What and why to refactor
backend/plugins/kiro is the only consumer of github.com/aws/aws-sdk-go
(v1). The AWS SDK for Go v1 reached
end-of-support on 2025-07-31;
it no longer receives bug or security fixes. Its final release, v1.55.8, marks
every package as deprecated, so staticcheck reports SA1019 for each import:
plugins/kiro/api/test_connection.go:24-25 aws, service/s3
plugins/kiro/tasks/identity_client.go:21-24 aws, aws/credentials, aws/session, service/identitystore
plugins/kiro/tasks/s3_client.go:25-28 aws, aws/credentials, aws/session, service/s3
plugins/kiro/tasks/s3_file_collector.go:24-25 aws, service/s3
This is what turned the lint job red on the Dependabot group #9192. It is
tolerated for now by a narrowly scoped lint exclusion (see the linked PR), but
that only hides the debt.
Describe the solution you'd like
Move the plugin to aws-sdk-go-v2:
aws/session + aws/credentials → config.LoadDefaultConfig(ctx, config.WithRegion(…), config.WithCredentialsProvider(credentials.NewStaticCredentialsProvider(…)))
service/s3 → github.com/aws/aws-sdk-go-v2/service/s3 (ListObjectsV2,
GetObject, …; request/response types move to s3/types, calls take a
context.Context)
service/identitystore → github.com/aws/aws-sdk-go-v2/service/identitystore
- adapt the test doubles in
tasks/s3_client_test.go,
tasks/s3_file_collector_test.go and tasks/discovery_test.go to the v2
client interfaces
- afterwards: drop
github.com/aws/aws-sdk-go from backend/go.mod and remove
the temporary exclusion from backend/.golangci.yaml
The new modules are Apache-2.0 licensed. Dependabot's existing
go-minor-patch group (patterns: ["*"]) already bundles the many v2
sub-modules, so no extra configuration is needed.
@warren830 — you authored the kiro plugin (#9073, #9076, #9082). Would you be
willing to take this on, or review a migration PR? The plugin talks to real
S3 buckets and IAM Identity Center, which I can't test without a Kiro/AWS
setup, so a run against a real environment by someone who has one would be
essential.
Related issues
Additional context
The plugin's unit tests (api, impl, models, tasks) pass with
v1.55.8 from #9192, so this is not urgent breakage — it is about not staying
on an unsupported SDK.
What and why to refactor
backend/plugins/kirois the only consumer ofgithub.com/aws/aws-sdk-go(v1). The AWS SDK for Go v1 reached
end-of-support on 2025-07-31;
it no longer receives bug or security fixes. Its final release, v1.55.8, marks
every package as deprecated, so
staticcheckreportsSA1019for each import:This is what turned the
lintjob red on the Dependabot group #9192. It istolerated for now by a narrowly scoped lint exclusion (see the linked PR), but
that only hides the debt.
Describe the solution you'd like
Move the plugin to aws-sdk-go-v2:
aws/session+aws/credentials→config.LoadDefaultConfig(ctx, config.WithRegion(…), config.WithCredentialsProvider(credentials.NewStaticCredentialsProvider(…)))service/s3→github.com/aws/aws-sdk-go-v2/service/s3(ListObjectsV2,GetObject, …; request/response types move tos3/types, calls take acontext.Context)service/identitystore→github.com/aws/aws-sdk-go-v2/service/identitystoretasks/s3_client_test.go,tasks/s3_file_collector_test.goandtasks/discovery_test.goto the v2client interfaces
github.com/aws/aws-sdk-gofrombackend/go.modand removethe temporary exclusion from
backend/.golangci.yamlThe new modules are Apache-2.0 licensed. Dependabot's existing
go-minor-patchgroup (patterns: ["*"]) already bundles the many v2sub-modules, so no extra configuration is needed.
@warren830 — you authored the kiro plugin (#9073, #9076, #9082). Would you be
willing to take this on, or review a migration PR? The plugin talks to real
S3 buckets and IAM Identity Center, which I can't test without a Kiro/AWS
setup, so a run against a real environment by someone who has one would be
essential.
Related issues
go-minor-patchgroup, red because ofSA1019)Additional context
The plugin's unit tests (
api,impl,models,tasks) pass withv1.55.8 from #9192, so this is not urgent breakage — it is about not staying
on an unsupported SDK.