NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #2244 most downloaded on NuGet
AWS region information, such as service principal names (Stability: Stable)
Last release 3 days ago
08 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Some releases are documented
notes for 16 of the last 60 stable releases
13 versions withdrawn
withdrawn after publishing
127 years old
625 releases · first in 1900
cfnspec: cloudformation spec v69.0.0 (#20240) (e82b63f) and
grant() for user pool (#20285) (10d13e4)noncurrentVersionsToRetain property to lifecycle rule (#20348) (85604d9), closes #19784One column per quarter.
Nothing published for this version
appsync: incorrect region used for imported Cognito user pool (#20193) (3e0393e), closes #20195
cfnspec: cloudformation spec v68.0.0
inOrganization to ArnPrincipal (#20109) (c545bfe), closes /github.com/aws/aws-cdk/pull/19975#discussion_r857385168 #19975function.addAlias() simplifies Alias creation (#20034) (a79bc47)DatabaseClusterFromSnapshot (#20020) (abc3502), closes #12877aws-cognito: send emails with a verified domain (#19790) (1d2b1d3), closes #19762
IntegTest to group test cases (#20015) (b4f8d91)DatabaseClusterFromSnapshot to set copyTagsToSnapshot property (#19932) (40a6ceb), closes #19884imagebuilder: revert property field typings
apigatewayv2: set throttling on stages (#19776) (3cabd10), closes #19626
IntegTestCase (#19829) (ad249c9)id contract is not clear (#19825) (5472b11), closes #13942 #17126onFailure for KafkaEventSources (#19995) (383171b), closes #19917cfnspec: cloudformation spec v63.0.0
cdk import (#17666) (4f12209)Fn.select incorrectly short-circuits complex expressions (#19680) (7f26fad)aws-ec2: Enable/disable EC2 "Detailed Monitoring"
addAction() on an imported application listener (#19293) (18a6b0c), closes #10902function.grantInvoke while also using currentVersion (#19464) (fd1fff9), closes #19273 #19318SnapshotCredentials.fromSecret() takes a Secret, not ISecret (#19639) (a74d82e), closes #19409appsync: support custom domain mappings (#19368) (8c7a4ac), closes #18040
StepFunctionsIntegration does not create required role and responses (#19486) (d59bee9).gitignore (#19482) (5ce0983)Invoke with Qualifier authorization strategy (#19318) (d06b27f), closes #19273stepfunctions-tasks: migrate from deprecated batch properties (#19298) (75f5b3b), closes #18993
hasNoXXX methods. (#19330) (6bdc9eb), closes #18874cli: deprecated stack ids printed at the end of synth (#19216) (7d8a479), closes #18599
s3:ObjectRestore:Delete to EventType for notification (#19250) (e0f863a), closes #19223watch logs always end with the 'truncated' message (#19241) (d3fdfe5), closes #18805cfnspec: cloudformation spec v58.0.0
grant*Data() methods are missing the dynamodb:DescribeTable permission (#19129) (4a44a65), closes #18773Table.grantWriteData() doesn't include enough KMS permissions (#19102) (77f1e0b), closes #10010logLevel property of BundlingOptions is ignored when nodeModules are defined (#18456) (5c40b90), closes #18383apigatewayv2: Import existing WebSocketApi from attributes
aws-stepfunctions-tasks: add environment property for SageMakerCreateTrainingJob (#18976) (60d6e66), closes #18919
deployedBucket attribute for sequencing (#15384) (edac101)assets: support networking mode for DockerImageAsset (#18114) (a7b39f5), closes #15516
cdk diff works for Nested Stacks (#18207) (1337b24), closes #5722amplify: support performance mode in Branch (#18598) (bdeb8eb), closes #18557
UserData.addSignalOnExitCommand does not work in combination with userDataCausesReplacement (#18726) (afdc550), closes #12749cfnspec: cloudformation spec v53.1.0
readTimeout maximum value for HttpOriginProps (#18697) (e64de67), closes #18628servicecatalog: TagOptions now have scope and props argument in constructor, and data is now passed via a allowedValueForTags field in props
TagOptions now have scope and props argument in constructor, and data is now passed via a allowedValueForTags field in propsBaseService.fromServiceArnWithCluster() for use in CodePipeline (#18530) (3d192a9)updateFunctionCode to complete (#18536) (0e08eeb), closes #18386 #18386grantWrite, grantReadWrite and grantPut methods (#18494) (940d043), closes #13616apigatewayv2: HttpIntegrationType.LAMBDA_PROXY has been renamed to HttpIntegrationType.AWS_PROXY
HttpIntegrationType.LAMBDA_PROXY has been renamed to HttpIntegrationType.AWS_PROXYFirehoseStreamAction has been renamed to FirehosePutRecordActionstringLikeRegexp() matcher (#18491) (b49b002)enabled property of ApiKeyProps is ignored (#18407) (c31f9b4)DYANMODB_WRITE_CAPACITY_UTILIZATION (#18085) (626e6aa), closes #17209cdk watch constantly prints 'messages suppressed' (#18486) (9b266f4), closes #18451Vpc.fromLookup() (#18554) (f55cd2b), closes #17600FirehoseStreamAction is now called FirehosePutRecordAction (#18356) (c016a9f), closes /github.com/aws/aws-cdk/pull/18321#discussion_r781620195apigatewayv2-authorizers: WebSocketLambdaAuthorizerProps.identitySource default changes from ['$request.header.Authorization'] to ['route.request.head
WebSocketLambdaAuthorizerProps.identitySource default changes from ['$request.header.Authorization'] to ['route.request.header.Authorization'].Cfn* constructs) with
names starting with a capital letter I followed by another capital
letter are no longer incorrectly treated as behavioral interfaces, and
might hence have different usage patterns in non-TypeScript languages.
Such interfaces were previously very difficult to use in non-TypeScript
languages, and required convoluted workarounds, which can now be removed.ScanOnPush is now enabled by default (#17994) (7588b51)AuthenticationMethod.CLIENT_CERTIFICATE_TLS_AUTH to kafka (#17920) (93cd776)identitySource default for WebSocketLambdaAuthorizer (#18315) (74eee1e), closes #18307colors (#18324) (ddc2bc6)DockerCredential.dockerHub() silently fails auth (#18313) (c2c87d9), closes #15737cli: breaks due to faulty version of colors
lambda-python: asset files are generated inside the 'asset-input' folder
lambda-python: assetHashType and assetHash properties moved to new bundling property.
assetHashType and assetHash properties moved to new bundling property.LambdaPythoncdk deploy steps take (#18230) (82fa742), closes #18213Duration.toString() throws an error (#18243) (df03df8), closes #18176Stack.addFileAsset() no longer has effect (#18116) (2290681), closes #17328opensearchservice: imported domain property domainEndpoint used to contain https:// prefix, now the prefix is dropped and it returns the same value as
domainEndpoint used to contain https:// prefix, now the prefix is dropped and it returns the same value as a domainEndpoint on a created domaindefaultChild of a KubernetesManifest is not a CfnResource (#18052) (ef8ab72)domainendpoint is a url not an endpoint (#18027) (fd149b1), closes #18017appsync: The CachingConfig#ttl property is now required.
CachingConfig#ttl property is now required.ttl property of CachingConfig is not required (#17981) (73e5fec)batchDeletePartition from grantRead() permissions (#17941) (3d64f9b), closes #17935 #15116DatabaseInstance (#17995) (0745193), closes #17948apigatewayv2-authorizers: The default value for the prop authorizerName in HttpJwtAuthorizerProps has changed.
authorizerName
in HttpJwtAuthorizerProps has changed.HttpJwtAuthorizer now takes the
construct id and the target jwt issuer as part of its constructor.HttpLambdaAuthorizer now takes
the construct id and the target lambda function handler as part of
its constructor.authorizerName in HttpUserPoolAuthorizerProps has changed.HttpIntegration and WebSocketIntegration
classes require an "id" parameter to be provided during its initialization.LambdaWebSocketIntegration is now
renamed to WebSocketLambdaIntegration. The new class accepts the
handler to the target lambda function directly in its constructor.HttpProxyIntegration and
HttpProxyIntegrationProps are now renamed to HttpUrlIntegration
and HttpUrlIntegrationProps respectively. The new class accepts the
target url directly in its constructor.LambdaProxyIntegration and
LambdaProxyIntegrationProps are now renamed to
HttpLambdaIntegration and HttpLambdaIntegrationProps respectively.
The new class accepts the lambda function handler directly in its
constructor.HttpAlbIntegration now accepts the
ELB listener directly in its constructor.HttpNlbIntegration now accepts the
ELB listener directly in its constructor.HttpServiceDiscoveryIntegration now
accepts the service discovery Service directly in its constructor.UserPoolAuthorizerProps is now
renamed to HttpUserPoolAuthorizerProps.IHttpRouteIntegration is replaced by
the abstract class HttpRouteIntegration.IWebSocketRouteIntegration is now
replaced by the abstract class WebSocketRouteIntegration.HttpApi instances
(or WebSocketApi instances). This is now disallowed, and separate
instances must be created for each instance of HttpApi or
WebSocketApi.fromGroupName() for IAM groups (#17243) (29b379c)stringLike() (#17692) (37596e6)Stage (#17730) (f17f29e), closes #17643waitForReplicationToFinish fails deployment (#17842) (36b8fdb), closes #16983nodeModules (#17851) (5737c33), closes #17830nodeModules fails with paths containing spaces (#17632) (986f291), closes #17631apigatewayv2: domain endpoint type, security policy and endpoint migration
warn users when deprecated elements are used
DynamoAttributeValue.listFromJsonPath (#17376) (bc10e6f), closes #17375Function.addEventSource fails for ManagedKafkaEventSource typed parameters (#17490) (a474ee8)policy.ts exports in index.ts exports (#17403) (a391468)apigatewayv2: http api - mTLS support (#17284) (54be156), closes #12559
AutoTerminationPolicy to EmrCreateCluster (#16976) (27ad7d8)apigatewayv2-authorizers: userPoolClient property in UserPoolAuthorizerProps is now renamed to userPoolClients.
userPoolClient property in UserPoolAuthorizerProps
is now renamed to userPoolClients.build field to cdk.json (#17176) (57ad1e0)description and enabled of TopicRule (#17225) (a9aae09)errorAction of TopicRule (#17287) (e412308)wmic not found on modern Windows systems (#17070) (332ce4d), closes #16419additionalInputs not working (#17279) (9e81dc7), closes #17224amplify: Add support for custom headers in the App (#17102) (9f3abd7), closes #17084
DefaultSynthesizer deployments are never skipped (#17099) (c74b012), closes #16959aws-autoscaling: add flag and aspect to require imdsv2
enableNetworkIsolation property to SageMakerCreateTrainingJobProps (#16792) (69ac520), closes #16779npm install [package]@[version] (#17078) (a129046)additionalInputs fails for deep directory (#17074) (403d3ce), closes #16936assertions: Starting this release, the assertions module will be published to Maven with the name 'assertions' instead of 'cdk-assertions'.
assertions module will be
published to Maven with the name 'assertions' instead of
'cdk-assertions'.assertions: Match.absentProperty() becomes Match.absent(), and its type changes from string to Matcher.
Match.absentProperty() becomes Match.absent(), and its type changes from string to Matcher.hasResourceProperties is incompatible with Match.not and Match.absent (#16678) (6f0a507), closes #16626Principal: * (#16843) (6829a2a)assertions: The templateMatches() API previously performed an exact match. The default behavior has been updated to be "object-like".
templateMatches() API previously performed
an exact match. The default behavior has been updated to be
"object-like".templateMatches() API (#16789) (0fb2179)connectAutoScalingGroupCapacity on imported clusters (#14650) (7f7be08)NetworkLoadBalancer.configureHealthCheck() (#16445) (140892a)User.fromUserArn does not work for ARNs that include a path (#16269) (5c69c94), closes 40aws-cdk/aws-iam/lib/role.ts#L191-L194 #16256autoDeleteObjects to false empties the bucket (#16756) (21836f2), closes #16603lambda: support for ARM architecture
assertions: the findResources() API previously returned a list of resources, but now returns a map of logical id to resource.
findResources() API previously returned a list of resources, but now returns a map of logical id to resource.findOutputs() API previously returned a list of outputs, but now returns a map of logical id to output.findMappings() API previously returned a list of mappings, but now returns a map of logical id to mapping.cacheInContext properties for machine images (#16021) (430f50a), closes #12484SecretString -> SecureString and note how SecureStrings cannot be created via CDK (#16228) (950e875)opensearch: rebrand Elasticsearch as OpenSearch (e6c4ca5), closes aws/aws-cdk#16467
assertions: hasOutput(props: any) becomes hasOutput(logicalId: string, props: any)
hasOutput(props: any) becomes hasOutput(logicalId: string, props: any)findOutputs(props: any = {}) becomes findOutputs(logicalId: string, props: any = {})hasMapping(props: any) becomes hasMapping(logicalId: string, props: any)findMappings(props: any = {}) becomes findMappings(logicalId: string, props: any = {})defaultStage are not available without casting it to IHttpStage (#15607) (27a0113)assertions: 'not' matcher (#16240) (b838f95), closes #15868
--no-rollback flag (#16293) (d763d90), closes #16289fromDatabaseInstanceAttributes() incorrectly stringifies ports with tokens (#16286) (41b831a), closes #11813assertions: queries and assertions against the Outputs and Mappings sections
apigatewayv2: http api - domain url for a stage (#15973) (bb5d587), closes #15801
aws-elbv2: ALB target group routing algorithms (#15622) (6b32b2f), closes #15160
assertions: Template.fromTemplate() is now renamed to Template.fromJSON() to provide clarity.
Template.fromTemplate() is now
renamed to Template.fromJSON() to provide clarity.TemplateAssertions is now renamed to
Template.assertions: retrieve matching resources from the template
cli: cdk deploy is listing deprecated ids
cdk deploy is listing deprecated ids (#15603) (22f2499)PrincipalWithConditions.addCondition does not work (#15414) (fdce08c)CodeBuildStep.partialBuildSpec not used, buildspec control for legacy API (#15625) (d8dc818), closes #15169appmesh: prefixPath property in HttpGatewayRouteMatch has been renamed to path, and its type changed from string to HttpGatewayRoutePathMatch
prefixPath property in HttpGatewayRouteMatch has been renamed to path, and its type changed from string to HttpGatewayRoutePathMatchAcceptLanguage enum has been renamed to MessageLanguage, and fields that accepted this enum have been updated to reflect this change.acceptLanguage in PortfolioShareOptions has been renamed to messageLanguage.acceptLanguage in PortfolioProps has been renamed to messageLanguage.acceptLanguage in CloudFormationProductProps has been renamed messageLanguage.prefixPath property in HttpRouteMatch has been renamed to path, and its type changed from string to HttpRoutePathMatchassets: docker images from tar file (#15438) (76f06fc), closes #15419
appmesh: the class HttpHeaderMatch has been renamed to HeaderMatch
HttpHeaderMatch has been renamed to HeaderMatchHttpRouteMatchMethod has been renamed to HttpRouteMethodServiceDiscovery.cloudMap() method has been changed to accept positional argumentsassertions: 'arrayWith' and 'objectLike' matchers
eks: kubectl version 1.21.0 breaks object pruning (#15314) (623689d), closes #15072
appmesh: static methods from TlsValidationTrust have been changed to accept positional arguments
TlsValidationTrust have been changed to accept positional argumentsTlsCertificate have been changed to accept positional argumentsTlsListener has been renamed to ListenerTlsOptionsstring instead of any for cloudwatch dimension values (#15097) (dc3cf13), closes #14978deploy-role could directly access buckets in target account (#15192) (d04e288), closes #12985 #14082 #134221 hour renders as 60 minutes (#15125) (adcd8c3)apigateway: disable execute api endpoint
cdk synth too eager with validation in Pipelines (#15147) (ae98e88), closes #14613 #15130--all selects stacks in nested assemblies (#15046) (0d00e50)cfnspec: cloudformation spec v39.1.0
cfnspec: imageScanningConfiguration property of ecr.CfnRepository now accepts scanOnPush instead of ScanOnPush (notice the casing change).
imageScanningConfiguration property of ecr.CfnRepository now accepts scanOnPush instead of ScanOnPush (notice the casing change).cdk bootstrap to update to bootstrap stack version '6'.fromCfnKey() method (#14859) (1ff5b9e), closes #9719 #14795 #14809autoDeleteObjects had redundant GetObject* permissions (#14573) (f9be15d), closes #14572appmesh: the creation property clientPolicy in VirtualNode has been renamed to tlsClientPolicy, and its type changed to TlsClientPolicy
clientPolicy in VirtualNode has been renamed to tlsClientPolicy, and its type changed to TlsClientPolicyTlsClientPolicy, validation property must be defined.tlsCertificate in VirtualNode has been renamed to tls, and its type changed to TlsListenertlsMode property has been removed from the options when creating a TlsCertificate, moved to the new TlsListener interface, and renamed modesecretsmanager: revert "Automatically grant permissions to rotation Lambda (#14471)", fixes #14868
ecs-service-extensions: allow taskRole to be passed in on creation of an ECS service
lambda-nodejs: using banner and footer now requires esbuild >= 0.9.0
banner and footer now requires esbuild >= 0.9.0package.json (#14745) (0b8ee97), closes #14658Your coding agent can read these notes before it upgrades. Set up the MCP server →