aws-events v5.18.0 - Keep only Guardrails infrastructure rules and targets in the CMDB

Jul 23, 2026GuardrailsMods

What's new?

  • Record only Guardrails infrastructure rules and targets in the CMDB. AWS > Events > Rule > CMDB and AWS > Events > Target > CMDB now offer a new value, "Enforce: Enabled for Guardrails infrastructure only". When set, Guardrails records only the EventBridge rules and targets that make up its own infrastructure (the Event Handlers) and stops tracking every other rule and target in the account. The default ("Enforce: Enabled", record everything) is unchanged, so nothing changes unless you opt in.
  • Real-time event forwarding now respects your CMDB settings. AWS Events forwards events to the Guardrails Event Handlers only for resource types whose CMDB is enabled. Disabling CMDB for Rules, Targets, or Event Buses now also stops Guardrails from forwarding and processing those events, instead of forwarding every EventBridge API call regardless of policy.

Bug fixes

  • Fixed an issue where AWS > Events > Rule > Active could finish a run without reporting a result when an inactive rule still had dependent targets — leaving the control unsettled until the next change. The control now reports its state correctly and defers deleting the rule while it still has targets.

Policy Types

Added

  • AWS > Turbot > Event Handlers > Events > Rules > Custom Event Patterns > @turbot/aws-events

Removed

  • AWS > Turbot > Event Handlers > Events > Rules > Event Sources > @turbot/aws-events