NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2037 most downloaded on PyPI
Scan dependencies for known vulnerabilities and licenses.
Last release 3 months ago
29 May 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
10 years old
118 releases · first in 2016
Nothing published for this version
Nothing published for this version
Removed the upper clause restriction for the packaging dependency
One column per quarter.
Started to use schema 2.0 of the PyUp vulnerability database.
Pinned packaging dependency to a compatible range.
Removed LegacyVersion use; this fixes the issue with packaging 22.0.
Fixed recursive requirements issue when an unpinned package is found.
Fixed #423: Bare output includes extra line in non-screen output with no vulnerabilities.
Add safety.alerts module to setup.cfg
safety.alerts module to setup.cfgSafety Alerts: GitHub PRs and GitHub issues support by @cb22 in https://github.com/pyupio/safety/pull/411
Full Changelog: https://github.com/pyupio/safety/compare/2.2.1...2.3.0
safety alert subcommand.Pull from Master by @yeisonvargasf in https://github.com/pyupio/safety/pull/410
Full Changelog: https://github.com/pyupio/safety/compare/2.2.0...2.2.1
Eat stderr messages from git commands. by @tarmack in https://github.com/pyupio/safety/pull/399
Full Changelog: https://github.com/pyupio/safety/compare/2.1.1...2.2.0
Fix crash when running on systems without git present (Thanks @andyjones)
It also includes a version field, and telemetry information that would be sent separately. There are no breaking changes in the output.
--disable-audit-and-monitor is not set--disable-audit-and-monitor flag can be set to disable sending a scan's result to pyup.io--project flag can be set to manually specify a project to associate these scans with. By default, it'll autodetect based on the current folder and git.Text & screen output: Upgraded the text and screen outputs, removing the old table style and adding new data and formats to vulnerabilities.
PyUp is excited to release Safety 2.0 CLI and Safety as a GitHub Action!
Compared to previous versions, Safety 2.0 will be a significant update that includes new features and refactors, resulting in breaking changes to some inputs and outputs. The new GitHub Action enables you to configure Python dependency security and compliance scans on your repositories on new commits, new branches, pull requests, and more.
--output flag replaces --bare, --text, --screen, and --json flags. In this new release, examples would be: --output json or --output bare.--continue-on-error flag suppresses non-zero exit codes to force pass CI/CD checks, if required.--debug flag allows for a more detailed output.--disable-telemetry flag has been added to disable telemetry data--policy-file flag to include a local security policy file. This file (called .safety-policy.yml, found in either the root directory where Safety is being run or in a custom location) is based on YAML 1.2 and allows for:
check/license/review), and the Safety options used (without their values). Users can disable this functionality by adding the --disable-telemetry flag.Removed the click context use, so Safety can be used in non-CLI cases
Fixed issue with paddings and margins at specific console outputs like Github actions console
Fixed issue in the Screen and Text report due to the remediations rendering for the users using an API Key
Compared to previous versions, Safety 2.0 will be a significant update that includes new features and refactors, resulting in breaking changes to some…
Vastly improved text, screen, and JSON outputs that include more detailed information about each scan and each vulnerability found.
This version of Safety is not stable; it is only a beta, pre-release version. Compared to previous versions, Safety 2.0 will be a significant update that includes new features and refactors, resulting in breaking changes to some inputs and outputs. See the changelogs (CHANGELOG.md) and readme update for more detailed information.
The most notable high-level changes are:
This work was done by @yeisonvargasf 👏
--output flag replaces --bare, --text, --screen, and --json flags. In this new release, examples would be: --output json or --output bare.--continue-on-error flag suppresses non-zero exit codes to force pass CI/CD checks, if required.--debug flag allows for a more detailed output.--disable-telemetry flag has been added to disable telemetry data--policy-file flag to include a local security policy file. This file (called .safety-policy.yml, found in either the root directory where Safety is being run or in a custom location) is based on YAML 1.2 and allows for:
check/license/review), and the Safety options used (without their values). Users can disable this functionality by adding the --disable-telemetry flag.Avoid 1.10.2post1 bug with pyup updates
Nothing published for this version
Provide CVSS values on full report for CVEs (requires a premium PyUp subscription)
Reduced Docker image and Binary size
Added README information about Python 2.7 workaround
Binary adjustments and enhancements on top of reported vulnerability
Fixed a hidden import caused the binary to produce errors on Linux.
Safety now supports binary releases.
Safety now supports binary releases.
Wrap words in full report (Thanks @mgedmin)
Update cryptography dependency from version 1.9 to version 2.3 due to security vulnerability
Nothing published for this version
Allows both unicode and non-unicode type encoding when parsing requriment files
- Fixed unicode error
Fixed a packaging error with the dparse dependency
- Safety now support pip 10
Safety now shows a filename if it finds an unpinned requirement. Thanks @nnadeau
Fixed an error that caused the CLI to fail on requirement files/stdin.
Added an indicator which DB is currently used
Fixed an error on unpinned VCS requirements. This is a regression, see https://github.com/pyupio/safety/issues/72
Internal refactoring. Removed dependency on setuptools and switched to the new dparse library.
Fixed a bug where absence of stty was causing a traceback in safety check on Python 2.7 for Windows.
stty was causing a traceback in safety check on Python 2.7 for Windows.Added the ability to ignore one (or multiple) vulnerabilities by ID via the --ignore/-i flag.
--ignore/-i flag.Added a couple of help text to the command line interface.
--bare output format.Added JSON as an output format. Use it with the --json flag. Thanks @Stype.
--json flag. Thanks @Stype.Fixed terminal size detection when fed via stdin.
Compatibility release. Safety should now run on macOs, Linux and Windows with Python 2.7, 3.3-3.6. Python 2.6 support is available on a best-effort ba
Fixed another error on Python 2. The fallback function for get_terminal_size wasn't working correctly.
Fixed an error on Python 2, FileNotFoundError was introduced in Python 3.
Added an API Key option that uses pyup.io's vulnerability database.
Made the requirements parser more robust. The parser should no longer fail on editable requirements and requirements that are supplied by package URL.
Fixed a bug where not all requirement files were read correctly.
Added option to read requirements from files.
Filter out non-requirements when reading from stdin.
Added option to read from stdin.
Fix import errors on python 2.6 and 2.7.
- Fix packaging bug.
- Releasing first prototype.
- First release on PyPI.
Your coding agent can read these notes before it upgrades. Set up the MCP server →