Security fix: ambient credentials no longer leaked to Mantle. Bedrock users should update immediately.
anthropic-sdk-typescript: bedrock-sdk v0.33.2 security patch released
Original: anthropics/anthropic-sdk-typescript: bedrock-sdk: v0.33.2
Importance: 認証情報漏洩の可能性を持つセキュリティバグの修正で、既存ユーザーに即影響
Summary
Anthropic's TypeScript SDK bedrock-sdk updated to v0.33.2 with a critical security fix. The patch prevents ambient first-party credentials from being sent to the Mantle endpoint, reducing risk of credential leakage. This is a recommended update for developers using AWS Bedrock integration.
Key Points
- Blocks credential transmission to Mantle endpoint
- Eliminates auth leakage risk for AWS Bedrock users
- Prevented unintended environment variable exposure
View developer notes (APIs, breaking changes, migration)
bedrock-sdk v0.33.2 addresses issue #357 by preventing ambient first-party credentials from being transmitted to the Mantle endpoint. The fix ensures environment-based credentials (IAM roles, AWS_ACCESS_KEY_ID, etc.) are not automatically included in requests. Developers using AWS Bedrock with TypeScript/Node.js are urged to update immediately. Breaking change: prior versions inadvertently exposed credentials.
Source: https://github.com/anthropics/anthropic-sdk-typescript/releases/tag/bedrock-sdk-v0.33.2
Outlet: SDK (anthropic-sdk-typescript)
This article is an AI-generated summary (OpenAI GPT-4o-mini) of publicly available information from Anthropic, OpenAI, Google, Meta, Mistral, DeepSeek, Sakana, and other vendors. The original source URL is always provided in accordance with fair-use citation requirements. Summaries are AI-generated and may contain mistranslations or misinterpretations. Always verify details with the original source.