Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
Gorget continues LLM Guard. Entries up to 0.3.16 describe LLM Guard releases by Protect AI; their issue links point to the archived protectai/llm-guard repository.
[0.5.0] - 2026-09-25
Added
- Your own models (docs):
PromptInjection(injection_labels=[...])for models whose labels are notINJECTION, with several injection categories added up;PromptInjection.detect()returns the score and category.PromptInjection(classifier=...): any callable classifier (scikit-learn, an internal service, a vendor API) instead of a Hugging Face model.AnonymizeandSensitivetakerecognizers(Presidio recognizers or any function wrapped ingorget.plugins.CallableRecognizer) and several NER models inrecognizer_conf;recognizer_conf=[]runs no built-in NER model.make_ner_configdescribes your own NER model.- Custom entity types that only your recognizers, models or regex patterns produce
(
CONTRACT_NUMBER) are detected by default and get their own placeholders. - API server: classifiers, recognizers, NER models and whole scanner classes by import path or
by name from the
gorget.pluginsentry point group; inline NER models in YAML.
- Conversations (docs):
gorget.conversation.scan_conversationchecks a chat history in the OpenAI format: the latest user message, recent user messages together (split instructions), tool results after the latest user message (indirect injection) and, opt-in, the injection risk accumulated over the conversation (ConversationRisk). API endpoints/analyze/conversationand/scan/conversationwith aconversationsection inscanners.yml.
Fixed
PromptInjectioninverted the scores of models whose injection label is not calledINJECTION.AnonymizeandSensitiveaddedCUSTOMto theentity_typeslist passed by the caller.- API server:
AnonymizeandSensitiveignoredrecognizer_confandlanguageand always used the English AI4Privacy model (CC-BY-NC-4.0); they now use the configured or language default model. - Model downloads wait and retry when Hugging Face answers 429 (rate limit) instead of failing.
[0.4.0] - 2026-09-24
Added
- ONNX Runtime backend without PyTorch or
optimum:pip install gorgetruns every scanner on CPU, PyTorch moved to thetorchextra. Results match the PyTorch pipelines (tested).GORGET_BACKEND,GORGET_ONNX_THREADSandGORGET_ONNX_PROVIDERStune it. - Russian personal data for
AnonymizeandSensitivewithlanguage="ru": Russian NER model, INN, SNILS and OGRN with control sums, passport series and numbers, Russian phone numbers. BERT_SMALL_GRAVITEE_PII_CONF: Apache-2.0 PII model that can be used commercially.llm_guardcompatibility package: existingllm_guardimports resolve to the samegorgetmodules.- Python 3.13 and 3.14 support.
Fixed
- No downloads at runtime: spaCy models are no longer installed with pip while scanning (it failed in uv and poetry environments), NLTK sentence splitting and the VADER lexicon no longer need NLTK data (NLTK 3.10 refuses to download through proxies).
- Vulnerable dependency pins:
transformers==4.51.3(7 advisories) andpresidio==2.2.358(holdscryptographybelow 44.1, CVE-2026-26007) are replaced with ranges. MaliciousURLsworks again: its PyTorch model was deleted from Hugging Face, the scanner now falls back to the ONNX export when a PyTorch repository is gone.EmotionDetectionwithuse_onnx=Truepointed at a missing file.FactualConsistencyandRelevanceimported PyTorch at module import time.Sensitiveignored itslanguageargument.- Cached models load without network access, so
HF_HUB_OFFLINE=1works with ONNX models. - Gated models raise a clear error that explains how to get access.
Changed
- Renamed the project to Gorget: the PyPI package is
gorget, the module isgorget, the API image isghcr.io/perruer/gorget-api. GorgetValidationErrorreplacesLLMGuardValidationError; the old name remains as an alias.- A warning is logged once when a model with a non-commercial license is loaded (the default
Anonymizemodel is CC-BY-NC-4.0). - Sentences are split with punctuation rules; blank lines and Chinese full stops end a sentence.
- The API image runs on ONNX Runtime without PyTorch; the CUDA image uses PyTorch.
Removed
onnxruntime-gpuextra: installgorget[torch]for GPUs, or replaceonnxruntimewithonnxruntime-gpu.- Links to the LLM Guard playground on Hugging Face (offline since 2025) and to the Protect AI Slack.
0.3.16 - 2025-05-19
Fixed
- Regex scanner redacts only the first occurrence (#229).
- BanSubstrings scanner redacts only the first occurrence (#210).
Changed
- Upgrade all dependencies.
- Stop substrings moved to the variables instead of JSON files.
- [BREAKING] New logic to calculate the risk score (#182).
0.3.15 - 2024-08-22
Changed
- Upgrade dependencies to the latest versions.
Biasscanner uses the prompt to increase the accuracy.
0.3.14 - 2024-06-17
Added
- In API, suppress specific scanners when running the analysis.
Changed
- Allow custom
uvicornconfiguration in the API deployment. - Add support of Python v3.12
- In API, removed
gunicornsupport asuvicornsupports workers.
Removed
- Caching is removed from the API deployment as it was causing issues when running multiple workers.
use_io_bindingparameter is removed for the ONNX inference to allow the client to control it.
0.3.13 - 2024-05-10
Fixed
BanSubstringsscanner to handle substrings with special characters.
Changed
Gibberishscanner has higher threshold to reduce false positives. In addition, it supports changinglabelsto remove overtriggering whenmild gibberishis detected.BanCodescanner was improved to trigger less false-positives.- Improved logging to support JSON format both in the library and
API. - Optimizations in the
APIto reduce the latency. BanCompetitorsscanner relies on the new model which also supports ONNX inference.
0.3.12 - 2024-04-23
Added
- Lazy loading of models in the API deployment. Now you can start loading models when the first request comes.
- Support for
gunicornin the API deployment. NoRefusalLightscanner that uses a common set of phrases to detect refusal as per research papers.AnonymizeandSensitivescanners have a support of lakshyakh93/deberta_finetuned_pii model.BanCodescanner to detect and block code snippets in the prompt.- Benchmarks on the AMD CPU.
APIhas a new endpointPOST /scan/promptto scan the prompt without sanitizing it. It is faster than thePOST /analyze/scanendpoint.- Example of running LLM Guard with ChatGPT streaming mode enabled.
APIsupports loading models from the local folder.
Fixed
InvisibleTextscanner to allow control characters like\n,\t, etc.
Changed
- [Breaking]: Introducing
Modelobject for better customization of the models. - Updated all libraries
- Introduced
revisionfor all models to ensure the same model is used for the same revision. Codescanner to rely on the output if there is no Code in the prompt.BanTopics,FactualConsistency: support of the new zero-shot-classification models.PromptInjectioncan support more match types for better accuracy.APIrelies on the lighter models for faster inference but with a bit lower accuracy. You can remove the change and build from source to use the full models.PromptInjectionscanned uses the new v2 model for better accuracy.
Removed
model_kwargsandpipeline_kwargsas they are part of theModelobject.
0.3.10 - 2024-03-14
Added
- Anonymize: New NER models from AI4Privacy Isotonic/distilbert_finetuned_ai4privacy_v2 and Isotonic/deberta-v3-base_finetuned_ai4privacy_v2.
- Gibberish scanner to check if the text contains gibberish.
- Ability to load models from local folders instead of pulling them from HuggingFace.
Fixed
-
Changed
- API Documentation and Code improvements.
- Improved logging to expose more information.
- Anonymize: Tweaks for pattern-based matching.
- Pass
pipelineandmodelkwargsfor better control over the models. - Relax validations to accept custom models.
- [Breaking]:
Anonymizescanner patterns are configured in Python instead of JSON file.
Removed
-
0.3.9 - 2024-02-08
Laiyer is now part of Protect AI
Added
Anonymize: language support withzh(#79, thanks to @Oscaner).Anonymize: more regex patterns, such asPO_BOX_RE,PRICE_RE,HEX_COLOR,TIME_RE,DATE_RE,URL_RE,PHONE_NUMBER_WITH_EXT,BTC_ADDRESS- Add NIST Taxonomy to the documentation.
- Pass HuggingFace Transformers
pipelinekwargsfor better control over the models. For example,BanTopics(topics=["politics", "war", "religion"], transformers_kwargs={"low_cpu_mem_usage": True})for better memory usage when handling big models. API: rate limiting.API: HTTP basic authentication and API key authentication.API: OpenTelemetry support for tracing and metrics.
Fixed
- Incorrect results when using
Deanonymizemultiple times (#82, thanks to @andreaponti5)
Changed
NoRefusalscanner relies on the proprietary model ProtectAI/distilroberta-base-rejection-v1.NoRefusalsupportmatch_typeparameter to choose betweensentenceandallmatches.- Using
structlogfor better logging. - [Breaking]:
Code: using new model philomath-1209/programming-language-identification with more languages support and better accuracy. Please update yourlanguagesparameter. API: ONNX is enabled by default.protobufversion is not capped to v3.APIusespyproject.tomlfor dependencies and builds.- [Breaking]:
APIconfiguration changes with separate sections forauth,rate_limitandcache.
Removed
- Roadmap documentation as it's not up-to-date.
0.3.7 - 2023-01-15
0.3.5 and 0.3.6 were skipped due to build issues.
Added
- URLReachability scanner to check if the URL is reachable.
- BanCompetitors scanner to check if the prompt or output contains competitors' names.
- InvisibleText scanner to check if the prompt contains invisible unicode characters (steganography attack).
- ReadingTime scanner to check if the output can be read in less than a certain amount of time.
- Example of invisible prompt attack using
InvisibleTextscanner. - Example of making Langchain agents secure.
Fixed
BanSubstrings: bug whencase_sensitivewas enabled.Biascalculation of risk score based on the threshold.
Changed
- Using
pyproject.tomlinstead ofsetup.pybased on the request. - [Breaking]
Regexscanners have a new signature. It acceptspatterns,is_blockedandmatch_type. - [Breaking]
BanSubstrings:match_typeparameter becameEnuminstead ofstr. - [Breaking]
Codescanners have a new signature. It acceptslanguagesandis_blockedinstead of 2 separate lists. Toxicity,PromptInjection,BiasandLanguagescanners support sentence match for better accuracy (will become slower).BanTopics,FactualConsistencyandNoRefusal: Updated zero-shot classification model to hMoritzLaurer/deberta-v3-base-zeroshot-v1.1-all-33 with different size options.- [Breaking]: Using keyword arguments for better readability of the code e.g.
scanner = BanSubstrings(["a", "b", "c"], "str", False, True, False)would raise an error. - [Breaking]: API config supports configuring same scanner multiple times with different inputs.
0.3.4 - 2023-12-21
Added
- Example of securing RAG with Langchain
- Example of securing RAG with LlamaIndex
Changed
- Upgraded all libraries to the latest versions
- Improvements to the documentation
Deanonymizescanner supports matching strategies- Support of ONNX runtime on GPU for even faster inference (with massive latency improvements) and updated benchmarks
Removed
- Usage of
dbmdz/bert-large-cased-finetuned-conll03-englishin theAnonymizescanner
0.3.3 - 2023-11-25
Added
- Benchmarks on Azure instances
Changed
- Upgraded
json_repairlibrary (issue) - Use proprietary prompt injection detection model ProtectAI/deberta-v3-base-prompt-injection
0.3.2 - 2023-11-15
Changed
- Using ONNX converted models hosted by Laiyer on HuggingFace
- Switched to better model for MaliciousURLs scanner - DunnBC22/codebert-base-Malicious_URLs
BanTopics,NoRefusal,FactualConsistencyandRelevancescanners support ONNX inferenceRelevancerely on optimized ONNX models- Switched to using
transformersinRelevancescanner to have less dependencies - Updated benchmarks for relevant scanners
- Use
papluca/xlm-roberta-base-language-detectionmodel for theLanguageandLanguageSamescanner PromptInjectioncalculates risk score based on the defined threshold- Up-to-date Langchain integration using LCEL
Removed
- Remove
lingua-language-detectordependency fromLanguageandLanguageSamescanners
0.3.1 - 2023-11-09
Fixed
- Handling long prompts by truncating it to the maximum length of the model
Changed
- Use single
PromptInjectionscanner with multiple models - Benchmarks are measured for each scanner individually
- In the
Refutationoutput scanner use the same model for the NLI as used in theBanTopics - Benchmarks for each individual scanner instead of one common
- Use
deepset/deberta-v3-base-injectionmodel for thePromptInjectionscanner - Optimization of scanners on GPU by using
batch_size=1 - Use
lingua-language-detectorinstead oflangdetectin theLanguagescanner - Upgrade all libraries including
transformersto the latest versions - Use Transformers recognizers in the
AnonymizeandSensitivescanner to improve named-entity recognition - Possibility of using ONNX runtime in scanners by enabling
use_onnxparameter - Use the newest
MoritzLaurer/deberta-v3-base-zeroshot-v1model for theBanTopicsandRefutationscanners - Use the newest
MoritzLaurer/deberta-v3-large-zeroshot-v1model for theNoRefusalscanner - Use better
unitary/unbiased-toxic-robertamodel for Toxicity scanners (both input and output) - ONNX on API deployment for faster CPU inference
- CUDA on API deployment for faster GPU inference
Removed
- Remove
PromptInjectionV2scanner to rely on the single one with a choice - Langchain
LLMChainexample as this functionality is deprecated, useLCELinstead
0.3.0 - 2023-10-14
Added
Regexscanner to the promptLanguagescanners both for prompt and outputJSONoutput scanner- Best practices to the documentation
LanguageSameoutput scanner to check that the prompt and output languages are the same
Changed
BanSubstringscan match all substrings in addition to any of themSensitiveoutput scanner can redact found entities- Change to faster model for
BanTopicsprompt and output scanners MoritzLaurer/DeBERTa-v3-base-mnli-fever-docnli-ling-2c - Changed model for the
NoRefusalscanner to faster MoritzLaurer/DeBERTa-v3-base-mnli-fever-docnli-ling-2c AnonymizeandSensitivescanners support more accurate models (e.g. beki/en_spacy_pii_distilbert and ability to choose them. It also reduced the latency of this scanner- Usage of
sentence-transformerslibrary replaced withFlagEmbeddingin theRelevanceoutput scanner - Ability to choose embedding model in
Relevancescanner and use the best model currently available - Cache tokenizers in memory to improve performance
- Moved API deployment to
llm_guard_api JSONscanner can repair the JSON if it is broken- Rename
Refutationscanner toFactualConsistencyto better reflect its purpose
Removed
- Removed chunking in
AnonymizeandSensitivescanners because it was breaking redaction
0.2.4 - 2023-10-07
Added
- Langchain example using LangChain Expression Language (LCEL)
- Added prompt injection scanner v2 model based on hubert233/GPTFuzz
Changed
- Using another Bias detection model which works better on different devices valurank/distilroberta-bias
- Updated the roadmap in README and documentation
BanSubstringscan redact found substrings- One
loggerfor all scanners devicebecame function to lazy load (avoidtorchimport when unnecessary)- Lazy load dependencies in scanners
- Added elapsed time in logs of
evaluate_promptandevaluate_outputfunctions - New secrets detectors
- Added GPU benchmarks on
g5.xlargeinstance - Tests are running on Python 3.9, 3.10 and 3.11
Removed
- Usage of
acceleratelibrary for inference. Instead, it will detect device usingtorch
0.2.3 - 2023-09-23
Changed
- Added Swagger documentation on the API documentation page
- Added
fail_fastflag to stop the execution after the first failure- Updated API and Playground to support
fail_fastflag - Clarified order of execution in the documentation
- Updated API and Playground to support
- Added timeout configuration for API example
- Better examples of
langchainintegration
0.2.2 - 2023-09-21
Fixed
- Missing secrets detection for Github token in the final build
0.2.1 - 2023-09-21
Added
- New pages in the docs about usage of LLM Guard
- Benchmark of AWS EC2
inf1.xlargeinstance - Example of API with Docker in llm_guard_api
Regexoutput scanner can redact the text using a regular expression
Changed
- Lowercase prompt in Relevance output scanner to improve quality of cosine similarity
- Detect code snippets from Markdown in
Codescanner to prevent false-positives - Changed model used for
PromptInjectiontoJasperLS/deberta-v3-base-injection, which produces less false-positives - Introduced
thresholdparameter forCodescanners to control the threshold for the similarity
0.2.0 - 2023-09-15
Added
- Documentation moved to
mkdocs - Benchmarks in the documentation
- Added documentation about adding more scanners
Makefilewith useful commands- Demo application using Streamlit deployed to HuggingFace Spaces
Fixed
MaliciousURLsscanner produced false positives when URLs are not extracted from the text
Changed
- Support of GPU inference
- Score of existing
Anonymizepatterns
Removed
URLentity type fromAnonymizescanner (it was producing false-positive results)
0.1.3 - 2023-09-02
Changed
- Lock
transformersversion to 4.32.0 becausespacy-transformersrequire it - Update the roadmap based on the feedback from the community
- Updated
NoRefusalscanner to use transformer to classify the output
Removed
- Jailbreak input scanner (it was doing the same as the prompt injection one)
0.1.2 - 2023-08-26
Added
Changed
- Introduced new linters for markdown
0.1.1 - 2023-08-20
Added
- Example integration with LangChain
Changed
- Flow picture instead of the logo
- Bump libraries
0.1.0 - 2023-08-12
Added
Changed
- All prompt scanners: Introducing a risk score, where 0 - means no risk, 1 - means high risk
- All output scanners: Introducing a risk score, where 0 - means no risk, 1 - means high risk
- Anonymize prompt scanner: Using the transformer based Spacy model
en_core_web_trf(reference) - Anonymize prompt scanner: Supporting faker for applicable entities instead of placeholder (
use_fakerparameter) - Anonymize prompt scanner: Remove all patterns for secrets detection, use Secrets prompt scanner instead.
- Jailbreak prompt scanner: Updated dataset with more examples, removed duplicates
Removed
- Anonymize prompt scanner: Removed
FILE_EXTENSIONentity type
0.0.3 - 2023-08-10
Added
- Dependabot support
- CodeQL support
- More pre-commit hooks to improve linters
Fixed
- Locked libraries in
requirements.txt - Logo link in README
0.0.2 - 2023-08-07
Fixed
- Fixed missing
.jsonfiles in the package
0.0.1 - 2023-08-07
Added
- Project structure
- Documentation
- Github Actions pipeline
- Prompt scanners with tests:
- Output scanners with tests: