NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #63 most downloaded on PyPI
The PyPA recommended tool for installing Python packages.
Last release 2 months ago
04 Aug 2026
Ships fairly regularly
a new release about every 3 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
18 years old
159 releases · first in 2008
Reallow keyring installed in a (non-activated) virtual environment to be be used via the import provider method while installing build dependencies. (
Reallow keyring installed in a (non-activated) virtual environment to be be used via the import provider method while installing build dependencies. (#14227)
Fix decoding the URL path twice while determining a link filename (CVE-2026-13346). (#14110 _)
Newly published packages will no longer be immediately visible to pip if the index uses caching. To install a newly published package, use --refresh-package. (#13680)
Drop support for detecting legacy, non-405, virtualenv (< 20) environments. (#14062)
Constraints files, including PIP_CONSTRAINT, no longer affect isolated build environments. Use --build-constraint or the PIP_BUILD_CONSTRAINT environment variable to constrain build dependencies instead.
The --use-feature=build-constraint flag is now always enabled and has no effect. (#14094)
Declare support for Python 3.15 (#14208)
Support self-referential extras officially. pip has supported this by accident since version 21.2. (#11296)
Add --only-deps flag to instruct pip to select only the dependencies of supplied packages. It cannot be used with --no-deps, -r, --group, or --requirements-from-script. (#11440)
Cache simple responses in accordance to their Cache-Control header instead of always revalidating on every request. To refresh cached package index responses and ensure newly published packages are found, use --refresh-package <package>. (#13680)
Add --no-require-hashes to disable automatic enablement of --require-hashes when encountering a requirement with hashes. (#14169)
Honor --only-final when sourcing requirements with -r pylock.toml. (#13950)
Add support for pylock.toml upload-time field, so --uploaded-prior-to works with -r pylock.toml. (#14168)
Better error messages in case of conflicts with requirements from -r pylock.toml. (#13963)
Add experimental support for isolating build subprocesses by creating standard virtual environments. This will fix most (if not all) subtle isolation issues that can lead to broken builds exclusive to pip. The feature can be enabled via --use-feature=venv-isolation and will be enabled by default in a future release.
Note that the feature has limited compatibility with --use-feature=inprocess-build-deps. While most builds should work with both features enabled, there are known edge cases. inprocess-build-deps will not be enabled by default until they are fixed. (#14070)
Present more informative diagnostic errors on uncaught network errors. (#14115)
Allow opting out of Git partial clones with PIP_NO_PARTIAL_CLONE_FOR_BROKEN_GIT_SERVER. (#11043)
Add a --no-proxy-env (or --proxy "") option to ignore proxies configured via non-pip environment variables or configuration files. A proxy set with --proxy is still used. (#5378)
Add support for pulling username from keyring subprocess provider (#12543)
Speedup tab autocompletion by lazy-importing certain modules. (#4768)
Improve cached wheel lookup performance when many cached wheels are checked for compatibility. (#14122)
Speed up path compaction when displaying uninstall changes. (#14107)
Only emit the invalid-metadata warning once per location per run, instead of repeating it during the same command. (#11436)
Handle BrokenPipeError when pip output is piped to a command that closes early. (#11608)
Follow symlinks while checking if installed scripts are on PATH. (#11953)
Stop dropping extras from messages about candidates with inconsistent metadata. (#12023)
Stop animating progress bars and status spinners when running on CI, even if FORCE_COLOR is set. (#13354)
Ensure truststore feature remains active while initially connecting to a HTTPS proxy. (#13465)
Address encoding warnings emitted when Python's UTF-8 Mode is enabled by continuing to use the configured locale. (#13922)
Raise an error when the 658 .metadata file used during dependency resolution disagrees with the downloaded wheel's METADATA on Name, Version, Requires-Dist, Requires-Python or Provides-Extra. (#13983)
Prevent system packages from leaking into isolated build environments on Python 3.15 (#14033)
Never use persistent wheel cache for local directory requirements even if there is a matching entry. (#14044)
Avoid re-fetching a pinned Git commit that is already present locally. (#14055)
Report the correct configuration level for cert in pip debug output. (#14056)
Fix pip show crash when a distribution has no Metadata-Version. (#14057)
Remove empty http-v2 cache directories when running pip cache purge. (#14058)
Report a copy failure in pip wheel instead of a misleading build failure. (#14059)
Make pip install conflict checks independent of installed distribution iteration order. (#14074)
Fix ProtocolError exceptions raised after an incomplete download from bypassing download resume logic and leading to a crash. (#14079)
Fix caching bug where local directory requirements would be cached if the directory name contains a dash. (#14080)
Avoid reparsing distribution metadata when formatting the default pip list columns output with the importlib backend. (#14089)
Fix decoding the URL path twice while determining a link filename (CVE-2026-13346). (#14110)
Avoid reading installed file lists in pip show unless --files is used. (#14117)
Additional rejection of tar archives that write outside the target directory through symlink traversal when extracting on Python versions pre-PEP 706. (#14127)
Fix pip list --not-required listing dependencies of packages excluded with --exclude. (#14129)
Fail an interrupted download instead of corrupting the saved file when the server resumes a range request from a different offset than was requested. (#14131)
Fix option errors printing the usage message with raw Rich markup. (#14136)
platformdirs 4.6.0+ adds support for XDG_* environment variables on macOS, so some directory locations may change if any of these are set:
XDG_CACHE_HOME: The pip cache directory will be at $XDG_CACHE_HOME/pip.
XDG_DATA_DIRS: The global configuration file will be inside $XDG_DATA_DIRS/pip
XDG_DATA_HOME: The user configuration file will be inside $XDG_DATA_HOME/pip, if the directory exists (#14142)
Recover credentials embedded in a redirect Location URL when handling a 401 response, even under --no-input. Previously this extraction was gated behind keyring being enabled, so --no-input (with the default keyring provider) caused downloads that rely on a cross-origin redirect with embedded credentials to fail with 401. (#14182)
Reject a package path in a pylock.toml fetched from a URL when it resolves outside the lock file's own location, so a remote lock file can no longer point at the local filesystem or another host. (#14159)
Respect --uploaded-prior-to, --no-binary, --only-binary, and --prefer-binary in pip list --outdated and pip list --uptodate when determining the latest available version. (#14190)
Show a clear error instead of a traceback for an invalid requirement marker. (#6385)
Upgrade certifi to 2026.6.17
Upgrade distlib to 0.4.2
Upgrade idna to 3.18
Upgrade platformdirs to 4.10.0
Upgrade pygments to 2.20.0
Upgrade requests to 2.34.2
Upgrade tomli to 2.4.1
Upgrade urllib3 to 2.7.0
Include a CycloneDX SBOM (Software Bill of Materials) file alongside vendored libraries.
One column per quarter.
Reject console_scripts and gui_scripts entry points whose name would install a script outside the scripts directory. (#14000 _)
Reject console_scripts and gui_scripts entry points whose name would install a script outside the scripts directory. (#14000)
Fix installation incorrectly failing when the target path contains a doubled slash, such as with pip install --root //.... (#14001)
Send a consistent Accept-Encoding header to avoid a spurious Cache entry deserialization failed warning. (#14012)
Fix issue where uninstallation left behind empty directories. Revert the removal of the adjacent __pycache__ directory when a .py file is removed. (#1
Fix issue where uninstallation left behind empty directories. Revert the removal of the adjacent __pycache__ directory when a .py file is removed. (#13973)
Emit a deprecation warning when pip imports an unexpected module after installation of a distribution has started. (#13912 _)
Drop support for Python 3.9. (#13795)
Add experimental support to read requirements from standardized pylock.toml files (-r pylock.toml). (#13876)
Allow --uploaded-prior-to to accept a duration in days (e.g., P3D for 3 days ago). (#13674)
Speed up dependency resolution when there are complex conflicts. (#13859)
Reduce memory usage when resolving large dependency trees. (#13843)
Emit a deprecation warning when pip imports an unexpected module after installation of a distribution has started. (#13912)
Allow URL constraints to apply to requirements with extras. (#12018)
Allow unpinned requirements to use hashes from constraints. Constraints like {name}=={version} --hash=... feeds into hash verification for a corresponding requirement. (#9243)
Improve conflict reports that involve direct URLs. (#13932)
Show all errors instead of first error for faulty dependency_groups definitions. (#13917)
Fix recovery hint for missing RECORD file to use --ignore-installed instead of --force-reinstall. (#12645)
Fix misleading error message when a constraint file cannot be opened. (#13226)
Show the filename rather than the full URL when downloading files from non-PyPI indexes in non-verbose mode. (#13494)
Remove the adjacent __pycache__ directory when a .py file is removed. (#13725)
Force UTF-8 encoding for 723 metadata. (#13861)
Minor performance improvement when filtering candidates during resolution. (#13916)
Fix a hang on Windows when stdout is closed during verbose output. (#13927)
Common path prefixes are determined by path segment, not character by character. (#13847)
Fix installing .tar.gz source distributions that look like a zip file. (#13867)
Upgrade certifi to 2026.2.25
Upgrade packaging to 26.2
Upgrade requests to 2.33.1
Upgrade tomli to 2.3.1
Upgrade urllib3 to 2.6.3
Use packaging 26.1's new dependency_groups module, removing dependency-groups vendor.
Use packaging.direct_url to manipulate direct_url.json. Besides difference in validation error messages, there should be no user-visible change.
Add an explicit AI policy.
Fix --pre not being respected from the command line when a requirement file includes an option e.g. -extra-index-url. (#13788 _)
Fix --pre not being respected from the command line when a requirement file includes an option e.g. -extra-index-url. (#13788)
Remove support for non-bare project names in egg fragments. Affected users should use the Direct URL requirement syntax _. (#13157 _)
Remove support for non-bare project names in egg fragments. Affected users should use the Direct URL requirement syntax. (#13157)
Display pip's command-line help in colour, if possible. (#12134)
Support installing dependencies declared with inline script metadata (723) with --requirements-from-script. (#12891)
Add --all-releases and --only-final options to control pre-release and final release selection during package installation. (#13221)
Add --uploaded-prior-to option to only consider packages uploaded prior to a given datetime when the upload-time field is available from a remote index. (#13625)
Add --use-feature inprocess-build-deps to request that build dependencies are installed within the same pip install process. This new mechanism is faster, supports --no-clean and --no-cache-dir reliably, and supports prompting for authentication.
Enabling this feature will also enable --use-feature build-constraints. This feature will become the default in a future pip version. (#9081)
pip cache purge and pip cache remove now clean up empty directories and legacy files left by older pip versions. (#9058)
Fix selecting pre-release versions when only pre-releases match. For example, package>1.0 with versions 1.0, 2.0rc1 now installs 2.0rc1 instead of failing. (#13746)
Revisions in version control URLs now must be percent-encoded. For example, use git+https://example.com/repo.git@issue%231 to specify the branch issue#1. If you previously used a branch name containing a % character in a version control URL, you now need to replace it with %25 to ensure correct percent-encoding. (#13407)
Preserve original casing when a path is displayed. (#6823)
Fix bash completion when the $IFS variable has been modified from its default. (#13555)
Precompute Python requirements on each candidate, reducing time of long resolutions. (#13656)
Skip redundant work converting version objects to strings when using the importlib.metadata backend. (#13660)
Fix pip index versions to honor only-binary/no-binary options. (#13682)
Fix fallthrough logic for options, allowing overriding global options with defaults from user config. (#13703)
Use a path-segment prefix comparison, not char-by-char. (#13777)
Upgrade CacheControl to 0.14.4
Upgrade certifi to 2026.1.4
Upgrade idna to 3.11
Upgrade packaging to 26.0
Upgrade platformdirs to 4.5.1
Remove the deprecated --global-option and --build-option. --config-setting is now the only way to pass options to the build backend. (#11859 _)
Remove support for the legacy setup.py develop editable method in setuptools editable installs; setuptools >= 64 is now required. (#11457)
Remove the deprecated --global-option and --build-option. --config-setting is now the only way to pass options to the build backend. (#11859)
Deprecate the PIP_CONSTRAINT environment variable for specifying build constraints.
Use the --build-constraint option or the PIP_BUILD_CONSTRAINT environment variable instead. When build constraints are used, PIP_CONSTRAINT no longer affects isolated build environments. To enable this behavior without specifying any build constraints, use --use-feature=build-constraint. (#13534)
Remove support for non-standard legacy wheel filenames. (#13581)
Remove support for the deprecated setup.py bdist_wheel mechanism. Consequently, --use-pep517 is now always on, and --no-use-pep517 has been removed. (#6334)
When 658 metadata is available, full distribution files are no longer downloaded when using pip lock or pip install --dry-run. (#12603)
Add support for installing an editable requirement written as a Direct URL (PackageName @ URL). (#13495)
Add support for build constraints via the --build-constraint option. This allows constraining the versions of packages used during the build process (e.g., setuptools) without affecting the final installation. (#13534)
On ResolutionImpossible errors, include a note about causes with no candidates. (#13588)
Building pip itself from source now uses flit-core instead of setuptools. This does not affect how pip installs or builds packages you use. (#13473)
Handle malformed Version metadata entries and show a sensible error message instead of crashing. (#13443)
Permit spaces between a filepath and extras in an install requirement. (#13523)
Ensure the self-check files in the cache have the same permissions as the rest of the cache. (#13528)
Avoid concurrency issues and improve performance when caching locally built wheels, especially when the temporary build directory is on a different filesystem than the cache. The wheel directory passed to the build backend is now a temporary subdirectory inside the cache directory. (#13540)
Include relevant user-supplied constraints in logs when reporting dependency conflicts. (#13545)
Fix a regression in configuration parsing that was turning a single value into a list and thus leading to a validation error. (#13548)
For Python versions that do not support 706, pip will now raise an installation error for a source distribution when it includes a symlink that points outside the source distribution archive. (#13550)
Prevent --user installs if site.ENABLE_USER_SITE is set to False. (#8794)
Upgrade certifi to 2025.10.5
Upgrade msgpack to 1.1.2
Upgrade platformdirs to 4.5.0
Upgrade requests to 2.32.5
Upgrade resolvelib to 1.2.1
Upgrade rich to 14.2.0
Upgrade tomli to 2.3.0
Upgrade truststore to 0.10.4
Declare support for Python 3.14 (#13506 _)
Declare support for Python 3.14 (#13506)
Automatic download resumption and retrying is enabled by default. (#13464)
Requires-Python error message displays version clauses in numerical order. (#13367)
Minor performance improvement getting the order to install a very large number of interdependent packages. (#13424)
Show time taken instead of eta 0:00:00 at download completion. (#13483)
Speed up small CLI tools by removing import re from the console script executable template. (#13165)
Remove warning when cloning from a Git reference that does not look like a commit hash. (#12283)
pip config debug now correctly separates options as set by the different files at the same level. (#12099)
Ensure truststore feature remains active even when a proxy is also in use. (#13343)
Include sub-commands in tab completion. (#13140)
pip list with the json or freeze format enabled will no longer crash when encountering a package with an invalid version. (#13345)
Provide a hint if a system error is raised involving long filenames or path segments on Windows. (#13346)
Resumed downloads are saved to the HTTP cache like any other normal download. (#13441)
Configured verbosity is consistently forwarded while calling Git during VCS operations. (#13329)
Suppress the progress bar, when running with --log and --quiet.
Consequently, a new auto mode for --progress-bar has been added. auto will enable progress bars unless suppressed by --quiet, while on will always enable progress bars. (#10915)
Fix normalization of local URLs with non-file schemes. (#13509)
Fix normalization of local file URLs on Windows in newer Python versions. (#13510)
Fix remaining test failures in Python 3.14 by adjusting path_to_url and similar functions. (#13423)
Fix missing network test markings, making the suite pass in offline environments again. (#13378)
Upgrade CacheControl to 0.14.3
Upgrade certifi to 2025.7.14
Upgrade distlib to 0.4.0
Upgrade msgpack to 1.1.1
Upgrade platformdirs to 4.3.8
Upgrade pygments to 2.19.2
Upgrade requests to 2.32.4
Upgrade resolvelib to 1.2.0
Upgrade rich to 14.1.0
Remove vendored typing-extensions.
pip's own licensing metadata now follows 639. In addition, the licenses of pip's vendored dependencies are now included in the License-File metadata field and in the wheel.
Fix req.source_dir AssertionError when using the legacy resolver. (#13353 _)
Fix req.source_dir AssertionError when using the legacy resolver. (#13353)
Fix crash on Python 3.9.6 and lower when pip failed to compile a Python module during installation. (#13364)
Names in dependency group includes are now normalized before lookup, which fixes incorrect Dependency group '...' not found errors. (#13372)
Fix issues with using tomllib from the stdlib if available, rather than tomli
Upgrade dependency-groups to 1.3.1
A warning is emitted when the deprecated pkg_resources library is used to inspect and discover installed packages. This warning should only be visible…
Drop support for Python 3.8. (#12989)
On python 3.14+, the pkg_resources metadata backend cannot be used anymore. (#13010)
Hide --no-python-version-warning from CLI help and documentation as it's useless since Python 2 support was removed. Despite being formerly slated for removal, the flag will remain as a no-op to avoid breakage. (#13303)
A warning is emitted when the deprecated pkg_resources library is used to inspect and discover installed packages. This warning should only be visible to users who set an undocumented environment variable to disable the default importlib.metadata backend. (#13318)
Deprecate the legacy setup.py bdist_wheel mechanism. To silence the warning, and future-proof their setup, users should enable --use-pep517 or add a pyproject.toml file to the projects they control. (#13319)
Suggest checking "pip config debug" in case of an InvalidProxyURL error. (#12649)
Using --debug also enables verbose logging. (#12710)
Display a transient progress bar during package installation. (#12712)
Minor performance improvement when installing packages with a large number of dependencies by increasing the requirement string cache size. (#12873)
Add a --group option which allows installation from 735 Dependency Groups. --group accepts arguments of the form group or path:group, where the default path is pyproject.toml, and installs the named Dependency Group from the provided pyproject.toml file. (#12963)
Add support to enable resuming incomplete downloads.
