NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2226 most downloaded on PyPI
Generate locked-down AWS IAM Policies
Last release 5 months ago
14 Apr 2026
Release timing varies
gaps range from 2 weeks to 9 months
Most releases are documented
notes for 51 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
85 releases · first in 2019
One column per quarter.
This leads to less user errors - and helps me out with the improved terraform module.
This leads to less user errors - and helps me out with the improved terraform module.
Quick fix for @jlongman's issue with write-policy - #118
Breaking change: Template format is vastly different. You will have to either pin to an old version or update your templates.
initialize command is now completely optional.analyze command is deprecated and removed. We moved this functionality over to Parliament heredownload-policies command is deprecated and removed.--crud flag for write-policy command. Now users do not have to specify the --crud flag. Policy Sentry will automatically detect the format.analyze and download-policies commands.ArnActionGroup with SidGroup. This will allow us to do conditions, etc. It is also easier to read.write-policy logic using ArnActionGroup is nuked. Now using SidGroup, since that will help us take advantage of condition keys. And it's clean(er).write-policy is easier to call as a method.Now you can skip the long wait under the initialize command - the initialize command finishes instantly. To rebuild the database, run initialize --bui
Now you can skip the long wait under the initialize command - the initialize command finishes instantly. To rebuild the database, run initialize --build, or to build it with the latest AWS docs, use initialize --fetch.
In the last version, if you specified "tagging" in your YML file, the write-policy command was ignoring it. This fixes that.
In the last version, if you specified "tagging" in your YML file, the write-policy command was ignoring it. This fixes that.
database: Fixes #51 - Give the user an error when the database file does not exist (in connect_db function). Except for the case of the initialize fun
get_actions_with_access_level now supports 'all' so you can query literally all IAM actions that have Permissions management or other access levels
get_actions_with_access_level now supports 'all' so you can query literally all IAM actions that have Permissions management or other access levels
arn is now role_arn to avoid confusion when writing templates
arn is now role_arn to avoid confusion when writing templatestag is now tagging to avoid inconsistency when writing templateswrite_policy_with_actions write_policy_with_access_levels can be called directly.get_crud_template_dict and get_actions_template_dict are available so developers can create the templates by calling the library. They can pass that into write_policy_with_actions and write_policy_with_access_levelsPrevious one was oversized and had some stale actions.
Previous one was oversized and had some stale actions.
Write-policy allows template via STDIN
Developers can now leverage Policy Sentry as a python package without needing to build the database from the html docs. Just use db_session = connect_
Developers can now leverage Policy Sentry as a python package without needing to build the database from the html docs. Just use db_session = connect_db('bundled') before passing in commands that require the db_session and you're ready to go. Also moved to a saner subfolder structure
Broke up the guts of get_actions_from_policy_file in the shared/analyze.py file to a separate function, get_actions_from_policy so we can use this out
Broke up the guts of get_actions_from_policy_file in the shared/analyze.py file to a separate function, get_actions_from_policy so we can use this outside of Policy Sentry. See the test_analyze_by_access_level unit test in tests/test_analyze.py for an example.
Added --fetch argument to policy_sentry initialize command.
--fetch argument to policy_sentry initialize command.overrides-resource-policies.yml to specifically identify API calls that modify resource based policies.Analyze functionality now creates a comprehensive report (CSV and raw JSON, and optionally markdown) of IAM actions allowed per policy across multiple
analyze-iam-policy is now analyzeFixed issue where initialize was not working due to db_session being declared outside of a function. This only applied to the last release.
get_links.py and other util scripts are now updated. We no longer have to maintain the big list of service-to-html-names.Query the IAM database directly via CLI using policy_sentry query action-table, policy_sentry query arn-table, or policy_sentry query condition-table
policy_sentry query action-table, policy_sentry query arn-table, or policy_sentry query condition-tables3:CreateBucket, or secretsmanager:CreateSecretMaking a quick fix for that issue so it doesn't block anyone.
Making a quick fix for that issue so it doesn't block anyone.
2019-10-24 Added Added boto3 and botocore to setup.py Cutting a new release to provide a quick fix for those issues This fixes #28 Changed Updated Pipfile.lock Fixed an issue with the list_policies command Fixed the help text for the download-policies --include-unattached flag
analyze-iam-policy Code to create policy-analysis directory, was missing with last release... added it
analyze-iam-policy Code to create policy-analysis directory, was missing with last release... added itaccess-level overrides now includes a TON of overrides.
We can now override Access levels so we aren't entirely dependent upon accurate AWS documentation for proper ACLs. Fixes #8.
policy_sentry/shared/data/access-level-overrides.yml for a preloaded set, based on the current known issues with AWS IAM access levels.Added test cases for YML files that have missing access level blocks - for example, if someone wants to generate a policy that doesn't include "Taggin
download-policies command added
download-policies command added
analyze-iam-policies supports directories toocreate-template command to make policy writing easier (and to avoid copy/paste situations)
create-template command to make policy writing easier (and to avoid copy/paste situations)
Added these services that were previously missing:
Added these services that were previously missing:
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →