NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2115 most downloaded on PyPI
Generate locked-down AWS IAM Policies
Last release 5 months ago
14 Apr 2026
Release timing varies
gaps range from 2 weeks to 9 months
Most releases are documented
notes for 51 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
85 releases · first in 2019
Nothing published for this version
drop Python 3.9 support @gruebel
One column per quarter.
Nothing published for this version
Bump pypa/gh-action-pypi-publish from 1.12.4 to 1.13.0 @[dependabot[bot]]
drop Python 3.8 support @gruebel
Updates database @github-actions
add sanity checks to validate the package @gruebel
remove deprecated code @gruebel
Bump actions/setup-python from 5.1.0 to 5.1.1 @dependabot
replace linters with ruff @gruebel
Updates database @github-actions
Bump actions/checkout from 3.6.0 to 4.0.0 @dependabot
Updates database @github-actions
update GHA files and add Python version test CI @gruebel
Updates database @github-actions
Making one last version publish for @samchecc
Making one last version publish for @samchecc
Updates database @github-actions
Updates database @github-actions
Update dependencies and fix ReadTheDocs build @kmcquade
CONTRIBUTING.md that links to the docs @agilgur5 (#398)pip3 install -r docs/requirements.txt as well @agilgur5 (#397)Updates database @github-actions
Update database again @kmcquade
Updates database @github-actions
Updates database @github-actions
Turn IAM definition log level into debug instead of info
Fix unit tests from newest scraping data @kmcquade
Nothing published for this version
Nothing published for this version
Nothing published for this version
Replace --wildcard-only with --resource-type "\*" in README @matty-rose
Updates database @github-actions
Update IAM definition @kmcquade
Adds per-Service Authorization URL to IAM Definition and associated query method @kmcquade
Update access levels, add Makefile, update IAM definition, update dependencies @kmcquade
Updates database @github-actions
Add method to get links to all AWS Actions @kmcquade
Adds hyperlinks to AWS IAM Action metadata. Adds new query for get\_api\_documentation\_link\_for\_action @kmcquade
Adds support for Terraform 0.13 @kmcquade
Change minimize to a boolean flag with an option minimize-length argument @dgubitosi
Minimization is improved by grouping results based on ARNs
--resource-type flag added to policy_sentry query action-table command (Fixes #255)get_statement_from_policy_using_sid, get_sid_names_from_policy to make it easier to future-proof unit tests that rely on the ever-changing AWS IAM data.get_actions_for_service (Fixes #245)create_policy_sid_namespace (Fixes #266)Speed improvements: The IAM definition is now a dictionary instead of a list. This is a breaking change if you use the raw IAM definition
write-policy --fmt yaml is now supportedBackend improvements:
Fixes issue with querying condition keys
Nothing published for this version
Fixed issue where query command was not leveraging local database
Nothing published for this version
Fixed query command for policy_sentry query action-table --service s3 --access-level read --wildcard-only --fmt yaml - previously was not transforming
policy_sentry query action-table --service s3 --access-level read --wildcard-only --fmt yaml - previously was not transforming user input properly.Nothing published for this version
Adds the ability to exclude some actions from the resulting policy.
Adds the ability to exclude some actions from the resulting policy.
Nothing published for this version
Adjusted logging level to some functions to reduce noise when leveraging as a library.
Adjusted logging level to some functions to reduce noise when leveraging as a library.
Added get_matching_raw_arn query function
get_matching_raw_arn query function (#169)get_actions_matching_arn query functionAdded logging for Query functions (#161) Added get_expanded_policy function and moved some of the analysis.analyze functions to analysis.expand (Fixes
Added logging for Query functions (#161) Added get_expanded_policy function and moved some of the analysis.analyze functions to analysis.expand (Fixes #164) Fixed analyze_by_access_level function (Fixes #162)
Fixes to scraping given AWS restructuring of Actions Resources and Condition Keys page
Fixed issue where service-wide wildcard-only actions were overwriting each other (#155). This affected the write-policy command
Policy Sentry is now 10x faster!!
Add skip-resource-constraints feature for CRUD mode (Fixes #145)
Changed get_actions_that_support_wildcard_arns_only and get_actions_at_access_level_that_support_wildcard_arns_only to accept "all" as input to the se
Changed get_actions_that_support_wildcard_arns_only and get_actions_at_access_level_that_support_wildcard_arns_only to accept "all" as input to the service parameter. This allows you to get results across all AWS service prefixes.
Removed write-policy-dir command.
Minor fix for kmsKey ARN type under imagebuilder service. Fixes #114
Fix redshift:getclustercredentials override
-v debug instead of --log-level DEBUGBreaking change and new: Template is modified again. This allows easy additions of wildcard-only actions with access levels specific to services (such…
--minimize is specified for write-policy, it will give me lowercase. Otherwise, it will be UpperCamelCase. Fixes #124.Your coding agent can read these notes before it upgrades. Set up the MCP server →