29s
CI / Actions Audit (pull_request) Successful in 34s
CI: Datastores / Gate: Datastores (pull_request) Successful in 0s
CI: Extensions / workflows/gcs-bootstrap - check (pull_request) Successful in 29s
CI: Extensions / workflows/s3-bootstrap - check (pull_request) Successful in 30s
CI: Extensions / workflows/gcs-bootstrap - fmt (pull_request) Successful in 24s
CI: Extensions / workflows/s3-bootstrap - fmt (pull_request) Successful in 27s
CI / Dependency Audit (pull_request) Successful in 2m32s
CI: Extensions / workflows/gcs-bootstrap - lint (pull_request) Successful in 27s
CI: Extensions / workflows/s3-bootstrap - lint (pull_request) Successful in 26s
CI: Extensions / workflows/gcs-bootstrap - test (pull_request) Successful in 31s
CI: Extensions / workflows/gcs-bootstrap - lockfile up to date (pull_request) Successful in 32s
CI: Extensions / workflows/s3-bootstrap - test (pull_request) Successful in 38s
CI: Models / Gate: Models (pull_request) Successful in 1s
CI: Extensions / workflows/s3-bootstrap - lockfile up to date (pull_request) Successful in 25s
CI: Vaults / Gate: Vaults (pull_request) Failing after 0s
CI / Gate: Audit (pull_request) Successful in 0s
CI: Extensions / Gate: Extensions (pull_request) Successful in 0s
CI: Reviews / Adversarial Code Review (pull_request) Successful in 1m23s
CI: Reviews / Claude Code Review (pull_request) Successful in 2m41s
CI: Reviews / Gate: Reviews (pull_request) Successful in 0s
2026-09-07 04:37:56 +00:00
Compare
Author
Owner

Adversarial Review

This PR bumps the AWS SDK from 3.1090.0 to 3.1127.0 across all hand-written extensions (codegen/, datastore/s3, vault/aws-sm, workflows/s3-bootstrap, datastore/benchmarks) and regenerates ~1147 model files and their lockfiles. The hand-written changes are purely mechanical version string replacements — no logic, control flow, or API surface changes.

Critical / High

None found.

Medium

  1. 9 auto-generated model directories still reference @aws-sdk/client-cloudcontrol@3.1090.0 (model/aws/artifact, model/aws/backupsearch, model/aws/cognitosync, model/aws/controlcatalog, model/aws/partnercentral, model/aws/savingsplans, model/aws/states, model/aws/thinclient, model/aws/usernotifications). The codegen template in codegen/shared/denoConfigGenerator.ts now emits 3.1127.0, so these models appear to have been skipped during regeneration. Running deno task generate:aws for these services should bring them in line. This is out of the review scope (model/ files are auto-generated) but worth flagging to avoid version skew at runtime if these models are used alongside extensions that expect the newer SDK — Deno would resolve two different versions of @aws-sdk/client-cloudcontrol, which wastes memory but shouldn't cause correctness issues since CloudControl's API surface is stable across these versions.

Low

  1. datastore/s3/deno.lock shrank from 832 to 314 lines. The separate commit 187ba086d ("fix: regenerate datastore/s3 lockfile with all source and test deps") cleaned up stale entries for old SDK versions (3.1024.0, 3.1046.0). This is correct behavior — the old lockfile was carrying dead weight. Verified: the new lockfile only lists 3.1127.0.

  2. Snapshot test changes are consistent. The "sync, and list" wording in the snapshot diffs matches the existing template in codegen/aws/extensionModelGenerator.ts:155 — this template was already updated before this PR (prior regeneration commits). The snapshots are just catching up.

Verdict

PASS — Straightforward, mechanical SDK version bump. All hand-written version references are consistent at 3.1127.0. The upgrade block in workflows/s3-bootstrap/extensions/models/provisioner.ts:61-66 is correctly structured with an identity upgradeAttributes function. Lockfiles were regenerated. No logic changes, no new code paths, no security concerns.

