You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Refactor][Build] Remove the end-of-support aws-sdk-go v1 from backend/go.mod #9196
backend/go.mod still requires github.com/aws/aws-sdk-go (v1). AWS ended
support for the v1 SDK on 2025-07-31:
no more bug fixes, no more security fixes. v1.55.8 is the last release and
deprecates every package, which is how it surfaced in #9192 (lint red with
11× SA1019).
Keeping an unsupported SDK in the dependency tree means:
any future CVE in it will not be fixed upstream by AWS,
every Dependabot gomod run that touches it re-triggers the deprecation
warnings, which currently have to be suppressed by a lint exclusion,
Optional guard: add a depguard rule (or a simple grep in CI) that rejects
new imports of github.com/aws/aws-sdk-go/, so v1 does not come back
through another plugin.
@warren830 — since kiro is currently the sole user of the AWS SDK in
DevLake, looping you in here as well. If you plan further AWS-based plugins,
starting them on v2 would avoid repeating this.
What and why to refactor
backend/go.modstill requiresgithub.com/aws/aws-sdk-go(v1). AWS endedsupport for the v1 SDK on
2025-07-31:
no more bug fixes, no more security fixes. v1.55.8 is the last release and
deprecates every package, which is how it surfaced in #9192 (
lintred with11×
SA1019).Keeping an unsupported SDK in the dependency tree means:
warnings, which currently have to be suppressed by a lint exclusion,
Describe the solution you'd like
backend/plugins/kiro, to aws-sdk-go-v2(separate issue: [Refactor][Kiro] Migrate the kiro plugin from aws-sdk-go v1 to aws-sdk-go-v2 #9195).
github.com/aws/aws-sdk-gofrombackend/go.mod/go.sum(
go mod tidy).staticcheckexclusion forSA1019/plugins/kiro/frombackend/.golangci.yaml(added in fix(ci): make Dependabot gomod PRs tested and lint-clean #9197).depguardrule (or a simple grep in CI) that rejectsnew imports of
github.com/aws/aws-sdk-go/, so v1 does not come backthrough another plugin.
@warren830 — since kiro is currently the sole user of the AWS SDK in
DevLake, looping you in here as well. If you plan further AWS-based plugins,
starting them on v2 would avoid repeating this.
Related issues
go-minor-patchgroup)Additional context
q_dev, the previous AWS-based plugin, was removed in #9079, so after thekiro migration no code in the repository depends on v1 anymore.