NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4361 most downloaded on PyPI
A static analyzer and interpreter for Python pickle data
Last release 3 months ago
26 Jun 2026
Ships unpredictably
gaps range from 9 days to 1.3 years
Nearly every release is documented
notes for 19 of 19 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
19 releases · first in 2021
One column per quarter.
Use a pre-generated TorchScript fixture to avoid torch.jit deprecation warnings in #254
MLAllowlist shadowing (https://github.com/trailofbits/fickling/commit/41ce7cb01edd97072994039574a2301ebb3f463d). Thanks to @reapermunky for the report! (GHSA-cffv-grgg-g429)
MLAllowlist functional again, and opt-in as originally intended. If you need to scan ML pickles with an import allowlist, update calls to check_safety() to pass MLAllowList in the analyzer parameter:pickled = Pickled([ ... ])
analyzer = Analyzer([MLAllowlist()])
res = check_safety(pickled, analyzer=analyzer)
STACK_GLOBAL (https://github.com/trailofbits/fickling/commit/d985f89cd558351b3da9a28ca264e78205e75cbd). Thanks to @seankohjs for the report! (GHSA-5j3x-jp52-966f)ScannerDeactivation analysis to detect pickle scanner tampering in #249torch.jit deprecation warnings in #254Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.11...v0.1.12
Expanded the unsafe modules blocklist with:
doctest, unittest, and test (https://github.com/trailofbits/fickling/commit/bbeeb0cafbaac850ad76e5ed90792013fb212a7f + https://github.com/trailofbits/fickling/commit/21fa48ad0e47a6a34925a88aa59b6ce4ce31433b). Thanks to @Lyutoon for the report! (GHSA-pc6j-px3p-rrj4)_posixsubprocess, site and atexit (https://github.com/trailofbits/fickling/commit/e8408615b63adf034f891f653692ab9b51f0f5af). Thanks to @reapermunky for the report! (GHSA-m6fh-58r7-x697)test_legacy_pickle test by @thomas-chauchefoin-tob in https://github.com/trailofbits/fickling/pull/250check_pickle to seek to file start and use correct opcode count API by @thomas-chauchefoin-tob in https://github.com/trailofbits/fickling/pull/253Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.10...v0.1.11
Expanded the unsafe modules blocklist with:
_frozen_importlib, _frozen_importlib_external, _imp to prevent access to references of blocked modules (https://github.com/trailofbits/fickling/commit/b9e690c5a57ee9cd341de947fc6151959f4ae359)inspect to block a getattr equivalent (https://github.com/trailofbits/fickling/commit/9a6d03fb74da5f37db8cf8ab6600bfb6679403eb)linecache and difflib to prevent file access, gc for module references (https://github.com/trailofbits/fickling/commit/7f39d97258217ee2c21a1f5031d4a6d7343eb30d). Thanks @fg0x0 for the report!platform to prevent file access (https://github.com/trailofbits/fickling/commit/351ed4d4242b447c0ffd550bb66b40695f3f9975). Thanks @mldangelo for the report!Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.9...v0.1.10
Expanded the unsafe modules blocklist to include uuid, _osx_support and _aix_support(GHSA-5hwf-rc88-82xm)
uuid, _osx_support and _aix_support(GHSA-5hwf-rc88-82xm)
run_hook() to cover missing pickle entry points (GHSA-wccx-j62j-r448)
Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.8...v0.1.9
Add AGENTS.md with vulnerability reporting guidelines
InterpretationError instead of ValueError (#207)OBJ (https://github.com/trailofbits/fickling/security/advisories/GHSA-mxhj-88fx-4pcv)
Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.7...v0.1.8
Address recent security reports in #195
ctypes and pydoc (GHSA-5hvc-6wx8-mvv4)
cProfile(GHSA-p523-jq9w-64x9)
importlib, runpy, code and multiprocessing (GHSA-q5qq-mvfm-j35x)
runpy (GHSA-wfq2-52f7-7qvj)
Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.6...v0.1.7
CVE-2025-67747 - Bypass via marshal.loads() and types.FunctionType() (GHSA-565g-hwwr-4pp3).
marshal.loads() and types.FunctionType() (GHSA-565g-hwwr-4pp3).
pty.spawn() (GHSA-r7v6-mfhq-g3m2).
Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.5...v0.1.6
Handle invalid opcodes during security analysis by @Boyan-MILANOV in https://github.com/trailofbits/fickling/pull/139
Implement code compilation feature in insert_function_call_on_unpickled_object by @Russell-Tran in https://github.com/trailofbits/fickling/pull/88
Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.3...v0.1.4
Make Torch an optional dependency by @suhacker1 in https://github.com/trailofbits/fickling/pull/95
Full Changelog: https://github.com/trailofbits/fickling/compare/v0.1.2...v0.1.3
Bump version number for updated Python version in build workflow
Refactor: the fickling.pickle module is renamed to fickling.fickle. The fickling.pickle module still works, but is deprecated and will eventually be r…
Refactor: the fickling.pickle module is renamed to fickling.fickle. The fickling.pickle module still works, but is deprecated and will eventually be removed from Fickling.
Adds a new API call to insert a function call into a pickle that operates on the last unpickled object.
Adds a new API call to insert a function call into a pickle that operates on the last unpickled object.
Adds a modular API for analyses and analysis results, permitting sorting and filtering results.
Adds a modular API for analyses and analysis results, permitting sorting and filtering results.
Improved unused variable detection checks
__builtin__sAdds a workaround for an issue with a third party dependency affecting Python 3.8 and earlier. Adds the socket module as an overtly unsafe import.
Adds a workaround for an issue with a third party dependency affecting Python 3.8 and earlier.
Adds the socket module as an overtly unsafe import.
Improvements to documentation and examples, as well as support for two additional pickling opcodes.
Improvements to documentation and examples, as well as support for two additional pickling opcodes.
Support for additional opcodes and minor bugfixes in AST generation.
Support for additional opcodes and minor bugfixes in AST generation.
This is the initial public release of Fickling.
This is the initial public release of Fickling.
Your coding agent can read these notes before it upgrades. Set up the MCP server →