Skip to content

Conversation

@snyk-bot
Copy link
Contributor

@snyk-bot snyk-bot commented Apr 2, 2023

Snyk has created this PR to upgrade @aws-sdk/client-s3 from 3.235.0 to 3.289.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 26 versions ahead of your current version.
  • The recommended version was released 23 days ago, on 2023-03-10.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-FASTXMLPARSER-3325616
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @aws-sdk/client-s3
  • 3.289.0 - 2023-03-10

    3.289.0(2023-03-10)

    Documentation Changes
    New Features
    • clients: update client endpoints as of 2023-03-10 (feb6f9b6)
    • client-secrets-manager: The type definitions of SecretString and SecretBinary now have a minimum length of 1 in the model to match the exception thrown when you pass in empty values. (4382b4eb)
    • client-ivschat: This release adds a new exception returned when calling AWS IVS chat UpdateLoggingConfiguration. Now UpdateLoggingConfiguration can return ConflictException when invalid updates are made in sequence to Logging Configurations. (8b55eb13)

    For list of updated packages, view updated-packages.md in assets-3.289.0.zip

  • 3.288.0 - 2023-03-09

    3.288.0(2023-03-09)

    Chores
    Documentation Changes
    • client-networkmanager: This update provides example usage for TransitGatewayRouteTableArn. (b39cd0ec)
    New Features
    • clients: update client endpoints as of 2023-03-09 (3b31ade0)
    • client-connect: This release adds a new API, GetMetricDataV2, which returns metric data for Amazon Connect. (acb5eef6)
    • client-servicediscovery: Updated all AWS Cloud Map APIs to provide consistent throttling exception (RequestLimitExceeded) (cb39c4dc)
    • client-redshift-data: Added support for Redshift Serverless workgroup-arn wherever the WorkgroupName parameter is available. (344d56c8)
    • client-sagemaker: Amazon SageMaker Inference now allows SSM access to customer's model container by setting the "EnableSSMAccess" parameter for a ProductionVariant in CreateEndpointConfig API. (253ef071)
    • client-quicksight: This release has two changes: add state persistence feature for embedded dashboard and console in GenerateEmbedUrlForRegisteredUser API; add properties for hidden collapsed row dimensions in PivotTableOptions. (6c3f7b10)
    • client-codeartifact: This release introduces the generic package format, a mechanism for storing arbitrary binary assets. It also adds a new API, PublishPackageVersion, to allow for publishing generic packages. (235876ea)
    • client-evidently: Updated entity override documentation (5df80f23)
    • client-sesv2: This release introduces a new recommendation in Virtual Deliverability Manager Advisor, which detects missing or misconfigured Brand Indicator for Message Identification (BIMI) DNS records for customer sending identities. (d58f7524)
    Bug Fixes
    • middleware-logger: retrieve filter overrides after middleware returns (#4502) (6405a58c)

    For list of updated packages, view updated-packages.md in assets-3.288.0.zip

  • 3.287.0 - 2023-03-08

    3.287.0(2023-03-08)

    New Features
    • clients: update client endpoints as of 2023-03-08 (2fb9a440)
    • client-mediapackage: This release provides the date and time live resources were created. (e91ea700)
    • client-lakeformation: This release adds two new API support "GetDataCellsFiler" and "UpdateDataCellsFilter", and also updates the corresponding documentation. (9a29cfb8)
    • client-athena: A new field SubstatementType is added to GetQueryExecution API, so customers have an error free way to detect the query type and interpret the result. (12c6c35a)
    • client-mediapackage-vod: This release provides the date and time VOD resources were created. (eb5cff67)
    • client-ec2: Introducing Amazon EC2 C7g, M7g and R7g instances, powered by the latest generation AWS Graviton3 processors and deliver up to 25% better performance over Graviton2-based instances. (8a6dcfa8)
    • client-sagemaker: There needs to be a user identity to specify the SageMaker user who perform each action regarding the entity. However, these is a not a unified concept of user identity across SageMaker service that could be used today. (392879ff)
    • client-route53resolver: Add dual-stack and IPv6 support for Route 53 Resolver Endpoint,Add IPv6 target IP in Route 53 Resolver Forwarding Rule (ab22b632)
    • client-dynamodb: Adds deletion protection support to DynamoDB tables. Tables with deletion protection enabled cannot be deleted. Deletion protection is disabled by default, can be enabled via the CreateTable or UpdateTable APIs, and is visible in TableDescription. This setting is not replicated for Global Tables. (af815752)
    • shared-ini-file-loader: enable uncached credential loading (#4253) (89dc903e)
    • middleware-logger: log request errors (#4252) (8c667ff1)
    Bug Fixes
    • client-support: apply sparse string list for metadata (#4500) (22048ebc)
    • clients: remove aggregated client from paginators (#4496) (aea457ab)

    For list of updated packages, view updated-packages.md in assets-3.287.0.zip

  • 3.282.0 - 2023-03-01

    3.282.0(2023-03-01)

    New Features
    • clients: update client endpoints as of 2023-03-01 (a52821d9)
    • client-pricing: This release adds 2 new APIs - ListPriceLists which returns a list of applicable price lists, and GetPriceListFileUrl which outputs a URL to retrieve your price lists from the generated file from ListPriceLists (f7201bf1)
    • client-codecatalyst: Published Dev Environments StopDevEnvironmentSession API (6458cf1e)
    • client-s3outposts: S3 on Outposts introduces a new API ListOutpostsWithS3, with this API you can list all your Outposts with S3 capacity. (9b55483d)
    • protocol-http: use lowercase keys in Fields class (#4450) (e0db41d8)

    For list of updated packages, view updated-packages.md in assets-3.282.0.zip

  • 3.281.0 - 2023-02-28

    3.281.0(2023-02-28)

    Documentation Changes
    • client-kms: AWS KMS is deprecating the RSAES_PKCS1_V1_5 wrapping algorithm option in the GetParametersForImport API that is used in the AWS KMS Import Key Material feature. AWS KMS will end support for this wrapping algorithm by October 1, 2023. (08b46cea)
    • fix missing dashes in client readmes (#4480) (95b351a0)
    • clients: add operations list to README (#4478) (f99f740c)
    New Features
    • clients: update client endpoints as of 2023-02-28 (387a8e77)
    • client-lightsail: This release adds Lightsail for Research feature support, such as GUI session access, cost estimates, stop instance on idle, and disk auto mount. (f86feb54)
    • client-managedblockchain: This release adds support for tagging to the accessor resource in Amazon Managed Blockchain (82de475e)
    • client-ec2: This release allows IMDS support to be set to v2-only on an existing AMI, so that all future instances launched from that AMI will use IMDSv2 by default. (b623f244)
    • client-comprehend: Amazon Comprehend now supports flywheels to help you train and manage new model versions for custom models. (af221943)
    • client-omics: Minor model changes to accomodate batch imports feature (386065a1)

    For list of updated packages, view updated-packages.md in assets-3.281.0.zip

  • 3.279.0 - 2023-02-24
  • 3.278.0 - 2023-02-23
  • 3.276.0 - 2023-02-21
  • 3.272.0 - 2023-02-15
  • 3.271.0 - 2023-02-14
  • 3.267.0 - 2023-02-08
  • 3.266.1 - 2023-02-07
  • 3.266.0 - 2023-02-06
  • 3.264.0 - 2023-02-02
  • 3.262.0 - 2023-01-31
  • 3.261.0 - 2023-01-30
  • 3.259.0 - 2023-01-26
  • 3.258.0 - 2023-01-25
  • 3.257.0 - 2023-01-24
  • 3.256.0 - 2023-01-23
  • 3.254.0 - 2023-01-19
  • 3.252.0 - 2023-01-17
  • 3.245.0 - 2023-01-05
  • 3.241.0 - 2022-12-29
  • 3.238.0 - 2022-12-23
  • 3.236.0 - 2022-12-21
  • 3.235.0 - 2022-12-20
from @aws-sdk/client-s3 GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@snyk-bot snyk-bot requested a review from pkspyder007 as a code owner April 2, 2023 23:29
@vercel
Copy link

vercel bot commented Apr 2, 2023

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
codu ✅ Ready (Inspect) Visit Preview 💬 Add feedback Apr 2, 2023 11:38pm

@NiallJoeMaher NiallJoeMaher merged commit da86425 into develop Apr 4, 2023
@NiallJoeMaher NiallJoeMaher deleted the snyk-upgrade-2760d8c3e7c82fe9954f070b43731868 branch April 4, 2023 08:37
NiallJoeMaher pushed a commit that referenced this pull request Oct 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants