NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #2244 most downloaded on NuGet
AWS region information, such as service principal names (Stability: Stable)
Last release 2 days ago
08 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Some releases are documented
notes for 16 of the last 60 stable releases
13 versions withdrawn
withdrawn after publishing
127 years old
625 releases · first in 1900
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
aws-appstream: AWS::AppStream::StackFleetAssociation: FleetName property is now immutable.
aws-appstream: AWS::AppStream::StackFleetAssociation: StackName property is now immutable.
aws-appsync: AWS::AppSync::ApiCache: AtRestEncryptionEnabled property is now immutable.
aws-appsync: AWS::AppSync::ApiCache: TransitEncryptionEnabled property is now immutable.
aws-bedrockagentcore: AWS::BedrockAgentCore::OnlineEvaluationConfig: OutputConfig attribute removed.
aws-cloud9: AWS::Cloud9::EnvironmentEC2: Id attribute removed.
aws-config: AWS::Config::ConfigurationRecorder: Id attribute removed.
aws-config: AWS::Config::OrganizationConfigRule: Id attribute removed.
aws-datazone: AWS::DataZone::PolicyGrant: Detail property is now required.
aws-datazone: AWS::DataZone::PolicyGrant: Principal property is now required.
aws-directoryservice: AWS::DirectoryService::MicrosoftAD: Id attribute removed.
aws-lambda: AWS::Lambda::NetworkConnector: VpcEgressConfiguration.NetworkProtocol property is now required.
aws-lambda: AWS::Lambda::NetworkConnector: VpcEgressConfiguration.SecurityGroupIds property is now required.
executionMode support in CodePipeline L3 construct (#35022) (7283d38), closes #35014Source.data objectKey can write outside the staging directory (#38921) (53439f9)loggingProperties prop on ClusterProps (and the LoggingProperties interface) has been removed from @aws-cdk/aws-redshift-alpha. Use the new logging prop with ClusterLogging.s3({ bucket, keyPrefix }) or ClusterLogging.cloudWatch({ logExports }) instead.One column per quarter.
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
** L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can
contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
aws-servicediscovery: AWS::ServiceDiscovery::Instance: primary identifier is now ServiceId and InstanceId, so InstanceReference now requires serviceId.
codebuild: add hostKernel to build environment ( #38513 ) ( deec895 ), closes #38338 #38338 #38275 #38338
Invalid URL error (#38867) (6eb07dd)resolveReferences should only update references that require updates on its second pass in nested stacks (#38813) (6cf5313)L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
** L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can
contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
aws-codecommit: AWS::CodeCommit::Repository: Id attribute removed.
aws-config: AWS::Config::DeliveryChannel: DeliveryFrequency property values narrowed to an enum.
aws-dms: AWS::DMS::ReplicationTask: Id attribute removed.
Bucket replication metrics cannot be enabled without replication time control (RTC) (#35929) (cd97d96), closes #35772 /github.com/aws/aws-cdk/issues/35772#issuecomment-3427574206dynamodb: TableV2 emits internal grants deprecation warnings ( #38806 ) ( 57b3043 ), closes #38709 #38399 #37892
TableV2 emits internal grants deprecation warnings (#38806) (57b3043), closes #38709 #38399 #37892defaultArguments. Previously, a managed argument set viadefaultArguments was silently honored in SparkJob and PythonShellJob (customerRayJob (constructdefaultArguments now throws a ValidationError at synthesis time:--enable-continuous-cloudwatch-log,--continuous-log-logGroup, --continuous-log-logStreamPrefix,--continuous-log-conversionPattern, --enable-continuous-log-filter,--enable-metrics, --enable-observability-metrics, --enable-spark-ui,--spark-event-logs-path, --job-language, --class, --extra-jars,--user-jars-first, --extra-py-files, --extra-files, library-set--debug, --mode, --JOB_NAME, --endpointA managed argument is rejected whether or not the current configuration emits it, so a
disabled feature (e.g. enableMetrics: false) cannot be re-enabled through
defaultArguments. Configure these through their dedicated props instead
(continuousLogging, enableMetrics, enableObservabilityMetrics, sparkUI,
className, extraJars, extraJarsFirst, extraPythonFiles, extraFiles). For
example, replace defaultArguments: { '--enable-continuous-cloudwatch-log': 'false' }
with continuousLogging: { enabled: false }. Arguments without a dedicated prop (e.g.
--enable-glue-datacatalog) are unaffected and remain settable via defaultArguments.
The checkNoReservedArgs(defaultArguments?) method on the Job base class was removed.
It is replaced by two protected members: setManagedArgument(key, value?), which each
job class calls to declare (and, when a value is present, emit) a managed argument, and
mergeDefaultArguments(defaultArguments?), which validates the caller-supplied
defaultArguments against the accumulated reserved set and returns the merged map.
FirewallRuleGroupAssociation now honors the previously-ignored mutationProtection and name props. Stacks that set mutationProtection: true will enable mutation protection on redeploy (which blocks further CloudFormation update/delete until it is set back to false); stacks that set name will write it to the template, which may replace the association.Action and Condition are no longer plain objects — use Action.job(...) / Action.crawler(...) and Condition.job(...) / Condition.crawler(...). Jobs are referenced via IJobRef and crawlers via ICrawlerRef (a CfnCrawler instance or CfnCrawler.fromCrawlerName(...)) instead of a CfnCrawler field or crawler-name string; IJob now extends the generated IJobRef. addDailyScheduledTrigger/addWeeklyScheduledTrigger/addCustomScheduledTrigger are replaced by addScheduledTrigger(id, { schedule, ... }) (use TriggerSchedule.daily()/weekly()/cron(...)). addNotifyEventTrigger is renamed addEventTrigger (NotifyEventTriggerOptions → EventTriggerOptions). All addXxxTrigger methods now return ITriggerRef instead of CfnTrigger.step: { interval, intervalUnit } instead of top-level interval/intervalUnit.subnet, vpc, or vpcSubnets; use network: ConnectionNetwork.subnet(...) or network: ConnectionNetwork.vpc(...) instead.s3-deployment: replace deprecated addDependency in integ test
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
AWS::Athena::Session removed.AWS::BCMDataExports::Table removed.AWS::Bedrock::DefaultPromptRouter and AWS::Bedrock::ModelInvocationJob removed.AWS::BedrockAgentCore::Browser, AWS::BedrockAgentCore::CodeInterpreter, and AWS::BedrockAgentCore::TokenVault removed; AWS::BedrockAgentCore::PaymentConnector ConnectorType and AWS::BedrockAgentCore::PaymentCredentialProvider CredentialProviderVendor are now immutable; AWS::BedrockAgentCore::CapacityProvider OperatingSystem allowed values in the LaunchParameters type reduced from [LINUX_X86_64, LINUX_ARM64, MAC_ARM64, WINDOWS_X86_64] to [LINUX_X86_64, LINUX_ARM64].AWS::CertificateManager::Certificate Id attribute removed.AWS::Chime::AppInstance and AWS::Chime::AppInstanceBot, the CreatedTimestamp and LastUpdatedTimestamp attribute types changed from number to string.AWS::CloudFormation::ResourceScan removed.AWS::CodeArtifact::Package removed.AWS::CodeBuild::Sandbox removed; AWS::CodeBuild::SourceCredential Id attribute removed.AWS::DAX::ParameterGroup Id attribute removed; Description property is now immutable.Id attribute removed from AWS::DMS::Endpoint, AWS::DMS::EventSubscription, and AWS::DMS::ReplicationSubnetGroup; AWS::DMS::ReplicationTask MigrationType property is now immutable.Id attribute removed from AWS::DocDB::DBClusterParameterGroup and AWS::DocDB::DBSubnetGroup.AWS::DynamoDB::Export removed.AWS::ElastiCache::ReservedCacheNode removed.AWS::EMR::NotebookExecution removed.AWS::Events::Replay removed.AWS::FIS::SafetyLever removed.Id attribute removed from AWS::Glue::Classifier, AWS::Glue::Connection, AWS::Glue::CustomEntityType, AWS::Glue::DataQualityRuleset, AWS::Glue::MLTransform, AWS::Glue::SecurityConfiguration, AWS::Glue::TableOptimizer, and AWS::Glue::Workflow.AWS::Glue::Connection: complex-property types AuthenticationConfigurationInput and OAuth2PropertiesInput renamed to AuthenticationConfiguration and OAuth2Properties