Skip to content

Build(deps): Bump aws-lambda-powertools from 3.34.0 to 3.35.0 in /python in the python group - #22

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python/python-7f1766ca27
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python/python-7f1766ca27

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown

Bumps the python group in /python with 1 update: aws-lambda-powertools.

Updates aws-lambda-powertools from 3.34.0 to 3.35.0

Release notes

Sourced from aws-lambda-powertools's releases.

v3.35.0

Summary

This release includes an important security improvement for Data Masking and a significant cold start optimization for Parser.

We are happy to welcome six new contributors in this release: @​Adityaj0, @​manshahH, @​ErezMizrahi, @​wuodar, @​MohammedAlkindi, and @​TanbirRamim. Thank you for taking the time to report problems, work through reviews, and improve the prokject.

Data Masking now fails closed

Previously, an error while applying a masking rule could emit a warning and return the original value unchanged. Since callers received a normal return value, they could continue logging or storing data believing that masking had succeeded.

Data Masking now raises DataMaskingError when a masking provider fails, a masking path is invalid, or a regular expression cannot be compiled. Existing Data Masking exceptions now inherit from this common base exception.

from aws_lambda_powertools.utilities.data_masking import DataMasking
from aws_lambda_powertools.utilities.data_masking.exceptions import DataMaskingError
data_masker = DataMasking()
try:
masked = data_masker.erase(
{"customer": {"email": "customer@example.com"}},
masking_rules={"customer.email": {"regex_pattern": "[", "mask_format": "*"}},
)
except DataMaskingError:
# Stop processing the payload when masking cannot be completed.
raise

Missing fields continue to follow the existing raise_on_missing_field setting. With its default value, a missing field raises DataMaskingFieldNotFoundError; when explicitly disabled, Data Masking emits a warning and continues.

See #8446 for the complete change.

Faster Parser imports

Importing parse or event_parser previously loaded all 16 Parser envelope modules, even when the application did not use an envelope.

Envelopes and BaseEnvelope are now loaded only when first accessed. Existing public imports continue to work, so no application changes are required.

In the Lambda benchmark contributed in #8405, this reduced INIT_DURATION by approximately 900ms on arm64 with Python 3.13 and 1024MB of memory. The exact improvement depends on the function and packaging configuration.

Thank you @​ErezMizrahi for finding this and working through the compatibility details with us.

Changes

... (truncated)

Changelog

Sourced from aws-lambda-powertools's changelog.

[v3.35.0] - 2026-09-15

Maintenance

  • version bump
  • deps: bump valkey-glide from 2.5.1 to 2.5.2 (#8459)

Commits
  • 4770746 chore: version bump
  • d7d5168 chore(deps): bump valkey-glide from 2.5.1 to 2.5.2 (#8459)
  • 440e3ec chore(deps-dev): bump cdklabs-generative-ai-cdk-constructs from 0.1.318 to 0....
  • 226f384 chore(deps-dev): bump types-python-dateutil from 2.9.0.20260518 to 2.9.0.2026...
  • b712d3c chore(deps): bump aws-encryption-sdk from 4.0.6 to 4.0.7 (#8460)
  • a5b8045 chore(deps): bump avro from 1.12.1 to 1.12.2 (#8462)
  • 94b9d5e fix(metrics): stop spurious overwrite warnings from set_default_dimensions (#...
  • 14af77f chore(feature_flags): warn on empty schema and empty rules (#8430)
  • 362a797 fix(event_handler): match generic alias response models in OpenAPI schema (#8...
  • 237f4db fix(feature_flags): missing context key never satisfies a condition (#8429)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python group in /python with 1 update: [aws-lambda-powertools](https://github.com/aws-powertools/powertools-lambda-python).


Updates `aws-lambda-powertools` from 3.34.0 to 3.35.0
- [Release notes](https://github.com/aws-powertools/powertools-lambda-python/releases)
- [Changelog](https://github.com/aws-powertools/powertools-lambda-python/blob/develop/CHANGELOG.md)
- [Commits](aws-powertools/powertools-lambda-python@v3.34.0...v3.35.0)

---
updated-dependencies:
- dependency-name: aws-lambda-powertools
  dependency-version: 3.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: auto-approve, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from a team as a code owner September 18, 2026 13:06
@greptile-apps

greptile-apps Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

PR author is in the excluded authors list.

@silvexis silvexis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot upgrade (aws-lambda-powertools 3.34.0 → 3.35.0). Required CI green and branch up to date with base. Approving per Dependabot policy.

@dependabot @github

dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Author

Looks like aws-lambda-powertools is updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 25, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/python/python-7f1766ca27 branch September 25, 2026 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant