| #30843 |
feat(apigatewayv2-authorizers): add payloadFormatVersion field to HttpLambdaAuthorizer |
@yasamoka |
2024-07-13 (740d) |
| #34202 |
feat(ecs-patterns): enable Backlog per instance scaling in QueueProcessingFargateService |
@Abdul-pitodia |
2025-04-20 (458d) |
| #34365 |
feat(codebuild): add ec2 image types |
@okasyun |
2025-05-11 (438d) |
| #34051 |
feat(backup): add indexActions prop to BackupPlanRule |
@georeeve |
2025-05-27 (421d) |
| #36892 |
feat(eks): support internal load balancers in isolated subnets |
@Ashutosh0x |
2026-02-05 (167d) |
| #36587 |
fix(lambda-nodejs): copy .npmrc for pnpm to enable private registry authentication |
@sebastianplesciuc |
2026-02-06 (166d) |
| #36073 |
feat(stepfunctions): add JSONata expression support for TaskRole |
@t3yamoto |
2026-02-09 (164d) |
| #35472 |
feat(stepfunctions-tasks): add awsSdkCredentials to CallAwsServiceCrossRegion for cross-account scenarios |
@t3yamoto |
2026-02-09 (163d) |
| #37250 |
fix(cloudfront): warn when minimumProtocolVersion is set without a certificate |
@tiwari91 |
2026-03-14 (130d) |
| #37251 |
docs(sns): add IAM action details to grant method docstrings |
@tiwari91 |
2026-03-14 (130d) |
| #37194 |
fix(core): assign concat() result for cdk-migrate telemetry |
@abhu85 |
2026-03-14 (130d) |
| #36996 |
docs(stepfunctions-tasks): clarify that fromStringSet only accepts static arrays |
@ak2ie |
2026-03-16 (128d) |
| #37243 |
fix(secretsmanager): grant KMS decrypt/encrypt directly to grantee in grantRead/grantWrite |
@saurav61091 |
2026-03-17 (128d) |
| #37068 |
fix(logs): correct metric name in metricIncomingLogEvents |
@abhu85 |
2026-03-18 (127d) |
| #37278 |
fix(ec2): fix typo in SecurityGroup egress error message |
@karesansui-u |
2026-03-18 (127d) |
| #35929 |
fix(s3): l2 construct Bucket replication metrics cannot be enabled without replication time control (RTC) |
@NaveenKumar-Marupalli |
2026-03-21 (124d) |
| #36558 |
fix(logs): add DateOfBirth as type of personally identifiable information (PII) for CloudWatch Logs data protection |
@rgoltz |
2026-03-21 (123d) |
| #37301 |
docs(ec2): fix default description for VpcEndPointServiceProps.allowedRegions |
@gamrothc |
2026-03-21 (123d) |
| #37280 |
feat(cloudfront-origins): add owner account id support for cross account vpc origins |
@kawaaaas |
2026-03-22 (123d) |
| #36913 |
feat(cloudfront-origins): add HttpApiOrigin to support API Gateway HTTP API as CloudFront origin |
@kawaaaas |
2026-03-22 (123d) |
| #36894 |
feat(cloudfront-origins): ip address type for rest api origin |
@kawaaaas |
2026-03-22 (123d) |
| #36990 |
feat(lambda-event-sources): add sqs provisioned poller config |
@kawaaaas |
2026-03-22 (122d) |
| #37303 |
fix(s3): avoid access denied when disabling autoDeleteObjects property |
@Adityakk9031 |
2026-03-22 (122d) |
| #37388 |
feat(eks-v2): allow providing an existing IAM role to ServiceAccount with POD_IDENTITY |
@letsgomeow |
2026-04-05 (109d) |
| #37392 |
feat(eks): allow providing an existing IAM role to ServiceAccount with POD_IDENTITY |
@letsgomeow |
2026-04-05 (109d) |
| #37185 |
feat(codepipeline-actions): expose PR-specific variables in CodeStarConnectionsSourceAction |
@hmkim |
2026-04-07 (106d) |
| #37589 |
fix(ecs): allow ephemeralStorageGiB for Windows Fargate platform version 1.0.0 |
@rgoltz |
2026-04-14 (100d) |
| #37521 |
fix: show helpful error when docker is missing during bundling fallback |
@knQzx |
2026-04-14 (99d) |
| #37598 |
feat(codebuild): add imageId, scalingConfiguration and proxyConfiguration to Fleet L2 construct |
@rgoltz |
2026-04-15 (98d) |
| #37384 |
fix(eks): truncate kubectl error output to avoid CloudFormation respo… |
@ashoknarayan |
2026-04-20 (94d) |
