Why is this needed?
We just bumped the minimum to >=3.3.1 to address CVE-2026-6550, but we still carry the full 3.x range. The 3.x line is in maintenance mode upstream and we'd rather simplify our dependency surface.
We are planning in 3 months (targeting August 2026) to drop support for 3.x entirely.
No Powertools utility will be affected by this change. However, if you bring Powertools alongside aws-encryption-sdk pinned to v3, you'll hit dependency resolution conflicts. If you're still on 3.x, please start planning your migration to 4.x.
Which area does this relate to?
Other
Solution
No response
Acknowledgment
Why is this needed?
We just bumped the minimum to
>=3.3.1to addressCVE-2026-6550, but we still carry the full 3.x range. The 3.x line is in maintenance mode upstream and we'd rather simplify our dependency surface.We are planning in 3 months (targeting August 2026) to drop support for 3.x entirely.
No Powertools utility will be affected by this change. However, if you bring Powertools alongside aws-encryption-sdk pinned to v3, you'll hit dependency resolution conflicts. If you're still on 3.x, please start planning your migration to 4.x.
Which area does this relate to?
Other
Solution
No response
Acknowledgment