# How to Update VulnClaw to the Latest Version: PyPI, Source, and Docker

> Update VulnClaw easily via PyPI pip install -U vulnclaw source git pull or Docker image rebuild. Keep your vulnerability scanner current.

- Repository: [Unclecheng/VulnClaw](https://github.com/Unclecheng-li/VulnClaw)
- Tags: how-to-guide
- Published: 2026-07-03

---

**Run `pip install -U vulnclaw` for PyPI installations, `git pull && pip install -e .` for local source clones, or rebuild the Docker image to update VulnClaw to the latest version.**

Keeping your installation of **Unclecheng-li/VulnClaw** current ensures you have the newest vulnerability-detection skills, **MCP** tool integrations, and bug fixes. Whether you originally installed the scanner from **PyPI**, cloned the repository, or deployed it with **Docker**, the correct upgrade path depends on your setup. This guide walks through each method using the exact commands and source files defined in the repository.

## Update VulnClaw to the Latest Version Using pip

The fastest way to update VulnClaw to the latest version is through the published Python wheel on **PyPI**.

### Run pip install --upgrade vulnclaw

Open your terminal and execute:

```bash
pip install -U vulnclaw

```

The `-U` flag is shorthand for `--upgrade`. This command replaces the currently installed distribution with the newest release built from the source in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml). That file holds the canonical package metadata, version string, and dependency constraints used during the publish step. Before each release, the maintainers run [`scripts/release_preflight.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/scripts/release_preflight.py) in CI to verify the build and publish steps, ensuring the wheel on PyPI is always installable.

### Verify the new installation

After the upgrade finishes, confirm the active version by querying the CLI entry point:

```bash
vulnclaw --version

```

According to the Unclecheng-li/VulnClaw source code, the CLI entry point in [`vulnclaw/cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/main.py) resolves the version string at import time via `importlib.metadata.version("vulnclaw")`. This means the reported number always reflects the version currently installed in your Python environment.

## Update VulnClaw to the Latest Version from Source

If you work with a local clone of the repository—perhaps to modify MCP plugins or test bleeding-edge commits—use an **editable install**.

### Pull the latest changes and reinstall

Navigate to your clone and sync with the upstream branch:

```bash
cd ~/code/VulnClaw
git fetch --all
git checkout main
git pull
pip install -e .

```

The `-e .` flag performs an editable install, so Python references the source tree directly rather than copying files into `site-packages`. Because [`vulnclaw/cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/main.py) reads version metadata from the installed distribution, reinstalling after a `git pull` ensures the interpreter registers updated modules and the incremented version declared in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml).

### Pin to a specific release tag

For reproducible environments, checkout a semantic-version tag instead of `main`:

```bash
git checkout v0.4.2
pip install -e .

```

## Update VulnClaw to the Latest Version with Docker

Containerized deployments are updated either by pulling a fresh image or rebuilding locally.

### Pull the latest pre-built image

If you use the public image without local modifications, run:

```bash
docker pull unclechengli/vulnclaw:latest

```

### Rebuild locally from the Dockerfile

For users with custom MCP plugins or local patches, rebuild from the `Dockerfile` located in the repository root:

```bash
git pull
docker compose build --no-cache
docker compose up -d

```

The `--no-cache` flag forces Docker to copy the latest source—including any changes to [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml)—into the new image layer. Once the container starts, the web UI becomes available on `127.0.0.1:7788` with the updated code and bundled tools.

## Post-Update Health Check

After you update VulnClaw to the latest version, validate the environment:

```bash
vulnclaw doctor

```

This command checks that Python, Node, and MCP services are healthy. Note that user-specific settings stored in `~/.vulnclaw/config.yaml`, such as custom LLM provider API keys, persist across upgrades and are never overwritten by package updates.

## Summary

- **PyPI:** Run `pip install -U vulnclaw` to fetch the newest wheel and upgrade immediately.
- **Source:** Execute `git pull` followed by `pip install -e .` inside your local clone to apply upstream changes.
- **Docker:** Either `docker pull unclechengli/vulnclaw:latest` or rebuild with `docker compose build --no-cache` to roll out the latest container image.
- **Verification:** Use `vulnclaw --version` and `vulnclaw doctor` to confirm the update succeeded.

## Frequently Asked Questions

### Will upgrading VulnClaw overwrite my configuration files?

No. The installer does not touch `~/.vulnclaw/config.yaml`, where your API keys and LLM provider settings are stored. Upgrading via pip, source, or Docker only replaces the application code and dependencies.

### How do I know which version of VulnClaw is currently installed?

Run `vulnclaw --version`. As implemented in Unclecheng-li/VulnClaw, the CLI entry point in [`vulnclaw/cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/main.py) queries `importlib.metadata` at runtime, so the printed string matches the version declared in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml).

### Can I downgrade VulnClaw if the latest version breaks my workflow?

Yes. For PyPI installs, run `pip install vulnclaw==<version>` with the desired semantic version. If you cloned the repository, checkout the corresponding tag and reinstall with `pip install -e .` to pin the CLI to that release.

### Why should I use docker compose build --no-cache instead of a cached build?

Docker layer caching can skip the copy step for [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml) and the source tree, causing the image to retain stale code. Adding `--no-cache` guarantees that the `Dockerfile` copies the latest upstream files into the image, ensuring the container launches with the exact code present after your `git pull`.