## floci-io/floci — 1.6.0…1.7.0

_168+ commits._

### Features
- **feat(guardduty): add GuardDuty detector and organization configuration emulation (#2346)** (6779aa8)
- **feat(cognito): add GetUserAttributeVerificationCode support (#1898)** (24cdabb)
- **feat(cloudhsmv2): implement CloudHSM v2 service (#1776)** (1cc97d5)
- **feat(firehose): honor BufferingHints with time and size based flush (#2314)** (bfda938)
- **feat(ec2): DescribeImages synthesizes an AMI for an unmatched wildcard name lookup (#2009)** (cdb6811)
- **feat(cloudformation): provision ApiGateway::Account, AutoScaling::LifecycleHook, and EC2::FlowLog (#2003)** (9280369)
- **feat(msk): add configuration CRUD (Create/List/Describe/Delete) (#2336)** (4c510e5)
- **feat(ec2): config toggle to report the AWS-faithful private IP (#2024)** (33d35b2)
- **feat(cloudformation): provision the network ACL family (#2001)** (5e01c07)
- **feat(opensearch): parse, store, and return AccessPolicies (#2327)** (78ad357)
- **feat(ec2): support transit gateways (#2329)** (20470b7)
- **feat(bedrockagentcore): emulate the AgentCore control plane and InvokeAgentRuntime stub (#2316)** (4e6e6df)
- **feat(ec2): allow a security group rule to take a prefix list as its source (#2271)** (dfcd492)
- **feat(kms): implement UpdateAlias (#2324)** (984886f)
- **feat(s3tables): emulate metadata service (#2322)** (b45de1b)
- **feat(ses): add DKIM actions with domain-inherited email DKIM (#1904)** (ff0201a)
- **feat(rds): model DB proxies and their target groups (#1813)** (e4010ec)
- **feat(ec2): DescribeVpcEndpointServices returns the common interface services with AZs (#2007)** (42a79a7)
- **feat(ses): implement PutAccountVdmAttributes and return VdmAttributes from GetAccount (v2) (#2265)** (80d1dc7)
- **feat(cloudformation): provision AWS::EC2::VPCEndpoint (#1995)** (a985fa4)
- **feat(cloudformation): provision AWS::Lambda::Permission and fix Version and Alias updates (#1997)** (105a8ee)
- **feat(ec2): support CreateImage (create AMI from instance) (#1979)** (30a6164)
- **feat(iam): support account aliases (#2103)** (1215429)
- **feat(swf): add Simple Workflow Service emulation (#2257)** (ecad6ac)
- **feat(cloudfront): enforce signed private content (#1831)** (5657e35)
- **feat(stepfunctions): add UpdateStateMachine and update in place on stack updates (#1867)** (97ac3ca)
- **feat(stepfunctions): run Map iterations concurrently honoring MaxConcurrency (#1810)** (a7da1b9)
- **feat(apigatewayv2): route execute-api hosts to WebSocket $connect and @connections (#2188)** (45bb37f)
- **feat(cloudformation): implement GetTemplateSummary (#2148)** (a235b76)
- **feat(apigateway): derive SQS QueueUrl from path-style integration URI when absent from template (#1903)** (cfbae88)
- **feat(cloudformation): provision AWS::ECS::CapacityProvider and ClusterCapacityProviderAssociations (#1999)** (907a2df)
- **feat(cloudcontrol): implement CreateResource / DeleteResource / GetResource (#2037)** (43f47a3)
- **feat(kinesis): add local inspection endpoints for UI (#1880)** (486be8f)
- **feat(logs): support log group deletion protection (#2256)** (4215006)
- **feat(dynamodb): global-table v2 replicas (UpdateTable ReplicaUpdates + Custom::DynamoDBReplica) (#1811)** (a29464a)
- **feat(cloudformation): resolve dynamic references in RDS credentials (#1809)** (d9e4447)
- **feat(cloudfront): serve distribution requests from S3 and custom origins (#1820)** (82f8016)
- **feat(cloudformation): provision AWS::Events::EventBus as a real custom bus (#1807)** (bc21367)
- **feat(apigateway): route execute-api hostnames for HTTP APIs (#2054)** (33ba5ac)
- **feat(lambda): support EFS file system configs (#2053)** (e1f389f)
- **feat(appsync): Phase 6 — Query Execution + HTTP Endpoint (#1884)** (819bfed)
- **feat(rds-data): adding data-api preparedstatement() support (#1887)** (19a32ab)
- **feat(iam): add GetAccountSummary support (#1986)** (c21337c)
- **feat(stepfunctions): emulate distributed Map ResultWriter (S3 export + manifest) (#1823)** (59cb643)
- **feat(ses): honor ConfigurationSetName on CreateEmailIdentity (v2) (#1812)** (cd3588b)
- **feat(apigateway): API key management — UpdateApiKey, DeleteApiKey, UsagePlan custom-id, generateDistinctId (#1883)** (b6765b3)
- **feat(iam): support OIDC identity providers (#2106)** (f17dd1e)
- **feat(lambdamicrovms): AWS Lambda MicroVMs service module and its CloudFormation types (#2079)** (40e8aad)
- **feat(ses): implement SendCustomVerificationEmail for v1 and v2 (#2191)** (bd01c1a)
- **feat(ec2): support managed prefix lists (#2105)** (ac4b865)
- **feat(eventbridge): deliver events to event-bus targets (#1814)** (50fe67d)
- **feat(eks): support IRSA with a real OIDC issuer and JWT validation (#2108)** (7e5afae)
- **feat(elbv2): honor preserve_host_header parameter (#2109)** (2594705)
- **feat(iam): add service-linked role create, delete and deletion status (#2179)** (c8403ac)
- **feat(kinesisanalytics): add Managed Service for Apache Flink (Kinesis Analytics V2) (#1914)** (d78520d)
- **feat(s3): resolve index documents for static-website directory requests (#1815)** (6d829ff)
- **feat(ec2): add ReplaceRoute (#2178)** (d943e09)

### Fixes
- **fix(cognito): expire refresh tokens and scope them to their own pool in REFRESH_TOKEN_AUTH (#2135)** (7d8aced)
- **fix(core): stop leaked executor threads from pinning test classloaders (#2363)** (6962e91)
- **fix(apigateway): verify and propagate HTTP API v2 JWT authorizer claims (#2353)** (0444753)
- **fix(lambda): validate Layers ARNs eagerly on CreateFunction/UpdateFunctionConfiguration (#2282)** (2f0ef45)
- **fix(iam): route long-term access keys to owning accounts (#2319)** (02898cf)
- **fix(appconfig): add DeleteConfigurationProfile/DeleteHostedConfigurationVersion/ListDeploymentStrategies/DeleteDeploymentStrategy (#2280)** (be62502)
- **fix(cloudwatch): keep GetLogEvents paging inside the list bounds (#2355)** (c163a86)
- **fix(cloudwatch): page FilterLogEvents forward with a usable nextToken (#2354)** (112602f)
- **fix(cloudformation): physically delete nested stacks and removed resources on update (#2345)** (291a974)
- **fix(core): extract shared pagination helper, reject maxResults=0 (#2343)** (25b46e2)
- **fix(compat): install AWS CLI v2 in the compat image so AWS_ENDPOINT_URL is honored (#2315)** (9fda5f5)
- **fix(ec2): sshd can only be started from an absolute path since OpenSSH v3.9 (#2351)** (c194bff)
- **fix(docker): label containers and volumes per emulator (#2341)** (d819c00)
- **fix(s3): enforce auth on object write paths when enforce-auth is enabled (#2326)** (16a8f04)
- **fix(lambda,iam): assume execution role for in-function SDK calls (#1909)** (573d4bd)
- **fix(lambda): give published versions their code location (#2012)** (42022fe)
- **fix(cognito): restore the SecureRandom import (#2337)** (7a2dc53)
- **fix(cognito): mark verified contact attribute on ConfirmSignUp (#1881)** (d891425)
- **fix(s3vectors): route ListVectors instead of falling through to S3 (#2285)** (6c4d63b)
- **fix(s3): route the accelerate subresource instead of falling through (#2330)** (833de25)
- **fix(elasticache): store the user Engine instead of hardcoding redis (#2331)** (7a4fc45)
- **fix(appconfig): accept top-level resource ARNs in TagResource/ListTagsForResource (#2279)** (0818e5e)
- **fix(iam,lambda): return resource tags in Get and Create responses (#2262)** (b71bfc4)
- **fix(cloudformation): don't double-encode string-form SNS RedrivePolicy and FilterPolicy (#2325)** (c12f3fa)
- **fix(apigateway): honor configured execute-api hostname (#2286)** (3cfa983)
- **fix(kinesis): reject records over the 1 MiB size limit (#1896)** (5afb60d)
- **fix(cloudformation): honor resource-level conditions (#2255)** (8ef71d6)
- **fix(s3): verify SigV4 signature on presigned URLs when enforce-auth is enabled (#1842)** (3fe836a)
- **fix(ec2): type a security group rule's tags as security-group-rule (#2272)** (4058dfa)
- **fix(cloudformation): expand AWS::Serverless::HttpApi via SAM transform (#2146)** (5812910)
- **fix(cloudformation): map FIFO and redrive attributes for AWS::SQS::Queue (#1939)** (58112b1)
- **fix(cloudformation): resolve ASG launch templates by id and MixedInstancesPolicy (#2005) (#2019)** (0971cf6)
- **fix(cloudformation): expand SAM AutoPublishAlias into Version + Alias (#1961)** (7d66bf0)
- **fix(cloudformation): infer Lambda FunctionName mode for pre-fix persisted stacks (#2177)** (0cbfba8)
- **fix(apigateway): fall back to REST API region scan for non-SigV4 Authorization headers (#2149)** (5156095)
- **fix(ec2): keep the source on security group rules (#2266)** (a6f5f12)
- **fix(cloudwatch): reject invalid log event tokens (#2249)** (12cf6e2)
- **fix(ec2): reject prefix list names AWS reserves for its own lists (#2274)** (2d003b5)
- **fix(test): pass the managed prefix list store in Ec2PublicIpOnLaunchTest (#2288)** (62ff490)
- **fix(ec2): assign a public IP only when the subnet opts in via MapPublicIpOnLaunch (#2023)** (2ab795c)
- **fix(s3): derive S3 host suffix matching from DNS config (#1843)** (188588b)
- **fix(ec2): start sshd even when run-instances omits a key pair (#2245)** (da5ff91)
- **fix(cloudwatch): return logStreamName on FilterLogEvents results (#2259)** (a0adea9)
- **fix(apigateway): apply MOCK integration response headers (#1822)** (a49c3e5)
- **perf(lambda): reuse a populated code volume across restarts via a completion marker (#1827)** (5d61e95)
- **fix(rds): preserve configured database images (#2035)** (9e7cdad)
- **fix(lambda): propagate image inspection failures (#2268)** (9ebf9fe)
- **fix(lambda): SIGTERM container before closing runtime API socket (#2098)** (b911ccd)
- **fix(stepfunctions): publish execution status after its terminal fields (#2234)** (4ba854a)
- **fix(docker): fall back to Windows named pipe when docker-host is at its unix-socket default (#2030)** (c48c062)
- **fix(stepfunctions): wrap optimized lambda:invoke result in the Invoke envelope (#2165)** (4581176)
- **fix(firehose): return Kinesis source in stream description (#2025)** (988696b)
- **fix(s3): preserve literal '+' in object keys and support encoding-type=url in list-objects (#1736)** (93b6f5e)
- **fix(ec2): delete key pairs by name through the storage backend (#2187)** (fc74987)
- **fix(cloudformation): pass the CloudFront service argument in the provisioner tests (#2261)** (6ca7d44)
- **fix(iam): seed the full AWS managed policy catalog (#2194)** (527615b)
- **fix(s3): isolate object byte storage between accounts (#2241)** (cdb2c36)
- **fix(lambda): scope resource-policy statements to the request Qualifier (#2129)** (ea74b97)
- **fix(s3vectors): return cosine distance from queries (#2175)** (2f5bc39)
- **fix(cloudformation): honor stack status filters (#2244)** (34c9c6c)
- **fix(cloudwatch): warn on unsupported Logs Insights filter operators (#2170)** (f1c8197)
- **fix(dynamodb): isolate item storage and locks between accounts (#2240)** (a803626)
- **fix(eventbridge): boolean/numeric pattern values are matched correctly (#1889)** (517094a)
- **fix(firehose): build S3 object keys with AWS prefix expressions and name suffix (#1858)** (a79e04e)
- **fix(rds): restore Terraform RDS and RabbitMQ compatibility (#1951)** (ea1231b)
- **fix(lambda): reconcile code volumes against real Docker state and clean up superseded ones (#2208)** (a5daab6)
- **fix(lambda): reassemble container log lines split across Docker frames (#1953)** (6344852)
- **fix(kms): reject mismatched keys in decryption requests (#1893)** (0cfffbe)
- **fix(s3): DeleteObjects honours empty key list (#2201)** (15d6ce8)
- **fix(rds): advertise reachable endpoints (#2074)** (f417164)
- **fix(apigatewayv2): encode binary Lambda request bodies (#2203)** (28e9f6e)
- **fix(cognito): reject invalid refresh tokens in InitiateAuth REFRESH_TOKEN_AUTH (#2132)** (3ce5041)
- **fix(apigateway): create the stage when CreateDeployment carries a stageName (#2130)** (f34e0b5)
- **fix(cloudformation): apply AssumeRolePolicyDocument when adopting an existing IAM role on update (#2143)** (4a5fae4)
- **fix(dynamodb): compare Value when legacy Expected supplies Exists (#2125)** (a2b20cc)
- **fix(elasticache): clean up container by id on readiness-timeout rollback (#2090)** (91b6a40)
- **fix(memorydb): clean up container by id on readiness-timeout rollback (#2092)** (11d5275)
- **fix(kinesis): resolve LATEST shard iterator position at GetShardIterator time (#1901)** (3b760bd)
- **fix(cognito): HMAC-sign refresh tokens to prevent forgery (#2139)** (c4f4181)
- **fix(cloudformation): create AWS::IAM::Role inline Policies instead of silently dropping them (#1969)** (8d2a5bd)
- **fix(lambda): disable HTTP/2 cleartext on the runtime API server (#2181)** (cb06a73)
- **fix(ses): pass the custom-verification-email store in the list-management test (#2182)** (396ef55)
- **fix(sqs): delayed FIFO message no longer blocks its message group (#2112)** (fa8f8d7)
- **fix(dynamodb): order Query by full composite sort key (#2114)** (cd3c6b5)
- **fix(rds): fault with DBInstanceNotFound/DBClusterNotFoundFault for missing identifiers in Describe* (#1740)** (02288ab)
- **fix(ecs): report service deployments and MISSING failures on DescribeServices (#2176)** (8b8f837)

### Tests
- **test(ses): guard LastKeyGenerationTimestamp fractional-epoch wire format (#2323)** (c745f82)
- **test(ec2): use storage factory in public IP regression (#2289)** (6b14999)
- **test(lambda): wait for the parked poll in the extension shutdown stop race (#2141)** (41d2a3c)

### Docs
- **docs: restore navigation for existing pages (#2252)** (0f888dc)
- **docs: add MAINTAINERS.md and route application code to the repo maintainers (#2320)** (9fccf7c)

### Chore
- **chore(release): 1.7.0** (75c8cfc)
- **chore(compat): align pinned SDK versions across the Python, Java, and CDK suites (#2253)** (ba84301)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/floci-io/floci?utm_source=github-action)._