Control the number of retry attempts using the --resume-retries flag. (#12991)
Use 753 "Well-known Project URLs in Metadata" normalization rules when identifying an equivalent project URL to replace a missing Home-Page field in pip show. (#13135)
Remove experimental warning from pip index versions command. (#13188)
Add a structured --json output to pip index versions (#13194)
Add a new, experimental, pip lock command, implementing 751. (#13213)
Speed up resolution by first only considering the preference of candidates that must be required to complete the resolution. (#13253)
Improved heuristics for determining the order of dependency resolution. (#13273)
Provide hint, documentation, and link to the documentation when resolution too deep error occurs. (#13282)
Include traceback on failure to import setuptools when setup.py is being invoked directly. (#13290)
Support for 738 Android wheels. (#13299)
Display wheel build tag in pip list columns output if set. (#5210)
Build environment dependencies are no longer compiled to bytecode during installation for a minor performance improvement. (#7294)
When using the importlib.metadata backend (the default on Python 3.11+), pip list does not show installed egg distributions more than once anymore. Additionally, egg distributions whose parent directory was in sys.path but the egg themselves were not in sys.path are not detected anymore. (#12308)
Disable Git and SSH prompts when --no-input is passed. (#12718)
Gracefully handle Windows registry access errors while guessing the MIME type of a file. (#12769)
Support multiple global configuration paths returned by platformdirs on MacOS. (#12903)
Resolvelib 1.1.0 fixes a known issue where pip would report a ResolutionImpossible error even though there is a valid solution. However, some very complex dependency resolutions that previously resolved may resolve slower or fail with an ResolutionTooDeep error. (#13001)
Show the correct path to the interpreter also when it's a symlink in a venv in the pip upgrade prompt. (#13156)
Parse wheel filenames according to binary distribution format specification. When a filename doesn't match the spec a deprecation warning is emitted and the filename is parsed using the old method. (#13229)
While resolving dependencies prefer if any of the known requirements are "direct", e.g. points to an explicit URL. (#13244)
When choosing a preferred requirement for resolving dependencies do not consider a specifier with a * in it, e.g. "==1.*", to be a pinned specifier. (#13252)
Fix a regression that causes dependencies to be checked before Requires-Python project metadata is checked, leading to wasted cycles when the Python version is unsupported. (#13270)
Don't require the wheel library to be installed to use --no-use-pep517, any more. (#13330)
Fix regression that suppressed errors indicating which packages were ignored due to incompatible requires-python metadata. (#13333)
Fix fish shell completion when commandline contains multiple commands. (#9727)
Upgrade CacheControl to 0.14.2
Upgrade certifi to 2025.1.31
Upgrade packaging to 25.0
Upgrade platformdirs to 4.3.7
Upgrade pygments to 2.19.1
Upgrade resolvelib to 1.1.0.
Upgrade rich to 14.0.0
Vendor tomli-w 1.2.0
Upgrade truststore to 0.10.1
Upgrade typing_extensions to 4.13.2
Added support for building only the man pages with minimal dependencies using the sphinx-build --tag man option. This enables distributors to generate man pages without requiring HTML documentation dependencies. (#13168)
Fix an unsupported type annotation on Python 3.10 and earlier. (#13181 _)
Deprecate the no-python-version-warning flag as it has long done nothing since Python 2 support was removed in pip 21.0. (#13154 _)
Deprecate the no-python-version-warning flag as it has long done nothing since Python 2 support was removed in pip 21.0. (#13154)
Prefer to display 639 License-Expression in pip show if metadata version is at least 2.4. (#13112)
Support 639 License-Expression and License-File metadata fields in JSON output. pip inspect and pip install --report now emit license_expression and license_file fields in the metadata object, if the corresponding fields are present in the installed METADATA file. (#13134)
Files in the network cache will inherit the read/write permissions of pip's cache directory (in addition to the current user retaining read/write access). This enables a single cache to be shared among multiple users. (#11012)
Return the size, along with the number, of files cleared on pip cache purge and pip cache remove (#12176)
Cache python-requires checks while filtering potential installation candidates. (#13128)
Optimize package collection by avoiding unnecessary URL parsing and other processing. (#13132)
Reorder the encoding detection when decoding a requirements file, relying on UTF-8 over the locale encoding by default, matching the documented behaviour. (#12771)
The pip version self check is disabled on EXTERNALLY-MANAGED environments. (#11820)
Fix a security bug allowing a specially crafted wheel to execute code during installation. (#13079)
The inclusion of packaging 24.2 changes how pre-release specifiers with < and > behave. Including a pre-release version with these specifiers now implies accepting pre-releases (e.g., <2.0dev can include 1.0rc1). To avoid implying pre-releases, avoid specifying them (e.g., use <2.0). The exception is !=, which never implies pre-releases. (#13163)
The --cert and --client-cert command-line options are now respected while installing build dependencies. Consequently, the private _PIP_STANDALONE_CERT environment variable is no longer used. (#5502)
The --proxy command-line option is now respected while installing build dependencies. (#6018)
Upgrade CacheControl to 0.14.1
Upgrade idna to 3.10
Upgrade msgpack to 1.1.0
Upgrade packaging to 24.2
Upgrade platformdirs to 4.3.6
Upgrade pyproject-hooks to 1.2.0
Upgrade rich to 13.9.4
Upgrade tomli to 2.2.1
Removed section about non-existing --force-keyring flag. (#12455)
Started releasing to PyPI from a GitHub Actions CI/CD workflow that implements trusted publishing and bundles 740 digital attestations.
Allow multiple nested inclusions of the same requirements file again. (#13046 _)
Allow multiple nested inclusions of the same requirements file again. (#13046)
Deprecate wheel filenames that are not compliant with 440. (#12918 _)
Deprecate wheel filenames that are not compliant with 440. (#12918)
Detect recursively referencing requirements files and help users identify the source. (#12653)
Support for 730 iOS wheels. (#12961)
Display a better error message when an already installed package has an invalid requirement. (#12953)
Ignore PIP_TARGET and pip.conf global.target when preparing a build environment. (#8438)
Restore support for macOS 10.12 and older (via truststore). (#12901)
Allow installing pip in editable mode in a virtual environment on Windows. (#12666)
Upgrade certifi to 2024.8.30
Upgrade distlib to 0.3.9
Upgrade truststore to 0.10.0
Upgrade urllib3 to 1.26.20
Deprecate pip install --editable falling back to setup.py develop when using a setuptools version that does not support 660 (setuptools v63 and older)…
Deprecate pip install --editable falling back to setup.py develop when using a setuptools version that does not support 660 (setuptools v63 and older). (#11457)
Check unsupported packages for the current platform. (#11054)
Use system certificates and certifi certificates to verify HTTPS connections on Python 3.10+. Python 3.9 and earlier only use certifi.
To revert to previous behaviour, pass the flag --use-deprecated=legacy-certs. (#11647)
Improve discovery performance of installed packages when the importlib.metadata backend is used to load distribution metadata (used by default under Python 3.11+). (#12656)
Improve performance when the same requirement string appears many times during resolution, by consistently caching the parsed requirement string. (#12663)
Minor performance improvement of finding applicable package candidates by not repeatedly calculating their versions (#12664)
Disable pip's self version check when invoking a pip subprocess to install PEP 517 build requirements. (#12683)
Improve dependency resolution performance by caching platform compatibility tags during wheel cache lookup. (#12712)
wheel is no longer explicitly listed as a build dependency of pip. setuptools injects this dependency in the get_requires_for_build_wheel() hook and no longer needs it on newer versions. (#12728)
Ignore --require-virtualenv for pip check and pip freeze (#12842)
Improve package download and install performance.
Increase chunk sizes when downloading (256 kB, up from 10 kB) and reading files (1 MB, up from 8 kB). This reduces the frequency of updates to pip's progress bar. (#12810)
Improve pip install performance.
Files are now extracted in 1MB blocks, or in one block matching the file size for smaller files. A decompressor is no longer instantiated when extracting 0 bytes files, it is not necessary because there is no data to decompress. (#12803)
Set no_color to global rich.Console instance. (#11045)
Fix resolution to respect --python-version when checking Requires-Python. (#12216)
Perform hash comparisons in a case-insensitive manner. (#12680)
Avoid dlopen failure for glibc detection in musl builds (#12716)
Avoid keyring logging crashes when pip is run in verbose mode. (#12751)
Fix finding hardlink targets in tar files with an ignored top-level directory. (#12781)
Improve pip install performance by only creating required parent directories once, instead of before extracting every file in the wheel. (#12782)
Improve pip install performance by calculating installed packages printout in linear time instead of quadratic time. (#12791)
Remove vendored tenacity.
Update the preload list for the DEBUNDLED case, to replace pep517 that has been renamed to pyproject_hooks.
Use tomllib from the stdlib if available, rather than tomli
Upgrade certifi to 2024.7.4
Upgrade platformdirs to 4.2.2
Upgrade pygments to 2.18.0
Upgrade setuptools to 70.3.0
Upgrade typing_extensions to 4.12.2
Correct —-ignore-conflicts (including an em dash) to --ignore-conflicts. (#12851)
Fix finding hardlink targets in tar files with an ignored top-level directory. (#12781 _)
Fix finding hardlink targets in tar files with an ignored top-level directory. (#12781)
Actually use system trust stores when the truststore feature is enabled.
Actually use system trust stores when the truststore feature is enabled.
Upgrade requests to 2.32.3
Vendored Libraries ------------------ - Upgrade truststore to 0.9.1.
Upgrade truststore to 0.9.1.
Report informative messages about invalid requirements. (#12713 _)
Report informative messages about invalid requirements. (#12713)
Eagerly import the self version check logic to avoid crashes while upgrading or downgrading pip at the same time. (#12675)
Accommodate for mismatches between different sources of truth for extra names, for packages generated by setuptools. (#12688)
Accommodate for development versions of CPython ending in + in the version string. (#12691)
Upgrade packaging to 24.1
Upgrade requests to 2.32.0
Remove vendored colorama
Remove vendored six
Remove vendored webencodings
Remove vendored charset_normalizer
requests provides optional character detection support on some APIs when processing ambiguous bytes. This isn't relevant for pip to function and we're able to remove it due to recent upstream changes.
Drop support for EOL Python 3.7. (#11934 _)
Drop support for EOL Python 3.7. (#11934)
Remove support for legacy versions and dependency specifiers.
Packages with non standard-compliant versions or dependency specifiers are now ignored by the resolver. Already installed packages with non standard-compliant versions or dependency specifiers must be uninstalled before upgrading them. (#12063)
Improve performance of resolution of large dependency trees, with more caching. (#12453)
Further improve resolution performance of large dependency trees, by caching hash calculations. (#12657)
Reduce startup time of commands (e.g. show, freeze) that do not access the network by 15-30%. (#4768)
Reword and improve presentation of uninstallation errors. (#10421)
Add a 'raw' progress_bar type for simple and parsable download progress reports (#11508)
pip list no longer performs the pip version check unless --outdated or --uptodate is given. (#11677)
Use the data_filter when extracting tarballs, if it's available. (#12111)
Display the Project-URL value under key "Home-page" in pip show when the Home-Page metadata field is not set.
The Project-URL key detection is case-insensitive, and ignores any dashes and underscores. (#11221)
Ensure -vv gets passed to any pip install build environment subprocesses. (#12577)
Deduplicate entries in the Requires field of pip show. (#12165)
Fix error on checkout for subversion and bazaar with verbose mode on. (#11050)
Fix exception with completions when COMP_CWORD is not set (#12401)
Fix intermittent "cannot locate t64.exe" errors when upgrading pip. (#12666)
Remove duplication in invalid wheel error message (#12579)
Remove the incorrect pip3.x console entrypoint from the pip wheel. This console script continues to be generated by pip when it installs itself. (#12536)
Gracefully skip VCS detection in pip freeze when PATH points to a non-directory path. (#12567)
Make the --proxy parameter take precedence over environment variables. (#10685)
Add charset-normalizer 3.3.2
Remove chardet
Remove pyparsing
Upgrade CacheControl to 0.14.0
Upgrade certifi to 2024.2.2
Upgrade distro to 1.9.0
Upgrade idna to 3.7
Upgrade msgpack to 1.0.8
Upgrade packaging to 24.0
Upgrade platformdirs to 4.2.1
Upgrade pygments to 2.17.2
Upgrade rich to 13.7.1
Upgrade setuptools to 69.5.1
Upgrade tenacity to 8.2.3
Upgrade typing_extensions to 4.11.0
Upgrade urllib3 to 1.26.18
Document UX research done on pip. (#10745)
Fix the direct usage of zipapp showing up as python -m pip.pyz rather than ./pip.pyz / .\pip.pyz (#12043)
Add a warning explaining that the snippet in "Fallback behavior" is not a valid pyproject.toml snippet for projects, and link to setuptools documentation instead. (#12122)
The Python Support Policy has been updated. (#12529)
Document the environment variables that correspond with CLI options. (#12576)
Update architecture documentation for command line interface. (#6831)
Remove setup.py since all the pip project metadata is now declared in pyproject.toml.
Move remaining pip development tools configurations to pyproject.toml.
Retry on HTTP status code 502 (#11843 _)
Retry on HTTP status code 502 (#11843)
Automatically use the setuptools PEP 517 build backend when --config-settings is used for projects without pyproject.toml. (#11915)
Make pip freeze and pip uninstall of legacy editable installs of packages whose name contains _ compatible with setuptools>=69.0.3. (#12477)
Support per requirement --config-settings for editable installs. (#12480)
Optimized usage of --find-links=<path-to-dir>, by only scanning the relevant directory once, only considering file names that are valid wheel or sdist names, and only considering files in the directory that are related to the install. (#12327)
Removed wheel from the [build-system].requires list fallback that is used when pyproject.toml is absent. (#12449)
Upgrade distlib to 0.3.8
Fix explanation of how PIP_CONFIG_FILE works (#11815)
Fix outdated pip install argument description in documentation. (#12417)
Replace some links to PEPs with links to the canonical specifications on the pypug:index (#12434)
Updated the pyproject.toml document to stop suggesting to depend on wheel as a build dependency directly. (#12449)
Update supported interpreters in development docs (#12475)
Most project metadata is now defined statically via pip's pyproject.toml file.
Fix a bug in extras handling for link requirements (#12372 _)
Handle a timezone indicator of Z when parsing dates in the self check. (#12338 _)
Added reference to vulnerability reporting guidelines _ to pip's security policy.
Added reference to vulnerability reporting guidelines to pip's security policy.
Drop a fallback to using SecureTransport on macOS. It was useful when pip detected OpenSSL older than 1.0.1, but the current pip does not support any Python version supporting such old OpenSSL versions. (#12175)
Improve extras resolution for multiple constraints on same base package. (#11924)
Improve use of datastructures to make candidate selection 1.6x faster. (#12204)
Allow pip install --dry-run to use platform and ABI overriding options. (#12215)
Add is_yanked boolean entry to the installation report (--report) to indicate whether the requirement was yanked from the index, but was still selected by pip conform to 592. (#12224)
Ignore errors in temporary directory cleanup (show a warning instead). (#11394)
Normalize extras according to 685 from package metadata in the resolver for comparison. This ensures extras are correctly compared and merged as long as the package providing the extra(s) is built with values normalized according to the standard. Note, however, that this does not solve cases where the package itself contains unnormalized extra values in the metadata. (#11649)
Prevent downloading sdists twice when 658 metadata is present. (#11847)
Include all requested extras in the install report (--report). (#11924)
Removed uses of datetime.datetime.utcnow from non-vendored code. (#12005)
Consistently report whether a dependency comes from an extra. (#12095)
Fix completion script for zsh (#12166)
Fix improper handling of the new onexc argument of shutil.rmtree() in Python 3.12. (#12187)
Filter out yanked links from the available versions error message: "(from versions: 1.0, 2.0, 3.0)" will not contain yanked versions conform PEP 592. The yanked versions (if any) will be mentioned in a separate error message. (#12225)
Fix crash when the git version number contains something else than digits and dots. (#12280)
Use -r=... instead of -r ... to specify references with Mercurial. (#12306)
Redact password from URLs in some additional places. (#12350)
pip uses less memory when caching large packages. As a result, there is a new on-disk cache format stored in a new directory ($PIP_CACHE_DIR/http-v2). (#2984)
Upgrade certifi to 2023.7.22
Add truststore 0.8.0
Upgrade urllib3 to 1.26.17
Disable 658 metadata fetching with the legacy resolver. (#12156 _)
Disable 658 metadata fetching with the legacy resolver. (#12156)
Disable PEP 658 metadata fetching with the legacy resolver. ( #12156 )
Deprecate support for eggs for Python 3.11 or later, when the new importlib.metadata backend is used to load distribution metadata. This only affects…
Deprecate support for eggs for Python 3.11 or later, when the new importlib.metadata backend is used to load distribution metadata. This only affects the egg distribution format (with the .egg extension); distributions using the .egg-info metadata format (but are not actually eggs) are not affected. For more information about eggs, see relevant section in the setuptools documentation.
Deprecate legacy version and version specifiers that don't conform to the specification. (#12063)
freeze no longer excludes the setuptools, distribute, and wheel from the output when running on Python 3.12 or later, where they are not included in a virtual environment by default. Use --exclude if you wish to exclude any of these packages. (#4256)
make rejection messages slightly different between 1 and 8, so the user can make the difference. (#12040)
Fix pip completion --zsh. (#11417)
Prevent downloading files twice when 658 metadata is present (#11847)
Add permission check before configuration (#11920)
Fix deprecation warnings in Python 3.12 for usage of shutil.rmtree (#11957)
Ignore invalid or unreadable origin.json files in the cache of locally built wheels. (#11985)
Fix installation of packages with 658 metadata using non-canonicalized names (#12038)
Correctly parse dist-info-metadata values from JSON-format index data. (#12042)
Fail with an error if the --python option is specified after the subcommand name. (#12067)
Fix slowness when using importlib.metadata (the default way for pip to read metadata in Python 3.11+) and there is a large overlap between already installed and to-be-installed packages. (#12079)
Pass the -r flag to mercurial to be explicit that a revision is passed and protect against hg options injection as part of VCS URLs. Users that do not have control on VCS URLs passed to pip are advised to upgrade. (#12119)
Upgrade certifi to 2023.5.7
Upgrade platformdirs to 3.8.1
Upgrade pygments to 2.15.1
Upgrade pyparsing to 3.1.0
Upgrade Requests to 2.31.0
Upgrade rich to 13.4.2
Upgrade setuptools to 68.0.0
Updated typing_extensions to 4.6.0
Upgrade typing_extensions to 4.7.1
Upgrade urllib3 to 1.26.16
Vendored Libraries ------------------ - Upgrade setuptools to 67.7.2
Upgrade setuptools to 67.7.2
Revert #11487 _, as it causes issues with virtualenvs created by the Windows Store distribution of Python. (#11987 _)
Revert #11487, as it causes issues with virtualenvs created by the Windows Store distribution of Python. (#11987)
Revert pkg_resources (via setuptools) back to 65.6.3
Update documentation to reflect the new behavior of using the cache of locally built wheels in hash-checking mode. (#11967)
Remove support for the deprecated --install-options. (#11358 _)
Remove support for the deprecated --install-options. (#11358)
--no-binary does not imply setup.py install anymore. Instead a wheel will be built locally and installed. (#11451)
--no-binary does not disable the cache of locally built wheels anymore. It only means "don't download wheels". (#11453)
Deprecate --build-option and --global-option. Users are invited to switch to --config-settings. (#11859)
Using --config-settings with projects that don't have a pyproject.toml now prints a deprecation warning. In the future the presence of config settings will automatically enable the default build backend for legacy projects and pass the settings to it. (#11915)
Remove setup.py install fallback when building a wheel failed for projects without pyproject.toml. (#8368)
When the wheel package is not installed, pip now uses the default build backend instead of setup.py install and setup.py develop for project without pyproject.toml. (#8559)
Specify egg-link location in assertion message when it does not match installed location to provide better error message for debugging. (#10476)
Present conflict information during installation after each choice that is rejected (pass -vv to pip install to show it) (#10937)
Display dependency chain on each Collecting/Processing log line. (#11169)
Support a per-requirement --config-settings option in requirements files. (#11325)
The --config-settings/-C option now supports using the same key multiple times. When the same key is specified multiple times, all values are passed to the build backend as a list, as opposed to the previous behavior, where pip would only pass the last value if the same key was used multiple times. (#11681)
Add -C as a short version of the --config-settings option. (#11786)
Reduce the number of resolver rounds, since backjumping makes the resolver more efficient in finding solutions. This also makes pathological cases fail quicker. (#11908)
Warn if --hash is used on a line without requirement in a requirements file. (#11935)
Stop propagating CLI --config-settings to the build dependencies. They already did not propagate to requirements provided in requirement files. To pass the same config settings to several requirements, users should provide the requirements as CLI arguments. (#11941)
Support wheel cache when using --require-hashes. (#5037)
Add --keyring-provider flag. See the Authentication page in the documentation for more info. (#8719)
In the case of virtual environments, configuration files are now also included from the base installation. (#9752)
Fix grammar by changing "A new release of pip available:" to "A new release of pip is available:" in the notice used for indicating that. (#11529)
Normalize paths before checking if installed scripts are on PATH. (#11719)
Correct the way to decide if keyring is available. (#11774)
More consistent resolution backtracking by removing legacy hack related to setuptools resolution (#11837)
Include AUTHORS.txt in pip's wheels. (#11882)
The uninstall and install --force-reinstall commands no longer call normalize_path() repeatedly on the same paths. Instead, these results are cached for the duration of an uninstall operation, resulting in improved performance, particularly on Windows. (#11889)
Fix and improve the parsing of hashes embedded in URL fragments. (#11936)
When package A depends on package B provided as a direct URL dependency including a hash embedded in the link, the --require-hashes option did not warn when user supplied hashes were missing for package B. (#11938)
Correctly report requested_extras in the installation report when extras are specified for a local directory installation. (#11946)
When installing an archive from a direct URL or local file, populate download_info.archive_info.hashes in the installation report, in addition to the legacy download_info.archive_info.hash key. (#11948)
Upgrade msgpack to 1.0.5
Patch pkg_resources to remove dependency on jaraco.text.
Upgrade platformdirs to 3.2.0
Upgrade pygments to 2.14.0
Upgrade resolvelib to 1.0.1
Upgrade rich to 13.3.3
Upgrade setuptools to 67.6.1
Upgrade tenacity to 8.2.2
Upgrade typing_extensions to 4.5.0
Upgrade urllib3 to 1.26.15
Cross-reference the --python flag from the --prefix flag, and mention limitations of --prefix regarding script installation. (#11775)
Add SECURITY.md to make the policy official. (#11809)
Add username to Git over SSH example. (#11838)
Quote extras in the pip install docs to guard shells with default glob qualifiers, like zsh. (#11842)
Make it clear that requirements/constraints file can be a URL (#11954)
Ignore PIP_REQUIRE_VIRTUALENV for pip index (#11671 _)
Deprecated a historical ambiguity in how egg fragments in URL-style requirements are formatted and handled. egg fragments that do not look like 508 na…
Change the hashes in the installation report to be a mapping. Emit the archive_info.hashes dictionary in direct_url.json. (#11312)
Implement logic to read the EXTERNALLY-MANAGED file as specified in 668. This allows a downstream Python distributor to prevent users from using pip to modify the externally managed environment. (#11381)
Enable the use of keyring found on PATH. This allows keyring installed using pipx to be used by pip. (#11589)
The inspect and installation report formats are now declared stable, and their version has been bumped from 0 to 1. (#11757)
Wheel cache behavior is restored to match previous versions, allowing the cache to find existing entries. (#11527)
Use the "venv" scheme if available to obtain prefixed lib paths. (#11598)
Deprecated a historical ambiguity in how egg fragments in URL-style requirements are formatted and handled. egg fragments that do not look like 508 names now produce a deprecation warning. (#11617)
Fix scripts path in isolated build environment on Debian. (#11623)
Make pip show show the editable location if package is editable (#11638)
Stop checking that wheel is present when build-system.requires is provided without build-system.build-backend as setuptools (which we still check for) will inject it anyway. (#11673)
Fix an issue when an already existing in-memory distribution would cause exceptions in pip install (#11704)
Upgrade certifi to 2022.12.7
Upgrade chardet to 5.1.0
Upgrade colorama to 0.4.6
Upgrade distro to 1.8.0
Remove pep517 from vendored packages
Upgrade platformdirs to 2.6.2
Add pyproject-hooks 1.0.0
Upgrade requests to 2.28.2
Upgrade rich to 12.6.0
Upgrade urllib3 to 1.26.14
Fixed the description of the option "--install-options" in the documentation (#10265)
Remove mention that editable installs are necessary for pip freeze to report the VCS URL. (#11675)
Clarify that the egg URL fragment is only necessary for editable VCS installs, and otherwise not necessary anymore. (#11676)
Fix entry point generation of pip.X, pipX.Y, and easy_install-X.Y to correctly account for multi-digit Python version segments (e.g. the "11" part of
Fix entry point generation of pip.X, pipX.Y, and easy_install-X.Y to correctly account for multi-digit Python version segments (e.g. the "11" part of 3.11). (#11547)
Deprecate --install-options which forces pip to use the deprecated install command of setuptools. (#11358 _)
Deprecate --install-options which forces pip to use the deprecated install command of setuptools. (#11358)
Deprecate installation with 'setup.py install' when no-binary is enabled for source distributions without 'pyproject.toml'. (#11452)
Deprecate `--no-binary disabling the wheel cache. (#11454)
Remove --use-feature=2020-resolver opt-in flag. This was supposed to be removed in 21.0, but missed during that release cycle. (#11493)
Deprecate installation with 'setup.py install' when the 'wheel' package is absent for source distributions without 'pyproject.toml'. (#8559)
Remove the ability to use pip list --outdated in combination with --format=freeze. (#9789)
Use shell=True for opening the editor with pip config edit. (#10716)
Use the data-dist-info-metadata attribute from 658 to resolve distribution metadata without downloading the dist yet. (#11111)
Add an option to run the test suite with pip built as a zipapp. (#11250)
Add a --python option to allow pip to manage Python environments other than the one pip is installed in. (#11320)
Document the new (experimental) zipapp distribution of pip. (#11459)
Use the much faster 'bzr co --lightweight' to obtain a copy of a Bazaar tree. (#5444)
Fix --no-index when --index-url or --extra-index-url is specified inside a requirements file. (#11276)
Ensure that the candidate pip executable exists, when checking for a new version of pip. (#11309)
Ignore distributions with invalid Name in metadata instead of crashing, when using the importlib.metadata backend. (#11352)
Raise RequirementsFileParseError when parsing malformed requirements options that can't be successfully parsed by shlex. (#11491)
Fix build environment isolation on some system Pythons. (#6264)
Upgrade certifi to 2022.9.24
Upgrade distlib to 0.3.6
Upgrade idna to 3.4
Upgrade pep517 to 0.13.0
Upgrade pygments to 2.13.0
Upgrade tenacity to 8.1.0
Upgrade typing_extensions to 4.4.0
Upgrade urllib3 to 1.26.12
Mention that --quiet must be used when writing the installation report to stdout. (#11357)
Show pip deprecation warnings by default. (#11330 _)
Send the pip upgrade prompt to stderr. (#11282 _)
Send the pip upgrade prompt to stderr. (#11282)
Ensure that things work correctly in environments where setuptools-injected distutils is available by default. This is done by cooperating with setuptools' injection logic to ensure that pip uses the distutils from the Python standard library instead. (#11298)
Clarify that pip cache's wheels-related output is about locally built wheels only. (#11300)
Remove the html5lib deprecated feature flag. (#10825 _)
Remove the html5lib deprecated feature flag. (#10825)
Remove --use-deprecated=backtrack-on-build-failures. (#11241)
Add support to use truststore as an alternative SSL certificate verification backend. The backend can be enabled on Python 3.10 and later by installing truststore into the environment, and adding the --use-feature=truststore flag to various pip commands.
truststore differs from the current default verification backend (provided by certifi) in it uses the operating system’s trust store, which can be better controlled and augmented to better support non-standard certificates. Depending on feedback, pip may switch to this as the default certificate verification backend in the future. (#11082)
Add --dry-run option to pip install, to let it print what it would install but not actually change anything in the target environment. (#11096)
Record in wheel cache entries the URL of the original artifact that was downloaded to build the cached wheels. The record is named origin.json and uses the PEP 610 Direct URL format. (#11137)
pip's deprecation warnings now subclass the built-in DeprecationWarning, and can be suppressed by running the Python interpreter with -W ignore::DeprecationWarning. (#11225)
Add pip inspect command to obtain the list of installed distributions and other information about the Python environment, in JSON format. (#11245)
Significantly speed up isolated environment creation, by using the same sources for pip instead of creating a standalone installation for each environment. (#11257)
Add an experimental --report option to the install command to generate a JSON report of what was installed. In combination with --dry-run and --ignore-installed it can be used to resolve the requirements. (#53)
Fix pip install --pre for packages with pre-release build dependencies defined both in pyproject.toml's build-system.requires and setup.py's setup_requires. (#10222)
When pip rewrites the shebang line in a script during wheel installation, update the hash and size in the corresponding RECORD file entry. (#10744)
Do not consider a .dist-info directory found inside a wheel-like zip file as metadata for an installed distribution. A package in a wheel is (by definition) not installed, and is not guaranteed to work due to how a wheel is structured. (#11217)
Use importlib.resources to read the vendor.txt file in pip debug. This makes the command safe for use from a zipapp. (#11248)
Make the --use-pep517 option of the download command apply not just to the requirements specified on the command line, but to their dependencies, as well. (#9523)
Remove reliance on the stdlib cgi module, which is deprecated in Python 3.11.
Remove html5lib.
Upgrade certifi to 2022.6.15
Upgrade chardet to 5.0.0
Upgrade colorama to 0.4.5
Upgrade distlib to 0.3.5
Upgrade msgpack to 1.0.4
Upgrade pygments to 2.12.0
Upgrade pyparsing to 3.0.9
Upgrade requests to 2.28.1
Upgrade rich to 12.5.1
Upgrade typing_extensions to 4.3.0
Upgrade urllib3 to 1.26.10
Revert #10979 _ since it introduced a regression in certain edge cases. (#10979 _)
Properly filter out optional dependencies (i.e. extras) when checking build environment distributions. (#11112 _)
Properly filter out optional dependencies (i.e. extras) when checking build environment distributions. (#11112)
Change the build environment dependency checking to be opt-in. (#11116)
Allow using a pre-release version to satisfy a build requirement. This helps manually populated build environments to more accurately detect build-time requirement conflicts. (#11123)
Enable the importlib.metadata metadata implementation by default on Python 3.11 (or later). The environment variable _PIP_USE_IMPORTLIB_METADATA can s
Enable the importlib.metadata metadata implementation by default on Python 3.11 (or later). The environment variable _PIP_USE_IMPORTLIB_METADATA can still be used to enable the implementation on 3.10 and earlier, or disable it on 3.11 (by setting it to 0 or false).
Drop --use-deprecated=out-of-tree-build, according to deprecation message. (#11001 _)
Start migration of distribution metadata implementation from pkg_resources to importlib.metadata. The new implementation is currently not exposed in any user-facing way, but included in the code base for easier development.
Drop --use-deprecated=out-of-tree-build, according to deprecation message. (#11001)
Add option to install and uninstall commands to opt-out from running-as-root warning. (#10556)
Include Project-URLs in pip show output. (#10799)
Improve error message when pip config edit is provided an editor that doesn't exist. (#10812)
Add a user interface for supplying config settings to build backends. (#11059)
Add support for Powershell autocompletion. (#9024)
Explains why specified version cannot be retrieved when Requires-Python is not satisfied. (#9615)
Validate build dependencies when using --no-build-isolation. (#9794)
Fix conditional checks to prevent pip.exe from trying to modify itself, on Windows. (#10560)
Fix uninstall editable from Windows junction link. (#10696)
Fallback to pyproject.toml-based builds if setup.py is present in a project, but setuptools cannot be imported. (#10717)
When checking for conflicts in the build environment, correctly skip requirements containing markers that do not match the current environment. (#10883)
Disable brotli import in vendored urllib3 so brotli could be uninstalled/upgraded by pip. (#10950)
Prioritize URL credentials over netrc. (#10979)
Filter available distributions using hash declarations from constraints files. (#9243)
Fix an error when trying to uninstall packages installed as editable from a network drive. (#9452)
Fix pip install issues using a proxy due to an inconsistency in how Requests is currently handling variable precedence in session. (#9691)
Upgrade CacheControl to 0.12.11
Upgrade distro to 1.7.0
Upgrade platformdirs to 2.5.2
Remove progress from vendored dependencies.
Upgrade pyparsing to 3.0.8 for startup performance improvements.
Upgrade rich to 12.2.0
Upgrade tomli to 2.0.1
Upgrade typing_extensions to 4.2.0
Add more dedicated topic and reference pages to the documentation. (#10899)
Capitalise Y as the default for "Proceed (y/n)?" when uninstalling. (#10936)
Add scheme:// requirement to --proxy option's description (#10951)
The wheel command now references the build interface section instead of stating the legacy setuptools behavior as the default. (#10972)
Improved usefulness of pip config --help output. (#11074)
Drop the doctype check, that presented a warning for index pages that use non-compliant HTML 5. (#10903 _)
Drop the doctype check, that presented a warning for index pages that use non-compliant HTML 5. (#10903)
Downgrade distlib to 0.3.3.
Use html.parser by default, instead of falling back to html5lib when --use-deprecated=html5lib is not passed. (#10869 _)
Print the exception via rich.traceback, when running with --debug. (#10791)
Only calculate topological installation order, for packages that are going to be installed/upgraded.
This fixes an AssertionError that occurred when determining installation order, for a very specific combination of upgrading-already-installed-package + change of dependencies + fetching some packages from a package index. This combination was especially common in Read the Docs' builds. (#10851)
Use html.parser by default, instead of falling back to html5lib when --use-deprecated=html5lib is not passed. (#10869)
Clarify that using per-requirement overrides disables the usage of wheels. (#9674)
Instead of failing on index pages that use non-compliant HTML 5, print a deprecation warning and fall back to html5lib-based parsing for now. This sim…
Instead of failing on index pages that use non-compliant HTML 5, print a deprecation warning and fall back to html5lib-based parsing for now. This simplifies the migration for non-compliant index pages, by letting such indexes function with a warning. (#10847)
Properly handle links parsed by html5lib, when using --use-deprecated=html5lib. (#10846 _)
Deprecate alternative progress bar styles, leaving only on and off as available choices. (#10462 _)
Completely replace tox in our development workflow, with nox.
Deprecate alternative progress bar styles, leaving only on and off as available choices. (#10462)
Drop support for Python 3.6. (#10641)
Disable location mismatch warnings on Python versions prior to 3.10.
These warnings were helping identify potential issues as part of the sysconfig -> distutils transition, and we no longer need to rely on reports from older Python versions for information on the transition. (#10840)
Changed PackageFinder to parse HTML documents using the stdlib html.parser.HTMLParser class instead of the html5lib package.
For now, the deprecated html5lib code remains and can be used with the --use-deprecated=html5lib command line option. However, it will be removed in a future pip release. (#10291)
Utilise rich for presenting pip's default download progress bar. (#10462)
Present a better error message when an invalid wheel file is encountered, providing more context where the invalid wheel file is. (#10535)
Documents the --require-virtualenv flag for pip install. (#10588)
pip install <tab> autocompletes paths. (#10646)
Allow Python distributors to opt-out from or opt-in to the sysconfig installation scheme backend by setting sysconfig._PIP_USE_SYSCONFIG to True or False. (#10647)
Make it possible to deselect tests requiring cryptography package on systems where it cannot be installed. (#10686)
Start using Rich for presenting error messages in a consistent format. (#10703)
Improve presentation of errors from subprocesses. (#10705)
Forward pip's verbosity configuration to VCS tools to control their output accordingly. (#8819)
Optimize installation order calculation to improve performance when installing requirements that form a complex dependency graph with a large amount of edges. (#10557)
When a package is requested by the user for upgrade, correctly identify that the extra-ed variant of that same package depended by another user-requested package is requesting the same package, and upgrade it accordingly. (#10613)
Prevent pip from installing yanked releases unless explicitly pinned via the == or === operators. (#10617)
Stop backtracking on build failures, by instead surfacing them to the user and aborting immediately. This behaviour provides more immediate feedback when a package cannot be built due to missing build dependencies or platform incompatibility. (#10655)
Silence Value for <location> does not match warning caused by an erroneous patch in Slackware-distributed Python 3.9. (#10668)
Fix an issue where pip did not consider dependencies with and without extras to be equal (#9644)
Upgrade CacheControl to 0.12.10
Upgrade certifi to 2021.10.8
Upgrade distlib to 0.3.4
Upgrade idna to 3.3
Upgrade msgpack to 1.0.3
Upgrade packaging to 21.3
Upgrade platformdirs to 2.4.1
Add pygments 2.11.2 as a vendored dependency.
Tree-trim unused portions of vendored pygments, to reduce the distribution size.
Upgrade pyparsing to 3.0.7
Upgrade Requests to 2.27.1
Upgrade resolvelib to 0.8.1
Add rich 11.0.0 as a vendored dependency.
Tree-trim unused portions of vendored rich, to reduce the distribution size.
Add typing_extensions 4.0.1 as a vendored dependency.
Upgrade urllib3 to 1.26.8
Always refuse installing or building projects that have no pyproject.toml nor setup.py. (#10531 _)
Always refuse installing or building projects that have no pyproject.toml nor setup.py. (#10531)
Tweak running-as-root detection, to check os.getuid if it exists, on Unix-y and non-Linux/non-MacOS machines. (#10565)
When installing projects with a pyproject.toml in editable mode, and the build backend does not support 660, prepare metadata using prepare_metadata_for_build_wheel instead of setup.py egg_info. Also, refuse installing projects that only have a setup.cfg and no setup.py nor pyproject.toml. These restore the pre-21.3 behaviour. (#10573)
Restore compatibility of where configuration files are loaded from on MacOS (back to Library/Application Support/pip, instead of Preferences/pip). (#10585)
Upgrade pep517 to 0.12.0
Improve deprecation warning regarding the copying of source trees when installing from a local directory. (#10128 _)
Improve deprecation warning regarding the copying of source trees when installing from a local directory. (#10128)
Suppress location mismatch warnings when pip is invoked from a Python source tree, so ensurepip does not emit warnings on CPython make install. (#10270)
On Python 3.10 or later, the installation scheme backend has been changed to use sysconfig. This is to anticipate the deprecation of distutils in Python 3.10, and its scheduled removal in 3.12. For compatibility considerations, pip installations running on Python 3.9 or lower will continue to use distutils. (#10358)
Remove the --build-dir option and aliases, one last time. (#10485)
In-tree builds are now the default. --use-feature=in-tree-build is now ignored. --use-deprecated=out-of-tree-build may be used temporarily to ease the transition. (#10495)
Un-deprecate source distribution re-installation behaviour. (#8711)
Replace vendored appdirs with platformdirs. (#10202)
Support PEP 610 to detect editable installs in pip freeze and pip list. The pip list column output has a new Editable project location column, and the JSON output has a new editable_project_location field. (#10249)
pip freeze will now always fallback to reporting the editable project location when it encounters a VCS error while analyzing an editable requirement. Before, it sometimes reported the requirement as non-editable. (#10410)
pip show now sorts Requires and Required-By alphabetically. (#10422)
Do not raise error when there are no files to remove with pip cache purge/remove. Instead log a warning and continue (to log that we removed 0 files). (#10459)
When backtracking during dependency resolution, prefer the dependencies which are involved in the most recent conflict. This can significantly reduce the amount of backtracking required. (#10479)
Cache requirement objects, to improve performance reducing reparses of requirement strings. (#10550)
Support editable installs for projects that have a pyproject.toml and use a build backend that supports 660. (#8212)
When a revision is specified in a Git URL, use git's partial clone feature to speed up source retrieval. (#9086)
Add a --debug flag, to enable a mode that doesn't log errors and propagates them to the top level instead. This is primarily to aid with debugging pip's crashes. (#9349)
If a host is explicitly specified as trusted by the user (via the --trusted-host option), cache HTTP responses from it in addition to HTTPS ones. (#9498)
Present a better error message, when a file: URL is not found. (#10263)
Fix the auth credential cache to allow for the case in which the index url contains the username, but the password comes from an external source, such as keyring. (#10269)
Fix double unescape of HTML data-requires-python and data-yanked attributes. (#10378)
New resolver: Fixes depth ordering of packages during resolution, e.g. a dependency 2 levels deep will be ordered before a dependency 3 levels deep. (#10482)
Correctly indent metadata preparation messages in pip output. (#10524)
Remove appdirs as a vendored dependency.
Upgrade distlib to 0.3.3
Upgrade distro to 1.6.0
Patch pkg_resources to use platformdirs rather than appdirs.
Add platformdirs as a vendored dependency.
Upgrade progress to 1.6
Upgrade resolvelib to 0.8.0
Upgrade urllib3 to 1.26.7
Update links of setuptools as setuptools moved these documents. The Simple Repository link now points to PyPUG as that is the canonical place of packaging specification, and setuptools's easy_install is deprecated. (#10430)
Create a "Build System Interface" reference section, for documenting how pip interacts with build systems. (#10497)
Fix 3.6.0 compatibility in link comparison logic. (#10280 _)
Fix 3.6.0 compatibility in link comparison logic. (#10280)
Modify the sysconfig.get_preferred_scheme function check to be compatible with CPython 3.10’s alphareleases. (#10252 _)
Modify the sysconfig.get_preferred_scheme function check to be compatible with CPython 3.10’s alphareleases. (#10252)
New resolver: When a package is specified with extras in constraints, and with extras in non-constraint requirements, the resolver now correctly ident
New resolver: When a package is specified with extras in constraints, and with extras in non-constraint requirements, the resolver now correctly identifies the constraint's existence and avoids backtracking. (#10233)
The source distribution re-installation feature removal has been delayed to 21.3.
The source distribution re-installation feature removal has been delayed to 21.3.
Remove deprecated --find-links option in pip freeze (#9069 _)
pip freeze, pip list, and pip show no longer normalize underscore (_) in distribution names to dash (-). This is a side effect of the migration to importlib.metadata, since the underscore-dash normalization behavior is non-standard and specific to setuptools. This should not affect other parts of pip (for example, when feeding the pip freeze result back into pip install) since pip internally performs standard PEP 503 normalization independently to setuptools.
Git version parsing is now done with regular expression to prepare for the pending upstream removal of non-PEP-440 version parsing logic. (#10117)
Re-enable the "Value for ... does not match" location warnings to field a new round of feedback for the distutils-sysconfig transition. (#10151)
Remove deprecated --find-links option in pip freeze (#9069)
New resolver: Loosen URL comparison logic when checking for direct URL reference equivalency. The logic includes the following notable characteristics:
The authentication part of the URL is explicitly ignored.
Most of the fragment part, including egg=, is explicitly ignored. Only subdirectory= and hash values (e.g. sha256=) are kept.
The query part of the URL is parsed to allow ordering differences. (#10002)
Support TOML v1.0.0 syntax in pyproject.toml. (#10034)
Added a warning message for errors caused due to Long Paths being disabled on Windows. (#10045)
Change the encoding of log file from default text encoding to UTF-8. (#10071)
Log the resolved commit SHA when installing a package from a Git repository. (#10149)
Add a warning when passing an invalid requirement to pip uninstall. (#4958)
Add new subcommand pip index used to interact with indexes, and implement pip index version to list available versions of a package. (#7975)
When pip is asked to uninstall a project without the dist-info/RECORD file it will no longer traceback with FileNotFoundError, but it will provide a better error message instead, such as:
ERROR: Cannot uninstall foobar 0.1, RECORD file not found. You might be able to recover from this via: 'pip install --force-reinstall --no-deps foobar==0.1'.
When dist-info/INSTALLER is present and contains some useful information, the info is included in the error message instead:
ERROR: Cannot uninstall foobar 0.1, RECORD file not found. Hint: The package was installed by rpm.
(#8954)
Add an additional level of verbosity. --verbose (and the shorthand -v) now contains significantly less output, and users that need complete full debug-level output should pass it twice (--verbose --verbose or -vv). (#9450)
New resolver: The order of dependencies resolution has been tweaked to traverse the dependency graph in a more breadth-first approach. (#9455)
Make "yes" the default choice in pip uninstall's prompt. (#9686)
Add a special error message when users forget the -r flag when installing. (#9915)
New resolver: A distribution's Requires-Python metadata is now checked before its Python dependencies. This makes the resolver fail quicker when there's an interpreter version conflict. (#9925)
Suppress "not on PATH" warning when --prefix is given. (#9931)
Include rustc version in pip's User-Agent, when the system has rustc. (#9987)
Update vendored six to 1.16.0 and urllib3 to 1.26.5 (#10043)
Correctly allow PEP 517 projects to be detected without warnings in pip freeze. (#10080)
Strip leading slash from a file:// URL built from an path with the Windows drive notation. This fixes bugs where the file:// URL cannot be correctly used as requirement, constraint, or index URLs on Windows. (#10115)
New resolver: URL comparison logic now treats file://localhost/ and file:/// as equivalent to conform to RFC 8089. (#10162)
Prefer credentials from the URL over the previously-obtained credentials from URLs of the same domain, so it is possible to use different credentials on the same index server for different --extra-index-url options. (#3931)
Fix extraction of files with utf-8 encoded paths from tars. (#7667)
Skip distutils configuration parsing on encoding errors. (#8931)
New resolver: Detect an unnamed requirement is user-specified (by building its metadata for the project name) so it can be correctly ordered in the resolver. (#9204)
Fix pip freeze to output packages installed from git in the correct git+protocol://git.example.com/MyProject#egg=MyProject format rather than the old and no longer supported git+git@ format. (#9822)
Fix warnings about install scheme selection for Python framework builds distributed by Apple's Command Line Tools. (#9844)
Relax interpreter detection to quelch a location mismatch warning where PyPy is deliberately breaking backwards compatibility. (#9845)
Upgrade certifi to 2021.05.30.
Upgrade idna to 3.2.
Upgrade packaging to 21.0
Upgrade requests to 2.26.0.
Upgrade resolvelib to 0.7.1.
Upgrade urllib3 to 1.26.6.
Remove unused optional tornado import in vendored tenacity to prevent old versions of Tornado from breaking pip. (#10020 _)
New resolver: Correctly exclude an already installed package if its version is known to be incompatible to stop the dependency resolution process with
New resolver: Correctly exclude an already installed package if its version is known to be incompatible to stop the dependency resolution process with a clear error message. (#9841)
Allow ZIP to archive files with timestamps earlier than 1980. (#9910)
Emit clearer error message when a project root does not contain either pyproject.toml, setup.py or setup.cfg. (#9944)
Fix detection of existing standalone pip instance for PEP 517 builds. (#9953)
Temporarily set the new "Value for ... does not match" location warnings level to *DEBUG*, to hide them from casual users. This prepares pip 21.1 for
Temporarily set the new "Value for ... does not match" location warnings level to DEBUG, to hide them from casual users. This prepares pip 21.1 for CPython inclusion, while pip maintainers digest the first intake of location mismatch issues for the distutils-sysconfig transition. (#9912)
This change fixes a bug on Python <=3.6.1 with a Typing feature added in 3.6.2 (#9831)
Fix compatibility between distutils and sysconfig when the project name is unknown outside of a virtual environment. (#9838)
Fix Python 3.6 compatibility when a PEP 517 build requirement itself needs to be built in an isolated environment. (#9878)
Temporarily set the new “Value for … does not match” location warnings level to DEBUG , to hide them from casual users. This prepares pip 21.1 for CPython inclusion, while pip maintainers digest the first intake of location mismatch issues for the distutils - sysconfig transition. ( #9912 )
This change fixes a bug on Python <=3.6.1 with a Typing feature added in 3.6.2 ( #9831 )
Fix compatibility between distutils and sysconfig when the project name is unknown outside of a virtual environment. ( #9838 )
Fix Python 3.6 compatibility when a PEP 517 build requirement itself needs to be built in an isolated environment. ( #9878 )
Update urllib3 to 1.26.4 to fix CVE-2021-28363
Start installation scheme migration from distutils to sysconfig. A warning is implemented to detect differences between the two implementations to encourage user reports, so we can avoid breakages before they happen.
Add the ability for the new resolver to process URL constraints. (#8253)
Add a feature --use-feature=in-tree-build to build local projects in-place when installing. This is expected to become the default behavior in pip 21.3; see Installing from local packages for more information. (#9091)
Bring back the "(from versions: ...)" message, that was shown on resolution failures. (#9139)
Add support for editable installs for project with only setup.cfg files. (#9547)
Improve performance when picking the best file from indexes during pip install. (#9748)
Warn instead of erroring out when doing a PEP 517 build in presence of --build-option. Warn when doing a PEP 517 build in presence of --global-option. (#9774)
Fixed --target to work with --editable installs. (#4390)
Add a warning, discouraging the usage of pip as root, outside a virtual environment. (#6409)
Ignore .dist-info directories if the stem is not a valid Python distribution name, so they don't show up in e.g. pip freeze. (#7269)
Only query the keyring for URLs that actually trigger error 401. This prevents an unnecessary keyring unlock prompt on every pip install invocation (even with default index URL which is not password protected). (#8090)
Prevent packages already-installed alongside with pip to be injected into an isolated build environment during build-time dependency population. (#8214)
Fix pip freeze permission denied error in order to display an understandable error message and offer solutions. (#8418)
Correctly uninstall script files (from setuptools' scripts argument), when installed with --user. (#8733)
New resolver: When a requirement is requested both via a direct URL (req @ URL) and via version specifier with extras (req[extra]), the resolver will now be able to use the URL to correctly resolve the requirement with extras. (#8785)
New resolver: Show relevant entries from user-supplied constraint files in the error message to improve debuggability. (#9300)
Avoid parsing version to make the version check more robust against lousily debundled downstream distributions. (#9348)
--user is no longer suggested incorrectly when pip fails with a permission error in a virtual environment. (#9409)
Fix incorrect reporting on Requires-Python conflicts. (#9541)
Make wheel compatibility tag preferences more important than the build tag (#9565)
Fix pip to work with warnings converted to errors. (#9779)
SECURITY: Stop splitting on unicode separators in git references, which could be maliciously used to install a different revision on the repository. (#9827)
Update urllib3 to 1.26.4 to fix CVE-2021-28363
Remove contextlib2.
Upgrade idna to 3.1
Upgrade pep517 to 0.10.0
Upgrade vendored resolvelib to 0.7.0.
Upgrade tenacity to 7.0.0
Update "setuptools extras" link to match upstream. (#4822829F-6A45-4202-87BA-A80482DF6D4E)
Improve SSL Certificate Verification docs and --cert help text. (#6720)
Add a section in the documentation to suggest solutions to the pip freeze permission denied issue. (#8418)
Add warning about --extra-index-url and dependency confusion (#9647)
Describe --upgrade-strategy and direct requirements explicitly; add a brief example. (#9692)
commands: debug: Use packaging.version.parse to compare between versions. (#9461 _)
commands: debug: Use packaging.version.parse to compare between versions. (#9461)
New resolver: Download and prepare a distribution only at the last possible moment to avoid unnecessary network access when the same version is already installed locally. (#9516)
Upgrade packaging to 20.9
Remove support for VCS pseudo URLs editable requirements. It was emitting deprecation warning since version 20.0. (#7554 _)
Drop support for Python 2. (#6148)
Remove support for legacy wheel cache entries that were created with pip versions older than 20.0. (#7502)
Remove support for VCS pseudo URLs editable requirements. It was emitting deprecation warning since version 20.0. (#7554)
Modernise the codebase after Python 2. (#8802)
Drop support for Python 3.5. (#9189)
Remove the VCS export feature that was used only with editable VCS requirements and had correctness issues. (#9338)
Add --ignore-requires-python support to pip download. (#1884)
New resolver: Error message shown when a wheel contains inconsistent metadata is made more helpful by including both values from the file name and internal metadata. (#9186)
Fix a regression that made pip wheel do a VCS export instead of a VCS clone for editable requirements. This broke VCS requirements that need the VCS information to build correctly. (#9273)
Fix pip download of editable VCS requirements that need VCS information to build correctly. (#9337)
Upgrade msgpack to 1.0.2.
Upgrade requests to 2.25.1.
pip wheel now verifies the built wheel contains valid metadata, and can be installed by a subsequent pip install. This can be disabled with --no-verif
pip wheel now verifies the built wheel contains valid metadata, and can be installed by a subsequent pip install. This can be disabled with --no-verify. (#9206)
Improve presentation of XMLRPC errors in pip search. (#9315)
Fixed hanging VCS subprocess calls when the VCS outputs a large amount of data on stderr. Restored logging of VCS errors that was inadvertently removed in pip 20.2. (#8876)
Fix error when an existing incompatibility is unable to be applied to a backtracked state. (#9180)
New resolver: Discard a faulty distribution, instead of quitting outright. This implementation is taken from 20.2.2, with a fix that always makes the resolver iterate through candidates from indexes lazily, to avoid downloading candidates we do not need. (#9203)
New resolver: Discard a source distribution if it fails to generate metadata, instead of quitting outright. This implementation is taken from 20.2.2, with a fix that always makes the resolver iterate through candidates from indexes lazily, to avoid downloading candidates we do not need. (#9246)
Upgrade resolvelib to 0.5.4.
Your coding agent can read these notes before it upgrades. Set up the MCP server →