NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1876 most downloaded on PyPI
Scan dependencies for known vulnerabilities and licenses.
Last release 4 months ago
29 May 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
10 years old
118 releases · first in 2016
fix: support SFTY-format vulnerability IDs in policy files
chore: update system-scan details in the README
One column per quarter.
bump: version 3.8.0b3 → 3.8.0b4
bump: version 3.8.0b2 → 3.8.0b3
bump: version 3.8.0b1 → 3.8.0b2
bump: version 3.8.0b0 → 3.8.0b1
feat: [WARNING: behavior change] migrate to httpx with explicit TLS/proxy configuration
fix: npm ecosystem check on render package details
bump: version 3.7.0b4 → 3.7.0b5
bump: version 3.7.0b3 → 3.7.0b4
bump: version 3.7.0b2 → 3.7.0b3
fix: replace deprecated pkg_resources with importlib.metadata
chore: prepare for stable release
refactor: firewall tools and parsers
fix: Import rich_utils as a module and don't access as an attribute.
chore: relax psutil version constraints
chore: prepare for stable release
fix: issues with encoding in all the outputs
## What's Changed * bump: version 3.5.2b1 → 3.5.2 (03e057b) * fix: resolve logger warnings
bump: version 3.5.2b0 → 3.5.2b1
chore: update CHANGELOG.md with note
fix: add missing uv index env var for auth
fix: poetry error on source and parsing pyproject.toml
bump: version 3.5.0b1 → 3.5.0b2
bump: version 3.5.0b0 → 3.5.0b1
bump: version 3.4.1b0 → 3.5.0b0
fix: the unix-like alias interceptors
chore: update dependencies licenses list
bump: version 3.4.0b8 → 3.4.0b9
bump: version 3.4.0b7 → 3.4.0b8
bump: version 3.4.0b6 → 3.4.0b7
bump: version 3.4.0b5 → 3.4.0b6
bump: version 3.4.0b4 → 3.4.0b5
bump: version 3.4.0b3 → 3.4.0b4
bump: version 3.4.0b2 → 3.4.0b3
bump: version 3.4.0b1 → 3.4.0b2
bump: version 3.4.0b0 → 3.4.0b1
Merge pull request #695 from pyupio/feature/firewall-organization
chore: use the new ci workflow badge
chore: add a refresh notice utility script and update the NOTICE file
ci: rename assets on release to avoid conflicts
ci: fetch tags and history on bump workflow
Package version upgrade for psutil and filelock
Remove email verification for running scans
Add CVE Details and Single-Key Filtering for JSON Output in safety scan
Migrate to PyPI Trusted Publisher for Automated Package Deployment
Support for scanning pyproject.toml files
fix: clarify-vulnerabilities-found/ Fixed the issue where the vulnerabilities
feat: enhance version comparison logic for check-updates command
fix/increase-auth-timeout: increase timeout to 5s
docs(contributing): add CONTRIBUTING.md with guidelines for contributors
Add Table of Contents to README.md
Handle get_from_cache=None and ensure directory exists
get_from_cache=None and ensure directory exists (#538)install_requires (#538)Increase request timeout to 30 seconds
fix: include scan template in build
fix: include all templates in the manifest
Added note on hiring and careers page link by @mwermuth in https://github.com/pyupio/safety/pull/510
Full Changelog: https://github.com/pyupio/safety/compare/3.1.0...3.2.0
feat: add headless auth by @yeisonvargasf in https://github.com/pyupio/safety/pull/508
Full Changelog: https://github.com/pyupio/safety/compare/3.0.1...3.1.0
update readme links to the new Github action by @yeisonvargasf in https://github.com/pyupio/safety/pull/493
Full Changelog: https://github.com/pyupio/safety/compare/3.0.0...3.0.1
…to core features, new capabilities, and breaking changes from 2.x.
check command, including automatic Python project scanning, native support for Poetry and Pipenv files, Python virtual environment folders, and more granular configuration options.safety check. To migrate a Safety 2.x policy, see Migrating from Safety 2.x to Safety CLI 3.safety check with a more powerful and easier to use command. The scan command:report field.safety check command can still be used with the API key --key argument, and scan and system-scan commands should also besafety check command still supports and relies on the policy schema from safety 2.3.5 and below, meaning no changes are required when migrating to safety 2.x to Safety 3.0.0 when only using the safety check command.scan and system-scan commands.safety check command, since this is now replaced by safety scan, a more comprehensive scanning command. The check command will continue receiving maintenance support until June 2024.safety alert command, which works in tandem with the safety check command. Safety alert functionality is replaced by Safety Platform. The alert command will continue receiving maintenance support until June 2024.safety validate will assume 3.0 policy file version by default.Your coding agent can read these notes before it upgrades. Set up the MCP server →