NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1178 most downloaded on PyPI
Python Development Workflow for Humans.
Last release 1 months ago
20 Aug 2026
Release timing varies
gaps range from 1 weeks to 5 months
Some releases are documented
notes for 24 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
10 years old
421 releases · first in 2017
Parallel index manifest prefetching ( PIPENV_PREFETCH_INDEX_MANIFESTS ): New experimental feature that fetches package index manifests concurrently du
PIPENV_PREFETCH_INDEX_MANIFESTS): New experimental feature that fetches package index manifests concurrently during lock operations, significantly reducing resolution time for large dependency setsParsedManifestCache): JSON-on-disk cache with TTL and atomic writes to avoid redundant index fetches across lock operationsverify_ssl fan-out for prefetcher: Each index source now independently respects its SSL verification and certificate settings during parallel prefetchpeek_etag stale-cache short-circuit: Resolver can now skip full manifest fetches when ETags indicate cached data is still freshprefetch_index_manifests setting: New boolean configuration option to enable/disable the parallel prefetch featureProject: Internal refactor completing Initiative D; project.build_script and related attributes now live on project.pipfileProject: Lockfile state management is now a dedicated subsystemunpack_url / get_http_url moved to pipenv/utils/unpack.py; legacy requirementslib.py removedPipfile.lock pins are fed as pip constraints on warm relock to speed up re-locking (reverted and re-landed with fixes)os.replace is retried on ERROR_ACCESS_DENIED with a wall-clock budget, fixing cache write failures on Windowsresolver_backend is now correctly plumbed through the venv_resolve_deps call chainproject.build_script call sites migrated to project.pipfile.build_scripttest_lockfile_location_is_pipfile_plus_lock made OS-portableInstallCommand, unpack, Downloader, network imports) to improve startup performance🔗 Full Changelog: v2026.7.1...v2026.8.0
One column per quarter.
Fixed host package leakage into project installs, preventing system-level packages from incorrectly being available in virtual environments
🔗 Full Changelog: v2026.7.0...v2026.7.1
Updated pip and cryptography dependencies to address security vulnerabilities
PIPENV_RESOLVER_TIMEOUT_S environment variable, making hung resolver processes recoverableDiagnostics.resolver_log with resolve records for improved debuggingpython_version = "3") in environment markersresolve_for_pipenv function, simplifying the resolver architectureResolverRequest/ResolverResponse schemas, improving protocol stability and error surfacingold_lock_data initialization)do_init so that ignore_pipfile/skip_lock flags are only pinned during initialization, not propagated to dependency installationSources.all to always return a listis_virtual_environment to tolerate virtual environment directories without a bin/Scripts subdirectorysys.path before importing the schema moduleresolved_default_deps as a dict rather than a list-r flag missing from README requirements.txt examplecheck command behaviors targeting the 2027 major release🔗 Full Changelog: v2026.6.2...v2026.7.0
Support cool-down-period configuration in the [pipenv] section of the Pipfile
cool-down-period configuration in the [pipenv] section of the Pipfile.netrc; environment variables in pylock source URLs are now expanded correctlypipenv update with no packages specifiedplette vendor dependency to 2.2.1idna dependency in the pip group🔗 Full Changelog: v2026.6.1...v2026.6.2
Prevent mutation of cached parsed Pipfile data during dependency locking, resolving potential issues with corrupted lock state across operations
🔗 Full Changelog: v2026.6.0...v2026.6.1
Strip credentials from pip argument vectors to prevent credential exposure in logs and process listings (GHSA-8xgg-v3jj-95m2)
data_filter fallback to prevent path traversal during package installation (GHSA-p4qx-p8p6-4gjf)git+ssh package sources in PipfilePIPENV_PROJECT_DIR not being expanded correctly in Pipfile script definitionspipenv shell breaking terminal input echo after exittarget_marker_version helper alias for backwards compatibility_target_marker_environment returning incorrect value when allow_global=Truepygments from 2.19.2 to 2.20.0pytest (development dependency)🔗 Full Changelog: v2026.5.2...v2026.6.0
Fixed pipenv audit --locked failing when used with Pipfile.lock and the legacy shell completion environment variable
pipenv audit --locked failing when used with Pipfile.lock and the legacy shell completion environment variableargcomplete instead of the legacy implementation🔗 Full Changelog: v2026.5.1...v2026.5.2
Resolved CLI regressions introduced by the argparse migration, including broken command-line options and argument handling
fork_compat history test on Windows where pexpect.spawn is unavailable, improving cross-platform test reliabilitypygments dependency from 2.19.2 to 2.20.0 in examples🔗 Full Changelog: v2026.5.0...v2026.5.1
Add "Did You Mean" suggestions for mistyped subcommands, helping users quickly identify and correct typos in CLI commands
click and click_didyoumean, reducing bundled dependencies in favor of external packagesimportlib-metadata and zipp following Python 3.9 end-of-lifecached_property Python 3.7 compatibility fallbackdependency_groups markers before passing dependencies to pip during locking, preventing resolution errorsdependency_groups markers from being written on pylock re-generationPipenvException calls super().__init__() so str(exc) returns the properly formatted message🔗 Full Changelog: v2026.4.0...v2026.5.0
--extras CLI option : Specify optional dependency categories directly from the command line
--extras CLI option: Specify optional dependency categories directly from the command line--exclude-index flag for requirements command: Exclude index URLs from generated requirements outputPIPENV_PYENV_ONLY environment variable: Restrict Python discovery exclusively to pyenv, ignoring other Python installationsPIPENV_KEYRING_PROVIDER environment variable: Enable Windows Credential Manager and other keyring backends for private index authenticationpython_version: Pipfile now accepts full PEP 440 specifiers (e.g., >=3.10) for Python version constraints[build-system] requires support in Pipfile: Define build system requirements directly in Pipfilepipenv sync from pylock.toml: Sync environments using pylock.toml without requiring Pipfile.lockpipenv sync and install --ignore-pipfile now work without a Pipfile present--system flag support improved across multiple commands--all flag for update and upgrade commands fixed to correctly target all packagesproper_case lookup timeout increased from 0.3s to 3s to reduce failures on slow networksPIPENV_VERSION environment variable is now ignored when running --version flagpipenv run argumentspipenv shell now correctly launches bash or PowerShell instead of defaulting to cmdpipenv shell now properly suspends with Ctrl+Z (job control restored)pipenv shell activates correctly even when shell startup scripts produce interactive outputsys_platform shorthand markers: Short-form platform markers are now correctly included in pip requirement linespython_full_version in marker evaluation, including major-only python_version valuespython_full_version specifiers when using the Windows py launcherfile:// URL dependencies: File-scheme dependencies are now correctly recorded during lockingpython_version mismatch with venv: Records the correct Python version when the venv Python and PATH Python disagreedistutils missing fallback: Falls back to sysconfig when distutils is unavailable (Python 3.12+)pip.conf extra-index hash collection: Hashes from pip.conf extra-index URLs are now collected during lockingpip.conf index suppression at install time: Prevents hash mismatch errors caused by pip.conf injecting extra indexes during installindex_lookup is now populated from all Pipfile sections when locking non-default categories--where exit code: Fixed incorrect exit code for the --where flag_create_builtin_venv_cmd: No longer incorrectly prepends a drive letter to Unix paths when run on Windowsvenv when virtualenv fails for non-standard interpretersResolutionTooDeepError: Fixed excessive recursion caused by incorrect marker evaluation during resolutionfix --where exit code: Corrected exit behavior for the requirements --where option🔗 Full Changelog: v2026.2.2...v2026.4.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Top level Pipfile sys_platform markers should be transitive; adds top level platform_machine entries that are also transitive. Marker entries continue
Nothing published for this version
Revert change that caused the credentials in source url issue. #5878
Additional property caching to avoid duplication of sources in the resolver. #5863
Fix regression of hash collection when downloading package from private indexes when the hash is not found in the index href url fragment. #5866
More gracefully handle @ symbols in vcs URLs to address recent regression with vcs URLs. #5849
Fix regression with ssh:// vcs URLs introduced in 2023.8.21 whereby ssh vcs URLs are expected to have at least one @ symbol. #5846
ssh:// vcs URLs introduced in 2023.8.21 whereby ssh vcs URLs are expected to have at least one @ symbol. #5846Add back some relevant caching to increase performance after the major refactor released with 2023.8.19 #5841
2023.8.19 #5841Fix the expected output of the version command. #5838
version command. #5838Fixes numerous reports about extras installs with vcs and file installs; format pip lines correctly to not generate deprecation warnings. #5793
--categories option now works with requirements.txt file. #5722--skip-lock flag which was deprecated, has now been removed to unblock modernizing the pipenv resolver code. #5805Upgrades pip==23.2 which includes everything from the pip changelog. Drops the "install_compatatability_finder" pip internals patch. #5808
pip==23.2 which includes everything from the pip changelog. Drops the "install_compatatability_finder" pip internals patch. #5808PIPENV_RESOLVER_PARENT_PYTHON environment variable to 1 (useful for internal debugging). #5809pythonfinder==2.0.5. #58122023.7.11 (2023-07-11)
Nothing published for this version
Drop the --keep-outdated flag and --selective-upgrade flags that have been deprecated in favor of update/upgrade commands. #5730
Fixes regression on Pipfile requirements syntax. Ensure default operator is provided to requirement lib to avoid crash. #5765
Fix regression with --system flag usage. #5773
--system flag usage. #5773Your coding agent can read these notes before it upgrades. Set up the MCP server →