respectively.AWS::Glue::DataQualityRuleset: Name, TargetTable.DatabaseName, and TargetTable.TableName properties are now required; Name property is now immutable; Tags property type changed from json to map<string>.AWS::Glue::CustomEntityType: Name property is now immutable; Tags property is no longer recognised as resource tags.AWS::Glue::MLTransform: TransformEncryption property is now immutable.AWS::GreengrassV2::Component and AWS::GreengrassV2::CoreDevice removed.AWS::IdentityStore::AllGroupMemberships removed.AWS::ImageBuilder::AllImageBuildVersions, AWS::ImageBuilder::AllWorkflowBuildVersions, AWS::ImageBuilder::WorkflowExecution, and AWS::ImageBuilder::WorkflowStepExecution removed.AWS::MediaLive::Offering removed.AWS::MediaConvert::Preset Id attribute removed.AWS::MediaPackage::HarvestJob removed.AWS::MemoryDB::MultiRegionParameterGroup and AWS::MemoryDB::ReservedNode removed.AWS::Omics::Reference removed.AWS::OSIS::PipelineBlueprint removed.AWS::Personalize::DataDeletionJob and AWS::Personalize::Recipe removed.AWS::RedshiftServerless::RecoveryPoint removed.AWS::Route53::RecordSet GeoProximityLocation property removed, along with its supporting GeoProximityLocation and Coordinates complex-property types; Id attribute removed.AWS::SageMaker::ModelCardExportJob, AWS::SageMaker::MonitoringScheduleAlert, and AWS::SageMaker::TransformJob removed.AWS::SES::ReceiptRuleSet Id attribute removed.AWS::Signer::SigningJob removed.AWS::SSM::Session removed; AWS::SSM::Association InstanceId property is now immutable.AWS::SSO::ApplicationProvider removed.AWS::StepFunctions::MapRun removed.AWS::Transcribe::MedicalTranscriptionJob removed.AWS::VpcLattice::ServiceNetwork SharingConfig property is now immutable.DataQualityTargetTable's constructor is removed — use DataQualityTargetTable.fromTable(database, table) or fromTableName(database, tableName); IDatabase now extends IDatabaseRef.DataQualityRulesetProps.clientToken is removed; use the CfnDataQualityRuleset L1 for request-level idempotency.DataQualityRulesetProps.rulesetName is now required. AWS::Glue::DataQualityRuleset made Name a required property, so the name can no longer be left for CloudFormation to generate.dynamodb: avoid TableGrantsProps deprecation warnings for TableV2 ( #38399 ) ( fb5c25b ), closes #37221
timeZone on the Firehose S3Bucket destination now throws a ValidationError during synthesis instead of failing at CloudFormation deployment. Affected values: 3-letter IANA abbreviations (e.g. EST), Etc/UTC, Etc/GMT, Factory, and strings containing characters outside [a-zA-Z/_]+. Use a supported standard IANA identifier (e.g. America/New_York) or UTC for synth to pass.Size objects now properly stringify (#38662) (90fe151)SymlinkFollowMode.BLOCK_EXTERNAL will throw errors while bundling (#38506) (a11e451)TableV2.grants.*Data does not include index resources (#37892) (e48a97f), closes #37569TableV2MultiAccountReplica rejects imported tables with tokenized ARNs (#38365) (08f05e5), closes #38354NatInstanceProvider and NatInstanceProviderV2 always trigger the keyName deprecation warning (#38347) (47f2151), closes #30806Type is now an opaque class; construct column types via the Schema factories or Schema.custom(...) rather than { isPrimitive, inputString } literals. StorageParameter.custom(key, value) requires a string value, and StorageParameter.writeKmsKeyId takes a kms.IKey instead of a string.S3TableProps.bucket/encryption/encryptionKey are removed. Use storage: S3TableStorage.managedBucket(S3TableEncryption.kms(key?)) / S3TableStorage.fromBucket(bucket) and clientSideEncryption: TableClientSideEncryption.kms(key?). S3Table.encryption/encryptionKey are removed (clientSideEncryptionKey exposes the client-side key; read bucket.encryptionKey for server-side). The TableEncryption enum and the deprecated Table/TableProps are removed — use S3Table.Connection (#38561) (f9d7eac)glue-alpha: this is a corrective breaking change. Apps that leaned on the bug, and did things like InputFormat x = OutputFormat.AVRO; will get a compi…
DataQualityRulesetProps.rulesetDqdl: string is replaced bydqdl: Dqdl. Build it with Dqdl.fromString('Rules = [ ... ]').s3Encryption, cloudWatchEncryption, and jobBookmarksEncryption are no longer object literals. Use S3Encryption.s3Managed() / S3Encryption.kms(key?), CloudWatchEncryption.kms(key?), and JobBookmarksEncryption.clientSideKms(key?). The CloudWatchEncryptionMode and JobBookmarksEncryptionMode enums are removed (their mode is now implicit); S3EncryptionMode is retained.InputFormat x = OutputFormat.AVRO; will get a compilation error in other jsii languages. The intended usage, on the other hand, was broken before and works now.workerType and numberOfWorkers are no longer top-level job props. For Spark jobs, pass them together via workerConfiguration: { workerType, numberOfWorkers }. PythonShellJob no longer accepts them (it is sized by maxCapacity). RayJob no longer accepts workerType (it is fixed to Z.2X).SparkJobProps.enableMetrics removed, which will cause a compilation error for any app using it. But there is no behavior change, since this is a dead prop.has_encrypted_data supplied via parameters now throws.hasEncryptedData property (#38511) (c977e36)bump brace-expansion to 5.0.9 to address CVE-2026-69152 ( #38520 ) ( 8764b7b ), closes #38496 #38410
cdk validate can hang indefinitely (#38510) (0a238f3), closes #38498 #38425GlueVersion.V5_0 instead of V3_0. Set glueVersion explicitly to keep the previous behavior.Database resources will change to RETAIN.Database by default (#38535) (9669928)bedrockagentcore: Gateway metric helpers now emit corrected CloudWatch dimensions per-gateway metrics use { Operation, Protocol, Resource } (was { Res
Gateway metric helpers now emit corrected CloudWatch dimensions per-gateway{ Operation, Protocol, Resource } (was { Resource }). Alarms/dashboards built on theRuntimeBase metric helpers now emit corrected CloudWatch dimensions per-resource metrics use { Operation, Name, Resource } (was { Resource }) and aggregated metrics use { AggregateOperation } (was { Resource: 'All' }). Alarms/dashboards built on the old dimensions must be updated.CallApiGatewayRestApiEndpoint does not support JsonATA for api_path (#37738) (9f0afdc), closes #37728 /github.com/aws/aws-cdk/blob/e207b76cc2503701b3c4e2c87023617b485b2fde/packages/aws-cdk-lib/aws-stepfunctions/lib/private/jsonata.ts#L1IDatabase.catalogArn and IDatabase.catalogId were removed in factor of a typeICatalog, which has catalogArn and catalogId. Consumers and implementations were updatedCatalog L2 (#38443) (6a8ba8e)S3Table (#38501) (eb81d5e), closes /docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-5bump brace-expansion to 5.0.8 to address CVE-2026-14257 ( #38410 ) ( 5aaa395 ), closes #38409 #38063
removalPolicy prop removed from FlowProps, GatewayProps, and BridgeProps. These resources now follow CloudFormation's default deletion behaviour (Delete).revert "fix(core): stack.node.addDependency gets slower as stacks grow ( #38314 )" ( #38417 ) ( d97dd8d ), closes #38406 #38406
core: bump @aws/cloudformation-validate to 1.5.1-beta to fix install on Node != 22.x ( #38382 ) ( d409b96 ), closes #38380
ecs: add support ECS-optimized Amazon Linux 2023 (Neuron) AMI
dropInvalidHeaderFields in case of default or switching from true to false (#36483) (208b9db), closes #36409L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
update L1 CloudFormation resource definitions ( #38151 ) ( f266a47 ), closes /docs.aws.amazon.com/AmazonS3/latest/userguide/s3-files-prereq-policies.h
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →