Skip to content

chore: Update aws-encryption-sdk requirement from <4,>=3.1.1 to >=3.1.1,<5#37

Merged
Specter099 merged 1 commit intomainfrom
dependabot/pip/aws-encryption-sdk-gte-3.1.1-and-lt-5
Mar 25, 2026
Merged

chore: Update aws-encryption-sdk requirement from <4,>=3.1.1 to >=3.1.1,<5#37
Specter099 merged 1 commit intomainfrom
dependabot/pip/aws-encryption-sdk-gte-3.1.1-and-lt-5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 10, 2026

Updates the requirements on aws-encryption-sdk to permit the latest version.

Release notes

Sourced from aws-encryption-sdk's releases.

4.0.4 -- 2026-02-26

Maintenance

  • deps: Extend supported MPL_ versions to include v1.11.2 #788

    MPL v1.11.2 fixes de-serializing Error_OpaqueWithText and bumps cryptography upperbound to <47 due to CVE-2026-26007 (#1800)

NOTE

This library is NOT impacted by CVE-2026-26007. This library does not use SECT curves.

Changelog

Sourced from aws-encryption-sdk's changelog.

4.0.4 -- 2025-09-03

Maintenance

  • deps: Extend supported MPL_ versions to include v1.11.2 [#788](https://github.com/aws/aws-encryption-sdk-python/issues/788) <https://github.com/aws/aws-encryption-sdk-python/pull/788>_

    MPL v1.11.2 fixes de-serializing Error_OpaqueWithText

4.0.3 -- 2025-09-03

Maintenance

  • deps: Extend supported MPL_ versions to include v1.11.1 [#770](https://github.com/aws/aws-encryption-sdk-python/issues/770) <https://github.com/aws/aws-encryption-sdk-python/pull/770>_

    MPL v1.11.1 updates pytz version range to include 2025 releases.

4.0.2 -- 2025-06-30

Maintenance

  • deps: Extend supported MPL_ versions to include v1.11.0 [#763](https://github.com/aws/aws-encryption-sdk-python/issues/763) <https://github.com/aws/aws-encryption-sdk-python/pull/763>_

    MPL v1.11.0 contains performance improvements for the hierarchical keyring and extends the range of supported cryptography versions.

4.0.1 -- 2025-03-26

Fixes

  • fix: Improve header serialization [#747](https://github.com/aws/aws-encryption-sdk-python/issues/747) <https://github.com/aws/aws-encryption-sdk-python/pull/747>_

    ESDK-Python <4.0.1 would truncate non-ASCII key provider IDs it wrote to message headers. If a Raw or Custom MasterKeyProvider or Keyring supplied a non-ASCII key provider ID / key namespace, ESDK-Python would truncate the the key provider ID it wrote to the message's header. The message can be decrypted by replacing the truncated provider ID with the expected provider ID in decryption code. Contact AWS for any questions about this approach.

Maintenance

  • deps: Extend supported MPL_ versions to include v1.10.0

4.0.0 -- 2024-10-29

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added chore Maintenance tasks, CI, tooling dependencies Dependency updates labels Mar 10, 2026
@dependabot dependabot bot requested a review from Specter099 as a code owner March 10, 2026 03:15
@dependabot dependabot bot added chore Maintenance tasks, CI, tooling dependencies Dependency updates labels Mar 10, 2026
Updates the requirements on [aws-encryption-sdk](https://github.com/aws/aws-encryption-sdk-python) to permit the latest version.
- [Release notes](https://github.com/aws/aws-encryption-sdk-python/releases)
- [Changelog](https://github.com/aws/aws-encryption-sdk-python/blob/master/CHANGELOG.rst)
- [Commits](aws/aws-encryption-sdk-python@v3.1.1...v4.0.4)

---
updated-dependencies:
- dependency-name: aws-encryption-sdk
  dependency-version: 4.0.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/pip/aws-encryption-sdk-gte-3.1.1-and-lt-5 branch from b3ac2b7 to 89979d3 Compare March 25, 2026 13:08
@Specter099 Specter099 merged commit cc6d203 into main Mar 25, 2026
7 of 8 checks passed
@Specter099 Specter099 deleted the dependabot/pip/aws-encryption-sdk-gte-3.1.1-and-lt-5 branch March 25, 2026 14:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance tasks, CI, tooling dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant