NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →

PackageTrack

Know what changed,
before it breaks something.

What changed, what was pulled, and how far behind you are, for the packages in your own lock file.

PyPI / cryptography

50.0.0

SecurityA random key is now substituted on failure, as described in RFC 3218. Credit to @X1AOxiang for reporting the issue. CVE-2026-69247

  • Breaking→ 49.0.0

    - BACKWARDS INCOMPATIBLE: Support for x86_64 macOS has been removed. We now only publish arm64 wheels for macOS.

  • Update→ 50.0.2

    - Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.

See the package page →

What you get

What moved in your dependencies, and what you should not be running.

  • One mail each morning.

    Which packages you are behind on, and what changed in the versions in between.

  • The day a version you run is withdrawn, you know.

    Including the dependencies you never installed by hand.

  • Breaking and security changes are marked.

    Beside the sentence from the release notes that says so, never on a hunch.

  • No code leaves your machine.

    Paste a lock file, drop it in, or push it from CI. Names and versions, nothing else.

  • Your team sees the same projects.

    Alerts can go to Slack, Discord or your own endpoint.

  • And the plumbing.

    9 lock and manifest formats, snapshot history and diffs, watching packages outside your projects, rules such as never shipping a withdrawn version, a daily, weekly or monthly digest, CSV and JSON export, an API, and an MCP server for your coding agent.

What we know about a package

Every package page is free, no account needed.

PyPIrequests2.34.2163 releases since 2011
  • Last release 4 months ago

    14 May 2026

  • Release timing varies

    gaps range from 8 days to 13 months

  • Nearly every release is documented

    notes for 60 of the last 60 stable releases

  • 2 versions withdrawn

    withdrawn after publishing

What goes into a digest

The daily digest is this, filtered to your lock file and led by withdrawn versions.

  • Deprecated

    starlette→ 1.7.0

    Warning OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

  • Deprecated

    multidict→ 6.9.1

    Replaced deprecated instrumentation codspeed mode with simulation -- by :user: asvetlov

  • Deprecated

    cachetools→ 7.2.0

    Deprecate use of cache=None to suppress caching with the @cached decorator.

  • Update

    zipp→ 4.1.1

    Correct ! negation and literal ^ characters in character classes in Path.glob and Path.rglob, without matching path separators.

Explore the archive

All ecosystems →
  1. boto32.5Bdownloads/mo
  2. packaging1.6Bdownloads/mo
  3. typing-extensions1.4Bdownloads/mo
  4. idna1.3Bdownloads/mo
  5. urllib31.3Bdownloads/mo

JavaScript

See all →
  1. semver3.6Bdownloads/mo
  2. minimatch3.0Bdownloads/mo
  3. debug3.0Bdownloads/mo
  4. ansi-styles2.9Bdownloads/mo
  5. brace-expansion2.5Bdownloads/mo
  1. org.springframework.boot:spring-boot#1by stars
  2. org.springframework.boot:spring-boot-autoconfigure#2by stars
  3. org.springframework.boot:spring-boot-starter#3by stars
  4. org.springframework.boot:spring-boot-starter-logging#4by stars
  5. org.springframework.boot:spring-boot-starter-validation#5by stars
  1. Newtonsoft.Json9.3Bdownloads/mo
  2. Microsoft.Extensions.DependencyInjection8.0Bdownloads/mo
  3. Microsoft.Extensions.Logging7.9Bdownloads/mo
  4. System.Text.Json6.4Bdownloads/mo
  5. Microsoft.Bcl.AsyncInterfaces4.8Bdownloads/mo
  1. hashbrown2.6Bdownloads/mo
  2. syn2.6Bdownloads/mo
  3. getrandom2.2Bdownloads/mo
  4. bitflags2.0Bdownloads/mo
  5. rand_core1.8Bdownloads/mo
  1. symfony/deprecation-contracts1.0Bdownloads/mo
  2. symfony/polyfill-mbstring1.3Bdownloads/mo
  3. psr/log1.3Bdownloads/mo
  4. symfony/console1.2Bdownloads/mo
  5. psr/http-message1.2Bdownloads/mo
  1. analyzer19Mdownloads/mo
  2. _fe_analyzer_shared19Mdownloads/mo
  3. vm_service18Mdownloads/mo
  4. yaml17Mdownloads/mo
  5. meta16Mdownloads/mo

Your coding agent reads the notes first

Claude Code, Cursor and any other MCP client get the archive as tools. Before an upgrade, the agent reads what changed between the version you run and the one it is about to install, withdrawn releases included. Package questions need no account; your own projects need an API key.

curl -fsSL https://packagetrack.dev/install.sh | sh
claude mcp add -s user packagetrackdev -- packagetrackdev-mcp

Cursor and Windsurf: add packagetrackdev-mcp under mcpServers. VS Code: under servers.

  1. 1

    Connected?

    In Claude Code, type /mcp and pick packagetrackdev. It reads connected, with five tools. Cursor and VS Code list it in their MCP settings.

  2. 2

    Ask it something

    No account needed. The agent answers with what the maintainers wrote, not from memory.

    Upgrade httpx to the newest release and tell me what changed since 0.24.1
  3. 3

    Make it a habit

    One line in your CLAUDE.md or .cursorrules and the agent reads the notes before every upgrade.

    Before upgrading a dependency, call packagetrack's package_changes with the installed and target versions.

Nothing about your code leaves your machine: no code, no file paths, no repository name. A tool call carries a package name and version strings. Your own projects need an API key.

Track your own projects

Paste a lock file or push one from the CLI. The digest and the alerts follow.

Create an account