chore: release 3.3.0 - #41
Merged
Merged
Conversation
Previously, ExpiringValue and family required specifying the TTL upon instantation, which occurs before the value has been retrieved. There are, however, cases where the expiration is not know until the value has been retrieved (OAuth2 token includes the expiration time for example). This change introduces `ValueWithExpiry`, which is a small wrapper around a value and an expiration time. The `refresh_fn` passed to the `ExpiringValue` constructor can now return either plain values or a wrapped values. When a wrapped value is returned, it is only cached until the expiration time. This change is backwards compatible.
With the new OAuth2 ROPC session provider, CredsViaOAuth2ROPC, this adds two new plug-ins for use with the CLI: - awsrun.plugins.creds.aws.OAuth2 - awsrun.plugins.creds.aws.OAuth2CrossAccount
Previously, users supplied a static 'duration' value to cache the STS tokens received from the assume_role calls. With the recent enhancement to ExpiringValue allowing dynamic expirations, the Expiration provided by AWS is used instead (minus a 5 minute buffer).
With the release of ruff 0.16 in July 2026, the default linting ruleset went from 59 to 413 rules. This commit addresses many of those new findings.
a-medv
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add new session provider awsrun.session.aws.CredsViaOAuth2ROPC and two plug-ins for the CLI that use it: awsrun.plugins.creds.aws.OAuth2 and awsrun.plugins.creds.aws.OAuth2CrossAccount. These allow awsrun to obtain STS credentials for AWS accounts using the OAuth2 Resource Owner Password Credentials (ROPC) flow. This is in addition to the existing support for SAML-based authentication.
As of July 2026, AWS offers a new IAM condition key for STS called sts:RoleAuthorizedByIdp. It can be used in a trust policy to ensure that the assumed role is in the list of roles included in the OIDC token provided by the IdP. When passing an OIDC token to AssumeRoleWithWebIdentity, the trust policy can be configured to require that the role being assumed is explicitly authorized by the IdP. Please refer to the AWS documentation for more information (search for sts:RoleAuthorizedByIdp on that page).
Remove flake8 and pylint from the development dependencies. These have been replaced by ruff. Starting with ruff 0.16, the default rules have grown from 59 to 413, so this release also addresses many of those linting issues.