NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1425 most downloaded on PyPI
A command-line utility that creates projects from project templates, e.g. creating a Python package project from a Python package project template.
Last release 7 months ago
04 Mar 2026
Release timing varies
gaps range from 4 weeks to 2.2 years
Most releases are documented
notes for 30 of 42 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
42 releases · first in 2013
You know that thing where you release an album, it's on the shelves, people are buying it, and then someone points out the spine says it's your previo
You know that thing where you release an album, it's on the shelves, people are buying it, and then someone points out the spine says it's your previous album? That's what happened with Cookiecutter 2.7.0. We put out the long-awaited release with 27 improvements and 17 contributors, and cookiecutter -V proudly announced: 2.6.0.
$ cookiecutter -V
Cookiecutter 2.6.0
$ # narrator voice: it was not 2.6.0
Go on, run this and see for yourself that the 2.7.1 release knows its own version number now:
uv tool upgrade cookiecutter
cookiecutter -V now reports the real version. Rather than patch VERSION.txt, this release removes it entirely. The version is now read from package metadata at runtime, so pyproject.toml is the single source of truth and there's nothing left to drift. Thanks @bollwyvl for the bug report PR and for suggesting the importlib.metadata approach, and thanks @tranzystorekk for filing #2195!
CI runs each Python version as its own job. Tests for 3.10 through 3.14 used to run sequentially inside a single job per OS, which pushed Windows past 30 minutes. Each version now runs in parallel with a 15-minute timeout. Windows tests focus on the boundary versions (3.10 and 3.14) since intermediate versions add little signal beyond Ubuntu and macOS.
@audreyfeldroy (Audrey M. Roy Greenfeld) and @pydanny (Daniel Roy Greenfeld) built this release, with help from Claude roleplaying as David Bowie.
Thanks to @bollwyvl (Nicholas Bollweg) for the version fix PR and the importlib.metadata suggestion, and @tranzystorekk for reporting the version mismatch.
One column per quarter.
The new SECURITY.md lays out the trust model: what Cookiecutter sandboxes (nothing), what's in scope for vulnerability reports, and how to report them…
Cookiecutter 2.7.0 is tested on Python 3.10 through 3.14, ships with a security policy documenting the trust model for template hook scripts, and publishes to PyPI with cryptographic provenance so you can verify every release. Seventeen contributors from the community helped build it.
uv tool upgrade cookiecutter
A security policy that explains what you're trusting. Cookiecutter templates can run arbitrary code through hook scripts, and that's by design. The new SECURITY.md lays out the trust model: what Cookiecutter sandboxes (nothing), what's in scope for vulnerability reports, and how to report them privately through GitHub. If you maintain templates or run unfamiliar ones, this is worth reading.
Python 3.10 through 3.14. Full test coverage across five Python versions. If you're on 3.7, 3.8, or 3.9, this is the release where you'll want to upgrade.
Pretty-printed JSON in templates. The jsonify Jinja2 extension takes an indent argument, so you can generate formatted JSON in your templates instead of single-line blobs. Thanks @pabloxio! (#2050)
Boolean variables from the command line. Pass use_docker=y via --no-input and it arrives as a proper boolean in your template context. Thanks @tylermilner! (#2029)
Structured bug reports. The GitHub issue form collects environment details upfront, so maintainers can reproduce your issue faster.
Tutorial videos and slides. Conference talk recordings and slide decks linked from the docs. Thanks @datasharp! (#2137)
Verified PyPI releases. Every release is published via OpenID Connect (no stored API tokens) with SLSA provenance attestations. You can cryptographically verify that the package you installed was built from this repository's CI.
Same results on every OS. Template generation produces deterministic directory ordering regardless of platform. No more platform-specific file conflict surprises. Thanks @RaulWCosta! (#2099)
Zip-based templates release file handles immediately. No more locked-file issues on Windows when using cached zip templates. Thanks @mohiuddin-khan-shiam! (#2147)
Type-checked top to bottom. mypy coverage spans the entire codebase, with type hints added module by module. Thanks @danieleades for the massive effort! (#2015, #2041, #2042, #2051, #2053–#2056, #2059, #2060)
Ruff everywhere. Linting and formatting moved from flake8/isort/black to Ruff, with expanded rule groups covering pyflakes, pygrep, perf, and string formatting. Thanks @danieleades! (#2012, #2014, #2016, #2019, #2020, #2061)
Modern packaging. Config lives in pyproject.toml, with separated dependency groups for lint and test. Thanks @jensens! (#2040)
Clearer installation docs. The README includes pipx as an alternative, and the programmatic usage example is corrected. Thanks @swikrityy-yy and @christine-ho-dev! (#2165, #2122)
Empty lists in cookiecutter.json raise a clear error. A template with [] as a default value gets a helpful ValueError instead of a confusing IndexError. Thanks @meganlkm! (#2171)
Directory names that render to empty strings. Handled gracefully instead of failing silently. Thanks @DanielZhangD! (#1991)
The safety vulnerability scanner in the lint dependency group pulls in its own tree of transitive dependencies. These packages are never installed by pip install cookiecutter or uv tool install cookiecutter. We updated the lockfile to resolve 8 CVEs across nltk, urllib3, cryptography, authlib, filelock, and marshmallow (CVE-2025-14009, CVE-2026-21441, CVE-2026-26007, and 5 others).
No Cookiecutter user was exposed to these vulnerabilities.
@audreyfeldroy (Audrey M. Roy Greenfeld) designed and built this release: the security policy, Python 3.14 support, dependency hardening, bug report form, and packaging modernization.
@pydanny (Daniel Roy Greenfeld) modernized the CI/CD workflow, migrated docs to justfile, and updated Python version support.
Thanks to:
jsonify indent parameterSupport Python 3.12 ( #1989 ) @ericof
@alanverresen, @dependabot, @dependabot[bot], @ericof, @jensens, @kurtmckee, @pre-commit-ci, @pre-commit-ci[bot] and @sacha-c
Default values can be passed as a dict ( #1924 ) @matveyvarg
@HarshRanaOC, @aantoin, @david-abn, @dependabot, @dependabot[bot], @ericof, @matveyvarg, @padraic-padraic, @pkrueger-cariad, @pre-commit-ci, @pre-commit-ci[bot], @staeff and @zahidkizmaz
Gracefully handle files with mixed lined endings ( #1942 ) @EricHripko
@EricHripko, @david-abn and @ericof
add checkout details to the context (fixes #1759 ) ( #1923 ) @JonZeolla
@BTatlock, @JonZeolla, @ericof, @kurtmckee, @limtis0, @paduszyk, @rmartin16, @tranzystorek-io and @tvoirand
Improve style of prompts using rich ( #1901 ) @vemonet
@Meepit, @dependabot, @dependabot[bot], @ericof, @pre-commit-ci, @pre-commit-ci[bot] and @vemonet
Add support for adding human-readable labels for choices when defining multiple choices questions ( #1898 ) @vemonet
@ericof, @pre-commit-ci, @pre-commit-ci[bot], @vemonet and @w1ndblow
Improve gitignore ( #1889 ) @audreyfeldroy
Fixed: recommonmark replaced with myst, as recommonmark is deprecated ( #1709 ) @insspb
_cookiecutter (#1874) @kjaymillermaster to main so CI runs correctly on merge (#1852) @kurtmckee.gitignore and cite where it was copied from (#1879) @kurtmckee@Alex0Blackwell, @KAZYPinkSaurus, @Lahiry, @MaciejPatro, @Paulokim1, @Tamronimus, @cksac, @cookies-xor-cream, @dariocurr, @dependabot, @dependabot[bot], @ericof, @insspb, @italomaia, @jeremyswerdlow, @juhannc, @kjaymiller, @kurtmckee, @liortct, @miro-jelaska, @mwtoews, @openrefactory, @pamelafox, @ri0t, @ryanrussell, @segunb, @simobasso, @timgates42, @tmeckel, @tranzystorek-io, @vemonet and @zhongdai
Fix local extensions documentation (#1686) @alkatar21
@alkatar21, @ericof and @jensens
This release log lists all changes from 1.7.3 to this release. It includes the log of the 2.0.x releases, which were never published on PyPI. Because
This release log lists all changes from 1.7.3 to this release. It includes the log of the 2.0.x releases, which were never published on PyPI. Because of that it might look a bit blurry.
We release the current stable state of the project, knowing there are a bunch of open pull requests. Those will be reviewed by the core-committers and merged or dropped.
Future releases will happen more frequently. Stay tuned.
Fetch fresh from PyPI https://pypi.org/project/cookiecutter/2.1.0/
cookiecutter --version and test on Python 3.10 (#1621) @ozer550@Cadair, @Casyfill, @Cy-dev-tex, @HosamAlmoghraby, @MaciejPatro, @SharpEdgeMarshall, @agateau, @audreyfeldroy, @brettcannon, @browniebroke, @chrisbrake, @cjolowicz, @cxnstantius, @dHannasch, @doobrie, @ericof, @gliptak, @glumia, @graue70, @insspb, @jaklan, @javiersanp, @jensens, @jonaswre, @jsoref, @juhuebner, @logworthy, @luzfcb, @lyz-code, @michaeljoseph, @milonimrod, @mwesterhof, @ndclt, @noirbizarre, @noone234, @oncleben31, @ozer550, @pydanny, @rgreinho, @sebix, @simobasso, @smoothml, @ssbarnea, @steltenpower, @wouterdb, @xyb, Christopher Wolfe and Hosam Almoghraby ( RIAG Digital )
Fixed jinja2 and markupsafe dependencies
Fixed: Jinja2&Six version limits causing build errors with ansible project (#1385) @insspb
This release was focused on internal code and CI/CD changes. During this release all code was verified to match pep8, pep257 and other code-styling gu
This release was focused on internal code and CI/CD changes. During this release all code was verified to match pep8, pep257 and other code-styling guides.
Project CI/CD was significantly changed, Windows platform checks based on Appveyor engine was replaced by GitHub actions tests. Appveyor was removed. Also our CI/CD was extended with Mac builds, to verify project builds on Apple devices.
Important Changes:
--skip-if-file-exists, allow to skip the existing files when doing overwrite_if_exists. @chhsiao1981 (#1076)Internal CI/CD and tests changes:
cov-report tox invocation environment @insspb (#1350)Code style and docs changes:
Fixed DeprecationWarning for a regular expression on python 3.6, thanks to @reinout
click API v7.0 from showing choices when already shown, thanks to @rly and @luzfcb (#1168)cookiecutter/main.py, cookiecutter/__init__.py, and cookiecutter/log.py to follow the PEP 257 style guide, thanks to @meahow (#998, #999, #1000)cookiecutter/utils.py to follow the PEP 257 style guide, thanks to @dornheimer(#1026){% endif %} to Choice Variables example. Thanks to @mattstibbs (#1249)TOXENV environment variable, thanks to @asottile (#1019)The primary goal of this release was to add support for templates from Zip files or Zip URLs.
The primary goal of this release was to add support for templates from Zip files or Zip URLs.
_template, thanks to @aroig (#774)git operation failures, thanks to @jmcarp (#905)expand_abbreviations() doc string as per pep257, thanks to @terryjbates (#772)cookiecutter/cli.py and cookiecutter/config.py according to pep257, thanks to @terryjbates (#922, #931)is_copy_only_path() according to pep257, thanks to @mathagician and @terryjbates (#935, #949)cookiecutter/extensions.py according to pep257, thanks to @meahow (#996)test_requirements.txt file for easier testing outside of tox, thanks to @ramnes (#945)cookiecutter.json, thanks to @karantan for the report and fix (#863, #864)Hotfix release to address an issue with dict variables.
Hotfix release to address an issue with dict variables.
The primary goal of this release was to add command-line support for passing extra context, address minor bugs and make a number of improvements.
The primary goal of this release was to add command-line support for passing extra context, address minor bugs and make a number of improvements.
python -m cookiecutter or from a checkout/zip file, thanks to @brettcannon (#788).--debug-file PATH to store a log file on disk. By default no log file is written. Entries for DEBUG level and higher. Thanks to @hackebrot (#792).cookiecutters_dir (default is ~/.cookiecutters/) can now be referenced by directory name, thanks to @michaeljoseph (#825).cookiecutter.json, thanks to @freakboy3742 and @hackebrot (#815, #858).jsonify filter to default jinja2 extensions that json.dumps a Python object into a string, thanks to @aroig (#791).pre_gen_project and post_gen_project hooks, thanks to @cheungnj (#860)__init__ methods for Environment objects, thanks to @pydanny (#677)ssh repository examples, thanks to @pokoli (#702)--template command line option, thanks to @purplediane (#754)environment.py, thanks to @terryjbates (#759)find.py, thanks to @terryjbates (#761)generate.py, thanks to @terryjbates (#764)hooks.py, thanks to @terryjbates (#766)repository.py, thanks to @terryjbates (#833)vcs.py, thanks to @terryjbates (#831)repo_name in documentation, thanks to @palmerev (#734)no_input option, thanks to @pokoli (#701)cli_runner test fixture to simplify CLI tests, thanks to @hackebrot (#790)render_variable function in prompt.py, thanks to @pydanny (#678)pre_gen_project and post_gen_project hooks, thanks to @hackebrot (#856)The goal of this release is changing to a strict Jinja2 environment, paving the way to more awesome in the future, as well as adding support for Jinja
The goal of this release is changing to a strict Jinja2 environment, paving the way to more awesome in the future, as well as adding support for Jinja2 extensions.
New Features:
cookiecutters_dir and replay_dir now support environment variable and user home expansion, thanks to @nfarrar for the suggestion and @hackebrot for the PR (#640, #642){% now 'utc' %}, thanks to @hackebrot (#653)Bug Fixes:
replay.dump() and replay.load() use the correct user config, thanks to @hackebrot (#590, #594)HISTORY.rst with utf-8 encoding when reading the changelog, thanks to @0-wiz-0 for submitting the issue and @hackebrot for the fix (#638, #639)Other Changes:
The goal of this release is to extend the user config feature and to make hook execution more robust.
The goal of this release is to extend the user config feature and to make hook execution more robust.
New Features:
pre_gen_project or post_gen_project
hook scripts fail, thanks to @eliasdorneles (#464, #549)--config-file and --default-config and environment variable
COOKIECUTTER_CONFIG, thanks to @jhermann, @pfmoore, and
@hackebrot (#258, #424, #565)Bug Fixes:
Other Changes:
Removed deprecated cookiecutter-pylibrary-minimal from the list, thanks to @ionelmc
Zimtsterne are cinnamon star cookies
New Feature:
Bug Fixes:
Other Changes:
rualmel.yaml instead of PyYAML, except for Windows users on Python 2.7, thanks to @pydanny (#557)Why 1.2.1 instead of 1.2.0? There was a problem in the distribution that we pushed to PyPI. Since you can't replace previous files uploaded to PyPI, we deleted the files on PyPI and released 1.2.1.
Nothing published for this version
Removed deprecated and fully extraneous compat.is_exe() function, thanks to @hackebrot (#485).
The primary goal of this release was to add copy without render and a few additional command-line options such as --overwrite-if-exists, —replay, and output-dir.
Features:
python -m cookiecutter.cli, thanks to
@vincentbernat and
@hackebrot (#449, #487).Other Changes:
compat.which(), thanks to
@pydanny (#511).https://en.wikipedia.org/wiki/Snickerdoodle
The goals of this release were to formally remove support for Python 2.6 and continue the move to using py.test.
The goals of this release were to formally remove support for Python 2.6 and continue the move to using py.test.
Features:
@hackebrot_ (#322, #332, #334, #336, #337, #338, #340, #341, #343, #345, #347, #351, #412, #413, #414).Other Changes:
Handle non-strings in JSON, thanks to @jacebrowning (#370, #368).
Add PendingDeprecation warning for users of Python 2.6, as support for it is gone in Python 2.7, thanks to @michaeljoseph (#201).
The goals of this release were to add the ability to Jinja2ify the cookiecutter.json default values, and formally launch support for Python 3.4.
Features:
cookiecutter.json values are now rendered Jinja2 templates, thanks to @bollwyvl (#291).py.test, thanks to @pfmoore (#319) and @ramiroluz (#310).PendingDeprecation warning for users of Python 2.6, as support for it is gone in Python 2.7, thanks to @michaeljoseph (#201).Bug Fixes:
Makefile, thanks to @inglesp (#297).git or hg installed, thanks to @pydanny (#303).Other changes:
gitter account for logged chat, thanks to @michaeljoseph.The goal of this release (Cookiecutter 0.8.0 on PyPI) was to allow for injection of extra context via the Cookiecutter API, and to continue fixing bug
The goal of this release (Cookiecutter 0.8.0 on PyPI) was to allow for injection of extra context via the Cookiecutter API, and to continue fixing bugs.
Features:
cookiecutter() now takes an optional extra_context parameter, thanks to @michaeljoseph, @fcurella, @aventurella, @emonty, @schacki, @ryanolson, @pfmoore, @pydanny, @audreyr (#260).cookiecutter.compat, making the eventual move to six easier, thanks to @michaeljoseph (#60, #102).cookiecutterrc defined aliases for cookiecutters, thanks to @pfmoore (#246)flake8 to tox to check for pep8 violations, thanks to @natim.Bug Fixes:
Added more Cookiecutters to the list:
The goal of this release was to fix cross-platform compatibility, primarily Windows bugs that had crept in during the addition of new features. As of
The goal of this release was to fix cross-platform compatibility, primarily Windows bugs that had crept in during the addition of new features. As of this release, Windows is a first-class citizen again, now complete with continuous integration.
Bug Fixes:
Other Changes:
Use the current Python interpreter to run Python hooks, thanks to @coderanger.
Bug fixes:
Other changes:
This is a release with significant improvements and changes. Please read through this list before you upgrade.
This is a release with significant improvements and changes. Please read through this list before you upgrade.
New features:
Bug fixes:
Other changes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →