NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2128 most downloaded on PyPI
AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized HTML report
Last release 3 months ago
14 Jun 2026
Release timing varies
gaps range from 1 weeks to 1.1 years
Most releases are documented
notes for 45 of 53 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
53 releases · first in 2020
One column per quarter.
Remove stale triage CSV worksheet references from the report (+ refresh demo report) @kmcquade
<details> <summary>4 changes</summary>
feat: detect + link pathfinding.cloud privilege-escalation paths (37 new detections) @kmcquade
<details> <summary>67 changes</summary>
add Python 3.14 support @gruebel
Bump actions/checkout from 4.2.2 to 5.0.0 @[dependabot[bot]]
drop Python 3.8 support @gruebel
update JS dependencies @gruebel
update deps and upper bound policy\_sentry @gruebel
Revert "[SCM ADMIN] Adding/Updating GUS aware code owners info @W-13958158" @svc-scm
update GHA workflows and add python version test jobs @gruebel
--flag-all-risky-actions flag is included @jacobappleton-orbis (#303)Nothing published for this version
More gamelift cred vending actions @iann0036
Optionally allow noisy results to flag risky actions regardless of resource constraints or conditions usage @kmcquade
Update security.yml to non-vulnerable GitHub actions version @kmcquade
AWS_DEFAULT_PROFILE is respected; Path fixes @kmcquade
AWS_DEFAULT_PROFILE is respected; Path fixes @kmcquade (#239)Fix some dependency issues @kmcquade
Future proof some unit tests that were failing @kmcquade
## Changes - Fix homebrew scripts @kmcquade (#218) - Fix typo
Add type hints to shared and output @gruebel
Updated report before 0.4.3 release @kmcquade
Add version bump automation @kmcquade
Avoid Flagging If Deny On Scan Actions Without Constraints @njgibbon
Scan Multiple AWS accounts via AssumeRole @kmcquade
Filter deny from unrestricted actions @schosterbarak
Update Credentials Exposure actions, dependencies @kmcquade
Statement scanning performance improvements @verkaufer
Add GitHub workflow to combine Dependabot PRs into a single one @kmcquade
Add release drafter GitHub Action @kmcquade
Credentials Exposure as a new finding
#99)#82)scan command now has a --minimize option, which you can use to reduce your report size. The example report size was reduced from 3.9MB (ouch!) to 212KB. (Fixes #125)Excluded actions no longer show up in results (Fixes #106)
Fixes issue where Inline Policies were showing up as findings even when they were attached to excluded IAM principals. Fixes #104
Summary page: new Bar chart to summarize results
scan-policy-file command now returns findings about Service Wildcard (#82)scan-policy-file command now returns findings about Credentials Exposure (#99).scan command for this release (the HTML Report)UI: The Exclusions configuration was not showing up in the report due to a typo
--input flag to --input-file for all commandsUI: Fixed an issue where the Remediation guidance was not showing up in the resulting report. Fixes #70
Definitions for Risk types are now available via Popovers. Fixes #66
See the updated example report: https://opensource.salesforce.com/cloudsplaining/
Made callable via script to partially fix #39
Nothing published for this version
* Excel/CSV export capability * Table row selection capability
Nothing published for this version
Bugfix: issue where "Data Exfiltration" count was showing up in the "Resource Exposure" count column in the IAM Principals tab
Exclusions fixes: Fixed issue where exclusions file was including dangling policies in the results (Fixes #33)
Fixed issue where Data Exposure tallies were missing in AWS Managed Table
Nothing published for this version
Nothing published for this version
Nothing published for this version
Removed the recursive download method
HTML report now always shows Trust Policies for Roles, even if they do not allow assumption from a Compute Service. This can help assessors with triag
HTML report now always shows Trust Policies for Roles, even if they do not allow assumption from a Compute Service. This can help assessors with triaging and pentesters for targeting. Fixes #15
Migrated to GitHub actions. Have to trigger a new release in order to get this working.
Migrated to GitHub actions. Have to trigger a new release in order to get this working.
Added separate tab for IAM Principals
Added recursive scanning option - and fixed exclude-actions
Added recursive scanning option - and fixed exclude-actions
Nothing published for this version
Provide option to skip opening HTML report (--skip-open-report) Provide report indicator on whether it is assumable by compute services HTML report tw
Provide option to skip opening HTML report (--skip-open-report) Provide report indicator on whether it is assumable by compute services HTML report tweaks
Open-sourced. Also fixed markdown bug
Open-sourced. Also fixed markdown bug
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →