Skip to content

fix(deps): update aws sdk - #873

Merged
janishorsts merged 1 commit into
mainfrom
renovate/aws-sdk
Aug 27, 2026
Merged

janishorsts merged 1 commit into
mainfrom
renovate/aws-sdk

Conversation

@renovate

@renovate renovate Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change OpenSSF
github.com/aws/aws-sdk-go-v2 require minor v1.43.7 → v1.45.0 OpenSSF Scorecard
github.com/aws/aws-sdk-go-v2/config require minor v1.32.38 → v1.33.0 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

aws/aws-sdk-go-v2 (github.com/aws/aws-sdk-go-v2)

v1.45.0

Compare Source

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/aws-sdk-go-v2/service/apigateway: v1.38.0
    • Feature: API Gateway supports VPC link V2 for REST APIs.
  • github.com/aws/aws-sdk-go-v2/service/athena: v1.56.0
    • Feature: Introduces Spark workgroup features including log persistence, S3/CloudWatch delivery, UI and History Server APIs, and SparkConnect 3.5.6 support. Adds DPU usage limits at workgroup and query levels as well as DPU usage tracking for Capacity Reservation queries to optimize performance and costs.
  • github.com/aws/aws-sdk-go-v2/service/bedrock: v1.50.0
    • Feature: Add support to automatically enforce safeguards across accounts within an AWS Organization.
  • github.com/aws/aws-sdk-go-v2/service/bedrockagentcorecontrol: v1.14.0
    • Feature: Support for agentcore gateway interceptor configurations and NONE authorizer type
  • github.com/aws/aws-sdk-go-v2/service/bedrockdataautomationruntime: v1.9.0
    • Feature: Adding new fields to GetDataAutomationStatus: jobSubmissionTime, jobCompletionTime, and jobDurationInSeconds
  • github.com/aws/aws-sdk-go-v2/service/bedrockruntime: v1.45.0
    • Feature: Add support to automatically enforce safeguards across accounts within an AWS Organization.
  • github.com/aws/aws-sdk-go-v2/service/cloudformation: v1.71.0
    • Feature: Adds the DependsOn field to the AutoDeployment configuration parameter for CreateStackSet, UpdateStackSet, and DescribeStackSet APIs, allowing users to set and read auto-deployment dependencies between StackSets
  • github.com/aws/aws-sdk-go-v2/service/computeoptimizerautomation: v1.0.0
    • Release: New AWS service client module
    • Feature: Initial release of AWS Compute Optimizer Automation. Create automation rules to implement recommended actions on a recurring schedule based on your specified criteria. Supported actions include: snapshot and delete unattached EBS volumes and upgrade volume types to the latest generation.
  • github.com/aws/aws-sdk-go-v2/service/connect: v1.148.0
    • Feature: New APIs to support aliases and versions for ContactFlowModule. Updated ContactFlowModule APIs to support custom blocks.
  • github.com/aws/aws-sdk-go-v2/service/controltower: v1.28.0
    • Feature: The manifest field is now optional for the AWS Control Tower CreateLandingZone and UpdateLandingZone APIs for Landing Zone version 4.0
  • github.com/aws/aws-sdk-go-v2/service/ec2: v1.274.0
    • Feature: This release adds a new capability to create and manage interruptible EC2 Capacity Reservations.
  • github.com/aws/aws-sdk-go-v2/service/ecr: v1.54.0
    • Feature: Add support for ECR managed signing
  • github.com/aws/aws-sdk-go-v2/service/eks: v1.75.0
    • Feature: Adds support for controlPlaneScalingConfig on EKS Clusters.
  • github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2: v1.54.1
    • Documentation: This release adds the health check log feature in ALB, allowing customers to send detailed target health check log data directly to their designated Amazon S3 bucket.
  • github.com/aws/aws-sdk-go-v2/service/invoicing: v1.9.0
    • Feature: Added the CreateProcurementPortalPreference, GetProcurementPortalPreference, PutProcurementPortalPreference, UpdateProcurementPortalPreferenceStatus, ListProcurementPortalPreferences and DeleteProcurementPortalPreference APIs for procurement portal preference management.
  • github.com/aws/aws-sdk-go-v2/service/kinesisvideo: v1.33.0
    • Feature: This release adds support for Tiered Storage
  • github.com/aws/aws-sdk-go-v2/service/kms: v1.49.0
    • Feature: Support for on-demand rotation of AWS KMS Multi-Region keys with imported key material
  • github.com/aws/aws-sdk-go-v2/service/lambda: v1.83.0
    • Feature: Launching Enhanced Error Handling and ESM Grouping capabilities for Kafka ESMs
  • github.com/aws/aws-sdk-go-v2/service/lexmodelsv2: v1.58.0
    • Feature: Adds support for Intent Disambiguation, allowing resolution of ambiguous user inputs when multiple intents match by presenting clarifying questions to users. Also adds Speech Detection Sensitivity configuration for optimizing voice activity detection sensitivity levels in various noise environments.
  • github.com/aws/aws-sdk-go-v2/service/marketplaceentitlementservice: v1.35.0
    • Feature: Endpoint update for new region
  • github.com/aws/aws-sdk-go-v2/service/marketplacemetering: v1.35.0
    • Feature: Endpoint update for new region
  • github.com/aws/aws-sdk-go-v2/service/mediapackagev2: v1.34.0
    • Feature: Adds support for excluding session key tags from HLS multivariant playlists
  • github.com/aws/aws-sdk-go-v2/service/odb: v1.6.0
    • Feature: Adds AssociateIamRoleToResource and DisassociateIamRoleFromResource APIs for managing IAM roles. Enhances CreateOdbNetwork and UpdateOdbNetwork APIs with KMS, STS, and cross-region S3 parameters. Adds OCI identity domain support to InitializeService API.
  • github.com/aws/aws-sdk-go-v2/service/organizations: v1.48.0
    • Feature: Add support for policy operations on the UPGRADE_ROLLOUT_POLICY policy type.
  • github.com/aws/aws-sdk-go-v2/service/qconnect: v1.24.0
    • Feature: This release introduces two new messaging channel subtypes: Push, WhatsApp, under MessageTemplate which is a resource in Amazon Q in Connect.
  • github.com/aws/aws-sdk-go-v2/service/quicksight: v1.98.0
    • Feature: Amazon Quick Suite now supports QuickChat as an embedding type when calling the GenerateEmbedUrlForRegisteredUser API, enabling developers to embed conversational AI agents directly into their applications.
  • github.com/aws/aws-sdk-go-v2/service/rds: v1.111.0
    • Feature: Add support for Upgrade Rollout Order
  • github.com/aws/aws-sdk-go-v2/service/redshift: v1.61.0
    • Feature: Added support for Amazon Redshift Federated Permissions and AWS IAM Identity Center trusted identity propagation.
  • github.com/aws/aws-sdk-go-v2/service/redshiftserverless: v1.32.0
    • Feature: Added UpdateLakehouseConfiguration API to manage Amazon Redshift Federated Permissions and AWS IAM Identity Center trusted identity propagation for namespaces.
  • github.com/aws/aws-sdk-go-v2/service/sagemaker: v1.226.0
    • Feature: Enhanced SageMaker HyperPod instance groups with support for MinInstanceCount, CapacityRequirements (Spot/On-Demand), and KubernetesConfig (labels and taints). Also Added speculative decoding and MaxInstanceCount for model optimization jobs.
  • github.com/aws/aws-sdk-go-v2/service/sagemakerruntimehttp2: v1.0.0
    • Release: New AWS service client module
    • Feature: Add support for bidirectional streaming invocations on SageMaker AI real-time endpoints
  • github.com/aws/aws-sdk-go-v2/service/securityir: v1.10.0
    • Feature: Add ListInvestigations and SendFeedback APIs to support SecurityIR AI agents
  • github.com/aws/aws-sdk-go-v2/service/sesv2: v1.55.0
    • Feature: Added support for new SES regions - Asia Pacific (Malaysia) and Canada (Calgary)
  • github.com/aws/aws-sdk-go-v2/service/transfer: v1.68.0
    • Feature: Adds support for creating Webapps accessible from a VPC.

v1.44.0

Compare Source

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/aws-sdk-go-v2/service/apigateway: v1.37.0
    • Feature: API Gateway now supports response streaming and new security policies for REST APIs and custom domain names.
  • github.com/aws/aws-sdk-go-v2/service/apigatewayv2: v1.33.0
    • Feature: Support for API Gateway portals and portal products.
  • github.com/aws/aws-sdk-go-v2/service/backup: v1.54.0
    • Feature: Amazon GuardDuty Malware Protection now supports AWS Backup, extending malware detection capabilities to EC2, EBS, and S3 backups.
  • github.com/aws/aws-sdk-go-v2/service/bcmpricingcalculator: v1.10.0
    • Feature: Add GroupSharingPreference, CostCategoryGroupSharingPreferenceArn, and CostCategoryGroupSharingPreferenceEffectiveDate to Bill Estimate. Add GroupSharingPreference and CostCategoryGroupSharingPreferenceArn to Bill Scenario.
  • github.com/aws/aws-sdk-go-v2/service/bedrockruntime: v1.44.0
    • Feature: This release includes support for Search Results.
  • github.com/aws/aws-sdk-go-v2/service/billing: v1.9.0
    • Feature: Added name filtering support to ListBillingViews API through the new names parameter to efficiently filter billing views by name.
  • github.com/aws/aws-sdk-go-v2/service/billingconductor: v1.27.0
    • Feature: This release adds support for Billing Transfers, enabling management of billing transfers with billing groups on AWS Billing Conductor.
  • github.com/aws/aws-sdk-go-v2/service/cloudtrail: v1.54.0
    • Feature: AWS CloudTrail now supports Insights for data events, expanding beyond management events to automatically detect unusual activity on data plane operations.
  • github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.60.0
    • Feature: Adding support for ocsf version 1.5, add optional parameter MappingVersion
  • github.com/aws/aws-sdk-go-v2/service/connectcampaignsv2: v1.9.0
    • Feature: This release added support for ring timer configuration for campaign calls.
  • github.com/aws/aws-sdk-go-v2/service/costexplorer: v1.60.0
    • Feature: Add support for COST_CATEGORY, TAG, and LINKED_ACCOUNT AWS managed cost anomaly detection monitors
  • github.com/aws/aws-sdk-go-v2/service/costoptimizationhub: v1.21.0
    • Feature: Release ListEfficiencyMetrics API
  • github.com/aws/aws-sdk-go-v2/service/datazone: v1.48.0
    • Feature: Amazon DataZone now supports business metadata (readme and metadata forms) at the individual attribute (column) level, a new rule type for glossary terms, and the ability to update the owner of the root domain unit.
  • github.com/aws/aws-sdk-go-v2/service/dynamodb: v1.53.0
    • Feature: Extended Global Secondary Index (GSI) composite keys to support up to 8 attributes.
  • github.com/aws/aws-sdk-go-v2/service/ec2: v1.272.0
    • Feature: This launch adds support for two new features: Regional NAT Gateway and IPAM Policies. IPAM policies offers customers central control for public IPv4 assignments across AWS services. Regional NAT is a single NAT Gateway that automatically expands across AZs in a VPC to maintain high availability.
  • github.com/aws/aws-sdk-go-v2/service/ecr: v1.53.0
    • Feature: Add support for ECR archival storage class and Inspector org policy for scanning
  • github.com/aws/aws-sdk-go-v2/service/ecs: v1.68.0
    • Feature: Added support for Amazon ECS Managed Instances infrastructure optimization configuration.
  • github.com/aws/aws-sdk-go-v2/service/emr: v1.56.0
    • Feature: Add CloudWatch Logs integration for Spark driver, executor and step logs
  • github.com/aws/aws-sdk-go-v2/service/fsx: v1.64.0
    • Feature: Adding File Server Resource Manager configuration to FSx Windows
  • github.com/aws/aws-sdk-go-v2/service/guardduty: v1.68.0
    • Feature: Add support for scanning and viewing scan results for backup resource types
  • github.com/aws/aws-sdk-go-v2/service/health: v1.35.0
