NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #852 most downloaded on crates.io
Mozilla trusted certificate authorities in self-signed X.509 format for use with crates other than webpki
Last release 2 months ago
18 Jul 2026
Ships fairly regularly
a new release about every 6 weeks
Some releases are documented
notes for 10 of 18 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
18 releases · first in 2024
One column per month.
Add "Telia EC TLS Root CA v3" and "Telia RSA TLS Root CA v3" - https://bugzilla.mozilla.org/show_bug.cgi?id=2047804
Changes:
Full Changelog: v/1.0.8...v/1.0.9
Remove SecureSign Root CA12 root; see https://bugzilla.mozilla.org/show_bug.cgi?id=2031105
SecureSign Root CA12 root; see https://bugzilla.mozilla.org/show_bug.cgi?id=2031105SecureSign Root CA12 root by @ctz in #124Full Changelog: v/1.0.7...v/1.0.8
For their April 2026 root store changes, Mozilla has made more changes than usual:
For their April 2026 root store changes, Mozilla has made more changes than usual:
These changes are part of Mozilla’s ongoing root store maintenance under the Mozilla Root Store Policy (MRSP), including §7.4 (Root CA Lifecycles) and §7.5.3 (Transition Plans). They reflect a combination of lifecycle-based transitions, CA operator requests, and alignment with intended certificate usage, including retiring older or less suitable root certificates, enforcing clear separation of trust purposes (e.g., TLS vs. S/MIME), and reducing unnecessary trust surface in the Web PKI ecosystem. Collectively, these actions help to ensure that root certificates are relied upon only for their intended and actively maintained use cases, or are retired in accordance with established distrust timelines.
This removes:
See their announcement for more details.
Full Changelog: v/1.0.6...v/1.0.7
"e-Szigno TLS Root CA 2023" added, see https://bugzilla.mozilla.org/show_bug.cgi?id=1873057
"e-Szigno TLS Root CA 2023" added, see https://bugzilla.mozilla.org/show_bug.cgi?id=1873057
Full Changelog: v/1.0.5...v/1.0.6
Removes the following trust anchors which have passed their distrust-after-last-issuance dates:
Removes the following trust anchors which have passed their distrust-after-last-issuance dates:
Full Changelog: v/1.0.4...v/1.0.5
https://bugzilla.mozilla.org/show_bug.cgi?id=1994866 tracks the voluntary removal of:
https://bugzilla.mozilla.org/show_bug.cgi?id=1994866 tracks the voluntary removal of:
Full Changelog: v/1.0.3...v/1.0.4
Addition of "OISTE Server Root RSA G1" & "OISTE Server Root ECC G1": https://bugzilla.mozilla.org/show_bug.cgi?id=1988913 .
Addition of "OISTE Server Root RSA G1" & "OISTE Server Root ECC G1": https://bugzilla.mozilla.org/show_bug.cgi?id=1988913.
Add "TrustAsia TLS ECC Root CA" and "TrustAsia TLS RSA Root CA" https://bugzilla.mozilla.org/show_bug.cgi?id=1972384
Full Changelog: v/1.0.1...v/1.0.2
Remove Chunghwa Telecom "ePKI Root Certification Authority". See the upstream issue for details.
Remove Chunghwa Telecom "ePKI Root Certification Authority". See the upstream issue for details.
Full Changelog: v/1.0.0...v/1.0.1
After 51 releases over about nine years, this is the first stable release of the webpki-roots and webpki-root-certs crates.
After 51 releases over about nine years, this is the first stable release of the webpki-roots and webpki-root-certs crates.
The 1.0.0 release is functionally equal to the 0.26.10 release. We will make a 0.26.11 release that uses 1.0.0 using the semver trick.
Full Changelog: v/0.26.10...v/1.0.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →