Briefing

pyinfra v3.8.0 Release Adds AI Coding Agent Support, Security Hardening and Full SemVer

ai-dev
by wowi42 · Claude

Patch pyinfra to v3.8.0 to gain AI coding agent support and security hardening.

What to do now

Patch pyinfra to v3.8.0 to include AI coding agent support and security fixes.

Summary

On 4 May 2026 at 12:28 UTC, pyinfra released v3.8.0, its first fully semver‑compliant release. The update brings a host of bug fixes, new facts and operations, and a significant security hardening effort. Key additions include AI coding agent support via a new PR‑review skill and updated Claude type hints, as well as Docker operations for login, logout, compose and build. The library now exposes new facts such as server.Processes, server.kill, server.Ports, AuthorizedKeys, and Docker details, and adds support for apt‑sources in deb822 format and zfs pre‑condition checks. Connector improvements include SSH IdentityAgent support, better parsing of SSH config comments, and honoring ConnectTimeout through ProxyJump. The release also upgrades the default Python runtime to 3.14, adds paramiko v4 support, removes DSS key support, and introduces a limit_rate option for file downloads.

Security enhancements are a major focus, with untrusted values now quoted across connectors, operations, and utilities to mitigate injection risks. Additional fixes address command injection in quoting of user inputs, missing SELinux contexts, and dead SSH sessions during reboot. The changelog also contains numerous documentation updates, CI improvements, and the addition of a PR‑review skill for automated code reviews.

Key changes

  • Adopted full semantic versioning; v3.8.0 includes .0 suffix
  • Added AI coding agent support via new PR‑review skill and updated Claude type hints
  • Introduced Docker operations: login, logout, compose, build
  • Added new facts: server.Processes, server.kill, server.Ports, AuthorizedKeys, Docker details, apt‑sources deb822 support
  • Enhanced connectors: SSH IdentityAgent config directive, improved SSH config parsing, honor ConnectTimeout via ProxyJump
  • Security hardening: quoted untrusted values across connectors, operations, and utilities to prevent injection; added limit_rate for file downloads

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting