Skip to content

chore(deps): bump the python-dependencies group across 1 directory with 3 updates - #129

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-dependencies-22dcc158f9
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-dependencies-22dcc158f9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on aws-cdk-lib, constructs and pystac[validation] to permit the latest version.
Updates aws-cdk-lib from 2.224.0 to 2.267.0

Release notes

Sourced from aws-cdk-lib's releases.

v2.267.0

⚠ BREAKING CHANGES

  • kinesisfirehose: After this change, specifying an unsupported timeZone on the Firehose S3Bucket destination now throws a ValidationError during synthesis instead of failing at CloudFormation deployment. Affected values: 3-letter IANA abbreviations (e.g. EST), Etc/UTC, Etc/GMT, Factory, and strings containing characters outside [a-zA-Z/_]+. Use a supported standard IANA identifier (e.g. America/New_York) or UTC for synth to pass.

Features

  • backup: add indexActions prop to BackupPlanRule (#34051) (b8be853), closes #34050
  • bedrockagentcore: add manageDeliveryResourcePolicy opt-out for runtime observability (#38372) (5fb086b), closes #38342
  • ci: integration test deployment on maintainer approval (#38519) (c5f6b4f), closes #37333
  • core: Size objects now properly stringify (#38662) (90fe151)
  • sqs: metricApproximateNumberOfMessagesOutstanding (#38661) (f29b27b)

Bug Fixes

  • assets: SymlinkFollowMode.BLOCK_EXTERNAL will throw errors while bundling (#38506) (a11e451)
  • bedrockagentcore: least-privilege browser recording S3 grant (#38604) (7e11d11)
  • ci: add environment for Atmosphere variables access (#38625) (785773e), closes #38519
  • cloudfront-origins: readTimeout and keepaliveTimeout reject valid values (#38432) (6251e1a), closes #38433 #18628
  • core: performance counters use too much memory (#38620) (d0ce23c)
  • core: single file bundled output should be file (#38548) (9e22774)
  • core: stack.node.addDependency gets slower as stacks grow (#38597) (2ab9be4), closes #38522
  • core: symlinks in directory bundling output (#38665) (8d8ae2c)
  • core: validation plugin check adds too much overhead (#38619) (df15b9f)
  • dynamodb: TableV2.grants.*Data does not include index resources (#37892) (e48a97f), closes #37569
  • dynamodb: TableV2MultiAccountReplica rejects imported tables with tokenized ARNs (#38365) (08f05e5), closes #38354
  • dynamodb: avoid TableGrantsProps deprecation warnings for TableV2 (#38399) (fb5c25b), closes #37221
  • ec2: NatInstanceProvider and NatInstanceProviderV2 always trigger the keyName deprecation warning (#38347) (47f2151), closes #30806
  • kinesisfirehose: add validation for customTimeZone in S3BucketProps (#38514) (8cf9f90), closes #36089
  • lambda: allow SnapStart for container image functions (#38680) (a5adc00), closes #38281 #38281 #38265
  • rds: serverlessV2 capacity props reject tokens at synth time (#38044) (b7880de), closes #38043 #9044 #31810 #32905
  • s3-deployment: increase default memory limit from 128MB to 1024MB (#35501) (7a04f32), closes #35487
  • stepfunctions-tasks: resolve EvaluateExpression paths via a values lookup (#38682) (02301ea)
  • stack.availabilityZones are not stable strings (#38580) (f89474a)

Alpha modules (2.267.0-alpha.0)

⚠ BREAKING CHANGES

  • glue-alpha: schema Type is now an opaque class; construct column types via the Schema factories or Schema.custom(...) rather than { isPrimitive, inputString } literals. StorageParameter.custom(key, value) requires a string value, and StorageParameter.writeKmsKeyId takes a kms.IKey instead of a string.
  • glue-alpha: S3TableProps.bucket/encryption/encryptionKey are removed. Use storage: S3TableStorage.managedBucket(S3TableEncryption.kms(key?)) / S3TableStorage.fromBucket(bucket) and clientSideEncryption: TableClientSideEncryption.kms(key?). S3Table.encryption/encryptionKey are removed (clientSideEncryptionKey exposes the client-side key; read bucket.encryptionKey for server-side). The TableEncryption enum and the deprecated Table/TableProps are removed — use S3Table.

Features

  • glue-alpha: add a typed secret input to Connection (#38585) (ede4a1c)
  • glue-alpha: add subnet selection to Connection (#38561) (f9d7eac)
  • glue-alpha: model S3Table storage/encryption as value objects (#38591) (9990e16)
  • glue-alpha: opaque Schema Type with Schema.custom, and stronger StorageParameter types (#38592) (5c45eb0)
  • msk-alpha: support Kafka 4.2 (#38323) (97b181c)
  • s3tables-alpha: add storage class configuration support (#37339) (63ccf6d)

... (truncated)

Changelog

Sourced from aws-cdk-lib's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

2.271.0-alpha.0 (2026-09-25)

2.270.0-alpha.0 (2026-09-17)

2.269.0-alpha.0 (2026-09-10)

⚠ BREAKING CHANGES

  • glue-alpha: Glue job constructs now reject construct-managed and Glue-reserved arguments passed through defaultArguments. Previously, a managed argument set via defaultArguments was silently honored in SparkJob and PythonShellJob (customer value won over the construct default) and silently ignored in RayJob (construct default won). Both behaviors let a caller bypass the construct's security and observability defaults with no error. Passing any of the following through defaultArguments now throws a ValidationError at synthesis time:
  • construct-managed arguments — --enable-continuous-cloudwatch-log, --continuous-log-logGroup, --continuous-log-logStreamPrefix, --continuous-log-conversionPattern, --enable-continuous-log-filter, --enable-metrics, --enable-observability-metrics, --enable-spark-ui, --spark-event-logs-path, --job-language, --class, --extra-jars, --user-jars-first, --extra-py-files, --extra-files, library-set
  • Glue-reserved arguments — --debug, --mode, --JOB_NAME, --endpoint

A managed argument is rejected whether or not the current configuration emits it, so a disabled feature (e.g. enableMetrics: false) cannot be re-enabled through defaultArguments. Configure these through their dedicated props instead (continuousLogging, enableMetrics, enableObservabilityMetrics, sparkUI, className, extraJars, extraJarsFirst, extraPythonFiles, extraFiles). For example, replace defaultArguments: { '--enable-continuous-cloudwatch-log': 'false' } with continuousLogging: { enabled: false }. Arguments without a dedicated prop (e.g. --enable-glue-datacatalog) are unaffected and remain settable via defaultArguments.

The checkNoReservedArgs(defaultArguments?) method on the Job base class was removed. It is replaced by two protected members: setManagedArgument(key, value?), which each job class calls to declare (and, when a value is present, emit) a managed argument, and mergeDefaultArguments(defaultArguments?), which validates the caller-supplied defaultArguments against the accumulated reserved set and returns the merged map.

  • route53resolver-alpha: FirewallRuleGroupAssociation now honors the previously-ignored mutationProtection and name props. Stacks that set mutationProtection: true will enable mutation protection on redeploy (which blocks further CloudFormation update/delete until it is set back to false); stacks that set name will write it to the template, which may replace the association.
  • glue-alpha: trigger Action and Condition are no longer plain objects — use Action.job(...) / Action.crawler(...) and Condition.job(...) / Condition.crawler(...). Jobs are referenced via IJobRef and crawlers via ICrawlerRef (a CfnCrawler instance or CfnCrawler.fromCrawlerName(...)) instead of a CfnCrawler field or crawler-name string; IJob now extends the generated IJobRef. addDailyScheduledTrigger/addWeeklyScheduledTrigger/addCustomScheduledTrigger are replaced by addScheduledTrigger(id, { schedule, ... }) (use TriggerSchedule.daily()/weekly()/cron(...)). addNotifyEventTrigger is renamed addEventTrigger (NotifyEventTriggerOptions → EventTriggerOptions). All addXxxTrigger methods now return ITriggerRef instead of CfnTrigger.
  • glue-alpha: PartitionProjectionConfiguration's variant fields (integerRange, dateRange, interval, digits, format, intervalUnit, values) are no longer public; DATE projection now takes step: { interval, intervalUnit } instead of top-level interval/intervalUnit.
  • glue-alpha: ConnectionOptions no longer has subnet, vpc, or vpcSubnets; use network: ConnectionNetwork.subnet(...) or network: ConnectionNetwork.vpc(...) instead.

Features

  • glue-alpha: ensure job parameters consistency (#38480) (bc7dc0c)

... (truncated)

Commits
  • 7d1069e chore(release): 2.267.0 (#38683)
  • 7904d73 chore: update CHANGELOG.v2.alpha
  • 6dc1328 chore: update CHANGELOG.v2
  • 71747d9 chore: update analytics metadata blueprints
  • ccd4868 chore(release): 2.267.0
  • c32f62e chore(spec2cdk): do not export canned metrics from a new submodule index (#38...
  • 9195f79 chore(spec2cdk): resolve attribute name collisions instead of generating dupl...
  • 02301ea fix(stepfunctions-tasks): resolve EvaluateExpression paths via a values looku...
  • a5adc00 fix(lambda): allow SnapStart for container image functions (#38680)
  • b8be853 feat(backup): add indexActions prop to BackupPlanRule (#34051)
  • Additional commits viewable in compare view

Updates constructs from 10.6.0 to 10.8.1

Release notes

Sourced from constructs's releases.

v10.8.1

10.8.1 (2026-08-03)

Bug Fixes

v10.8.0

10.8.0 (2026-07-30)

Features

  • constructs: restrict package exports to public API (#2878) (9f11c08)

v10.7.2

10.7.2 (2026-07-29)

Bug Fixes

  • ids with a newline can produce duplicate addresses (#2876) (25edded)

v10.7.1

10.7.1 (2026-07-20)

Bug Fixes

  • Node.path takes a lot of time on deep construct trees (#2873) (857a94f)

v10.7.0

10.7.0 (2026-07-15)

Features

Commits
  • 740480f fix: dropping jsii.tsc.outDir breaks Java/Go transliteration for jsii-rosetta...
  • 9f11c08 feat(constructs): restrict package exports to public API (#2878)
  • 61a20b4 chore(deps): upgrade cdklabs-projen-project-types (#2877)
  • 25edded fix: ids with a newline can produce duplicate addresses (#2876)
  • b0d316d chore(deps): upgrade dev dependencies (#2875)
  • 4756e27 chore(deps): upgrade dev dependencies (#2874)
  • 857a94f fix: Node.path takes a lot of time on deep construct trees (#2873)
  • 67495a0 feat: removeDependency (#2872)
  • 34b862f chore(deps): upgrade dev dependencies (#2871)
  • 9b63ef8 chore(deps): upgrade dev dependencies (#2870)
  • Additional commits viewable in compare view

Updates pystac[validation] to 1.15.2

Release notes

Sourced from pystac[validation]'s releases.

v1.15.2

1.15.2 (2026-07-27)

Bug Fixes

Changelog

Sourced from pystac[validation]'s changelog.

1.15.2 (2026-07-27)

Bug Fixes

1.15.1 (2026-06-30)

Bug Fixes

  • actually link pystac-core and pystac via release-please (207e38d)
  • consolidate core and top-level package in release-please (#1760) (c6a9fbd)
  • more release-please flailing (#1762) (bcf1062)
  • remove invalid version specifier (#1756) (bc70651)

1.15.0 (2026-06-25)

Bug Fixes

Miscellaneous Chores

  • manually set next versions (64fd083)

1.14.3 (2026-01-08)

Bug Fixes

1.14.2 (2025-12-17)

Bug Fixes

  • Remove unused pystac.validation import (#1583)
  • clone extra_fields for Item (#1601) (6ba7da1)
  • make release-please two separate jobs (#1607) (bb6d289)
  • Make extent not required for VerticalSpatialDimension (#1596)

... (truncated)

Commits
  • af10871 chore(main): release 1.15.2 (#1775)
  • 1f8d728 build(deps): bump actions/checkout in the actions-deps group (#1778)
  • 70a6405 build(deps): bump setuptools from 82.0.1 to 83.0.0 (#1776)
  • 6ec1e30 build(deps): bump soupsieve from 2.8.3 to 2.8.4 (#1766)
  • 57b8d50 build(deps): bump mistune from 3.2.1 to 3.3.0 (#1767)
  • c171db2 build(deps): bump jupyter-server from 2.18.0 to 2.20.0 (#1770)
  • c82570e fix: circular imports for extensions (#1764)
  • f0c30cc build(deps): bump cryptography from 46.0.7 to 48.0.1 (#1774)
  • a448ffc build(deps-dev): bump jupyterlab from 4.5.7 to 4.5.9 (#1773)
  • bb1d200 build(deps-dev): bump starlette from 1.0.1 to 1.3.1 (#1771)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 8, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 8, 2026 20:26
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-dependencies-22dcc158f9 branch from 653aa81 to 27af764 Compare September 21, 2026 20:27
@dependabot
dependabot Bot deployed to synthtest September 21, 2026 20:27 Active
…th 3 updates

Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk), [constructs](https://github.com/aws/constructs) and [pystac[validation]](https://github.com/stac-utils/pystac) to permit the latest version.

Updates `aws-cdk-lib` from 2.224.0 to 2.267.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](aws/aws-cdk@v2.224.0...v2.267.0)

Updates `constructs` from 10.6.0 to 10.8.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](aws/constructs@v10.6.0...v10.8.1)

Updates `pystac[validation]` to 1.15.2
- [Release notes](https://github.com/stac-utils/pystac/releases)
- [Changelog](https://github.com/stac-utils/pystac/blob/main/CHANGELOG.md)
- [Commits](stac-utils/pystac@v1.15.1...v1.15.2)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.263.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: constructs
  dependency-version: 10.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pystac[validation]
  dependency-version: 1.15.2
  dependency-type: direct:development
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-dependencies-22dcc158f9 branch from 27af764 to 7b493a8 Compare September 29, 2026 16:19
@dependabot
dependabot Bot deployed to synthtest September 29, 2026 16:19 Active

This branch was successfully deployed

1 active deployment
synthtest — 7b493a88 Deployed Sep 29, 2026 by dependabot[bot] via CDK Operations #524
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants