[8.1.2] - 2026-10-08
Added
- Accept
tifas an alias fortiffoutput format #608
Changed
- Lambda functions now run on Node.js 24 (
nodejs24.x), and the ECS container image now runs on Node.js 24 (was Node.js 20) - ECS now fetches each origin image with a single GET request instead of a HEAD preflight followed by a GET
- ECS container logs no longer include per-request debug output, and the origin override log line records only the origin host instead of the full header value
Fixed
- ECS image responses now send
Cross-Origin-Resource-Policy: cross-origin, so other sites can embed images with<img>. Invalidate your CloudFront distribution to apply the header to images already cached #624 - Lambda SVG requests with no edits no longer return a 500 error #604
- ECS
autoformat no longer drops transparency or animation. When the negotiated format cannot keep the source's alpha channel or animation frames, the source format is kept instead. Explicit policy and URL formats are unchanged - Lambda S3 Object Lambda error responses now send a valid
Cache-Control: max-age=10,publicheader
Security
- Bump
adm-zipto 0.6.1 to mitigate CVE-2026-76845 and CVE-2026-77301 - Override
brace-expansionto 1.1.21, 2.1.7, and 5.0.12 to mitigate CVE-2026-102276, CVE-2026-102277, and CVE-2026-102278. The copy bundled insideaws-cdk-libis still 5.0.9 and will be updated when anaws-cdk-librelease includes the fix - Bump
compressionto 1.8.2 to mitigate CVE-2026-87776 - Bump
momentto 2.31.0 to mitigate CVE-2026-17495 - Bump
morganto 1.12.1 to mitigate CVE-2026-87859. Container access logs now escape quotes in the Referer and User-Agent fields, so log metric filters that match raw quotes in those fields may need updating - Bump
proxy-addrto 2.0.8 to mitigate CVE-2026-90711 - Bump
sharpto 0.35.5 to mitigate GHSA-wq5f-xc86-pv6w in its bundled librsvg - Bump
source-map-jsto 1.2.2 to mitigate CVE-2026-93749 - Fix a potential ReDoS in the Lambda image handler where bucket names from the
SOURCE_BUCKETSenvironment variable were used to build a regular expression. Thes3:bucket tag is now matched literally, and invalid bucket names inSOURCE_BUCKETSare logged and ignored