Skip to content

Conversation

@Sunwuyuan
Copy link
Member

snyk-top-banner

Snyk has created this PR to upgrade @aws-sdk/client-s3 from 3.826.0 to 3.914.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 48 versions ahead of your current version.

  • The recommended version was released 21 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-12613773
666 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
666 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
666 Proof of Concept
critical severity Predictable Value Range from Previous Values
SNYK-JS-FORMDATA-10841150
666 Proof of Concept
high severity Uncaught Exception
SNYK-JS-MULTER-10773732
666 No Known Exploit
medium severity Improper Handling of Unexpected Data Type
SNYK-JS-ONHEADERS-10773729
666 No Known Exploit
medium severity Improper Validation of Specified Type of Input
SNYK-JS-VALIDATOR-13395830
666 Proof of Concept
Release notes
Package name: @aws-sdk/client-s3
  • 3.914.0 - 2025-10-21

    3.914.0(2025-10-21)

    Chores
    New Features
    • clients: update client endpoints as of 2025-10-21 (1164402e)
    • client-marketplace-metering: Added ClientToken parameter to MeterUsage API for specifying idempotent requests. (fcf86371)
    • client-dynamodb: Add AccountID based endpoint metric to endpoint rules. (e23ed853)
    • client-mediaconvert: This release adds the ability to set resolution for the black video generator and also adds the StartJobsQuery and GetJobsQueryResults APIs which allow asynchronous search of job history using new filters. (3dbc5fe9)
    • client-emr: Added RECONFIGURING to the InstanceFleetState convenience enum. (321c78e2)
    Bug Fixes
    • nested-clients: propagate clientConfig to inner STS client in role assumption (#7445) (6ec7126b)
    • cloudfront-signer: encode uri components in base url (#7437) (8458bab0)

    For list of updated packages, view updated-packages.md in assets-3.914.0.zip

  • 3.913.0 - 2025-10-17

    3.913.0(2025-10-17)

    Chores
    • build: throw error on CJS rollup circular dependency (#7432) (9ecb6d6c)
    • deps-dev: bump happy-dom from 16.3.0 to 20.0.0 (#7431) (8b193e9f)
    Documentation Changes
    • client-ec2: Documentation updates for Amazon EC2. (2ce38470)
    • client-gameliftstreams: Updates documentation to clarify valid application binaries for an Amazon GameLift Streams application and provide descriptions of stream session error status reasons (9f9708cc)
    New Features
    • clients: update client endpoints as of 2025-10-17 (ea0970e0)
    • client-imagebuilder: Update endpoint ruleset parameters casing (986c9ed0)
    • client-networkmanager: Update endpoint ruleset parameters casing (c86c0dc8)
    • client-iotthingsgraph: Update endpoint ruleset parameters casing (94413b01)
    • client-pi: Update endpoint ruleset parameters casing (0f6f3e8d)
    • client-kendra-ranking: Update endpoint ruleset parameters casing (73c5dbe4)
    • client-elasticsearch-service: Update endpoint ruleset parameters casing (eefda1be)
    • client-codestar-notifications: Update endpoint ruleset parameters casing (0f695e07)
    • client-finspace-data: Update endpoint ruleset parameters casing (5c5e8f54)
    • client-route53-recovery-readiness: Update endpoint ruleset parameters casing (8fafbe7d)
    • client-tnb: Update endpoint ruleset parameters casing (1fc96976)
    • client-license-manager-user-subscriptions: Update endpoint ruleset parameters casing (d658dddb)
    • client-iot-data-plane: Update endpoint ruleset parameters casing (8ef7b350)
    • client-cloudfront: Update endpoint ruleset parameters casing (9ac953ab)
    • client-iottwinmaker: Update endpoint ruleset parameters casing (82cf5d2f)
    • client-bcm-recommended-actions: Update endpoint ruleset parameters casing (c14b0b55)
    • client-wellarchitected: Update endpoint ruleset parameters casing (1949eebf)
    • client-signer: Update endpoint ruleset parameters casing (df5dd23d)
    • client-datasync: Update endpoint ruleset parameters casing (2815add6)
    • client-finspace: Update endpoint ruleset parameters casing (53e1c2fe)
    • client-application-insights: Update endpoint ruleset parameters casing (b5f3c084)
    • client-dsql: Update endpoint ruleset parameters casing (23d58cee)
    • client-lakeformation: Update endpoint ruleset parameters casing (6af5cf47)
    • client-kinesis-video-media: Update endpoint ruleset parameters casing (4e702efe)
    • client-swf: Releasing minor endpoint updates. (35898348)
    • client-organizations: Update endpoint ruleset parameters casing (fafc6a15)
    • client-network-firewall: Update endpoint ruleset parameters casing (d857525e)
    • client-migration-hub-refactor-spaces: Update endpoint ruleset parameters casing (d433cd0c)
    • client-evidently: Update endpoint ruleset parameters casing (1adb9cf1)
    • client-amp: Update endpoint ruleset parameters casing (6c92a72a)
    • client-cloudfront-keyvaluestore: Update endpoint ruleset parameters casing (5fcd5f7f)
    • client-geo-maps: Added support for optional style parameters in maps, including Terrain, ContourDensity, Traffic, and TravelModes. (6ed4cf46)
    • client-marketplace-catalog: The ListEntities API now supports two new CAPI filters: DeliveryOptionTypes for SaaS products and CompatibleAWSServices for Container products. (3db86ffb)
    • client-chime-sdk-meetings: Update endpoint ruleset parameters casing (dddc0327)
    • client-directory-service: Update endpoint ruleset parameters casing (2fb16dad)
    • client-amplifybackend: Update endpoint ruleset parameters casing (dddaa8ae)
    • client-bedrock-data-automation-runtime: Update endpoint ruleset parameters casing (9387c242)
    • client-arc-zonal-shift: Update endpoint ruleset parameters casing (0aec3254)
    • client-mediaconnect: Update endpoint ruleset parameters casing (78df38f1)
    • client-rolesanywhere: Update endpoint ruleset parameters casing (daa2efd5)
    • client-license-manager: Update endpoint ruleset parameters casing (5e00b26a)
    • client-sagemaker-geospatial: Update endpoint ruleset parameters casing (d2812edf)
    • client-appconfigdata: Update endpoint ruleset parameters casing (d60aeecb)
    • client-qapps: Update endpoint ruleset parameters casing (f6a60440)
    • client-controlcatalog: Update endpoint ruleset parameters casing (d460ba1d)
    • client-eventbridge: Update endpoint ruleset parameters casing (a482f642)
    • client-appintegrations: Update endpoint ruleset parameters casing (49ab6466)
    • client-timestream-write: Update endpoint ruleset parameters casing (ec2b4f23)
    • client-iotdeviceadvisor: Update endpoint ruleset parameters casing (b58fcb6c)
    Bug Fixes
    • middleware-location-constraint: insert LocationConstraint only additively (#7433) (58fd243b)

    For list of updated packages, view updated-packages.md in assets-3.913.0.zip

  • 3.911.0 - 2025-10-15

    3.911.0(2025-10-15)

    Chores
    New Features
    • clients: update client endpoints as of 2025-10-15 (8544d3a1)
    • client-docdb: Add support for NetworkType field in CreateDbCluster, ModifyDbCluster, RestoreDbClusterFromSnapshot and RestoreDbClusterToPointInTime for DocumentDB. (63f5c257)
    • client-bedrock: Amazon Bedrock Automated Reasoning Policy now offers enhanced AWS KMS integration. The CreateAutomatedReasoningPolicy API includes a new kmsKeyId field, allowing customers to specify their preferred KMS key for encryption, improving control and compliance with AWS encryption mandates. (cf20670c)
    • client-lightsail: Add support for manage Lightsail Bucket CORS configuration (719ff902)
    • client-ec2: Introducing EC2 Capacity Manager for monitoring and analyzing capacity usage across On-Demand Instances, Spot Instances, and Capacity Reservations. (4d78ec9b)
    • client-elastic-load-balancing-v2: This release expands Listener Rule Conditions to support RegexValues and adds support for a new Transforms field in Listener Rules. (4e96bda6)
    • client-timestream-influxdb: This release adds support for creating and managing InfluxDB 3 Core and Enterprise DbClusters. (cd8530e8)
    • client-guardduty: Added default pagination value for ListMalwareProtectionPlans API and updated UpdateFindingsFeedback API (0251678c)
    Bug Fixes
    • xml-builder: move DOMParser init from module level to function call (#7426) (68252cba)
    Tests

    For list of updated packages, view updated-packages.md in assets-3.911.0.zip

  • 3.910.0 - 2025-10-14

    3.910.0(2025-10-14)

    Chores
    • codegen: sync for node-http timeout fixes, deprecated documentation (#7422) (c8809d46)
    Documentation Changes
    New Features
    • client-ec2: This release adds support for creating instant, point-in-time copies of EBS volumes within the same Availability Zone (35be968f)
    • client-connect: SDK release for TaskTemplateInfo in Contact for DescribeContact response. (a34b5ea7)
    • client-transcribe: Move UntagResource API body member to query parameter (eefe2472)
    • client-backup: The AWS Backup job attribute extension enhancement helps customers better understand the plan that initiated each job, and the properties of the resource each job creates. (69c1ccd9)
    • client-datazone: Support creating scoped and trustedIdentityPropagation enabled connections. (acbdd2f7)
    • client-transfer: SFTP connectors now support routing connections via customers' VPC. This enables connections to remote servers that are only accessible in a customer's VPC environment, and to servers that are accessible over the internet but need connections coming from an IP address in a customer VPC's CIDR range. (2951a5b6)
    • client-appstream: This release introduces support for Microsoft license included applications streaming. (d7579fed)

    For list of updated packages, view updated-packages.md in assets-3.910.0.zip

  • 3.908.0 - 2025-10-10

    3.908.0(2025-10-10)

    Chores
    • codegen: sync for bowser removal, lstat fixes (#7418) (511167d5)
    Documentation Changes
    • client-rds: Updated the text in the Important section of the ModifyDBClusterParameterGroup page. (23a42361)
    New Features
    • clients: update client endpoints as of 2025-10-10 (b5e87b16)
    • client-lambda: Add InvokedViaFunctionUrl context key to limit invocations to only FURL invokes. (cf1e3beb)
    • client-bedrock-agentcore-control: Bedrock AgentCore release for Gateway, and Memory including Self-Managed Strategies support for Memory. (dd8408b9)
    • client-odb: This release adds APIs that allow you to specify CIDR ranges in your ODB peering connection. (72de496b)
    • client-cloudfront: Added new viewer security policy, TLSv1.2_2025, for CloudFront. (bbe5fc55)
    • client-bedrock-agentcore: Bedrock AgentCore release for Runtime, and Memory. (9ad809ec)
    • client-glue: Addition of AuditContext in GetTable/GetTables Request (cf3d8e19)
    Bug Fixes
    • codegen: apply reserved word escaping to union shape in Json serializer (#7419) (9ee6cdcd)

    For list of updated packages, view updated-packages.md in assets-3.908.0.zip

  • 3.907.0 - 2025-10-09

    3.907.0(2025-10-09)

    Chores
    • util-user-agent-browser: remove bowser from default UA provider (#7413) (a94d95f7)
    • ci: run publish for codegen (#7415) (b2f1ac0c)
    New Features
    • clients: update client endpoints as of 2025-10-09 (98148915)
    • client-wafv2: This release adds the ability to throw WafLimitsExceededException when the maximum number of Application Load Balancer (ALB) associations per AWS WAF v2 WebACL is exceeded. (33438d9d)
    • client-quicksight: This release adds support for ActionConnector and Flow, which are new resources associated with Amazon Quick Suite. Additional updates include expanded Data Source options, further branding customization, and new capabilities that can be restricted by Admins. (72c12a09)
    Tests
    • core: modify request compression threshold values (#7414) (6b45d720)

    For list of updated packages, view updated-packages.md in assets-3.907.0.zip

  • 3.906.0 - 2025-10-08

    3.906.0(2025-10-08)

    Chores
    New Features
    • clients: update client endpoints as of 2025-10-08 (9f44c29c)
    • client-license-manager-user-subscriptions: Released support for IPv6 and dual-stack active directories (288c63a8)
    • client-outposts: This release adds the new StartOutpostDecommission API, which starts the decommission process to return Outposts racks or servers. (2bfac290)
    • client-bedrock-agentcore-control: Adding support for authorizer type AWS_IAM to AgentCore Control Gateway. (c3b83d46)
    • client-service-quotas: introduces Service Quotas Automatic Management. Users can opt-in to monitoring and managing service quotas, receive notifications when quota usage reaches thresholds, configure notification channels, subscribe to EventBridge events for automation, and view notifications in the AWS Health dashboard. (136894bf)

    For list of updated packages, view updated-packages.md in assets-3.906.0.zip

  • 3.901.0 - 2025-10-01
  • 3.899.0 - 2025-09-29
  • 3.896.0 - 2025-09-24
  • 3.895.0 - 2025-09-23
  • 3.894.0 - 2025-09-22
  • 3.893.0 - 2025-09-19
  • 3.892.0 - 2025-09-18
  • 3.891.0 - 2025-09-17
  • 3.890.0 - 2025-09-16
  • 3.888.0 - 2025-09-12
  • 3.887.0 - 2025-09-11
  • 3.886.0 - 2025-09-10
  • 3.884.0 - 2025-09-08
  • 3.883.0 - 2025-09-05
  • 3.882.0 - 2025-09-04
  • 3.879.0 - 2025-08-29
  • 3.878.0 - 2025-08-28
  • 3.876.0 - 2025-08-26
  • 3.873.0 - 2025-08-21
  • 3.872.0 - 2025-08-20
  • 3.864.0 - 2025-08-08
  • 3.863.0 - 2025-08-07
  • 3.862.0 - 2025-08-06
  • 3.859.0 - 2025-08-01
  • 3.858.0 - 2025-07-31
  • 3.857.0 - 2025-07-30
  • 3.856.0 - 2025-07-29
  • 3.855.0 - 2025-07-28
  • 3.850.0 - 2025-07-21
  • 3.848.0 - 2025-07-17
  • 3.846.0 - 2025-07-16
  • 3.845.0 - 2025-07-15
  • 3.844.0 - 2025-07-09
  • 3.842.0 - 2025-07-02
  • 3.840.0 - 2025-06-30
  • 3.839.0 - 2025-06-27
  • 3.837.0 - 2025-06-25
  • 3.835.0 - 2025-06-23
  • 3.832.0 - 2025-06-18
  • 3.830.0 - 2025-06-16
  • 3.828.0 - 2025-06-11
  • 3.826.0 - 2025-06-06
from @aws-sdk/client-s3 GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade @aws-sdk/client-s3 from 3.826.0 to 3.914.0.

See this package in npm:
@aws-sdk/client-s3

See this project in Snyk:
https://app.snyk.io/org/sunwuyuan/project/7f95d725-ca6f-4cce-ab56-8b055b9f632f?utm_source=github&utm_medium=referral&page=upgrade-pr
@vercel
Copy link

vercel bot commented Nov 12, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
our-world Error Error Nov 12, 2025 3:55am

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants