NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1943 most downloaded on PyPI
Infrastructure as code static analysis
Last release 3 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Most releases are documented
notes for 49 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
7 years old
3768 releases · first in 2019
chore(deps): bump bc-detect-secrets from 1.5.50 to 1.5.52
chore(deps): bump bc-detect-secrets from 1.5.50 to 1.5.52
Picks up an accuracy fix in AzureStorageKeyDetector: the existing
Cosmos DB skip in integrity_regex was case-sensitive and missed
Pascal-case identifiers (e.g. CosmosDbConnectionString) as well as
bare documents.azure.com endpoints, causing Cosmos DB connection
strings to be reported as Azure Storage Account access keys.
Upstream fix: bridgecrewio/detect-secrets#299
Co-authored-by: mblonder mblonder@paloaltonetworks.com
terraform_json: handle HCL JSON array and single-dict block formats in parser - #7707
One column per quarter.
terraform_plan: skip resources being removed from state ('forget' action) - #7676
terraform: add CKV_AWS_394 for unconstrained aws_availability_zones data source - #7658
feat(terraform): add CKV_AWS_394 for unconstrained aws_availability_z…
feat(terraform): add CKV_AWS_394 for unconstrained aws_availability_z…
general: honour scope.provider for platform-downloaded custom po… - #7677
terraform: Added current Azure Terraform resources and taggable resources as of hashicorp/azurerm provider version 4.81 - #7652
sca: match CVE suppressions case-insensitively - #7659
fix(sca): match CVE suppressions case-insensitively
fix(sca): match CVE suppressions case-insensitively
chore(ci): pin pipenv on all python versions
chore(ci): pin pipenv and bump danger-check to node 20
kubernetes: Fix K8S suppressions annotations - #7651
sca: correct Windows path handling in image referencer - #7650
bump detect-secrets to 1.5.49
bump detect-secrets to 1.5.49
chore(deps): allow aiohttp 3.14.x
chore(deps): allow aiohttp 3.14.x
terraform: handle null container_properties in aws_batch_job_def… - #7636
kubernetes: CKV_K8S_40 should pass when hostUsers is false - #7580
general: fix github only output for sca - #7598
terraform: prevent crash in S3AllowsAnyPrincipal with unparsed v… - #7581
general: fix danger node version - #7589
change comment to trigger pipeline
change comment to trigger pipeline
attempt to fix node version
Co-authored-by: Max Amelchenko mamelchenko@paloaltonetworks.com
Nothing published for this version
terraform_plan: handle computed log_bucket in CKV_GCP_62 and CKV_GCP_63 - #7582
serverless: disable vars opt out - #7574
- no noteworthy changes
general: increase domain allow list as it blocks prisma release - #7567
general: verify ECDSA-P256 signatures on external custom checks before loading - #7556
terraform: add CKV_AWS_393 for GitHub OIDC trust on aws_iam_role - #7561
serverless: disable env/file variable resolution by default - #7554
terraform: include 90-day boundary in rotation check CKV_AWS_304 - #7544
secrets: report all multiline regex matches per file, not just first occurrence - FIX - #7540
secrets: Revert "fix(secrets): report all multiline regex matches per file, not just first occurrence" - #7537
helm: Accept helm version greater than v3 - #7399
terraform: fix wrong windows path - #7529
general: Revert Switch Terraform regex eval to RE2 for better performance - #7520
Nothing published for this version
general: Strip unnecessary control bytes from CLI code block - #7515
general: make version cache init lazy - #7509
Nothing published for this version
terraform: add aws:VpceAccount to recognized condition keys in check CKV_AWS_70 - #7514
Nothing published for this version
general: add domain allowlist validation for Prisma Cloud and Bridgecrew API URLs - #7496
Nothing published for this version
Nothing published for this version
Nothing published for this version
## Bug Fix - general: Log update - #7482
Nothing published for this version
general: Prevent run failure invalid policy - #7476
terraform: support modern TLS security policies in CKV_AWS_206 - #7466
Nothing published for this version
secrets: eliminate race condition in secrets scanner when running concurrently with other scanners - #7456
secrets: add _thread_safe_transient_settings( to secret runner - #7455
terraform: return inner module path when dest_dir already exists on Linux - #7436
bicep: revert bump pycep to support better bicep syntax - #7446
terraform: deprecate dotnet v6 and support v9 and v10 - #7442
Nothing published for this version
general: better shell commands - #7438
general: secret detection in build log files with line prefixes - #7431
cloudformation: render variables in cfn vertices config - #7423
general: Add BC_CA_BUNDLE environment variable support for custom CA certificates - #7419
Nothing published for this version
terraform: handle file path instead of directory - #7408
Your coding agent can read these notes before it upgrades. Set up the MCP server →