| #37676 |
docs(ec2): modify enum RouterType.GATEWAY JsDoc to include Virtual Private Gateway |
@NaveenKumar-Marupalli |
2026-04-23 (91d) |
| #37690 |
fix(stepfunctions-tasks): scope SubmitBatchJob IAM resource to job definition name |
@JahanzaibTayyab |
2026-04-25 (88d) |
| #37688 |
fix(stepfunctions): default StateMachine IAM role missing confused deputy protection best practices |
@NaveenKumar-Marupalli |
2026-04-26 (88d) |
| #36919 |
feat(cloudwatch): support live data for SingleValueWidget in cloudwatch dashboards |
@Darasimi-Ajewole |
2026-04-26 (87d) |
| #37695 |
fix(cloudwatch): make concrete widgets assignable to widget interface |
@cyphercodes |
2026-04-27 (87d) |
| #37736 |
fix(elasticache): use time string for serverless backup time |
@MukundaKatta |
2026-04-30 (83d) |
| #37638 |
fix(rds): fix default port in proxy |
@tiksangng |
2026-05-04 (79d) |
| #37759 |
fix(core): preserve unresolved Tags property tokens |
@tejakusireddy |
2026-05-05 (79d) |
| #37787 |
fix(backup): use Conditions instead of ListOfTags in BackupSelection |
@emfrab |
2026-05-07 (76d) |
| #36640 |
feat(pipelines): default manual approval steps to service role |
@lexedwards |
2026-05-11 (73d) |
| #36225 |
feat(neptune-alpha): add publiclyAccessible |
@dennis-ruhe-npo |
2026-05-11 (72d) |
| #37297 |
feat(cloudwatch): add L2 construct for AlarmMuteRule |
@kawaaaas |
2026-05-14 (69d) |
| #37316 |
feat(cloudfront-origins): add mutual TLS (mTLS) authentication support for custom origins |
@kawaaaas |
2026-05-14 (69d) |
| #37881 |
fix(eks-v2): expose access entry groups and username |
@MukundaKatta |
2026-05-15 (69d) |
| #37890 |
feat(sns-subscriptions): support cross-region delivery from opt-in regions |
@DavidA94 |
2026-05-15 (68d) |
| #36584 |
fix(ecs): stack name can result in noncompliant capacity provider name |
@kichik |
2026-05-19 (64d) |
| #37954 |
fix(logs): emit root ARN in resource policy to prevent CloudFormation drift |
@nithinnnv |
2026-05-21 (63d) |
| #37670 |
fix(s3-deployment): sanitize all log outputs to mitigate CWE-117/93 |
@jonmiller-iv |
2026-05-21 (62d) |
| #37963 |
fix(custom-resource-handler): remove hardcoded partition in s3 auto-delete-objects handler |
@Khangdang1690 |
2026-05-21 (62d) |
| #37965 |
fix(stepfunctions-tasks): mapFromJsonPath produces invalid M.$.$ key for tokenized JsonPath |
@Khangdang1690 |
2026-05-21 (62d) |
| #37968 |
fix(bedrockagentcore): fromAsset, fromS3, fromEcrRepository, fromCodeAsset - AgentRuntimeArtifact does not support multiple Runtimes with single artifact due to permissions grant problem |
@NaveenKumar-Marupalli |
2026-05-22 (62d) |
| #37988 |
feat(glue-alpha): support Apache Iceberg tables |
@ksco92 |
2026-05-24 (59d) |
| #37991 |
docs(sns): expand grant* JSDoc with granted actions |
@MukundaKatta |
2026-05-24 (59d) |
| #37994 |
fix(events): cannot specify a custom id on rule targets |
@tskawada |
2026-05-25 (58d) |
| #38008 |
fix(glue-alpha): omit comments from struct type strings |
@sjh9714 |
2026-05-26 (57d) |
| #37858 |
feat(lambda-python-alpha): opt-in local (docker-less) bundling for PythonFunction |
@CoreOxide |
2026-05-27 (56d) |
| #38032 |
fix(batch): use uppercase MANAGED/UNMANAGED for ComputeEnvironment type to avoid CloudFormation drift (under feature flag) |
@1mwataru |
2026-05-28 (55d) |
| #37958 |
feat(synthetics): added additional synthetics python selenium runtimes |
@acehlis |
2026-05-29 (54d) |
| #37941 |
fix(lambda-nodejs): add support for propagating devEngines field |
@zbrydon |
2026-05-30 (54d) |
| #37998 |
fix(stepfunctions): grant KMS permissions for distributed map S3 IO |
@dcsid |
2026-05-30 (54d) |
| #38012 |
fix(lambda): exclude unattached stack layers from function version hash |
@arieleli01212 |
2026-05-31 (52d) |
| #37742 |
feat(aws-cdk-lib): add s3FilesVolumeConfiguration to Volume |
@kench |
2026-06-01 (51d) |
| #37562 |
chore: change security group validation error for allowAllOubound from ipv6 to ipv4 |
@geotrieu |
2026-06-03 (50d) |
| #38046 |
fix(lambda-nodejs): bundling fails in pnpm workspaces using catalogs |
@ymulenll |
2026-06-04 (48d) |
| #38098 |
docs(s3): enableEventBridgeNotification() emits object created S3 events |
@2dukes |
2026-06-05 (47d) |
| #38104 |
fix(s3): make Bucket assignable to IBucket under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38036 |
fix(ec2): make VpcBase assignable to IVpc under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38066 |
fix(events): make EventBus and ApiDestination assignable to their interfaces under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38081 |
fix(appconfig): make ConfigurationBase assignable to IConfiguration under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38082 |
fix(lambda): make Alias and Version assignable to IAlias/IVersion under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38084 |
fix(secretsmanager): make SecretBase and SecretTargetAttachment assignable to their interfaces under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38091 |
fix(codedeploy): make ServerDeploymentGroup assignable to IServerDeploymentGroup under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38093 |
fix(apigateway): make RestApiBase assignable to IRestApi under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38097 |
fix(ecs): make Cluster and task definitions assignable to their interfaces under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #37880 |
fix(codepipeline): clean up cross-region replication buckets |
@nanookclaw |
2026-06-06 (46d) |
| #38105 |
fix(dynamodb): make Table and TableV2 assignable to their interfaces under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38106 |
fix(apigatewayv2): make HttpApi assignable to IHttpApi under exactOptionalPropertyTypes |
@laazyj |
2026-06-06 (46d) |
| #38107 |
fix(batch): make ComputeEnvironments and JobQueue assignable to their interfaces under exactOptionalPropertyTypes |
@laazyj |
2026-06-07 (45d) |
| #38108 |
fix(pipelines): make Step subclasses assignable to IFileSetProducer under exactOptionalPropertyTypes |
@laazyj |
2026-06-07 (45d) |
| #38123 |
docs(dynamodb): fix typo in TableV2MultiAccountReplica docs |
@engjonah |
2026-06-10 (43d) |
| #38143 |
fix(s3): cannot create ACCOUNT_REGIONAL bucket with specified bucketName in L2 Bucket |
@NaveenKumar-Marupalli |
2026-06-17 (35d) |
| #37984 |
fix(bedrock-agentcore-alpha): add tracing resource policy opt-out |
@gingeekrishna |
2026-06-19 (33d) |
Pre-existing backlog of beginning-contributor PRs pending maintainer CI action, snapshotted 2026-07-23.
170 PR(s) — 🔒 Pending CI approval: 88 ·⚠️ No build CI activity: 82
🔒 Pending CI approval (86)
executionModesupport in CodePipeline L3 constructEventBus.archive()does not forward kmsKey to the underlying Archive constructChoice.afterwards()excludes the otherwise branch from end states by defaultTableV2MultiAccountReplicaomits top-level SSESpecification for KMS encryptionStepScalingPolicyemits spurious cooldown deprecation warningMemorydoes not set defaultChild, breaking applyRemovalPolicyMemoryno longer creates an unused execution roleSecurityGroupvalidation error msg (trivial)Bucketreplication metrics cannot be enabled without replication time control (RTC)StateMachineIAM role missing confused deputy protection best practicesSingleValueWidgetin cloudwatch dashboardsdevEnginesfieldbucketNamein L2BucketClose this issue once all listed PRs have been handled.