## Adversarial Review This PR bumps the AWS SDK from `3.1090.0` to `3.1127.0` across all hand-written extensions (`codegen/`, `datastore/s3`, `vault/aws-sm`, `workflows/s3-bootstrap`, `datastore/benchmarks`) and regenerates ~1147 model files and their lockfiles. The hand-written changes are purely mechanical version string replacements — no logic, control flow, or API surface changes. ### Critical / High None found. ### Medium 1. **9 auto-generated model directories still reference `@aws-sdk/client-cloudcontrol@3.1090.0`** (`model/aws/artifact`, `model/aws/backupsearch`, `model/aws/cognitosync`, `model/aws/controlcatalog`, `model/aws/partnercentral`, `model/aws/savingsplans`, `model/aws/states`, `model/aws/thinclient`, `model/aws/usernotifications`). The codegen template in `codegen/shared/denoConfigGenerator.ts` now emits `3.1127.0`, so these models appear to have been skipped during regeneration. Running `deno task generate:aws` for these services should bring them in line. This is out of the review scope (model/ files are auto-generated) but worth flagging to avoid version skew at runtime if these models are used alongside extensions that expect the newer SDK — Deno would resolve two different versions of `@aws-sdk/client-cloudcontrol`, which wastes memory but shouldn't cause correctness issues since CloudControl's API surface is stable across these versions. ### Low 1. **`datastore/s3/deno.lock` shrank from 832 to 314 lines.** The separate commit `187ba086d` ("fix: regenerate datastore/s3 lockfile with all source and test deps") cleaned up stale entries for old SDK versions (`3.1024.0`, `3.1046.0`). This is correct behavior — the old lockfile was carrying dead weight. Verified: the new lockfile only lists `3.1127.0`. 2. **Snapshot test changes are consistent.** The "sync, and list" wording in the snapshot diffs matches the existing template in `codegen/aws/extensionModelGenerator.ts:155` — this template was already updated before this PR (prior regeneration commits). The snapshots are just catching up. ### Verdict **PASS** — Straightforward, mechanical SDK version bump. All hand-written version references are consistent at `3.1127.0`. The upgrade block in `workflows/s3-bootstrap/extensions/models/provisioner.ts:61-66` is correctly structured with an identity `upgradeAttributes` function. Lockfiles were regenerated. No logic changes, no new code paths, no security concerns.
Author
Owner

Code Review

This PR is a mechanical AWS SDK bump from 3.1090.0 to 3.1127.0, applied consistently across all hand-written extension code (datastore/s3, vault/aws-sm, workflows/s3-bootstrap) and the codegen pipeline (templates and enrichment source files). The model files are legitimate codegen output: codegen/ also changes, satisfying the CLAUDE.md legitimacy rule.

Blocking Issues

None.

Suggestions

  1. @smithy/node-http-handler not bumped alongside @aws-sdk/client-bedrock-agent-runtime (codegen/aws/enrichments/bedrock-knowledgebase/config.ts:8, methods.ts:9): The bedrock enrichment pins @smithy/node-http-handler@4.9.7, but the deno.lock shows @aws-sdk/client-bedrock-agent-runtime@3.1127.0 pulling in @smithy/node-http-handler@4.12.1 transitively. Two different versions of the handler will coexist in the npm resolution graph. This is a pre-existing issue (unchanged in this PR), but worth tracking: if the NodeHttpHandler interface changed between 4.9.7 and 4.12.1, the explicit import in createClient() could silently use a stale type. Consider bumping to match the SDK's transitive dependency in a follow-up.

Notes

  • All version strings are updated consistently: deno.json import maps, npm: specifiers in source files, deno.lock files, manifest.yaml versions, test file imports, and the codegen snapshot.
  • The provisioner.ts upgrade chain (2026.06.04.1 → … → 2026.09.06.1) is ordered correctly and the new entry describes a no-behavior-change version bump.
  • All sanitizeResources: false test options include the required comment explaining the connection-pool rationale.
  • No credential leaks, no shell injection vectors, no path traversal concerns.
  • The two new generated files under model/aws/iotsitewise/ (new resource types) are expected codegen output, not hand-edits.
## Code Review This PR is a mechanical AWS SDK bump from 3.1090.0 to 3.1127.0, applied consistently across all hand-written extension code (`datastore/s3`, `vault/aws-sm`, `workflows/s3-bootstrap`) and the codegen pipeline (templates and enrichment source files). The model files are legitimate codegen output: `codegen/` also changes, satisfying the CLAUDE.md legitimacy rule. ### Blocking Issues None. ### Suggestions 1. **`@smithy/node-http-handler` not bumped alongside `@aws-sdk/client-bedrock-agent-runtime`** (`codegen/aws/enrichments/bedrock-knowledgebase/config.ts:8`, `methods.ts:9`): The bedrock enrichment pins `@smithy/node-http-handler@4.9.7`, but the deno.lock shows `@aws-sdk/client-bedrock-agent-runtime@3.1127.0` pulling in `@smithy/node-http-handler@4.12.1` transitively. Two different versions of the handler will coexist in the npm resolution graph. This is a pre-existing issue (unchanged in this PR), but worth tracking: if the `NodeHttpHandler` interface changed between 4.9.7 and 4.12.1, the explicit import in `createClient()` could silently use a stale type. Consider bumping to match the SDK's transitive dependency in a follow-up. ### Notes - All version strings are updated consistently: deno.json import maps, `npm:` specifiers in source files, deno.lock files, manifest.yaml versions, test file imports, and the codegen snapshot. - The `provisioner.ts` upgrade chain (`2026.06.04.1 → … → 2026.09.06.1`) is ordered correctly and the new entry describes a no-behavior-change version bump. - All `sanitizeResources: false` test options include the required comment explaining the connection-pool rationale. - No credential leaks, no shell injection vectors, no path traversal concerns. - The two new generated files under `model/aws/iotsitewise/` (new resource types) are expected codegen output, not hand-edits.
Author
Owner

Adversarial Review

This PR bumps the AWS SDK from 3.1090.0 to 3.1127.0 across all hand-written extensions (datastore/s3, vault/aws-sm, workflows/s3-bootstrap), all codegen source files (codegen/aws/libGenerator.ts, codegen/shared/denoConfigGenerator.ts, enrichment configs/methods), snapshot tests, and ~1139 auto-generated model files. It also updates the docstring in generated models to mention "list" alongside other operations, and bumps manifest versions for the three hand-written extensions.

Critical / High

None found.

Medium

None found.

Low

  1. codegen/aws/enrichments/rds-dbcluster/list.enrich.ts:13-19 — IMDS disabling is fire-and-forget with a global side effect. The listClusters function sets AWS_EC2_METADATA_DISABLED=true globally and never restores it. This is flagged as an existing pattern (not introduced in this PR), but the version bump means a new SDK's credential chain behavior could interact differently with globally-mutated env vars. Theoretical risk only — the comment says enrichments run at codegen time, not extension runtime, so the blast radius is contained.

  2. workflows/s3-bootstrap/extensions/models/provisioner_impl.ts:255 — IAM policy ARN construction uses single-colon arn:aws:iam::<accountId>:policy/<name>. This is the correct format for IAM (IAM is a global service; the region field is empty), so this is not actually a bug. Noting it because the double-colon pattern can look suspicious at a glance, but it's correct here.

Verdict

PASS — This is a clean, mechanical dependency version bump. All AWS SDK version pins are consistently updated from 3.1090.0 to 3.1127.0 across hand-written source, codegen templates, enrichment configs, test fixtures, snapshot expectations, deno.json import maps, and lock files. No stale 3.1090.0 references remain in hand-written code (the only occurrence is in an upgrade description string in provisioner.ts:63, which is correct — it documents the version change). The deno.lock files are regenerated with updated transitive dependency hashes. Manifest versions are bumped. The snapshot test changes are consistent with the docstring tweak (adding "list" to the operations list) and the version bump. No logic, security, or API contract changes are introduced.

## Adversarial Review This PR bumps the AWS SDK from `3.1090.0` to `3.1127.0` across all hand-written extensions (`datastore/s3`, `vault/aws-sm`, `workflows/s3-bootstrap`), all codegen source files (`codegen/aws/libGenerator.ts`, `codegen/shared/denoConfigGenerator.ts`, enrichment configs/methods), snapshot tests, and ~1139 auto-generated model files. It also updates the docstring in generated models to mention "list" alongside other operations, and bumps manifest versions for the three hand-written extensions. ### Critical / High None found. ### Medium None found. ### Low 1. **`codegen/aws/enrichments/rds-dbcluster/list.enrich.ts:13-19` — IMDS disabling is fire-and-forget with a global side effect.** The `listClusters` function sets `AWS_EC2_METADATA_DISABLED=true` globally and never restores it. This is flagged as an existing pattern (not introduced in this PR), but the version bump means a new SDK's credential chain behavior could interact differently with globally-mutated env vars. Theoretical risk only — the comment says enrichments run at codegen time, not extension runtime, so the blast radius is contained. 2. **`workflows/s3-bootstrap/extensions/models/provisioner_impl.ts:255` — IAM policy ARN construction uses single-colon `arn:aws:iam::<accountId>:policy/<name>`.** This is the correct format for IAM (IAM is a global service; the region field is empty), so this is not actually a bug. Noting it because the double-colon pattern can look suspicious at a glance, but it's correct here. ### Verdict **PASS** — This is a clean, mechanical dependency version bump. All AWS SDK version pins are consistently updated from `3.1090.0` to `3.1127.0` across hand-written source, codegen templates, enrichment configs, test fixtures, snapshot expectations, `deno.json` import maps, and lock files. No stale `3.1090.0` references remain in hand-written code (the only occurrence is in an upgrade description string in `provisioner.ts:63`, which is correct — it documents the version change). The `deno.lock` files are regenerated with updated transitive dependency hashes. Manifest versions are bumped. The snapshot test changes are consistent with the docstring tweak (adding "list" to the operations list) and the version bump. No logic, security, or API contract changes are introduced.
Author
Owner

Code Review

This PR bumps the AWS SDK from 3.1090.0 to 3.1127.0 across the entire repo, along with associated manifest version bumps and a snapshot fix.

Blocking Issues

None.

Suggestions

  1. Snapshot staleness pre-existing on main (informational, not blocking): extensionModelGenerator.ts on main already generates "get, update, delete, sync, and list can be driven through \swamp model`."(line 155), but the snapshot file onmainstill records the old text"and sync". This means the snapshot tests were already failing on main` before this PR. The PR correctly updates the snapshots to match the generator's actual output — good fix — but it's worth noting the pre-existing breakage so the team can investigate whether snapshot-test CI was being skipped.

  2. Upgrade entry description (trivial): In workflows/s3-bootstrap/extensions/models/provisioner.ts, the upgrade entry for 2026.09.06.1 describes itself as "No schema or behavior change." This is accurate and clear. No action needed.

  3. Lock files present and updated: deno.lock files are updated in all four packages (datastore/s3, datastore/benchmarks, vault/aws-sm, workflows/s3-bootstrap). Cannot run deno install --frozen in CI to verify, but the presence and modification of lock files is consistent with the import map changes. ✓

The change is mechanically consistent: every occurrence of 3.1090.0 across deno.json import maps, direct npm: specifiers in source files, enrichment configs, the codegen lib generator, and the deno config generator has been updated to 3.1127.0. Manifest versions are bumped and the provisioner model includes a correct no-op upgrade entry.

## Code Review This PR bumps the AWS SDK from `3.1090.0` to `3.1127.0` across the entire repo, along with associated manifest version bumps and a snapshot fix. ### Blocking Issues None. ### Suggestions 1. **Snapshot staleness pre-existing on `main`** (informational, not blocking): `extensionModelGenerator.ts` on `main` already generates `"get, update, delete, sync, and list can be driven through \`swamp model\`."` (line 155), but the snapshot file on `main` still records the old text `"and sync"`. This means the snapshot tests were already failing on `main` before this PR. The PR correctly updates the snapshots to match the generator's actual output — good fix — but it's worth noting the pre-existing breakage so the team can investigate whether snapshot-test CI was being skipped. 2. **Upgrade entry description** (trivial): In `workflows/s3-bootstrap/extensions/models/provisioner.ts`, the upgrade entry for `2026.09.06.1` describes itself as "No schema or behavior change." This is accurate and clear. No action needed. 3. **Lock files present and updated**: `deno.lock` files are updated in all four packages (`datastore/s3`, `datastore/benchmarks`, `vault/aws-sm`, `workflows/s3-bootstrap`). Cannot run `deno install --frozen` in CI to verify, but the presence and modification of lock files is consistent with the import map changes. ✓ The change is mechanically consistent: every occurrence of `3.1090.0` across `deno.json` import maps, direct `npm:` specifiers in source files, enrichment configs, the codegen lib generator, and the deno config generator has been updated to `3.1127.0`. Manifest versions are bumped and the provisioner model includes a correct no-op upgrade entry.
fix: regenerate vault/aws-sm lockfile with all source and test deps
All checks were successful
CI: Vaults / vault/azure-kv - lint (pull_request) Successful in 33s
CI: Vaults / vault/gcp-sm - lint (pull_request) Successful in 26s
CI: Vaults / vault/1password - test (pull_request) Successful in 41s
CI: Vaults / vault/aws-sm - test (pull_request) Successful in 45s
CI: Vaults / vault/azure-kv - test (pull_request) Successful in 46s
CI: Vaults / vault/gcp-sm - test (pull_request) Successful in 42s
CI: Vaults / vault/1password - lockfile up to date (pull_request) Successful in 21s
CI: Vaults / vault/aws-sm - lockfile up to date (pull_request) Successful in 35s
CI: Vaults / vault/gcp-sm - lockfile up to date (pull_request) Successful in 36s
CI: Vaults / vault/azure-kv - lockfile up to date (pull_request) Successful in 38s
CI: Datastores / Gate: Datastores (pull_request) Successful in 0s
CI / Actions Audit (pull_request) Successful in 30s
CI: Extensions / workflows/gcs-bootstrap - check (pull_request) Successful in 31s
CI: Extensions / workflows/s3-bootstrap - check (pull_request) Successful in 26s
CI: Extensions / workflows/gcs-bootstrap - fmt (pull_request) Successful in 28s
CI: Extensions / workflows/s3-bootstrap - fmt (pull_request) Successful in 29s
CI: Extensions / workflows/gcs-bootstrap - lint (pull_request) Successful in 27s
CI / Dependency Audit (pull_request) Successful in 2m22s
CI: Extensions / workflows/s3-bootstrap - lint (pull_request) Successful in 31s
CI: Extensions / workflows/gcs-bootstrap - test (pull_request) Successful in 36s
CI: Extensions / workflows/s3-bootstrap - test (pull_request) Successful in 35s
CI: Models / Gate: Models (pull_request) Successful in 0s
CI: Extensions / workflows/gcs-bootstrap - lockfile up to date (pull_request) Successful in 23s
CI: Vaults / Gate: Vaults (pull_request) Successful in 1s
CI: Extensions / workflows/s3-bootstrap - lockfile up to date (pull_request) Successful in 26s
CI / Gate: Audit (pull_request) Successful in 1s
CI: Extensions / Gate: Extensions (pull_request) Successful in 1s
CI: Reviews / Adversarial Code Review (pull_request) Successful in 2m32s
CI: Reviews / Claude Code Review (pull_request) Successful in 3m42s
CI: Reviews / Gate: Reviews (pull_request) Successful in 0s
f805b794c6
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Author
Owner

Adversarial Review

This PR is a mechanical AWS SDK version bump from 3.1090.0 to 3.1127.0 across all extensions (codegen, datastore/s3, vault/aws-sm, workflows/s3-bootstrap, benchmarks) plus a minor doc fix in generated model headers ("and sync" → "sync, and list"). Version pins are consistent across all source files, deno.json imports, and lock files.

Critical / High

None found.

Medium

None found.

Low

  1. codegen/aws/enrichments/bedrock-knowledgebase/config.ts:8 / methods.ts:9@smithy/node-http-handler left at 4.9.7 while SDK bumps to 3.1127.0

    The SDK's transitive @smithy/node-http-handler dependency is now 4.12.1 (visible in updated lockfiles), but the enrichment explicitly pins 4.9.7. Both versions will coexist at runtime (Deno resolves npm: specifiers independently), and the NodeHttpHandler API is stable within the same major version, so this is functionally fine. Worth noting for a future housekeeping pass to keep the explicit pin aligned with the SDK's transitive version to avoid loading two copies of the same package.

Verification checklist

  • All @aws-sdk/client-* pins are 3.1127.0 across codegen source, enrichments, hand-written extensions, deno.json files, and test fixtures.
  • denoConfigGenerator.ts and libGenerator.ts emit the new version into generated code.
  • Snapshot updates match the version bump and doc-header change; no unexpected output diffs.
  • workflows/s3-bootstrap/provisioner.ts has a matching upgrade entry (toVersion: "2026.09.06.1") with a pass-through upgradeAttributes.
  • All three manifest files (datastore/s3, vault/aws-sm, workflows/s3-bootstrap) are bumped to 2026.09.06.1.
  • Lock files regenerated (stale specifiers from 3.1024.0, 3.1046.0, 3.1090.0 cleaned up in datastore/s3/deno.lock).
  • No logic, schema, or behavioral changes — only version strings and their downstream effects.

Verdict

PASS — Clean, consistent SDK version bump with no logic changes. All version pins align. Ship it.

## Adversarial Review This PR is a mechanical AWS SDK version bump from `3.1090.0` to `3.1127.0` across all extensions (codegen, datastore/s3, vault/aws-sm, workflows/s3-bootstrap, benchmarks) plus a minor doc fix in generated model headers ("and sync" → "sync, and list"). Version pins are consistent across all source files, deno.json imports, and lock files. ### Critical / High None found. ### Medium None found. ### Low 1. **`codegen/aws/enrichments/bedrock-knowledgebase/config.ts:8` / `methods.ts:9` — `@smithy/node-http-handler` left at 4.9.7 while SDK bumps to 3.1127.0** The SDK's transitive `@smithy/node-http-handler` dependency is now `4.12.1` (visible in updated lockfiles), but the enrichment explicitly pins `4.9.7`. Both versions will coexist at runtime (Deno resolves `npm:` specifiers independently), and the `NodeHttpHandler` API is stable within the same major version, so this is functionally fine. Worth noting for a future housekeeping pass to keep the explicit pin aligned with the SDK's transitive version to avoid loading two copies of the same package. ### Verification checklist - [x] All `@aws-sdk/client-*` pins are `3.1127.0` across codegen source, enrichments, hand-written extensions, deno.json files, and test fixtures. - [x] `denoConfigGenerator.ts` and `libGenerator.ts` emit the new version into generated code. - [x] Snapshot updates match the version bump and doc-header change; no unexpected output diffs. - [x] `workflows/s3-bootstrap/provisioner.ts` has a matching upgrade entry (`toVersion: "2026.09.06.1"`) with a pass-through `upgradeAttributes`. - [x] All three manifest files (`datastore/s3`, `vault/aws-sm`, `workflows/s3-bootstrap`) are bumped to `2026.09.06.1`. - [x] Lock files regenerated (stale specifiers from `3.1024.0`, `3.1046.0`, `3.1090.0` cleaned up in `datastore/s3/deno.lock`). - [x] No logic, schema, or behavioral changes — only version strings and their downstream effects. ### Verdict **PASS** — Clean, consistent SDK version bump with no logic changes. All version pins align. Ship it.
Author
Owner

Code Review

This PR is a straightforward AWS SDK bump from 3.1090.0 to 3.1127.0, touching:

  • All hand-written extension sources that import AWS SDK packages
  • codegen/shared/denoConfigGenerator.ts and codegen/aws/libGenerator.ts (codegen sources)
  • Corresponding deno.lock and manifest.yaml files
  • 1139 auto-generated model files (expected codegen output)

Blocking Issues

None.

Suggestions

  1. workflows/s3-bootstrap/extensions/models/provisioner_test.ts — test SDK clients not destroyed
    The S3Client, IAMClient, and STSClient instances created inside ensureBucket, hardenBucket, getAccountId, and ensurePolicy test cases are never explicitly destroyed. This is fine with sanitizeResources: false, but adding a .destroy() call on the client in the test's finally block (before server.shutdown()) would be tidier. Not a problem in practice since the test process exits.

  2. codegen/aws/enrichments/cfn-stackset/methods.tsdetectDrift sleeps before first poll
    The polling loop sleeps for pollIntervalMs unconditionally before checking the operation status. If CloudFormation completes the drift detection very quickly, the first status check is delayed by the full interval (default 5 s). A more responsive pattern polls first, then sleeps. Low-impact for a monitoring operation, but worth noting for future work.

  3. codegen/aws/enrichments/bedrock-knowledgebase/methods.ts — double cast on filter
    Line 123 uses filter as unknown as RetrievalFilter even though RetrievalFilter is already imported at the top of the file. A direct filter as RetrievalFilter cast is sufficient. Minor nit.


Correctness / security / compliance checklist (all pass):

  • No hand-edited files under model/ — codegen sources also change, which accounts for the model regeneration ✓
  • No any in hand-written code ✓
  • Named exports only ✓
  • All npm/JSR imports use exact version pins in changed files ✓
  • deno.lock committed for all changed packages ✓
  • No credential leaks, no injection vectors (all user-facing inputs validated via strict regex in GlobalArgsSchema) ✓
  • Tests use Deno.serve({ port: 0 }) local mock servers, no live cloud calls ✓
  • sanitizeResources: false present with explanatory comments on all SDK-client tests ✓
  • Env vars not mutated in tests (SDK bump adds no new env-var mutation) ✓
  • Upgrade entry for 2026.09.06.1 present in provisioner.ts
## Code Review This PR is a straightforward AWS SDK bump from 3.1090.0 to 3.1127.0, touching: - All hand-written extension sources that import AWS SDK packages - `codegen/shared/denoConfigGenerator.ts` and `codegen/aws/libGenerator.ts` (codegen sources) - Corresponding `deno.lock` and `manifest.yaml` files - 1139 auto-generated model files (expected codegen output) ### Blocking Issues None. ### Suggestions 1. **`workflows/s3-bootstrap/extensions/models/provisioner_test.ts` — test SDK clients not destroyed** The `S3Client`, `IAMClient`, and `STSClient` instances created inside `ensureBucket`, `hardenBucket`, `getAccountId`, and `ensurePolicy` test cases are never explicitly destroyed. This is fine with `sanitizeResources: false`, but adding a `.destroy()` call on the client in the test's `finally` block (before `server.shutdown()`) would be tidier. Not a problem in practice since the test process exits. 2. **`codegen/aws/enrichments/cfn-stackset/methods.ts` — `detectDrift` sleeps before first poll** The polling loop sleeps for `pollIntervalMs` unconditionally before checking the operation status. If CloudFormation completes the drift detection very quickly, the first status check is delayed by the full interval (default 5 s). A more responsive pattern polls first, then sleeps. Low-impact for a monitoring operation, but worth noting for future work. 3. **`codegen/aws/enrichments/bedrock-knowledgebase/methods.ts` — double cast on `filter`** Line 123 uses `filter as unknown as RetrievalFilter` even though `RetrievalFilter` is already imported at the top of the file. A direct `filter as RetrievalFilter` cast is sufficient. Minor nit. --- **Correctness / security / compliance checklist (all pass):** - No hand-edited files under `model/` — codegen sources also change, which accounts for the model regeneration ✓ - No `any` in hand-written code ✓ - Named exports only ✓ - All npm/JSR imports use exact version pins in changed files ✓ - `deno.lock` committed for all changed packages ✓ - No credential leaks, no injection vectors (all user-facing inputs validated via strict regex in `GlobalArgsSchema`) ✓ - Tests use `Deno.serve({ port: 0 })` local mock servers, no live cloud calls ✓ - `sanitizeResources: false` present with explanatory comments on all SDK-client tests ✓ - Env vars not mutated in tests (SDK bump adds no new env-var mutation) ✓ - Upgrade entry for `2026.09.06.1` present in `provisioner.ts` ✓
stack72 deleted branch chore/bump-aws-sdk-3.1127.0 2026-09-07 05:35:15 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
swamp-club/swamp-extensions!261
No description provided.