Skip to content

chore: release 3.3.0 - #41

Merged
pkazmier merged 10 commits into
fidelity:masterfrom
fidelity-contributions:release-3.3.0
Sep 25, 2026
Merged

pkazmier merged 10 commits into
fidelity:masterfrom
fidelity-contributions:release-3.3.0

Conversation

@pkazmier

Copy link
Copy Markdown
Member
  • Add new session provider awsrun.session.aws.CredsViaOAuth2ROPC and two plug-ins for the CLI that use it: awsrun.plugins.creds.aws.OAuth2 and awsrun.plugins.creds.aws.OAuth2CrossAccount. These allow awsrun to obtain STS credentials for AWS accounts using the OAuth2 Resource Owner Password Credentials (ROPC) flow. This is in addition to the existing support for SAML-based authentication.

    As of July 2026, AWS offers a new IAM condition key for STS called sts:RoleAuthorizedByIdp. It can be used in a trust policy to ensure that the assumed role is in the list of roles included in the OIDC token provided by the IdP. When passing an OIDC token to AssumeRoleWithWebIdentity, the trust policy can be configured to require that the role being assumed is explicitly authorized by the IdP. Please refer to the AWS documentation for more information (search for sts:RoleAuthorizedByIdp on that page).

  • Remove flake8 and pylint from the development dependencies. These have been replaced by ruff. Starting with ruff 0.16, the default rules have grown from 59 to 413, so this release also addresses many of those linting issues.

pkazmier and others added 10 commits August 11, 2026 15:21
Previously, ExpiringValue and family required specifying the TTL upon
instantation, which occurs before the value has been retrieved.  There
are, however, cases where the expiration is not know until the value has
been retrieved (OAuth2 token includes the expiration time for example).

This change introduces `ValueWithExpiry`, which is a small wrapper
around a value and an expiration time. The `refresh_fn` passed to the
`ExpiringValue` constructor can now return either plain values or a
wrapped values. When a wrapped value is returned, it is only cached
until the expiration time.

This change is backwards compatible.
With the new OAuth2 ROPC session provider, CredsViaOAuth2ROPC, this adds
two new plug-ins for use with the CLI:

- awsrun.plugins.creds.aws.OAuth2
- awsrun.plugins.creds.aws.OAuth2CrossAccount
Previously, users supplied a static 'duration' value to cache the STS
tokens received from the assume_role calls. With the recent enhancement
to ExpiringValue allowing dynamic expirations, the Expiration provided
by AWS is used instead (minus a 5 minute buffer).
With the release of ruff 0.16 in July 2026, the default linting ruleset
went from 59 to 413 rules. This commit addresses many of those new
findings.
@pkazmier
pkazmier requested a review from a-medv September 25, 2026 18:26
@pkazmier
pkazmier merged commit 562cd60 into fidelity:master Sep 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants