Maintenance: end of support for aws-encryption-sdk 3.x
envgap__aws-powertools__powertools-lambda-python-8190
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
5bc8d00eeeaf5fac4627ccd1f8f22fb5374e0989- Manifest
pyproject.toml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
aws-powertools/powertools-lambda-python #8190 · read the original issue
### Why is this needed? We just bumped the minimum to `>=3.3.1 `to address `CVE-2026-6550`, but we still carry the full 3.x range. The 3.x line is in maintenance mode upstream and we'd rather simplify our dependency surface. We are planning in 3 months (targeting August 2026) to drop support for 3.x entirely. No Powertools utility will be affected by this change. However, if you bring Powertools alongside aws-encryption-sdk pinned to v3, you'll hit dependency resolution conflicts. If you're still on 3.x, please start planning your migration to 4.x. ### Which area does this relate to? Other ### Solution _No response_ ### Acknowledgment - [x] This request meets [Powertools for AWS Lambda (Python) Tenets](https://docs.powertools.aws.dev/lambda/python/latest/#tenets) - [ ] Should this be considered in other Powertools for AWS Lambda languages? i.e. [Java](https://github.com/aws-powertools/powertools-lambda-java/), [TypeScript](https://github.com/aws-powertools/powertools-lambda-typescript/), and [.NET](https://github.com/aws-powertools/powertools-lambda-dotnet/)
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]