    • Feature: Adds actionability and personas properties to Health events exposed through DescribeEvents, DescribeEventsForOrganization, DescribeEventDetails, and DescribeEventTypes APIs. Adds filtering by actionabilities and personas in EventFilter, OrganizationEventFilter, EventTypeFilter.
  • github.com/aws/aws-sdk-go-v2/service/iam: v1.52.0
    • Feature: Added the EnableOutboundWebIdentityFederation, DisableOutboundWebIdentityFederation and GetOutboundWebIdentityFederationInfo APIs for the IAM outbound federation feature.
  • github.com/aws/aws-sdk-go-v2/service/inspector2: v1.45.0
    • Feature: This release introduces BLOCKED_BY_ORGANIZATION_POLICY error code and IMAGE_ARCHIVED scanStatusReason. BLOCKED_BY_ORGANIZATION_POLICY error code is returned when an operation is blocked by an AWS Organizations policy. IMAGE_ARCHIVED scanStatusReason is returned when an Image is archived in ECR.
  • github.com/aws/aws-sdk-go-v2/service/invoicing: v1.8.0
    • Feature: Add support for adding Billing transfers in Invoice configuration
  • github.com/aws/aws-sdk-go-v2/service/lambda: v1.82.0
    • Feature: Added support for creating and invoking Tenant Isolated functions in AWS Lambda APIs.
  • github.com/aws/aws-sdk-go-v2/service/mediaconnect: v1.46.0
    • Feature: This release adds support for global routing in AWS Elemental MediaConnect. You can now use router inputs and router outputs to manage global video and audio routing workflows both within the AWS-Cloud and over the public internet.
  • github.com/aws/aws-sdk-go-v2/service/medialive: v1.87.0
    • Feature: MediaLive is adding support for MediaConnect Router by supporting a new input type called MEDIACONNECT_ROUTER. This new input type will provide seamless encrypted transport between MediaConnect Router and your MediaLive channel.
  • github.com/aws/aws-sdk-go-v2/service/networkfirewall: v1.58.0
    • Feature: Partner Managed Rulegroup feature support
  • github.com/aws/aws-sdk-go-v2/service/networkflowmonitor: v1.11.0
    • Feature: Added new enum value (AWS::EKS::Cluster) for type field under MonitorLocalResource
  • github.com/aws/aws-sdk-go-v2/service/partnercentralchannel: v1.0.0
    • Release: New AWS service client module
    • Feature: Initial GA launch of Partner Central Channel
  • github.com/aws/aws-sdk-go-v2/service/route53: v1.60.0
    • Feature: Add dual-stack endpoint support for Route53
  • github.com/aws/aws-sdk-go-v2/service/rum: v1.30.0
    • Feature: CloudWatch RUM now supports mobile application monitoring for Android and iOS platforms
  • github.com/aws/aws-sdk-go-v2/service/s3: v1.91.0
    • Feature: Adds support for blocking SSE-C writes to general purpose buckets.
  • github.com/aws/aws-sdk-go-v2/service/sagemaker: v1.224.0
    • Feature: Added support for enhanced metrics for SageMaker AI Endpoints. This features provides Utilization Metrics at instance and container granularity and also provides easy configuration of metric publish frequency from 10 sec -> 5 mins
  • github.com/aws/aws-sdk-go-v2/service/secretsmanager: v1.40.0
    • Feature: Adds support to create, update, retrieve, rotate, and delete managed external secrets.
  • github.com/aws/aws-sdk-go-v2/service/sfn: v1.40.0
    • Feature: Adds support to TestState for mocked results and exceptions, along with additional inspection data.
  • github.com/aws/aws-sdk-go-v2/service/signin: v1.0.0
    • Release: New AWS service client module
    • Feature: AWS Sign-In manages authentication for AWS services. This service provides secure authentication flows for accessing AWS resources from the console and developer tools. This release adds the CreateOAuth2Token API, which can be used to fetch OAuth2 access tokens and refresh tokens from Sign-In.
  • github.com/aws/aws-sdk-go-v2/service/sts: v1.41.0
    • Feature: IAM now supports outbound identity federation via the STS GetWebIdentityToken API, enabling AWS workloads to securely authenticate with external services using short-lived JSON Web Tokens.
  • github.com/aws/aws-sdk-go-v2/service/transcribestreaming: v1.33.0
    • Feature: This release adds support for additional locales in AWS transcribe streaming.

v1.43.8

Compare Source

General Highlights

  • Dependency Update: Update to smithy-go v1.27.10.
  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/aws-sdk-go-v2: v1.43.8
    • Bug Fix: Make X-Amz-Checksum-Mode appear on query parameters on presigned URLs
  • github.com/aws/aws-sdk-go-v2/service/account: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/acmpca: v1.51.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/autoscaling: v1.73.0
    • Feature: Adds support for Distribution Segments in mixed instances policies, providing ordered prioritization across On-Demand Capacity Reservations, Capacity Blocks, interruptible Capacity Reservations, and On-Demand capacity.
  • github.com/aws/aws-sdk-go-v2/service/billingconductor: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudcontrol: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudhsmv2: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudwatchevents: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/codebuild: v1.73.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/codegurureviewer: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/codepipeline: v1.50.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/dataexchange: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/deadline: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/detective: v1.42.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/devopsagent: v1.11.0
    • Feature: Adds the UpdateApprovalAction API for resolving agent action approvals in AWS DevOps Agent agent spaces.
  • github.com/aws/aws-sdk-go-v2/service/directoryservice: v1.42.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/drs: v1.44.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/ec2: v1.323.0
    • Feature: Fleet feature to support Capacity Reservation Resource Groups with Amazon EC2 Capacity Blocks and interruptible Capacity Reservations
  • github.com/aws/aws-sdk-go-v2/service/eks: v1.93.0
    • Feature: This feature would give customers the ability to tune TerminatedPodGcThreshold configuration in an Amazon EKS cluster.
  • github.com/aws/aws-sdk-go-v2/service/emrcontainers: v1.46.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/eventbridge: v1.49.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/evs: v1.14.0
    • Feature: EVS now supports i7i.metal-48xl EC2 bare metal instance type, delivering high random IOPS performance with real-time latency, ideal for IO intensive and latency-sensitive workloads such as transactional databases, real-time analytics, and AI ML pre-processing.
  • github.com/aws/aws-sdk-go-v2/service/frauddetector: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/fsx: v1.69.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/globalaccelerator: v1.39.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/iamtoolbox: v1.0.0
    • Release: New AWS service client module
    • Feature: AWS Identity and Access Management (IAM) announces access troubleshooter, helping you debug access denied errors faster. Supported error messages now include an identifier you can use to retrieve detailed evaluations of the policies considered and their results. Preview in US East (N. Virginia).
  • github.com/aws/aws-sdk-go-v2/service/inspector: v1.34.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/iot: v1.78.0
    • Feature: As part of this release, we are extending capability of AWS IoT Rules Engine to support IoT InfluxDB Action. The IoT InfluxDB action lets customers send messages from IoT sensors and applications to InfluxDB.
  • github.com/aws/aws-sdk-go-v2/service/iotsecuretunneling: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/iottwinmaker: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/ivs: v1.56.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/ivsrealtime: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/licensemanager: v1.42.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/marketplacecatalog: v1.46.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/marketplacemetering: v1.40.3
    • Documentation: Updated documentation to clarify duplicate-billing prevention and BatchMeterUsage retry guidance
  • github.com/aws/aws-sdk-go-v2/service/mediapackage: v1.43.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/mediapackagevod: v1.43.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/mediastore: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/networkmanager: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/outposts: v1.68.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/paymentcryptography: v1.34.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/pi: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/qconnect: v1.35.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/resourceexplorer2: v1.28.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/servicecatalogappregistry: v1.39.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/servicediscovery: v1.44.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/shield: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/signer: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/storagegateway: v1.47.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/swf: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/transcribestreaming: v1.39.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/transfer: v1.76.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/translate: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/voiceid: v1.34.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/vpclattice: v1.27.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/wafv2: v1.78.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/wisdom: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/workspacesthinclient: v1.24.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/xray: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner August 27, 2026 18:20
@renovate renovate Bot added the renovate label Aug 27, 2026
@renovate
renovate Bot requested review from gilescope and removed request for a team August 27, 2026 18:20
@renovate

renovate Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 12 additional dependencies were updated

Details:

Package Change
github.com/aws/aws-sdk-go-v2/credentials v1.19.37 -> v1.20.0
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.38 -> v1.19.0
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.38 -> v1.5.0
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.38 -> v2.8.0
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.39 -> v1.5.0
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.17 -> v1.13.19
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.38 -> v1.14.0
github.com/aws/aws-sdk-go-v2/service/signin v1.5.7 -> v1.7.0
github.com/aws/aws-sdk-go-v2/service/sso v1.33.7 -> v1.35.0
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.7 -> v1.40.0
github.com/aws/aws-sdk-go-v2/service/sts v1.45.7 -> v1.47.0
github.com/aws/smithy-go v1.27.8 -> v1.28.1

@renovate renovate Bot added the renovate label Aug 27, 2026
@github-actions

Copy link
Copy Markdown

➖ Are we earthbuild yet?

No change in "earthly" occurrences

📈 Overall Progress

Branch Total Count
main 3612
This PR 3612
Difference +0

Keep up the great work migrating from Earthly to Earthbuild! 🚀

💡 Tips for finding more occurrences

Run locally to see detailed breakdown:

./.github/scripts/count-earthly.sh

Note that the goal is not to reach 0.
There is anticipated to be at least some occurrences of earthly in the source code due to backwards compatibility with config files and language constructs.

@socket-security

socket-security Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​aws/​aws-sdk-go-v2@​v1.43.7 ⏵ v1.45.072 +1100100100100
Updatedgolang/​github.com/​aws/​aws-sdk-go-v2/​config@​v1.32.38 ⏵ v1.33.088100100100100

View full report

@janishorsts
janishorsts enabled auto-merge (squash) August 27, 2026 20:40
@renovate
renovate Bot force-pushed the renovate/aws-sdk branch from 7d8021a to 156e52a Compare August 27, 2026 20:52
@janishorsts
janishorsts merged commit 4afbe04 into main Aug 27, 2026
92 of 93 checks passed
@janishorsts
janishorsts deleted the renovate/aws-sdk branch August 27, 2026 21:57
janishorsts pushed a commit that referenced this pull request Sep 9, 2026
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
kmannislands added a commit that referenced this pull request Sep 11, 2026
`go mod tidy` drops 26 lines that nothing in the module graph reaches:
24 belong to aws-sdk-go-v2 modules left behind by the recent renovate
bumps (#873, #877), and 2 are an older earthbuild/buildkit pin.

This is unrelated to the regproxy change and is split out so the pin
bump above stays a one-line diff. main's go.sum is untidy without it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
kmannislands added a commit that referenced this pull request Sep 11, 2026
`go mod tidy` drops 26 lines that nothing in the module graph reaches:
24 belong to aws-sdk-go-v2 modules left behind by the recent renovate
bumps (#873, #877), and 2 are an older earthbuild/buildkit pin.

This is unrelated to the regproxy change and is split out so the pin
bump above stays a one-line diff. main's go.sum is untidy without it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
kmannislands added a commit that referenced this pull request Sep 11, 2026
* docs: rename Earthly to EarthBuild across markdown

Apply the project rename in markdown docs per AGENTS.md conventions:
`Earthly` (project name) becomes `EarthBuild`, and the `earthly` CLI
becomes `earth`.

Preserve literal identifiers: EARTHLY_* env vars, the earthly.dev
domain and subdomains, github.com/earthly repos, earthly/* image and
repo names, +earthly-* targets, /usr/bin/earthly paths, .earthlyignore,
and the __earthly__ completion function.

Leave references to the upstream project untouched: AGENTS.md, the
README fork banner, and docs/migrating-from-earthly.md all describe the
migration from the original Earthly and keep that name. CHANGELOG.md is
left as-is to preserve historical release notes. Also fix the in-page
TOC anchors whose renamed headings would otherwise break.

* Update .github/actions/failure-diagnostics/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* docs: complete earthly to earth rename in identifiers and paths

Address PR review feedback: rename earthly-prefixed literals that have
earth equivalents in v0.8.18+ (installation name drives the config dir,
buildkit container, and cache volume names).

- Rename EARTHLY_CONFIG/EARTHLY_BUILD_ARGS env vars to EARTH_ prefix
- Rename earthly-cache volume and earthly-buildkitd container references
- Rename ~/.earthly paths to ~/.earth
- Rename .earthlyignore to .earthignore (the code's preferred file)
- Fix docs.earthly.dev to docs.earthbuild.dev in docs-internals
- Revert accidental 'Migrating from earth' back to 'Migrating from earthly'
- Rename doc files/dirs: earthly-command, earthly-config, earthlyignore
  and update all inbound links, anchors, and gitbook redirects
- Update failure-diagnostics action to inspect ~/.earth

* docs: rename remaining ~/.earthly and earthly-buildkitd references

Sweep user-facing docs for installation-name-derived identifiers that
resolve to earth on official releases:
- ~/.earthly/config.yml -> ~/.earth/config.yml
- earthly-buildkitd -> earth-buildkitd (commands and example output)
- earthly-cache -> earth-cache in uninstall steps

Left intact: /etc/.earthly paths (hardcoded in the image entrypoint),
CONTRIBUTING.md (from-source dev workflow), and CHANGELOG.md (history).

* docs: use EARTH_ env var prefix for CLI settings

CLI flag env vars are read via the EarthEnvVars helper, which prefers
the EARTH_ prefix (EARTHLY_ is deprecated). Update all 'Also available
as an env var setting' references and the .env example in the command
reference, plus EARTH_BUILDKIT_HOST/EARTH_TARGET_PADDING/EARTH_FULL_TARGET.

Left intact: image/buildkitd env vars hardcoded as EARTHLY_ in the
entrypoint scripts (EARTHLY_ADDITIONAL_BUILDKIT_CONFIG, EARTHLY_EXEC_CMD,
EARTHLY_TMP_DIR, EARTHLY_RESET_TMP_DIR).

* docs: use EARTH_ORG env var in config reference

* docs: rename earthly-buildkitd to earth-buildkitd in Go example

* Update examples/tutorial/js/part6/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update examples/tutorial/js/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update examples/tutorial/python/part1/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update examples/tutorial/python/part2/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update examples/tutorial/python/part3/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update examples/tutorial/python/part4/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update examples/tutorial/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update release/apt-repo/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update release/yum-repo/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update .gitbook.yaml

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update CONTRIBUTING.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* Update release/apt-repo/README.md

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* fix: complete EARTHLY_ -> EARTH_ migration for internal vars (#800)

* fix: complete EARTHLY_ -> EARTH_ migration for internal vars

The EARTHLY_ -> EARTH_ rename was done for the CLI surface but not for the
variables EarthBuild sets on itself. Because the deprecation scan cannot tell
a user-set variable from one the product set, the published image emitted six
unactionable warnings per invocation, and EARTHLY_WITH_DOCKER warned you to
migrate to a name that was silently ignored.

Make EarthBuild only ever write EARTH_ names, so the scan becomes correct by
construction and no allowlist is needed:

- Rename the image ENVs, the earthly-entrypoint.sh exports, and the Go writers
  into the buildkitd container. Readers accept the EARTHLY_ spelling via a new
  earth_env shim (buildkitd/earth-env.sh), warning but still working.
- Read WITH_DOCKER through env.Lookup so EARTH_WITH_DOCKER is honoured and the
  earth-in-earth cgroup bind-mount is no longer lost by following the warning.
- Pass WITH DOCKER settings to dockerd-wrapper.sh as flags rather than
  EARTHLY_* environment variables. That removes them from the namespace
  entirely, so they can never trip the scan again. An older CLI paired with a
  newer buildkitd image still works, with a warning.
- Drop EARTHLY_IMAGE and EARTHLY_GIT_CONFIG, which had no reader and no writer
  respectively.

dockerd-wrapper.sh is bind-mounted into RUN commands as a single file, so it
carries its own copy of earth_env rather than sourcing the shared one.

Also sweeps the docs, which #753 deliberately left on the EARTHLY_ spelling
because these variables had no working EARTH_ equivalent until now.

Fixes #751

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* style: tighten comments in the internal env var rename

Drop bare ticket links used as justification, and reword a test comment that
framed itself around the migration rather than the behaviour it covers.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* Update buildkitd/buildkitd.go

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* fix: ship the CLI as earth in the published docker image (#801)

* fix: ship the CLI as earth in the published docker image

The v0.8.18 release notes document the CLI binary rename earthly -> earth,
and the release assets follow it, but the published earthbuild/earthbuild
image shipped only earthly -- there was no earth anywhere on the filesystem,
so following the release notes into the image failed with "earth: not found".

+earthly-docker hardcoded DEFAULT_INSTALLATION_NAME="earthly" while the
release path passes "earth". That value is an ldflag which also drives the
config dir, the buildkitd container name, the cache volume name and the
buildkit port offset, so the image's CLI disagreed with the released binaries
on all of them -- visible to anyone extracting the CLI from the image, which
is how the issue was found.

DEFAULT_INSTALLATION_NAME is now threaded into +earthly-docker instead of
hardcoded, and declared once as a global in release/Earthfile so the release
binaries and the image cannot drift apart again. The CLI installs as
/usr/bin/earth with an earthly symlink kept for one deprecation cycle.

Two things fall out of the rename:

PortOffset special-cased only "earthly" as the official name, so switching the
image to "earth" would have moved buildkit to 8846 and the local registry to
8845 while earthly-entrypoint.sh and buildkitd.tcp.template hardcode
8372/8371. Both official spellings now offset to zero.

earthly-entrypoint.sh hardcoded /root/.earthly/certs for the certificates the
CLI generates under ~/.<installation name>/certs, which would have become
three dangling symlinks and a TLS failure with no diagnostic. The path now
derives from the installation name the image was built with, and the script
fails loudly if the directory is absent.

Also fixes two defects in the rename notice itself: it claimed earthly "is
currently symlinked" whether or not it was, and its rm suggestion was gated on
a path built from the deprecated name, so it tested for the invoked binary
rather than its replacement.

Fixes #796.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* style: tighten comments in the earth binary rename

Drop changelog voice, ticket references and reviewer-facing justification from
the comments introduced with the image binary rename. State the invariant each
one is protecting instead: that the image and the release binaries must agree on
the installation name, that the official names must map to a zero port offset
because other files hardcode the resulting ports, and that /etc/.earthly is a
caller-supplied mount point rather than a CLI-derived path.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: follow the image config dir to ~/.earth

The config tests assert the default config location, which the installation
name determines. The image installs as earth, so the default is ~/.earth.

Cases that set an installation name explicitly keep their own directories.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: stop the image shadowing a caller's installation name

The entrypoint needs the installation name to locate the certificates the CLI
generates under ~/.<name>/certs, and took it from EARTH_INSTALLATION_NAME baked
into the image. That is the CLI's own variable, and env.Lookup prefers it over
EARTHLY_INSTALLATION_NAME, so the baked value silently overrode a caller using
the deprecated spelling: the CLI kept writing to ~/.earth while the caller
expected their own directory.

Carry the build-time name in EARTH_IMAGE_INSTALLATION_NAME, which the CLI does
not read, and use it only as the fallback when resolving the name.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* ci: address the buildkit daemon under the pinned earth name

#796 makes the published image install the CLI as `earth`, which also
renames the daemon it manages: `earthly-buildkitd` becomes
`earth-buildkitd`. CI built its binaries with
DEFAULT_INSTALLATION_NAME=earthly, so the image test's docker.sock case
looked for `earth-buildkitd`, found nothing, and tried to pull
`ghcr.io/earthbuild/earthbuild:buildkitd-image-test` -- a tag
`+earthly-docker` never builds.

Pin DEFAULT_INSTALLATION_NAME=earth in ci.yml and build-earthly.yml and
follow the name through everywhere CI addresses the daemon directly:
reusable-test.yml and reusable-misc-tests-{1,2}.yml, the registry-certs
test, and the bug-report template.

tests/bootstrap/test-bootstrap.sh derives the name from
$default_install_name instead of hardcoding it, so it tracks whatever CI
passes rather than needing a second edit next time.

earth-retry.sh and the failure-diagnostics defaults keep the deprecated
names alongside the new ones: both are best-effort cleanup and
diagnostics, and a job may still have either container.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: follow the installation name for the in-image config path

Review feedback on #801: the entrypoint derived the certs directory from
the installation name but kept the config at a hardcoded
/etc/.earthly/config.yml, so the two disagreed as soon as the image
switched to `earth`.

The config now sits at /etc/.<installation name>/config.yml alongside the
other per-installation paths, and the variable is `earth_config` to
match. The pre-rename path is still honoured when a caller mounts a
config there and nothing is mounted at the derived path, so an existing
`-v ./config.yml:/etc/.earthly/config.yml` keeps working for one
deprecation cycle; `earthly_config` stays exported as an alias for the
test call sites that read it.

setup-registry.sh and tests/warn-if-not-logged-in write to the derived
path rather than relying on that fallback, and the Earthfile reads
buildkit_additional_config back from the same place.

Also renames earthly-entrypoint.sh to earth-entrypoint.sh, with
/usr/bin/earthly-entrypoint.sh kept as a symlink: the CI integration
guides name that path explicitly, so it gets the same deprecation cycle
as /usr/bin/earthly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: silence SC2016 on the entrypoint symlink assertion

+lint-scripts-misc runs shellcheck at default severity, so the info-level
SC2016 fails the build. The single quotes are deliberate: the readlink
is evaluated by `sh -c` inside the container, not by the test script, so
the warning does not apply here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* test: drive the earth binary throughout the integration suite (#803)

* test: drive the earth binary throughout the integration suite

`earthly` compatibility symlink. The integration suite still reached the
CLI through the deprecated name, so ~176 call sites were exercising the
symlink rather than the binary users actually get. This drives `earth`
throughout and keeps one deliberate case on `earthly`.

+deprecated-name-test is that case: it asserts the symlink reaches the
CLI and that the rename warning is emitted, so the compatibility path
stays covered deliberately rather than incidentally.

Three things a mechanical s/earthly/earth/ gets wrong, all handled here:

1. COMP_POINT is a byte offset into COMP_LINE. Most cases derive it via
   `wc -m`, but two are literal (10 and 9). autocomplete/complete.go
   returns early when compPoint > len(compLine), so a stale offset
   yields no completions and the test fails confusingly rather than
   obviously. Now 8 and 7.
2. The bash completion file is named `earthly` regardless of
   installation name (bootstrap_cmds.go), so the assertions in
   tests/autocompletion/install must keep the old name.
3. The eine tests copy the binary in rather than taking it from the
   image, so their COPY destination moves to `earth` alongside their
   invocations.

Also left on the deprecated spelling on purpose: earthly_config (a shell
variable exported by the entrypoint), earthly.output and
/tmp/*-earthly-script (filenames), github.com/earthly/earthly+base (a
remote target ref), +earthly-docker (a target name), and the
.earthly-test2 / .earthly-not-test directories belonging to cases that
set an installation name explicitly.

CI's installation-name pin and the earth-buildkitd rename live in #801,
so that PR is green on its own; this one is purely the suite rename.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: read the config path from earth_config

The suite read $earthly_config, which earth-entrypoint.sh now exports
only as a deprecated alias of $earth_config. Keeping the call sites on
the alias meant the integration tests were exercising the compatibility
shim rather than the spelling callers get, which is the opposite of what
this branch is for.

The alias itself stays: it is a contract for callers outside this repo,
and scripts/tests/earth-image.sh still asserts it resolves.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: remove the unrunnable AWS OIDC integration test

tests/oidc has not been exercised since #32 (Aug 2025), which commented
out the docker-test-oidc-command and podman-test-oidc-command jobs
pending an AWS account; those commented jobs were later dropped from the
workflows entirely, so nothing builds ./tests/oidc+test today.

It could not be reinstated as written in any case. It depends on three
things the fork removed: `earth account login`, which no longer exists as
a subcommand; EARTHLY_TOKEN, documented as removed in
docs/migrating-from-earthly.md along with Earthly Cloud auth; and the
cloud-backed secret `test-oidc-user/token` plus the
`PROJECT other-service+oidc-ci-test/my-project` reference in aws.earth,
neither of which resolves without a cloud provider.

Note this leaves the live --run-with-aws-oidc feature with only unit
coverage (util/oidcutil). The commented-out test-aws-oidc block in
tests/Earthfile still records the error-case assertions if someone
reinstates integration coverage; its pointer to this directory is
dropped.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(deps): update github.com/tonistiigi/fsutil digest to 83cac42 (#865)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module github.com/sirupsen/logrus to v1.10.2 (#867)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module google.golang.org/grpc to v1.83.2 (#868)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module google.golang.org/protobuf to v1.36.12 (#869)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): update dependency kubernetes-sigs/kind to v0.33.0 (#870)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module github.com/gofrs/flock to v0.13.1 (#871)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): update dependency com.eed3si9n:sbt-assembly to v2.5.0 (#854)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix: register shell completion for the installed binary name (#857)

The bash and zsh completion entries written by `bootstrap
--with-autocomplete` hardcoded `earthly` as the command word, and
installed to files named `earthly` / `_earthly`. The released binary is
`earth`, so `earth <TAB>` offered nothing.

Derive the command word and the completion filenames from the basename of
the running executable instead. The installation name is deliberately not
used: it names on-disk resources and can be overridden independently of
what the user actually types.

A binary still installed as `earthly` also registers `earth`, matching
the alias symlinkEarthlyToEarth already creates for it.

The uninstall docs in docs/alt-installation already documented
`completions/earth` and `_earth`; this makes the code match.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* chore(deps): update dependency scala to v3.9.0 (#872)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update aws sdk (#873)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update otel (#874)

* fix(deps): update otel

* fix: bump to the highest possible otel

* chore: bump semconv to v1.43.0

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* chore(deps): update dependency golangci/golangci-lint to v2.13.2 (#875)

* chore(deps): update dependency golangci/golangci-lint to v2.13.2

* fix: lint

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* chore(deps): update dependency sbt/sbt to v2.0.8 (#876)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update aws sdk (#877)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): update dockerfile-dependencies (#880)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* docs: add missing param to top-level WITH DOCKER doc (#881)

The Earthfile reference doc for `WITH DOCKER` mentions the `--platform`
flag in the list of args, but it isn't shown in the top level invocation
doc. Add it there.

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* fix(deps): update otel (#879)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): lock file maintenance (#885)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): update public.ecr.aws/amazonlinux/amazonlinux docker tag to v2023.12.20260831.0 (#886)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module github.com/aws/aws-sdk-go-v2/config to v1.33.2 (#887)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module al.essio.dev/pkg/shellescape to v1.6.1 (#888)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* refactor: migrate from encoding/json to encoding/json/v2 (#883)

* refactor: migrate from encoding/json to standard library encoding/json/v2

* chore: tidy

---------

Co-authored-by: Squirrel <gilescope@gmail.com>

* chore(deps): update dependency bundler to v4.0.20 (#889)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* refactor: use std uuid (#882)

* refactor: use std uuid

* fix: lint

* fix(deps): update dependency org.clojure:clojure to v1.12.6 (#891)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module golang.org/x/crypto to v0.56.0 (#892)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): update dependency org.apache.maven.plugins:maven-compiler-plugin to v3.16.0 (#893)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): update jdkato/vale docker tag to v3.20.0 (#894)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): update public.ecr.aws/amazonlinux/amazonlinux docker tag to v2027 (#895)

* chore(deps): update public.ecr.aws/amazonlinux/amazonlinux docker tag to v2027

* fix: support both Amazon Linux 2023 and 2027

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

* chore(deps): update dependency org.apache.maven.plugins:maven-surefire-plugin to v3.6.0 (#896)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module github.com/docker/cli to v29.8.0+incompatible (#897)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update aws sdk (#898)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore: tidy

* chore: sort gitbook redirects alphabetically

* chore: tidy release/README.md

* Apply suggestion from @janishorsts

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>

---------

Co-authored-by: Janis Horsts <janis.horsts@gmail.com>
Co-authored-by: Kieran Mann <kieranjarrettmann@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: John Moon <john.moon@voyagertechnologies.com>
Co-authored-by: Squirrel <gilescope@gmail.com>
kmannislands added a commit that referenced this pull request Oct 7, 2026
`go mod tidy` drops 26 lines that nothing in the module graph reaches:
24 belong to aws-sdk-go-v2 modules left behind by the recent renovate
bumps (#873, #877), and 2 are an older earthbuild/buildkit pin.

This is unrelated to the regproxy change and is split out so the pin
bump above stays a one-line diff. main's go.sum is untidy without it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
kmannislands added a commit that referenced this pull request Oct 7, 2026
`go mod tidy` drops 26 lines that nothing in the module graph reaches:
24 belong to aws-sdk-go-v2 modules left behind by the recent renovate
bumps (#873, #877), and 2 are an older earthbuild/buildkit pin.

This is unrelated to the regproxy change and is split out so the pin
bump above stays a one-line diff. main's go.sum is untidy without it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
kmannislands added a commit that referenced this pull request Oct 7, 2026
`go mod tidy` drops 26 lines that nothing in the module graph reaches:
24 belong to aws-sdk-go-v2 modules left behind by the recent renovate
bumps (#873, #877), and 2 are an older earthbuild/buildkit pin.

This is unrelated to the regproxy change and is split out so the pin
bump above stays a one-line diff. main's go.sum is untidy without it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
kmannislands added a commit that referenced this pull request Oct 7, 2026
…lence (#914)

* fix(regproxy): end a proxied connection on half-close, not 50ms of silence

The client half of the registry proxy inferred the end of docker's
request from its socket going quiet for 50ms, then closed its send
direction. Both halves of that were wrong: a request split across
packets with a gap in it was cut short, and because the same 50ms ended
the whole connection, a kept-alive connection carrying the manifest and
blob requests of one pull was torn down after the first of them.

registry.Copy, which replaces CopyWithDeadline and StreamRW on both
sides of the stream, ends each direction when its source ends it and
passes that end on as a half-close, so nothing is inferred from
silence. See the fork commit for the full account.

This does not compile until the buildkit pin moves to a commit
containing registry.Copy; the pin bump comes with it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* build: pin buildkit to the commit carrying registry.Copy

regproxy needs registry.Copy, which EarthBuild/buildkit#24 added. That
PR has merged, so both buildkit pins move to the fork's main at its
merge commit (343d8bfee):

- go.mod's replace, for the library the CLI compiles in: the client
  half of the fix, regproxy.handle.
- buildkitd/Earthfile's BUILDKIT_BASE_IMAGE, for the daemon image: the
  server half, Server.Proxy. Without it the CLI ships the new client
  while the daemon keeps the 50ms-silence copy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* build: tidy go.sum

`go mod tidy` drops 26 lines that nothing in the module graph reaches:
24 belong to aws-sdk-go-v2 modules left behind by the recent renovate
bumps (#873, #877), and 2 are an older earthbuild/buildkit pin.

This is unrelated to the regproxy change and is split out so the pin
bump above stays a one-line diff. main's go.sum is untidy without it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(regproxy): drive the proxy end to end against buildkit's Server.Proxy

buildkit#24's tests run the real Server.Proxy against a hand-written
client. Nothing ran this repo's client against it, which is the pairing
that ships. These tests put the whole chain between a real net/http
client and an httptest registry, over real gRPC on loopback:

  http.Client -> Controller.Start -> handle -> gRPC -> Server.Proxy -> registry

Four cases: a plain response; a response the registry stalls 300ms
mid-body; a request body that stalls 300ms mid-way (the client's own
half of the fix); and two requests 200ms apart on one kept-alive
connection, asserting the registry accepted exactly one connection.

Against origin/main the last three fail as #912 describes: a body cut
off at 65536 of 131072 bytes, a request write on a closed connection,
and two registry connections where one was wanted. In-process, no
Docker or network; about 0.7s.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant