NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2159 most downloaded on PyPI
Dump the software license list of Python packages installed with pip.
Last release 1 months ago
31 Aug 2026
Release timing varies
gaps range from 2 weeks to 1.2 years
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
76 releases · first in 2018
Aligned with PEP-749 (formerly PEP-753) regarding typing.TYPE_CHECKING deprecation
v6.0.0b11)A second peek at some of the big changes coming in pip-licenses v6.
Note
This will also, be an opt-in pre-release (via pip install --pre ... (and does not supersede the LTS v5.5.5 yet) A few things are going to change before the final v6 release. See Version 6.x Series for planned work.
piplicenses.py has been split into a modular package with organized submodules:
piplicenses/__init__.py - Main package entry pointpiplicenses/__main__.py - CLI entry pointpiplicenses/cli/ - Command-line argument parsing and configurationpiplicenses/core.py - Core license discovery logicpiplicenses/output/ - Output formatting (tables, JSON, CSV, HTML, etc.)piplicenses/sorting.py - License comparison and filtering utilitiespiplicenses/constants.py - Centralized constants and field definitionspiplicenses/tomli_bridge.py - TOML file handling shimConfiguration object for better type safety and IDE supportpiplicenses.main() entry point moved to piplicenses.__main__.main()--with-license-file → --with-license-files (plural form added)--with-notice-file → --with-notice-files (plural form added)--no-version → --without-version (standardized naming)--no-license-path → --without-license-paths (standardized naming)--with-other-files - Include other licensing-related files--no-file-paths - Suppress all file path outputs--format=expression - Support for PEP-639 license expressionstyping.TYPE_CHECKING deprecationextract_urls() function for comprehensive Project-URL parsinghome-page metadata field for compatibility--with-license-files flag for extracting all license files<thead> and <tbody> tagsmake local-ci-check target for pre-push validationactions/checkout@v7.0.0 (from v6.0.2)actions/attest@v4.1.1 (from v4.1.0)codecov/codecov-action@v7.0.0 (from v6.0.0)actions/upload-artifact@v7.0.1 (from v7.0.0)twine from development dependencies (simplified build process)mypy==1.19.1 for Python 3.9 supportpyproject.toml structure for modern Python packaging standardsNote
This is a beta release. All features and APIs are subject to change before the final 6.0.0 release.
Full Changelog: v-6.0.0a1...v-6.0.0b11
One column per quarter.
Multiple Development (v6 betas) re-joined by @reactive-firewall in #361
Full Changelog: v-6.0.0a1...v-6.0.0b10
Important pip-licenses was NOT impacted by CVE-2025-47273 . pip install pip-licenses>=5 will not have install the affected package setuptools<78.1.1 (…
A sneak peek at some of the changes coming in pip-licenses v6 and some minor documentation corrections.
Note
This will be an opt-in pre-release (via pip install --pre ... (and does not supersede the LTS v5.5.5)
Include with this release is a preview of the next LTS container version via, a long overdue, updated Dockerfile
Important
pip-licenses was NOT impacted by CVE-2025-47273. pip install pip-licenses>=5 will not have install the affected package setuptools<78.1.1 (despite an outdated example in the README.md); Most users should have been unaffected (except possibly on outdated forks?) unless doing very strange (unsupported) things with pip-licenses's source builds like monkey-patching the build logic, then maybe 🙉.
Numerous examples throughout the README.md (which is included in the official distributions, and may worry your favorite security tools) have been updated thanks to work by @matejkloska 🎉
Important
pip-licenses was NOT impacted by CVE-2026-4539 for normal use-cases. pip install pip-licenses>=5 will not install the affected developer package Pypgments; Most users should have been unaffected (except possibly on forked projects).
Fixed false positive of: CVE-2026-4539 reDoS. Removed optional (and historical) use of twine to fix alert.
Important
Furthermore, pip-licenses was NOT impacted by CVE-2026-44432.
Furthermore, pip-licenses was NOT impacted by CVE-2026-44431.
Fixed false positive of CVE-2026-44432. Removed optional (and historical) use of twine to fix alerts.
Fixed false positive of CVE-2026-44431.
Important
🚧 Upgrades are in-progress, please pardon the noisy changes and dust.
--with-*-files (as originally suggested by @johnthagen) plural nomenclature (These initial new flags are currently implemented in a purely stop-gap form (as they are based on the PR stefan6419846/pip-licenses-cli#132 (which was originally a fix for stefan6419846/pip-licenses-cli#8 that @johnthagen is similar to #71 and #242). To completely fix GHI #71 and related, full support of multiple licenses for a single package will become the default. This seemingly small design change will have impacts throughout the entire codebase. But for most users this hopefully will just look like adding an s to the --with-license-file flag (and the plan is to replace the old flag mostly behind the scenes to minimize potential breaking changes) or even no change to usage just a noisy depreciation warning that can be ignored (this re-design is not really about removing any features)
So yeah this would-be the next v5.5.x if not for all that; hence the bump to v6 (alpha))
Full Changelog: v-5.5.5...v-6.0.0a1
Updated cc lines and officially made note of change in maintainers
Expanded typing annotations through-out codebase
prek/pre-commit for CI linting and local developer workflowsFixed a regression in linting via black by deprecating support for python 3.9, closing GHI #264
pyproject.toml with PEP 753pyproject.toml (e.g., packaging metadata) into alignment with PEP 639 and related packaging guidance.
MANIFEST.in to setuptools-scm build logic with better filtering, closing GHI #266black by deprecating support for python 3.9, closing GHI #264
black 26.1.0suggestions to codebase, closing GHI #269Breaking change: The --from=all output now includes the License-Expression value
tomli with builtin tomllib for Python 3.11License-Expression metadata field, see PEP 639--from=expression option--from=all output now includes the License-Expression value--partial and --allow-only if a license matches multiple allowed licenses.--with-license-file option in documentationClarified support for Python 3.12
Fixes "tomli" to be output only with --with-system option
--with-system optionImplement new feature pyproject.toml support
Implement new option --partial-match
--partial-matchMaintain to pass test with wcwidth>=0.2.10
Always terminate --allow-only and --fail-on messages with a newline
--allow-only and --fail-on messages with a newline--output-file with a newlineBetter handling extracting URLs from Project-URL
Project-URLFix to treat package names as normalized as in PEP 503 with --packages and --ignore-packages option
--packages and --ignore-packages optionImplement new option --no-version
--no-versionImplement new option --with-maintainers
--with-maintainers--python--ignore-packages parametersAuthor field is UNKNOWN, the output is automatically completed from Author-emailhome-page field is UNKNOWN, the output is automatically completed from Project-URLNothing published for this version
Nothing published for this version
Nothing published for this version
Support case-insensitive license name matching around --fail-on and --allow-only parameters
--fail-on and --allow-only parametersEscape unicode output (to e.g. {) in the html output
{) in the html outputAdd type annotations and code formatter
Fix "pip-licenses" is missing in output of pip-licenses --with-system option
pip-licenses --with-system optionMigrate Docker base image from Alpine to Debian 11-slim
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Search for path defined in PEP 639 with --with-license-file option
--with-license-file optionSkip directories when detecting license files
* Support pip 21.3 or later
Ignore spaces around --fail-on and --allow-only parameters
--fail-on and --allow-only parametersFix the order in which multiple licenses are output
Handle multiple licenses better with options --fail-on and --allow-only
--fail-on and --allow-onlyPython Software Foundation License, MIT LicensePython Software Foundation License; MIT LicenseImplement new option --packages
--packagesNothing published for this version
Fix license summary refer to --from option
--from optionImproves the readability of the help command
Implement new option --from=all
--from=allImplement new option for use in continuous integration
--fail-on--allow-onlyClarified support for Python 3.9
setup.cfg--from=mixedImplement new option for manage unicode characters
--filter-strings--filter-code-pageFixed the file that is selected when multiple matches are made with LICENSE* with run --with-license-file
LICENSE* with run --with-license-fileImplement new option --with-notice-file
--with-notice-fileLICENCE with run --with-license-fileSuppress errors when opening license files
Implement new option --format=plain-vertical
--format=plain-verticalCOPYING *Better license file open handling in Python 3
Removed migration path to obsolete options
--from-classifier--format-markdown--format-rst--format-confluence--format-html--format-json--no-license-pathSupports compatibility to work with either PTable or prettytable
Implement new option --output-file
--output-fileAdd a help text for --format=json-license-finder option
--format=json-license-finder optionImplement new option --format=json-license-finder
--format=json-license-finderRead license file works well with Windows
Skip parsing of license file for packages specified with --ignore-packages option
--ignore-packages optionImplement new option --format=csv
--format=csvImplement new option --from=mixed as a mixed mode
--from=mixed as a mixed modeImplement new option --from=meta, from=classifier
--from=meta, from=classifierChange warning output to standard error
Supports execution within Docker container
OSI Approved string with multiple licensesYour coding agent can read these notes before it upgrades. Set up the MCP server →