github pypa/pipenv v2026.9.0
Release v2026.9.0

4 hours ago

🤖 AI-Generated Changelog

Added

  • pipenv sync --clean: New flag to automatically uninstall packages that are present in the environment but missing from the lockfile, keeping environments in sync with declared dependencies
  • Pure-Python resolver backend: New experimental --backend CLI flag and [pipenv] resolver_backend Pipfile setting to opt into an alternative pure-Python dependency resolver (Initiative G), featuring:
    • PEP 517 isolated environment builds for sdist metadata extraction
    • PEP 658 metadata fetching with wheel-head fallback
    • Parallel wheel pre-fetch before installation (~30% cold-install speedup)
    • Transitive marker propagation via Requirement.introducing_marker
    • Hash collection from all distfile siblings
    • Yanked release support per PEP 592
  • Per-package config settings: pipenv install now persists configuration settings on a per-package basis, isolating options between packages

Changed

  • Pipfile package name recasing is now opt-in via [pipenv] package_name_case Pipfile setting (previously controlled by PIPENV_RECASE_PIPFILE env var); recasing is disabled by default for performance
  • virtualenv minimum version raised to >=21.14.6
  • Resolver round cap raised to pip's 200_000 to handle complex dependency graphs

Fixed

  • Requirements export: PyPI mirror selection is now honored when exporting requirements, fixing cases where the configured mirror was ignored
  • Dependency markers: not in exclusions for python_version are no longer incorrectly collapsed; legacy not in exclusions are preserved exactly, and == version groups are version-sorted
  • pipenv sync --dry-run: No longer uninstalls packages; all lockfile sections are preserved during dry runs
  • pipenv --envs: Fixed broken documentation URL to point to a valid page
  • Redundant --upgrade flag dropped from pip install calls during sync
  • sdist archive names are now sanitized and urllib3 timeouts are applied correctly
  • Effective resolver backend is now included in the resolution cache key, preventing stale cache hits across backend switches
  • Pure-Python resolver now correctly threads extras through find_matches/get_dependencies and applies pip's narrow requirement selection

Documentation

  • Added note that pipenv sync does not remove packages missing from the lockfile (addressed by new --clean flag)

🔗 Full Changelog: v2026.8.0...v2026.9.0

Don't miss a new pipenv release

NewReleases is sending notifications on new releases.