{"package":"aws-encryption-sdk","ecosystem":"conda","latest_version":"3.1.1","description":"AWS Encryption SDK implementation for Python","license":"Apache-2.0","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://github.com/aws/aws-encryption-sdk-python","repository":"","downloads_weekly":76,"health":{"score":39,"risk":"critical","breakdown":{"maintenance":5,"popularity":0,"security":23,"maturity":9,"community":2},"deprecated":false,"max_score":100},"vulnerabilities":{"count":1,"critical":0,"high":0,"medium":1,"low":0,"details":[{"vuln_id":"CVE-2026-6550","severity":"medium","summary":"AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache","affected_versions":">=2.0.0,<3.3.1|>=4.0.0,<4.0.5|=2.0.0|=2.1.0|=2.2.0|=2.3.0|=2.4.0|=2.5.0|=2.5.1|=3.0.0|=3.1.0|=3.1.1|=3.2.0|=3.3.0|=4.0.0|=4.0.1|=4.0.2|=4.0.3|=4.0.4","fixed_version":"4.0.5","source":"osv","published_at":"2026-04-24T15:59:17Z","in_kev":false,"epss_prob":0.00011,"epss_percentile":0.01279,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"3.1.1","total_count":1,"recent":["3.1.1"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":1,"first_published":"2023-03-20 20:11:07.580000+00:00","last_published":"2025-04-22 14:58:37.273000+00:00","dependencies_count":0,"dependencies":[]},"github_stats":null,"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"use_with_caution","issues":["Low health score (39/100)"],"use_version":"3.1.1","version_hint":"Update to >= 4.0.5 to fix known vulnerabilities","summary":"aws-encryption-sdk@3.1.1 low health (39/100) — consider alternatives"},"version_scoped":null,"requested_version":null,"_cache":"hit","_response_ms":0,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":false},"version_history_summary":{"total_versions":1,"first_release_age_days":1136,"last_release_days_ago":372,"avg_days_between_releases":null,"release_velocity":"stale"},"popularity_warning":{"this_ecosystem_downloads":76,"more_popular_in":{"ecosystem":"pypi","downloads_weekly":718460},"hint":"This is the conda package 'aws-encryption-sdk' (76 dl/week). A much more popular package with the same name exists in pypi (718,460 dl/week). Confirm you queried the right ecosystem."}}