NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1030 most downloaded on PyPI
Infrastructure as code static analysis
Last release 2 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Most releases are documented
notes for 49 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
7 years old
3768 releases · first in 2019
arm: add CKV_AZURE_163 Enable vulnerability scanning for container images - #6339
One column per quarter.
Nothing published for this version
azure: drop support for dotnet v7.0 - #6383
Nothing published for this version
Nothing published for this version
arm: Add check for AzureML workspace not configured with private endpoint - #6387
azure: Add policy to ensure proper AzureML Workspace network access - #6362
Nothing published for this version
arm: AppServicePythonVersion - 82 check the 'python version' is the latest, if used to run the web app - #6282
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
terraform: Add provider address to resources - #6266
Nothing published for this version
Nothing published for this version
Nothing published for this version
sast: don't scan hidden files - #6349
terraform: Handle registry modules with a version in CKF_TF_2 - #6354
arm: Ensure Databricks Workspace data plane to control plane co… - #6319
arm: add AppServiceJavaVersion - #6258
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
secrets: entropy limit as env variable - #6332
Nothing published for this version
terraform: Remove invalid CIDRs in CKV2_AWS_44 - #6301
arm: add CKV_AZURE_73 to ensure that Automation account variables are encrypted - #6271
Nothing published for this version
terraform: handle module source tag ref when it is not the first parameter - #6314
sast: fix random test sast js - #6315
Nothing published for this version
sast: CDK TypeScript policies - #6161
secrets: bump bc-detect-secrets to 1.5.10 - #6297
general: Add deep-analysis to GHA - #6288
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
ansible: add missing arg to ansible runner - #6276
sast: Enable cdk ts integraion test - #6158
Nothing published for this version
github: add summary message in github_failed_only output - #6131
Nothing published for this version
Nothing published for this version
sast: add typescript - DONT MERGE - #6193
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
general: Update range includes to handle lists of ranges and lists of values - #6192
sast: TypeScript cdk policies p7 - #6186
bicep: Add bicep version of policy - #6191
sca: support licenses custom policies enforcement rules - #6173
sast: fix skipped_checks paths before upload to the platform - #6183
Nothing published for this version
sca: using the new api license/get-licenses-violations instead of packages/get-licenses-violations (which is deprecated) - #6174
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →