releases.sh

--ignore-protect flag for delete; invokes pending remote components resolved

v3.256.0

August 4, 2026PulumiView original ↗
3 features7 enhancements24 fixesThis release3 featuresNew capabilities7 enhancementsImprovements to existing features24 fixesBug fixesAI-tallied from the release notes
From the original release noteView original ↗

3.256.0 (2026-08-04)

Features

  • [cli] Add --ignore-protect flag to pulumi up, pulumi preview and pulumi destroy to allow deleting protected resources without unprotecting them in the state first #24053
  • [cli/env] Add an optional --export-env-vars flag to the env provider {aws,azure,gcp}-login commands to also set the standard SDK environment variables referencing the login outputs #24055
  • [cli] Add a --server flag to pulumi package add, publish, get-schema, get-mapping, gen-sdk, info and pulumi schema check that skips package resolution and uses the given URL as the plugin download URL #24107

Bug Fixes

  • [backend/service] Fix pulumi login --insecure not being reflected in the stack's service secrets manager state, which caused TLS verification failures against self-hosted backends using self-signed certificates #24134
  • [cli] Scope current stack selection to the active backend so switching backends no longer surfaces stale stack errors #23974
  • [programgen/go] Parent an invoke written inside a component to that component, lower a component's outputs, and only import fmt when a component needs it #24019
  • [programgen/python] Parent an invoke written inside a component to that component, so it resolves the component's providers #24018
  • [sdk/nodejs] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24042
  • [engine] Gate invokes on the created-ness of their declared dependencies, including the children of remote components, resolving them as unknown during previews that still have to create them #24040
  • [sdk/go] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24044
  • [pcl] Declare invoke dependencies to the engine so invokes that depend on pending resources, including remote components, resolve as unknown during previews #24041
  • [sdk/python] Defer output-form invokes that depend on a remote component whose resources are pending creation, by declaring invoke dependencies to the engine #24043
  • [cli/env] env provider no longer writes a new environment revision when the resulting definition is unchanged #24055
  • [sdk/go] Output-form invokes now infer their resource dependencies from their arguments, so they are skipped during preview while a dependent resource is pending creation and their results carry those dependencies #24054
  • [sdkgen/go] Fixes nested optional output conversions #24096
  • [engine] Fix a plugin process leak in NewPolicyAnalyzer when ConfigureStack fails after the plugin has booted #24106
  • [programgen/go] Avoid redundant applies when projecting properties from generated Go object outputs #24112
  • [backend/diy] Fix 403 errors writing to third-party S3-compatible backends (e.g. IBM COS, MinIO) by defaulting request_checksum_calculation to when_required when the s3:// backend URL sets a custom endpoint #24109
  • [programgen/nodejs] Avoid redundant applies when projecting properties from Node.js outputs #24119
  • [programgen/python] Avoid redundant applies when projecting properties from Python outputs #24120
  • [sdk] Fix apply erroring for skipped resources #24108
  • [cli] Retry rate-limited (HTTP 429) API requests when they are safe to retry, honoring the server's Retry-After header #24131
  • [cli] Exit non-zero from remote operations (pulumi up --remote, pulumi deployment run) when the deployment fails #24155
  • [cli/new] Resolve and install packages required by the program during pulumi new, as pulumi install does #24126
  • [cli] Make --remote not require a Pulumi.yaml file to be present #24128
  • [cli/import] Generate explicit providers in the import file resources #24135
  • [sdk/nodejs] Fix trustedDependencies parsing for bun #24145
  • [auto/go] ImportResources no longer leaks --stack into the converter's arguments when converter args are passed #24146
  • [auto/go] Fix ImportResources when GenerateCode(false) is set #24147
  • [sdk/go] Fix hooks and transforms causing panics with mocks #24161
  • [programgen/go] Fix plain invokes emitting nonexistent ...ArgsArgs argument types #24172

Improvements

  • [cli/import] Error when running pulumi import --from terraform in a Pulumi HCL project #23744
  • [programgen] Add ID type to PCL #22702
  • [engine] Give the resource monitor's Invoke its own response message, separating it from the one a provider returns #24100
  • [cli/do] Allow stateful resources to register their own provider resources based on provider inputs on the command line #24098
  • [cli] Refresh the first-login welcome message to link your Pulumi Cloud console and the Pulumi changelog #24122
  • [cli/do] Add support for the --provider argument for stateful operations #24132
  • [programgen/go] Better typing for maps, using known types rather than map[string]interface{} #24142
  • [cli/import] Serve the package-resolver service to state converters via resolver_target on ConvertStateRequest, so converters can resolve package specifications the same way the CLI does #24174

Miscellaneous

  • [cli] Retire the Pulumi AI mode of pulumi new (interactive choice and --ai/--language flags). The backing service has been shut down; use pulumi neo instead. #24116
  • [sdk/dotnet] Upgrade dotnet to v3.110.0 #24175
  • [yaml] Upgrade yaml to v1.38.1 #24175

Fetched August 4, 2026