NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1439 most downloaded on PyPI
RestrictedPython is a defined subset of the Python language which allows to provide a program input into a trusted environment.
Last release 1 months ago
19 Aug 2026
Release timing varies
gaps range from 9 days to 7 months
Most releases are documented
notes for 21 of 25 stable releases
11 versions withdrawn
withdrawn after publishing
19 years old
47 releases · first in 2007
Officially support Python 3.15 after performing a security audit of its changes:
Officially support Python 3.15 after performing a security audit of its changes:
Disallow lazy import statements (PEP 810) as they bypass a guarded __import__.
Disallow unpacking in comprehensions (PEP 798) as it bypasses the _getiter_ guard.
Add the attributes of asynchronous generator objects (ag_await, ag_frame, ag_code) to the restricted names in INSPECT_ATTRIBUTES as they were missing there.
Fix the combined coverage report: the coverage tox environment now combines the coverage data of all supported Python versions instead of measuring a single one, and enforces 100 % coverage. The broken combined-coverage environment has been removed, as it erased the data it was supposed to combine.
One column per quarter.
Prevent access to string.Formatter and its unsafe traversal methods via safer_getattr. (CVE-2026-76825)
Add type annotations to the package code. For clarification, restricted Python code does not support type annotations.
Allow ast.Module, ast.Expression and ast.Interactive as body in compile_restricted_function
Disallow mode="function" in compile_restricted (it never worked).
Prevent access to string.Formatter and its unsafe traversal methods via safer_getattr. (CVE-2026-76825)
Switch to PyPI Trusted Publishing for the package release process
Switch to PyPI Trusted Publishing for the package release process
Also validate positional-only argument names (parameters before /) so they cannot start with an underscore, closing a sandbox escape where a positional-only parameter could shadow an injected protected name such as _getattr_, _getitem_, _write_ or _print_.
Allow to use the package with Python 3.15 -- Caution: No security audit has been done so far.
Allow to use the package with Python 3.15 -- Caution: No security audit has been done so far.
Remove documentation that appears to promote unsupported direct guards usage.
Remove documentation that appears to promote unsupported direct guards usage.
Move package metadata from setup.py to pyproject.toml.
Drop support for Python 3.9.
Allow the ... (Ellipsis) statement.
tagging release 8.1
Allow to use the package with Python 3.14 including t-string support.
Nothing published for this version
- This feature was introduced into RestrictedPython in version 6.0 for Python 3.11+. (CVE-2025-22153)
Disallow try/except* clauses due to a possible sandbox escape and probable uselessness of this feature in the context of RestrictedPython. In addition, remove ExceptionGroup from safe_builtins (as useful only with try/except*). - This feature was introduced into RestrictedPython in version 6.0 for Python 3.11+. (CVE-2025-22153)
Drop support for Python 3.8.
Update setuptools version pin. (#292)
tagging release 7.4
Allow to use the package with Python 3.13.
Drop support for Python 3.7.
Provide new function RestrictedPython.Guards.safer_getattr_raise. It is similar to safer_getattr but handles its parameter default like getattr, i.e. it raises AttributeError if the attribute lookup fails and this parameter is not provided, fixes #287.
Prevent information leakage via AttributeError.obj and the string module. (CVE-2024-47532)
Increase the safety level of safer_getattr allowing applications to use it as getattr implementation. Such use should now follow the same policy and give the same level of protection as direct attribute access in an environment based on RestrictedPython's safe_builtints.
Prevent information leakage via AttributeError.obj and the string module. (CVE-2024-47532)
Remove unneeded setuptools fossils that may cause installation problems with recent setuptools versions.
Remove unneeded setuptools fossils that may cause installation problems with recent setuptools versions.
Add support for single mode statements / execution.
Fix a potential breakout capability in the provided safer_getattr method that is part of the safer_builtins.
Nothing published for this version
Add support for the matmul (@) operator.
Add support for the matmul (@) operator.
Forbid using some attributes providing access to restricted Python internals. (CVE-2023-37271)
Drop support for Python 3.6.
Officially support Python 3.12.
Prevent DeprecationWarnings from ast.Str and ast.Num on Python 3.12
Forbid using some attributes providing access to restricted Python internals. (CVE-2023-37271)
Fix information disclosure problems through Python's "format" functionality (format and format_map methods on str and its instances, string.Formatter). (CVE-2023-41039)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Backwards incompatible changes ++++++++++++++++++++++++++++++
Drop support for Python 2.7 and 3.5.
Officially support Python 3.11.
Allow to use the Python 3.11 feature of exception groups and except* (PEP 654).
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Avoid deprecation warnings when using Python 3.8+. (#192 _)
Document that __name__ is needed to define classes.
Add support for Python 3.10. Auditing the Python 3.10 change log did not reveal any changes which require actions in RestrictedPython.
Avoid deprecation warnings when using Python 3.8+. (#192)
Nothing published for this version
Add support for (Python 3.8+) assignment expressions (i.e. the := operator)
Add support for (Python 3.8+) assignment expressions (i.e. the := operator)
Add support for Python 3.9 after checking the security implications of the syntax changes made in that version.
Add support for the bytes and sorted builtins (#186)
Document parameter mode for the compile_restricted functions (#157)
Fix documentation for compile_restricted_function (#158)
Breaking changes ++++++++++++++++
Revert the allowance of the ... (Ellipsis) statement, as of 4.0. It is not needed to support Python 3.8. The security implications of the Ellipsis Statement is not 100 % clear and is not checked. ... (Ellipsis) is disallowed again.
Add support for f-strings in Python 3.6+. (#123)
Breaking changes ++++++++++++++++
Changes since 3.6.0:
The compile_restricted* functions now return a namedtuple CompileResult instead of a simple tuple.
Drop the old implementation of version 3.x: RCompile.py, SelectCompiler.py, MutatingWorker.py, RestrictionMutator.py and tests/verify.py.
Drop support for long-deprecated sets module.
RestrictedPython now ships with a default implementation for _getattr_ which prevents from using the format() method on str/unicode as it is not safe, see: http://lucumr.pocoo.org/2016/12/29/careful-with-str-format/
Caution: If you do not already have secured the access to this format() method in your _getattr_ implementation use RestrictedPython.Guards.safer_getattr() in your implementation to benefit from this fix.
Mostly complete rewrite based on Python AST module. [loechel (Alexander Loechel), icemac (Michael Howitz), stephan-hof (Stephan Hofmockel), tlotze (Thomas Lotze)]
Add support for Python 3.5, 3.6, 3.7.
Add preliminary support for Python 3.8. as of 3.8.0a3 is released.
Warn when using another Python implementation than CPython as it is not safe to use RestrictedPython with other versions than CPyton. See https://bitbucket.org/pypy/pypy/issues/2653 for PyPy.
Allow the ... (Ellipsis) statement. It is needed to support Python 3.8.
Allow yield and yield from statements. Generator functions would now work in RestrictedPython.
Allow the following magic methods to be defined on classes. (#104) They cannot be called directly but by the built-in way to use them (e. g. class instantiation, or comparison):
__init__
__contains__
__lt__
__le__
__eq__
__ne__
__gt__
__ge__
Imports like from a import * (so called star imports) are now forbidden as they allow to import names starting with an underscore which could override protected build-ins. (#102)
Allow to use list comprehensions in the default implementation of RestrictionCapableEval.eval().
Switch to pytest as test runner.
Bring test coverage to 100 %.
Improve .Guards.safer_getattr to prevent accessing names starting with underscore. (#142)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add name check for names assigned during imports using the from x import y format.
Add name check for names assigned during imports using the from x import y format.
Add test for name check when assigning an alias using multiple-context with statements in Python 2.7.
Add tests for protection of the iterators for dict and set comprehensions in Python 2.7.
Remove support for DocumentTemplate.sequence - this is handled in the DocumentTemplate package itself.
Remove support for DocumentTemplate.sequence - this is handled in the DocumentTemplate package itself.
Remove a testing dependency on zope.testing.
Remove a testing dependency on zope.testing.
Filter DeprecationWarnings when importing Python's sets module.
Add tests for Utilities module.
Filter DeprecationWarnings when importing Python's sets module.
Drop legacy support for Python 2.1 / 2.2 (__future__ imports of nested_scopes / generators.).
Drop legacy support for Python 2.1 / 2.2 (__future__ imports of nested_scopes / generators.).
Fix deprecation warning: with is now a reserved keyword on Python 2.6. That means RestrictedPython should run on Python 2.6 now. Thanks to Ranjith Kan…
Fix deprecation warning: with is now a reserved keyword on Python 2.6. That means RestrictedPython should run on Python 2.6 now. Thanks to Ranjith Kannikara, GSoC Student for the patch.
Add tests for ternary if expression and for with keyword and context managers.
Changed homepage URL to the PyPI site
Changed homepage URL to the PyPI site
Improve README.txt.
Your coding agent can read these notes before it upgrades. Set up the MCP server →