Skip to content

build(deps): bump software.amazon.msk:aws-msk-iam-auth from 2.3.8 to 2.3.9 - #404

Merged
ferenc-csaky merged 1 commit into
mainfrom
dependabot/maven/software.amazon.msk-aws-msk-iam-auth-2.3.9
Sep 28, 2026
Merged

ferenc-csaky merged 1 commit into
mainfrom
dependabot/maven/software.amazon.msk-aws-msk-iam-auth-2.3.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps software.amazon.msk:aws-msk-iam-auth from 2.3.8 to 2.3.9.

Release notes

Sourced from software.amazon.msk:aws-msk-iam-auth's releases.

2.3.9

What's Changed

Bug fixes

  • Fixed credential resolution failures when dualstack endpoints are enabled (AWS_USE_DUALSTACK_ENDPOINT, the aws.useDualstackEndpoint system property, or use_dualstack_endpoint in the AWS config profile). (#252, fixes #248)
    • Removed the explicit STS endpoint override. Endpoint resolution is now delegated to the AWS SDK's endpoint ruleset, which resolves regional, dualstack, and FIPS endpoints correctly. Resolved endpoints for existing non-dualstack regional configurations are unchanged.
    • With dualstack enabled and no awsStsRegion configured, provider construction now fails fast with an actionable error naming the awsStsRegion JAAS option, instead of repeatedly retrying the nonexistent sts.aws-global.api.aws hostname.
    • When the last configured credential provider (for example the awsRoleArn STS provider) fails and the chain falls back to the default providers, a WARN is now logged naming the failed provider, so the connection no longer silently authenticates as an unintended ambient identity. Setting awsAddDefaultProviders="false" remains the way to fail fast instead of falling back.
    • fipsEnabled is now set on the STS client only when the awsShouldUseFips JAAS option requests it, so ambient FIPS configuration is honored.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [software.amazon.msk:aws-msk-iam-auth](https://github.com/aws/aws-msk-iam-auth) from 2.3.8 to 2.3.9.
- [Release notes](https://github.com/aws/aws-msk-iam-auth/releases)
- [Commits](aws/aws-msk-iam-auth@v2.3.8...v2.3.9)

---
updated-dependencies:
- dependency-name: software.amazon.msk:aws-msk-iam-auth
  dependency-version: 2.3.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 28, 2026
@ferenc-csaky
ferenc-csaky merged commit 2f086c4 into main Sep 28, 2026
37 checks passed
@ferenc-csaky
ferenc-csaky deleted the dependabot/maven/software.amazon.msk-aws-msk-iam-auth-2.3.9 branch September 28, 2026 11:07
ferenc-csaky pushed a commit that referenced this pull request Sep 28, 2026
…2.3.9 (#404)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant