Know what changed,
before it breaks something.
What changed, what was pulled, and how far behind you are, for the packages in your own lock file.
PyPI / cryptography
50.0.0
SecurityA random key is now substituted on failure, as described in RFC 3218. Credit to @X1AOxiang for reporting the issue. CVE-2026-69247
Breaking→ 49.0.0
- BACKWARDS INCOMPATIBLE: Support for x86_64 macOS has been removed. We now only publish arm64 wheels for macOS.
Update→ 50.0.2
- Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
What you get
What moved in your dependencies, and what you should not be running.
One mail each morning.
Which packages you are behind on, and what changed in the versions in between.
The day a version you run is withdrawn, you know.
Including the dependencies you never installed by hand.
Breaking and security changes are marked.
Beside the sentence from the release notes that says so, never on a hunch.
No code leaves your machine.
Paste a lock file, drop it in, or push it from CI. Names and versions, nothing else.
Your team sees the same projects.
Alerts can go to Slack, Discord or your own endpoint.
And the plumbing.
9 lock and manifest formats, snapshot history and diffs, watching packages outside your projects, rules such as never shipping a withdrawn version, a daily, weekly or monthly digest, CSV and JSON export, an API, and an MCP server for your coding agent.
What we know about a package
Every package page is free, no account needed.
Last release 4 months ago
14 May 2026
Release timing varies
gaps range from 8 days to 13 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
What goes into a digest
The daily digest is this, filtered to your lock file and led by withdrawn versions.
- Deprecated
starlette→ 1.7.0
Warning OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.
- Deprecated
multidict→ 6.9.1
Replaced deprecated instrumentation codspeed mode with simulation -- by :user: asvetlov
- Deprecated
cachetools→ 7.2.0
Deprecate use of cache=None to suppress caching with the @cached decorator.
- Update
zipp→ 4.1.1
Correct ! negation and literal ^ characters in character classes in Path.glob and Path.rglob, without matching path separators.
Explore the archive
All ecosystems →Python
See all →- boto3The AWS SDK for Python (Boto3)2.5Bdownloads/mo
- packagingCore utilities for Python packages1.6Bdownloads/mo
- typing-extensionsBackported and Experimental Type Hints for Python 3.9+1.4Bdownloads/mo
- idnaInternationalized Domain Names in Applications (IDNA)1.3Bdownloads/mo
- urllib3HTTP library with thread-safe connection pooling, file post, and more.1.3Bdownloads/mo
JavaScript
See all →- semverThe semantic version parser used by npm.3.6Bdownloads/mo
- minimatcha glob matcher in javascript3.0Bdownloads/mo
- debugLightweight debugging utility for Node.js and the browser3.0Bdownloads/mo
- ansi-stylesANSI escape codes for styling strings in the terminal2.9Bdownloads/mo
- brace-expansionBrace expansion as known from sh/bash2.5Bdownloads/mo
Java
See all →- org.springframework.boot:spring-bootSpring Boot#1by stars
- org.springframework.boot:spring-boot-autoconfigureSpring Boot AutoConfigure#2by stars
- org.springframework.boot:spring-boot-starterCore starter, including auto-configuration support, logging and YAML#3by stars
- org.springframework.boot:spring-boot-starter-loggingStarter for logging default logging#4by stars
- org.springframework.boot:spring-boot-starter-validationStarter for using Java Bean Validation with Hibernate Validator#5by stars
- github.com/ollama/ollama#1by stars
- github.com/kubernetes/kubernetes#2by stars
- github.com/fatedier/frp#3by stars
- github.com/JuliusBrussee/caveman#4by stars
- github.com/infiniflow/ragflow#5by stars
.NET
See all →- Newtonsoft.JsonJson.NET is a popular high-performance JSON framework for .NET9.3Bdownloads/mo
- Microsoft.Extensions.DependencyInjectionDefault implementation of dependency injection for Microsoft.Extensions.DependencyInjection.8.0Bdownloads/mo
- Microsoft.Extensions.LoggingLogging infrastructure default implementation for Microsoft.Extensions.Logging.7.9Bdownloads/mo
- System.Text.JsonProvides high-performance and low-allocating types that serialize objects to JavaScript Object Notation (JSON) text and deserialize JSON text to objects, with UTF-8 support built-in. Also provides types to read and write JSON text encoded as UTF-8, and to create an in-memory document object model (DOM), that is read-only, for random access of the JSON elements within a structured view of the data. The System.Text.Json library is built-in as part of the shared framework in .NET Runtime. The package can be installed when you need to use it in other target frameworks.6.4Bdownloads/mo
- Microsoft.Bcl.AsyncInterfacesProvides the IAsyncEnumerable<T> and IAsyncDisposable interfaces and helper types for .NET Standard 2.0. This package is not required starting with .NET Standard 2.1 and .NET Core 3.0.4.8Bdownloads/mo
Rust
See all →- hashbrownA Rust port of Google's SwissTable hash map2.6Bdownloads/mo
- synParser for Rust source code2.6Bdownloads/mo
- getrandomA small cross-platform library for retrieving random data from system source2.2Bdownloads/mo
- bitflagsA macro to generate structures which behave like bitflags.2.0Bdownloads/mo
- rand_coreCore random number generator traits and tools for implementation.1.8Bdownloads/mo
PHP
See all →- symfony/deprecation-contractsA generic function and convention to trigger deprecation notices1.0Bdownloads/mo
- symfony/polyfill-mbstringSymfony polyfill for the Mbstring extension1.3Bdownloads/mo
- psr/logCommon interface for logging libraries1.3Bdownloads/mo
- symfony/consoleEases the creation of beautiful and testable command line interfaces1.2Bdownloads/mo
- psr/http-messageCommon interface for HTTP messages1.2Bdownloads/mo
Dart
See all →- analyzerThis package provides a library that performs static analysis of Dart code.19Mdownloads/mo
- _fe_analyzer_sharedLogic that is shared between the front_end and analyzer packages.19Mdownloads/mo
- vm_serviceA library to communicate with a service implementing the Dart VM service protocol.18Mdownloads/mo
- yamlA parser for YAML, a human-friendly data serialization standard17Mdownloads/mo
- metaAnnotations used to express developer intentions that can't otherwise be deduced by statically analyzing source code.16Mdownloads/mo
Your coding agent reads the notes first
Claude Code, Cursor and any other MCP client get the archive as tools. Before an upgrade, the agent reads what changed between the version you run and the one it is about to install, withdrawn releases included. Package questions need no account; your own projects need an API key.
curl -fsSL https://packagetrack.dev/install.sh | shclaude mcp add -s user packagetrackdev -- packagetrackdev-mcpCursor and Windsurf: add packagetrackdev-mcp under mcpServers. VS Code: under servers.
- 1
Connected?
In Claude Code, type
/mcpand pickpackagetrackdev. It reads connected, with five tools. Cursor and VS Code list it in their MCP settings. - 2
Ask it something
No account needed. The agent answers with what the maintainers wrote, not from memory.
Upgrade httpx to the newest release and tell me what changed since 0.24.1 - 3
Make it a habit
One line in your
CLAUDE.mdor.cursorrulesand the agent reads the notes before every upgrade.Before upgrading a dependency, call packagetrack's package_changes with the installed and target versions.
Nothing about your code leaves your machine: no code, no file paths, no repository name. A tool call carries a package name and version strings. Your own projects need an API key.
Track your own projects
Paste a lock file or push one from the CLI. The digest and the alerts follow.
Create an account