NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1204 most downloaded on PyPI
A simple, safe single expression evaluator library.
Last release 22 days ago
12 Sep 2026
Release timing varies
gaps range from 2 weeks to 1.9 years
Some releases are documented
notes for 10 of 27 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
27 releases · first in 2014
So the next phase is a 1.1.x stream where it's backwards compatible, BUT with deprecation warnings about any use of the system without opt in to allow…
3 Security improvements:
fixed in:
#199
This highlights again the need to switch to allow-lists rather than deny-lists for security on simpleeval.
So the next phase is a 1.1.x stream where it's backwards compatible, BUT with deprecation warnings about any use of the system without opt in to allow-lists, and then a 2.x release where it's required.
A few other process improvements that were helpful in getting those fixes in:
Full Changelog: 1.0.7...1.0.8
One column per quarter.
Performance fixes for problems introduced by security fixes in 1.0.5 / 1.0.6
Performance fixes for problems introduced by security fixes in 1.0.5 / 1.0.6
unable to pass unhashable items as kwargs introduced by security fixes in 1.0.5 this morning.
Tiny bugfix release.
Fixes:
Fixes Security issues with "dangerous" modules & functions leaking through as attributes of other names, see:
Fixes Security issues with "dangerous" modules & functions leaking through as attributes of other names, see:
Fixes CVE-2026-32640
Breaking Change:
ModuleWrapper, or subclass SimpleEval to bypass it.Nothing published for this version
Fix support for 3.14 (deprecated features actually being removed, so getattr use was incorrect).
getattr use was incorrect).getattr use was incorrect).No functional changes - but release with the pip version removed from requirements.
No functional changes - but release with the pip version removed from requirements.
Update the packaging / build after the 1.0.0 release.
Update the packaging / build after the 1.0.0 release.
No new features since 1.0.0
See the 1.0.0 release notes for details.
…now this draws a line in what's possible without breaking changes.
_frame methods.KeyError when names not foundSo 1.0 as a 'this is the way it works'. It's been basically stable for years now, I've just never called it that - hopefully now this draws a line in what's possible without breaking changes.
There's lots of ideas to make it better - but that's better as a new 2.x branch with allowing a few breaking changes (mostly for security).
Better handling of empty strings passed as input.
.parse from #115{} operators / functions ( #75 via #123 )x = {"a": 1, "b": 2, **c}KInd of hoping this is the last 0.9 release, and I find time to stablize as 1.0, and start the 2.0 work some time soon...
KInd of hoping this is the last 0.9 release, and I find time to stablize as 1.0, and start the 2.0 work some time soon...
Changelog:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →