Conversation
Bumps [software.amazon.awscdk:aws-cdk-lib](https://github.com/aws/aws-cdk) from 2.59.0 to 2.253.0. - [Release notes](https://github.com/aws/aws-cdk/releases) - [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md) - [Commits](aws/aws-cdk@v2.59.0...v2.253.0) --- updated-dependencies: - dependency-name: software.amazon.awscdk:aws-cdk-lib dependency-version: 2.253.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
phipag
left a comment
There was a problem hiding this comment.
Reviewed and approved by @phipag. aws-cdk-lib 2.59.0 to 2.253.0 in the cloudformation example CDK infra. Note that CI does not cover this pom because infra/cdk is not registered as a module in examples/pom.xml, so this was verified manually instead. It compiles clean with zero deprecation warnings, synth succeeds, and the synthesized templates are functionally identical to 2.59.0 apart from JSON key ordering. Bootstrap version requirement and all 14 feature flags are unchanged. The two High severity CDK advisories affect NodejsFunction bundling only, which this example does not use.
|
Tick the box to add this pull request to the merge queue (same as
|



Bumps software.amazon.awscdk:aws-cdk-lib from 2.59.0 to 2.253.0.
Release notes
Sourced from software.amazon.awscdk:aws-cdk-lib's releases.
... (truncated)
Changelog
Sourced from software.amazon.awscdk:aws-cdk-lib's changelog.
... (truncated)
Commits
a6eb4e1chore(release): 2.253.0 (#37770)10d65f9chore: trigger build55a4299chore: update analytics metadata blueprintse9c0b5achore(release): 2.253.0a52af7dfix(ecs): enabling the circuitBreaker is not recommended loudly enough (#37755)a661c2dfeat: update L1 CloudFormation resource definitions (#37753)c29dc17fix(cloudwatch): remove false positive warning for CDK tokens in MathExpressi...dedf99bchore: replaceLazywithIBox(#37739)4031918fix(codebuild): correct S3 log encryption boolean inversion (#37761)99d0a5bfix(eks): add dependency from HelmChart custom resource to s3 chartAsset IAM ...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.