What's Changed
New Contributors
[1.5.23] — 2026-10-07
Added
- AppConfig — gradual rollout and alarm rollback — deployments completed as soon as they started. They now move through
DEPLOYING,BAKINGandCOMPLETEon the strategy's schedule, a CloudWatch alarm in the environment'sMonitorsthat goes toALARMrolls the deployment back, and a concurrent or stale deployment returnsConflictException. Contributed by @Jolley71717. - API Gateway v1 —
AWSintegrations targeting SQS — a non-proxy integration whose URI issqs:path/{account}/{queue}now renders itsrequestTemplates, sends the message to the queue and maps the reply throughintegrationResponses; otherAWSservice URIs still take the Lambda path. Contributed by @pingedbrain. Reported by @teruyukisuda. - CloudFormation — IoT things, certificates and attachments —
AWS::IoT::Thing,AWS::IoT::Certificate,AWS::IoT::ThingPrincipalAttachmentandAWS::IoT::PolicyPrincipalAttachmentfailed withUnrecognized resource types; they now provision onto the IoT registry with AWS'sRefandFn::GetAttvalues.CreateCertificateFromCsrwas added, andDescribeCertificatenow reportscertificateMode. Contributed by @iot-rocket. - CloudFormation — enum properties are validated before provisioning — a value outside a resource schema's enum was refused only by that resource's create, after earlier resources existed; it now fails the stack with
VALIDATION_FAILEDbefore anything is provisioned. Contributed by @iot-rocket. - CloudFront — custom error responses —
CustomErrorResponseswere stored but never applied; when the origin answers a configuredErrorCode, the data plane now returnsResponsePagePathwithResponseCode. Contributed by @skialpine. - Cognito —
CustomMessage_AdminCreateUsertrigger —AdminCreateUsernow invokes the pool'sCustomMessageLambda before sending the invitation, and{username}expands to the email or phone number in pools withUsernameAttributes. Contributed by @kjdev. - DynamoDB — multi-attribute GSI keys — a GSI with several
HASHorRANGEattributes failed everyQuerywith "Query condition missed key schema element".Querynow needs equality on every partition-key attribute and takes sort-key attributes left to right, only the last with a range condition. Reported by @jun-ut. - IoT — domain configurations —
CreateDomainConfiguration,DescribeDomainConfiguration,ListDomainConfigurations,UpdateDomainConfiguration,DeleteDomainConfigurationandAWS::IoT::DomainConfiguration. Contributed by @iot-rocket. - IoT — job templates —
CreateJobTemplate,DescribeJobTemplate,ListJobTemplates,DeleteJobTemplate,CreateJobwithjobTemplateArn, andAWS::IoT::JobTemplate. Contributed by @iot-rocket. - SES — identity notifications —
SetIdentityNotificationTopicstored topics that nothing published to; v1 sends now publish aDelivery,BounceorComplaintnotification per recipient, following the mailbox simulator. Contributed by @kjdev. - SES — receipt rule sets and rules — rule sets can be created, activated, described, listed and deleted, and rules created, described and deleted; they are stored only, since inbound mail is not emulated. Contributed by @AdrianAcala. Reported by @wparad.
- SES v2 — tenants and resource associations —
CreateTenant,GetTenant,ListTenants,DeleteTenant,PutTenantSuppressionAttributesand the tenant resource association operations; a resource with associations cannot be deleted. Contributed by @AdrianAcala. Reported by @wparad. - SES v2 — dedicated IP pools —
CreateDedicatedIpPool,GetDedicatedIpPool,ListDedicatedIpPoolsandDeleteDedicatedIpPool, with tags on the pool ARN. Reported by @wparad. - Signer — CloudFormation profiles, profile permissions and
CancelSigningProfile—AWS::Signer::SigningProfileandAWS::Signer::ProfilePermissionprovision, andAddProfilePermission,ListProfilePermissions,RemoveProfilePermissionandCancelSigningProfileare routed. Contributed by @iot-rocket.
Fixed
- API Gateway — management IAM actions — with
AUTH=true, management requests were checked against SDK operation names; they now useapigateway:GET,POST,PUT,PATCHandDELETEon the requested resource path, so scoped grants and stage denies apply. Contributed by @AdrianAcala. - AppConfig —
GetLatestConfigurationandStopDeployment— a poll returned the full configuration every time, andStopDeploymentmarked any deploymentROLLED_BACK. An unchanged poll now returns an empty body, andStopDeploymentfollows the documented states. Contributed by @Jolley71717. - CloudWatch —
Values/CountsandStatisticValues— values were stored once per count and statistic sets as their average, soSampleCount,Sum,MinimumandMaximumwere wrong. They now aggregate weighted, and percentiles are omitted for negative values and for statistic sets that are not one repeated value. Contributed by @DimQ1. - CloudWatch Logs — IAM tag conditions — with
AUTH=true, authorization now includes existing and requested tags, and ARN-based tagging APIs authorize the supplied ARN instead of*. Contributed by @AdrianAcala. - Cognito —
RESET_REQUIREDusers cannot sign in with a password — afterAdminResetUserPassword, password and SRP sign-in with the old password succeeded; they now returnPasswordResetRequiredException. Contributed by @prandogabriel. - Container reaping — one unreadable container no longer stops the sweep — if one container's inspect failed, the boot sweep removed no leftover containers; containers are now listed without inspecting each one. Reported by @iot-rocket.
- DynamoDB — Query and Scan stop each page at 1 MB — without
Limit, every matching item came back in one response with noLastEvaluatedKey; a page now stops at 1 MB of data read and returnsLastEvaluatedKey. Contributed by @DimQ1. - DynamoDB — index Query and writes no longer slow down as a table grows — a GSI or LSI
Queryread every item in the table and every write recounted it; index partitions andItemCountare now kept per write. Contributed by @DimQ1. - DynamoDB —
ClientRequestTokenexpires after 10 minutes — transaction tokens were kept forever; after 10 minutes a reused token is a new request. Contributed by @DimQ1. - DynamoDB — transactions are authorized per item — with
AUTH=true,TransactWriteItemsandTransactGetItemswere checked as non-existent IAM actions on the first table; each item is now checked asPutItem,UpdateItem,DeleteItem,ConditionCheckItemorGetItemon its own table. Contributed by @drakeo338. Reported by @Zordrak. - DynamoDB Streams — no-op writes and closed streams — a write that changed nothing produced a
MODIFYrecord, and a disabled or deleted stream vanished. No record is written now, and a closed stream stays readable for 24 hours asDISABLED. Contributed by @DimQ1. - IoT — the gateway certificate names the
DescribeEndpointhosts —https://<endpointAddress>failed hostname verification underUSE_SSL=1; the certificate now carries the IoT data and credentials hosts. Contributed by @iot-rocket. - Kinesis —
SubscribeToShardkeeps its position across retention pruning — removing expired records could skip newly appended ones. Contributed by @AdrianAcala. - Lambda — one request ID per Docker invocation — RIE logs carried a second START/END/REPORT set under a different RequestId; MiniStack's ID now reaches RIE and the logs are saved once. Contributed by @gakuto-cw21.
- Lambda —
invoked_function_arnkeeps the alias or version invoked. Contributed by @jayjanssen. - Lambda — event source mappings pick up new work at once — a new SQS message, Kinesis record or DynamoDB stream record waited for the poller's idle tick; it now wakes the poller. Contributed by @antonie-popovic.
- RDS — global cluster tags —
CreateGlobalClusterdroppedTags; they are now stored and returned inTagList. Contributed by @jayjanssen. - RDS Data API — MySQL
generatedFields— it was always empty; it now holds theAUTO_INCREMENTid. Contributed by @skialpine. - S3 — cross-account replication — the destination bucket was looked up only in the caller's account, so every replica
FAILED; it is now found in its owner's account, and its bucket policy must grant the replication role. Contributed by @pingedbrain. - S3 — re-creating a bucket you own — outside us-east-1 it returned 200; it now returns
BucketAlreadyOwnedByYou(409). Contributed by @DimQ1. - S3 — truncated uploads — a body shorter than
Content-Lengthor a malformedaws-chunkedupload was stored as a partial object; it now returnsIncompleteBody(400). Contributed by @DimQ1. - SES —
SendEmailvalidation — an address without a domain returnsInvalidParameterValue"Missing final '@Domain'", and an unknown configuration set returnsConfigurationSetDoesNotExist. Contributed by @DimQ1. - SES —
SendRawEmailrelay sends oneMessage-ID— a clientMessage-IDwas kept next to MiniStack's. Contributed by @kjdev. - SNS — published messages are no longer retained — every publish was kept on its topic and persisted. Contributed by @DimQ1.
- SQS — FIFO delays and
MaxNumberOfMessages— FIFO queues ignoredDelaySecondsand accepted per-message delays, andMaxNumberOfMessageswas clamped. A FIFO message now waits the queue delay, a nonzero per-message delay returnsInvalidParameterValue, andMaxNumberOfMessagesoutside 1–10 returnsInvalidParameterValue. Contributed by @DimQ1. - SQS — queue
DelaySecondsapplies to messages from other services — deliveries from SNS, EventBridge, S3 notifications and Lambda were visible at once. Contributed by @DimQ1. - SSM —
PutParametervalidation — a parameter withoutType, a name starting withawsorssm, andTagswithOverwritewere accepted; they are now refused, and an overwrite withoutTypekeeps the stored type. Contributed by @fabio-andre-rodrigues. Reported by @jin-gizmo. - Step Functions —
$$.State.RetryCount— it resolved tonull; it now counts a state's retries, and a Task'sParametersare evaluated for each attempt. Contributed by @skialpine. - Step Functions — the first matching retrier decides — a retrier that had used its
MaxAttemptswas skipped, so a laterStates.ALLretried anyway. Contributed by @skialpine. - Step Functions —
StopExecutionkeeps itserrorandcause—DescribeExecutionreturned neither; it now returns both. Contributed by @skialpine. - Step Functions — a retried
StopExecutionsucceeds — stopping an already-aborted execution returnedValidationException; it now returns the originalstopDate. Contributed by @jayjanssen. - TLS — the generated certificate works with rustls — it was a CA certificate, which rustls refuses as a server's; it is now a server certificate. Contributed by @antonie-popovic.