RATATOSKRATATOSK
Sign in

Cloud Custodian

0.9.52.0Security
Sep 3, 2026

CHECK 3OTHER 159

A broad multi-cloud release adds resource integrations, filters, and policy actions across AWS, Azure, and GCP, alongside correctness fixes and dependency updates. Operators should also review the LDAP input handling improvement and the behavior changes affecting existing configurations.

Check if affected (3)

  • breakingThe Status field, replaced by State

    Applies if you configure Status.

    The AWS c7n-org accounts configuration retires Status in favor of State.

    cloud-custodian#11043

  • breakingThe SCM basic auth method, replaced by an Entra ID bearer token

    Applies if you use SCM basic auth.

    Azure Functions replace SCM basic auth with an Entra ID bearer token.

    cloud-custodian#11008

  • breakingThe cloud-run label mutation fields, restricted to the schema

    Applies if you use cloud-run.

    The GCP cloud-run resource drops non-schema fields from label mutations.

    cloud-custodian#11052

All 159 other recorded changesadditions 119 · fixes 25 · value changes 10 · constraints 4 · defaults 1

additions (119)

  • * aws - bedrock add tagging, marked for op and stop by @KodyMullins in https://github.com/cloud-custodian/cloud-custodian/pull/10611
  • * aws - vpc-endpoint - add delete action by @Hari-Xpress in https://github.com/cloud-custodian/cloud-custodian/pull/10813
  • * aws - security-hub resource with master filter by @PratMis in https://github.com/cloud-custodian/cloud-custodian/pull/10826
  • * aws - cloudfront - Add Cloudfront Functions and KeyValue Store Resources by @algobarb in https://github.com/cloud-custodian/cloud-custodian/pull/10831
  • * aws - resource: kms-key - Added last-usage filter for KMS Keys by @Benco351 in https://github.com/cloud-custodian/cloud-custodian/pull/10822
  • * aws - bedrock agent - metrics filter by @kapilt in https://github.com/cloud-custodian/cloud-custodian/pull/10823
  • * [Cleanrooms]: adding Clean Rooms and Clean Rooms ML resources by @rondodev in https://github.com/cloud-custodian/cloud-custodian/pull/10830
  • * [Account] adding payment-cryptography-replication-regions filter by @rondodev in https://github.com/cloud-custodian/cloud-custodian/pull/10868
  • * aws - Payment Cryptography - cross-account filter implementation by @rondodev in https://github.com/cloud-custodian/cloud-custodian/pull/10892
  • * aws - waf/waf-regional - add delete action for WAF Classic Web ACLs by @SriLakshmi556 in https://github.com/cloud-custodian/cloud-custodian/pull/10849
  • * aws - Quicksight Account Subscription and Custom Permissions by @mattheidelbaugh in https://github.com/cloud-custodian/cloud-custodian/pull/10921
  • * Cross account whitelist org unit by @mattheidelbaugh in https://github.com/cloud-custodian/cloud-custodian/pull/10838
  • * aws - dsql implementation by @mattheidelbaugh in https://github.com/cloud-custodian/cloud-custodian/pull/10887
  • * aws - bedrock inference profile - total tokens metric by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10898
  • * feat: Added Services & DefaultServiceQuotas to quota.py. by @toastdriven in https://github.com/cloud-custodian/cloud-custodian/pull/10475
  • * aws - Add termination-policy filter for EMR clusters by @mrinalpravi in https://github.com/cloud-custodian/cloud-custodian/pull/10848
  • * aws - memorydb - Adding db-parameter filter and parameter-group resource by @rondodev in https://github.com/cloud-custodian/cloud-custodian/pull/10946
  • * feat: 8653 aws ec2 compute optimizer feature by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10512
  • * aws - cfn - add mark-for-op support (#7240) by @scott-sixfeetup in https://github.com/cloud-custodian/cloud-custodian/pull/10463
  • * feat: 9978 aws es update domain config action by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10505
  • * aws - vpc-endpoint - service-details filter for cross-region endpoints by @jerryhxu in https://github.com/cloud-custodian/cloud-custodian/pull/10918
  • * aws - glue - add database tag support by @Mukeshkr-19 in https://github.com/cloud-custodian/cloud-custodian/pull/10986
  • * aws - bedrock evaluation jobs by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10923
  • * [Bedrock] adding bedrock-mantle-project resource by @rondodev in https://github.com/cloud-custodian/cloud-custodian/pull/10937
  • * aws - security lake by @mattheidelbaugh in https://github.com/cloud-custodian/cloud-custodian/pull/10948
  • * aws - cleanrooms - Add members filter to collaboration resource by @algobarb in https://github.com/cloud-custodian/cloud-custodian/pull/11032
  • * aws - sagemaker studio: app, user-profile, space resources (#10858) by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10920
  • * feat: Added VPCLatticeRule resource. by @toastdriven in https://github.com/cloud-custodian/cloud-custodian/pull/10565
  • * aws - s3 output - configurable server-side encryption for policy logs by @strixthekiet in https://github.com/cloud-custodian/cloud-custodian/pull/10991
  • * azure - Add azure cognitive services deployment resource and actions by @KodyMullins in https://github.com/cloud-custodian/cloud-custodian/pull/10634
  • * azure - ai foundry agent and application resources by @KodyMullins in https://github.com/cloud-custodian/cloud-custodian/pull/10656
  • * azure - add machine-learning-job resource by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10862
  • * feat: 8673 azure - add matched security rules to NSGs by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10464
  • * Add Azure Machine Learning data container resource by @KodyMullins in https://github.com/cloud-custodian/cloud-custodian/pull/10927
  • * azure - add machine-learning-online-endpoint resource by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10861
  • * azure - add machine-learning-model-version resource by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10872
  • * feat: 9971 azure budget resource by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10495
  • * azure - add private dns zone and record set resources by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/11053
  • * azure - add machine learning job archive action by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/11005
  • * gcp - vertex ai endpoint monitor action by @KodyMullins in https://github.com/cloud-custodian/cloud-custodian/pull/10622
  • * gcp - api-key - add gcp-audit mode support by @mgogoulos in https://github.com/cloud-custodian/cloud-custodian/pull/10628
  • * gcp - Add update action to dns policy resource by @KodyMullins in https://github.com/cloud-custodian/cloud-custodian/pull/10669
  • * gcp - Add bigquery data set update action by @KodyMullins in https://github.com/cloud-custodian/cloud-custodian/pull/10670
  • * gcp - add regional commitment resource. by @KodyMullins in https://github.com/cloud-custodian/cloud-custodian/pull/10668
  • * feat: gcp - ai endpoint metrics by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10893
  • * gcp - v2 notebooks by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10881
  • * gcp - vertex-ai-custom-job - add Custom Job resource by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10891
  • * gcp - dns-managed-zone - add enable-dnssec action by @mgogoulos in https://github.com/cloud-custodian/cloud-custodian/pull/10620
  • * gcp - add compute instance metadata by @mgogoulos in https://github.com/cloud-custodian/cloud-custodian/pull/10636
  • * gcp vertex ai dataset by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10926
  • * Add vertex ai hyper parameter tuning job by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10889
  • * gcp - add vertex-ai-model resource by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10993
  • * gcp - add Vertex AI evaluation run resource support by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/11013
  • * gcp - notebook-v2 - add get and update-metadata action (#10919) by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10994
  • * feat: #8623 tencentcloud - add action + protocol to ingress filter by @calebsyring in https://github.com/cloud-custodian/cloud-custodian/pull/10468
  • [aws.bedrock-evaluation-job](https://cloudcustodian.io/docs/aws/resources/bedrock-evaluation-job.html) added
  • [aws.bedrock-mantle-project](https://cloudcustodian.io/docs/aws/resources/bedrock-mantle-project.html) added
  • [aws.cleanrooms-collaboration](https://cloudcustodian.io/docs/aws/resources/cleanrooms-collaboration.html) added
  • [aws.cleanrooms-collaboration-member](https://cloudcustodian.io/docs/aws/resources/cleanrooms-collaboration-member.html) added
  • [aws.cleanrooms-configured-table](https://cloudcustodian.io/docs/aws/resources/cleanrooms-configured-table.html) added
  • [aws.cleanrooms-membership](https://cloudcustodian.io/docs/aws/resources/cleanrooms-membership.html) added
  • [aws.cloudfront-function](https://cloudcustodian.io/docs/aws/resources/cloudfront-function.html) added
  • [aws.cloudfront-key-value-store](https://cloudcustodian.io/docs/aws/resources/cloudfront-key-value-store.html) added
  • [aws.default-service-quota](https://cloudcustodian.io/docs/aws/resources/default-service-quota.html) added
  • [aws.dsql-cluster](https://cloudcustodian.io/docs/aws/resources/dsql-cluster.html) added
  • [aws.dsql-stream](https://cloudcustodian.io/docs/aws/resources/dsql-stream.html) added
  • [aws.memorydb-parameter-group](https://cloudcustodian.io/docs/aws/resources/memorydb-parameter-group.html) added
  • [aws.sagemaker-app](https://cloudcustodian.io/docs/aws/resources/sagemaker-app.html) added
  • [aws.sagemaker-space](https://cloudcustodian.io/docs/aws/resources/sagemaker-space.html) added
  • [aws.sagemaker-user-profile](https://cloudcustodian.io/docs/aws/resources/sagemaker-user-profile.html) added
  • [aws.security-hub](https://cloudcustodian.io/docs/aws/resources/security-hub.html) added
  • [aws.security-lake](https://cloudcustodian.io/docs/aws/resources/security-lake.html) added
  • [aws.security-lake-subscriber](https://cloudcustodian.io/docs/aws/resources/security-lake-subscriber.html) added
  • [aws.service-quota-service](https://cloudcustodian.io/docs/aws/resources/service-quota-service.html) added
  • [aws.vpc-lattice-rule](https://cloudcustodian.io/docs/aws/resources/vpc-lattice-rule.html) added
  • [azure.ai-foundry-agent](https://cloudcustodian.io/docs/azure/resources/ai-foundry-agent.html) added
  • [azure.ai-foundry-application](https://cloudcustodian.io/docs/azure/resources/ai-foundry-application.html) added
  • [azure.ai-foundry-deployment](https://cloudcustodian.io/docs/azure/resources/ai-foundry-deployment.html) added
  • [azure.budget](https://cloudcustodian.io/docs/azure/resources/budget.html) added
  • [azure.cognitiveservice-deployment](https://cloudcustodian.io/docs/azure/resources/cognitiveservice-deployment.html) added
  • [azure.machine-learning-data-container](https://cloudcustodian.io/docs/azure/resources/machine-learning-data-container.html) added
  • [azure.machine-learning-job](https://cloudcustodian.io/docs/azure/resources/machine-learning-job.html) added
  • [azure.machine-learning-model-version](https://cloudcustodian.io/docs/azure/resources/machine-learning-model-version.html) added
  • [azure.machine-learning-online-endpoint](https://cloudcustodian.io/docs/azure/resources/machine-learning-online-endpoint.html) added
  • [azure.private-dns-zone](https://cloudcustodian.io/docs/azure/resources/private-dns-zone.html) added
  • [azure.private-record-set](https://cloudcustodian.io/docs/azure/resources/private-record-set.html) added
  • [gcp.notebook-v2](https://cloudcustodian.io/docs/gcp/resources/notebook-v2.html) added
  • [gcp.region-commitment](https://cloudcustodian.io/docs/gcp/resources/region-commitment.html) added
  • [gcp.vertex-ai-custom-job](https://cloudcustodian.io/docs/gcp/resources/vertex-ai-custom-job.html) added
  • [gcp.vertex-ai-dataset](https://cloudcustodian.io/docs/gcp/resources/vertex-ai-dataset.html) added
  • [gcp.vertex-ai-evaluation-run](https://cloudcustodian.io/docs/gcp/resources/vertex-ai-evaluation-run.html) added
  • [gcp.vertex-ai-hyperparameter-tuning-job](https://cloudcustodian.io/docs/gcp/resources/vertex-ai-hyperparameter-tuning-job.html) added
  • [gcp.vertex-ai-model](https://cloudcustodian.io/docs/gcp/resources/vertex-ai-model.html) added
  • [terraform._](https://cloudcustodian.io/docs/terraform/resources/_.html) added
  • aws.account - added filters: [payment-cryptography-replication-regions](https://cloudcustodian.io/docs/aws/resources/account.html#aws-account-filters-payment-cryptography-replication-regions)
  • aws.athena-data-catalog - added actions: [mark](https://cloudcustodian.io/docs/aws/resources/athena-data-catalog.html#aws-athena-data-catalog-actions-mark), [unmark](https://cloudcustodian.io/docs/aws/resources/athena-data-catalog.html#aws-athena-data-catalog-actions-unmark), [untag](https://cloudcustodian.io/docs/aws/resources/athena-data-catalog.html#aws-athena-data-catalog-actions-untag)
  • aws.bedrock-agent - added filters: [metrics](https://cloudcustodian.io/docs/aws/resources/bedrock-agent.html#aws-bedrock-agent-filters-metrics)
  • aws.bedrock-model-invocation-job - added actions: [auto-tag-user](https://cloudcustodian.io/docs/aws/resources/bedrock-model-invocation-job.html#aws-bedrock-model-invocation-job-actions-auto-tag-user), [copy-related-tag](https://cloudcustodian.io/docs/aws/resources/bedrock-model-invocation-job.html#aws-bedrock-model-invocation-job-actions-copy-related-tag), [mark-for-op](https://cloudcustodian.io/docs/aws/resources/bedrock-model-invocation-job.html#aws-bedrock-model-invocation-job-actions-mark-for-op), [remove-tag](https://cloudcustodian.io/docs/aws/resources/bedrock-model-invocation-job.html#aws-bedrock-model-invocation-job-actions-remove-tag), [rename-tag](https://cloudcustodian.io/docs/aws/resources/bedrock-model-invocation-job.html#aws-bedrock-model-invocation-job-actions-rename-tag), [stop](https://cloudcustodian.io/docs/aws/resources/bedrock-model-invocation-job.html#aws-bedrock-model-invocation-job-actions-stop), [tag](https://cloudcustodian.io/docs/aws/resources/bedrock-model-invocation-job.html#aws-bedrock-model-invocation-job-actions-tag) - added filters: [marked-for-op](https://cloudcustodian.io/docs/aws/resources/bedrock-model-invocation-job.html#aws-bedrock-model-invocation-job-filters-marked-for-op)
  • aws.cfn - added actions: [mark-for-op](https://cloudcustodian.io/docs/aws/resources/cfn.html#aws-cfn-actions-mark-for-op) - added filters: [marked-for-op](https://cloudcustodian.io/docs/aws/resources/cfn.html#aws-cfn-filters-marked-for-op)
  • aws.ec2 - added filters: [compute-optimizer](https://cloudcustodian.io/docs/aws/resources/ec2.html#aws-ec2-filters-compute-optimizer)
  • aws.elasticsearch - added actions: [update-domain-config](https://cloudcustodian.io/docs/aws/resources/elasticsearch.html#aws-elasticsearch-actions-update-domain-config)
  • aws.emr - added filters: [termination-policy](https://cloudcustodian.io/docs/aws/resources/emr.html#aws-emr-filters-termination-policy)
  • aws.glue-database - added actions: [auto-tag-user](https://cloudcustodian.io/docs/aws/resources/glue-database.html#aws-glue-database-actions-auto-tag-user), [copy-related-tag](https://cloudcustodian.io/docs/aws/resources/glue-database.html#aws-glue-database-actions-copy-related-tag), [mark-for-op](https://cloudcustodian.io/docs/aws/resources/glue-database.html#aws-glue-database-actions-mark-for-op), [remove-tag](https://cloudcustodian.io/docs/aws/resources/glue-database.html#aws-glue-database-actions-remove-tag), [rename-tag](https://cloudcustodian.io/docs/aws/resources/glue-database.html#aws-glue-database-actions-rename-tag), [tag](https://cloudcustodian.io/docs/aws/resources/glue-database.html#aws-glue-database-actions-tag) - added filters: [marked-for-op](https://cloudcustodian.io/docs/aws/resources/glue-database.html#aws-glue-database-filters-marked-for-op)
  • aws.kms-key - added filters: [last-usage](https://cloudcustodian.io/docs/aws/resources/kms-key.html#aws-kms-key-filters-last-usage)
  • aws.memorydb - added filters: [db-parameter](https://cloudcustodian.io/docs/aws/resources/memorydb.html#aws-memorydb-filters-db-parameter)
  • aws.payment-cryptography-key - added filters: [cross-account](https://cloudcustodian.io/docs/aws/resources/payment-cryptography-key.html#aws-payment-cryptography-key-filters-cross-account)
  • aws.quicksight-account - added filters: [subscription](https://cloudcustodian.io/docs/aws/resources/quicksight-account.html#aws-quicksight-account-filters-subscription)
  • aws.quicksight-dashboard - added actions: [auto-tag-user](https://cloudcustodian.io/docs/aws/resources/quicksight-dashboard.html#aws-quicksight-dashboard-actions-auto-tag-user), [copy-related-tag](https://cloudcustodian.io/docs/aws/resources/quicksight-dashboard.html#aws-quicksight-dashboard-actions-copy-related-tag), [mark-for-op](https://cloudcustodian.io/docs/aws/resources/quicksight-dashboard.html#aws-quicksight-dashboard-actions-mark-for-op), [remove-tag](https://cloudcustodian.io/docs/aws/resources/quicksight-dashboard.html#aws-quicksight-dashboard-actions-remove-tag), [tag](https://cloudcustodian.io/docs/aws/resources/quicksight-dashboard.html#aws-quicksight-dashboard-actions-tag) - added filters: [marked-for-op](https://cloudcustodian.io/docs/aws/resources/quicksight-dashboard.html#aws-quicksight-dashboard-filters-marked-for-op)
  • aws.quicksight-datasource - added actions: [auto-tag-user](https://cloudcustodian.io/docs/aws/resources/quicksight-datasource.html#aws-quicksight-datasource-actions-auto-tag-user), [copy-related-tag](https://cloudcustodian.io/docs/aws/resources/quicksight-datasource.html#aws-quicksight-datasource-actions-copy-related-tag), [mark-for-op](https://cloudcustodian.io/docs/aws/resources/quicksight-datasource.html#aws-quicksight-datasource-actions-mark-for-op), [remove-tag](https://cloudcustodian.io/docs/aws/resources/quicksight-datasource.html#aws-quicksight-datasource-actions-remove-tag), [tag](https://cloudcustodian.io/docs/aws/resources/quicksight-datasource.html#aws-quicksight-datasource-actions-tag) - added filters: [marked-for-op](https://cloudcustodian.io/docs/aws/resources/quicksight-datasource.html#aws-quicksight-datasource-filters-marked-for-op)
  • aws.quicksight-user - added actions: [auto-tag-user](https://cloudcustodian.io/docs/aws/resources/quicksight-user.html#aws-quicksight-user-actions-auto-tag-user), [copy-related-tag](https://cloudcustodian.io/docs/aws/resources/quicksight-user.html#aws-quicksight-user-actions-copy-related-tag), [mark-for-op](https://cloudcustodian.io/docs/aws/resources/quicksight-user.html#aws-quicksight-user-actions-mark-for-op), [remove-tag](https://cloudcustodian.io/docs/aws/resources/quicksight-user.html#aws-quicksight-user-actions-remove-tag), [tag](https://cloudcustodian.io/docs/aws/resources/quicksight-user.html#aws-quicksight-user-actions-tag) - added filters: [marked-for-op](https://cloudcustodian.io/docs/aws/resources/quicksight-user.html#aws-quicksight-user-filters-marked-for-op), [permissions](https://cloudcustodian.io/docs/aws/resources/quicksight-user.html#aws-quicksight-user-filters-permissions)
  • aws.vpc-endpoint - added actions: [delete](https://cloudcustodian.io/docs/aws/resources/vpc-endpoint.html#aws-vpc-endpoint-actions-delete)
  • aws.waf - added actions: [delete](https://cloudcustodian.io/docs/aws/resources/waf.html#aws-waf-actions-delete)
  • aws.waf-regional - added actions: [delete](https://cloudcustodian.io/docs/aws/resources/waf-regional.html#aws-waf-regional-actions-delete)
  • gcp.bq-dataset - added actions: [update](https://cloudcustodian.io/docs/gcp/resources/bq-dataset.html#gcp-bq-dataset-actions-update)
  • gcp.compute-project - added actions: [set-common-instance-metadata](https://cloudcustodian.io/docs/gcp/resources/compute-project.html#gcp-compute-project-actions-set-common-instance-metadata)
  • gcp.dns-managed-zone - added actions: [enable-dnssec](https://cloudcustodian.io/docs/gcp/resources/dns-managed-zone.html#gcp-dns-managed-zone-actions-enable-dnssec), [set-dnssec-key-specs](https://cloudcustodian.io/docs/gcp/resources/dns-managed-zone.html#gcp-dns-managed-zone-actions-set-dnssec-key-specs)
  • gcp.dns-policy - added actions: [update](https://cloudcustodian.io/docs/gcp/resources/dns-policy.html#gcp-dns-policy-actions-update)
  • gcp.instance - added actions: [set-metadata](https://cloudcustodian.io/docs/gcp/resources/instance.html#gcp-instance-actions-set-metadata)
  • gcp.vertex-ai-endpoint - added actions: [monitor](https://cloudcustodian.io/docs/gcp/resources/vertex-ai-endpoint.html#gcp-vertex-ai-endpoint-actions-monitor)

fixes (25)

  • * fix: handle IAM ResourveNotFoundException correctly by @Shreyas0047 in https://github.com/cloud-custodian/cloud-custodian/pull/10812
  • * aws - lambda - trim-versions - fix retain-latest schema default by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10885
  • * aws - sns - resolve topics directly by arn in event mode by @sontek in https://github.com/cloud-custodian/cloud-custodian/pull/10922
  • * aws - kafka - fix UnboundLocalError by @jerryhxu in https://github.com/cloud-custodian/cloud-custodian/pull/10924
  • * aws - iam-policy - detect list-form Action/Resource in has-allow-all by @naohito-intuit in https://github.com/cloud-custodian/cloud-custodian/pull/10952
  • * fix(athena): skip AWS-managed AwsDataCatalog in universal tag/untag action by @bishtashish708 in https://github.com/cloud-custodian/cloud-custodian/pull/10967
  • * aws - wafv2 - fix set-wafv2 on CloudFront ignoring CLOUDFRONT scope by @SriLakshmi556 in https://github.com/cloud-custodian/cloud-custodian/pull/10975
  • * directconnect tag fix by @jismail3000 in https://github.com/cloud-custodian/cloud-custodian/pull/10985
  • * aws - mu - strip read-only fields from ConfigRule before PutConfigRule update by @naohito-intuit in https://github.com/cloud-custodian/cloud-custodian/pull/10951
  • * aws.s3: don't abort augment() on a single bucket's connection error by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/11016
  • * aws - iam - retry concurrent tag updates by @1fanwang in https://github.com/cloud-custodian/cloud-custodian/pull/11044
  • * aws - wafv2 - fix wafv2-enabled filter ignoring CLOUDFRONT scope by @bdwyertech in https://github.com/cloud-custodian/cloud-custodian/pull/11039
  • * aws - cross-account filter - ForAnyValue Bugfix by @mattheidelbaugh in https://github.com/cloud-custodian/cloud-custodian/pull/11074
  • * fix: avoid KeyError in marked-for-op on non-EC2 resources by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10882
  • * fix(gcp): add get_metric_resource_name for Cloud Run revisions by @ChallaBharadwajReddy in https://github.com/cloud-custodian/cloud-custodian/pull/10807
  • * fix(10897): gcp - vertex-ai - get_resource() fix by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10894
  • * fix(gcp): normalize None source results before augment (#10955) by @faan-rubrik in https://github.com/cloud-custodian/cloud-custodian/pull/10969
  • * gcp - metrics filter - honor missing-value: 0 by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10929
  • * gcp - recommender - fix concatenated usage commitment recommender id by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10903
  • * gcp - fix region-parented resource enumeration when no explicit region is provided by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/11009
  • * escape spreadsheet formula characters in csv report output by @uwezkhan in https://github.com/cloud-custodian/cloud-custodian/pull/10836
  • * core - ValueFilter: recalculate value_path per resource (#10521) by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10934
  • * core - resolver - skip short rows in value_from CSV column lookup by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10880
  • * core - fix get_human_size overflow for exabyte-scale sizes by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10904
  • * core - reduce filter - fix discard-percent leaking across groups by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10907

value changes (10)

  • * aws - workspaces-bundle - pull tags via universal augment by @ajkerrigan in https://github.com/cloud-custodian/cloud-custodian/pull/10866
  • * Wafv2 Refactor Scope Region Logic by @mattheidelbaugh in https://github.com/cloud-custodian/cloud-custodian/pull/10827
  • * aws - paymentcrypto - Update Augment to add get_key details by @algobarb in https://github.com/cloud-custodian/cloud-custodian/pull/10925
  • * aws - iam-user - avoid quadratic dedup in policy filter by @anxkhn in https://github.com/cloud-custodian/cloud-custodian/pull/10901
  • * aws - emr-serverless-app - augment with GetApplication detail (autoStopConfiguration) by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10928
  • tools/c7n_mailer - escape untrusted uid before building ldap filter
  • releng - bump azure cosmosdb version v6.4.0 --> v9.9.0
  • Bump pyjwt from 2.12.1 to 2.13.0
  • Bump pydantic-settings from 2.14.0 to 2.14.2
  • releng - dependency updates 2026-08

constraints (4)

  • * fix(account): use get_support_region() in service-limit filter for GovCloud support by @patryktomaszewski in https://github.com/cloud-custodian/cloud-custodian/pull/10805
  • * aws - tags - allow resource lookups in tag values by @ajkerrigan in https://github.com/cloud-custodian/cloud-custodian/pull/10942
  • * azure - tags - resolve resource lookups in tag values by @UTKARSH698 in https://github.com/cloud-custodian/cloud-custodian/pull/10961
  • * gcp - support regional persistent disks for disk actions by @jimfulton in https://github.com/cloud-custodian/cloud-custodian/pull/10995

defaults (1)

  • * QueryResourceManager - retry InternalServerException by default by @mattheidelbaugh in https://github.com/cloud-custodian/cloud-custodian/pull/11041
Add Cloud Custodian to your stack

A weekly email arrives when a release needs action. Like the breaking changes in this release.

Add to stack