github astral-sh/ty 0.0.84

4 hours ago

Release Notes

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

Install ty 0.0.84

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ty/releases/download/0.0.84/ty-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ty/releases/download/0.0.84/ty-installer.ps1 | iex"

Download ty 0.0.84

File Platform Checksum
ty-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
ty-x86_64-apple-darwin.tar.gz Intel macOS checksum
ty-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
ty-i686-pc-windows-msvc.zip x86 Windows checksum
ty-x86_64-pc-windows-msvc.zip x64 Windows checksum
ty-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
ty-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
ty-powerpc64-unknown-linux-gnu.tar.gz PPC64 Linux checksum
ty-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
ty-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
ty-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
ty-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
ty-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
ty-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
ty-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
ty-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum
ty-arm-unknown-linux-musleabihf.tar.gz ARMv6 MUSL Linux (Hardfloat) checksum
ty-armv7-unknown-linux-musleabihf.tar.gz ARMv7 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/ty

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>

Don't miss a new ty release

NewReleases is sending notifications on new releases.