NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3503 most downloaded on PyPI
A library that provides cryptographic and general-purpose routines for Secure Systems Lab projects at NYU
Last release 1 months ago
04 Sep 2026
Ships fairly regularly
a new release about every 4 months
Nearly every release is documented
notes for 46 of 49 stable releases
1 version withdrawn
withdrawn after publishing
10 years old
50 releases · first in 2017
The 1.5.0 release was yanked but all of it's features (listed below) are included in 1.5.1.
The 1.5.0 release was yanked but all of it's features (listed below) are included in 1.5.1.
crypto extra) (#1205)CryptoSigner, GCPSigner, and SSlibKey (#1124)tkey:) (#1149)ecdsa-sha2-nistp384 and ecdsa-sha2-nistp521signer module (#1137)python-pkcs11 (#1156)import_() (#1109, #1156)ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, and ecdsa-sha2-nistp521 asecdsa instead. (#363, #1138)rsassa-pss-sha224 and rsa-pkcs1v15-sha224) fromOne column per quarter.
1.5.0 has been yanked from PyPI, please use release 1.5.1 (see 1.5.1 Changelog for details)
1.5.0 has been yanked from PyPI, please use release 1.5.1 (see 1.5.1 Changelog for details)
CryptoSigner, GCPSigner, and SSlibKey (#1124)tkey:) (#1149)ecdsa-sha2-nistp384 and ecdsa-sha2-nistp521
schemes in key generation and signing (#1181)signer module (#1137)python-pkcs11 (#1156)import_() (#1109, #1156)ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, and ecdsa-sha2-nistp521 as
keytype values. Use ecdsa instead. (#363, #1138)rsassa-pss-sha224 and rsa-pkcs1v15-sha224) from
the default verification registry (#1171)Key, Signature, and Envelope hashable (#1163)gpg.exe (#1140)Envelope.from_dict (#1139)See CHANGELOG.md for details.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
The hash module will be removed in the next major version. Consider using
hashlib from the standard library directly instead.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
Small release with mostly internal changes.
Thanks to @L77H and @NicholasTanz for the bulk of the work on this release.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
This is a small release that only re-enables the use of SigstoreSigner. Note that SigstoreSigner and SigstoreKey are still not part of the default set of supported signers & keys but now they can be enabled.
See CHANGELOG.md for details.
See CHANGELOG.md for details.
Securesystemslib API is now considered stable. The core functionality is
provided in the Signer interface and the half a dozen integrated Signer
implementations that can be found in the signer module. Smaller helper
modules dsse, formats, hash and storage are also part of the API.
Several legacy modules have been removed.
"file2" signer uri (#759)"file" signer uri (#759)SSlibSigner class and *_securesystemslib_key methods (#771)key*, interface, util and schema modules (#772, #773, #776)hash, and formats module (#774, #776)See CHANGELOG.md for details.
See CHANGELOG.md for details.
cryptography private key with new constructor (#675)cryptography public key with new from_crypto method (#678)SSlibKey.from_pem factory method in favor of from_crypto (#678)This release contains improved Sigstore support.
This release contains improved Sigstore support.
SigstoreSigner.import_via_auth()Advance notice to folks using the keys, ecdsa_keys, rsa_keys and ed25519_keys modules: these modules are headed for deprecation. Please have a look at…
This release is reaping the rewards of the new signer API with four(!) new signing methods: Two cloud based KMSs, post-quantum crypto support and a "keyless" signing system.
Advance notice to folks using the keys, ecdsa_keys, rsa_keys and
ed25519_keys modules: these modules are headed for deprecation. Please have
a look at the signer API and get in touch if the functionality you need
isn't there (or if more documentation is needed).
CryptoSigner as a more featureful replacement for SSLibSigner (#604)SSLibSigner has been deprecated: Please use CryptoSigner instead (#604)keys module is not used for signature verification in signer API (#585)Full Changelog: https://github.com/secure-systems-lab/securesystemslib/compare/v0.28.0...v0.29.0
Signer: de/serialization helpers
EXPERIMENTAL DSSE implementation
Private key URI schemes for signer instantiation
Replaced deprecated distutils.version.StrictVersion
distutils.version.StrictVersion (#433)GPGSigner to support gpg signing via Signer interface (#341, #419)
Race condition in gpg test cleanup function
FormatError in keys.verify_signature() (#391)Removed broken Dependabot badge in README
__eq__ method for Signature objects (#383)unrecognized_fields attribute for Signature objects (#387)NOTE: This is the first release of securesystemslib to require Python 3.6 or newer.
NOTE: This is the first release of securesystemslib to require Python 3.6 or newer.
NOTE: this will be the final release of securesystemslib that supports Python 2.7. This is because Python 2.7 was marked end-of-life in January of 202
NOTE: this will be the final release of securesystemslib that supports Python 2.7. This is because Python 2.7 was marked end-of-life in January of 2020, and since then several of securesystemslib's direct and transitive dependencies have stopped supporting Python 2.7. securesystemslib's major users, the Python implementations of tuf (v0.167.0) and in-toto (v1.1.0), have already dropped support for Python 2.7.
Add signing abstraction to facilitate custom implementations
Enable setting which GPG client to use through an environment variable
interface.generate_and_write_unencrypted_{rsa,ed25519,ecdsa}_keypair
interface.generate_and_write_unencrypted_{rsa,ed25519,ecdsa}_keypair (#288)interface.generate_and_write_{rsa,ed25519,ecdsa}_keypair_with_prompt (#288)interface.import_privatekey_from_file(#288)interface.generate_and_write_{rsa,ed25519,ecdsa}_keypair require a password
as first positional argument (#288)interface.import_{rsa,ed25519,ecdsa}_privatekey_from_file do not error on
empty password, but pass it on to lower level decryption routines (#288)interface.import_ecdsa_privatekey_from_file supports loading unencrypted
private keys (#288)interface and gpg.functions docstrings, and example snippets, and
use Sphinx compatible Google Style docstring format (#288, #300)Add interface.import_publickeys_from_file() convenience function (#278, #285)
interface.import_publickeys_from_file() convenience function (#278, #285)gpg.export_pubkeys() convenience function (#277)hash module for blake2b-256 algorithm (#283)_prompt) and global (SUPPORTED_KEY_TYPES) from
interface module (#276)Added new, self-explanatory, AnyNonEmptyString schema
util.get_file_length(), and
a file's hashes, util.get_file_hashes() (#259)keys.format_metadata_to_key() to take an optional list of hashing
algorithms rather than requiring users modify settings.HASH_ALGORITHMS to
change this behaviour (#227)storage.FileSystemBackend.create_folder (#252)util.ensure_parent_dir() (#260)Allow Blake (blake2s and blake2b) hashing algorithms
Re-enable OpenPGP signature verification without GnuPG
Fix dependency monitoring and revise requirements files
Default to pure Python ed25519 signature verification when nacl is unavailable
Fix MANIFEST.in to include all test data in source release
Add support for *OpenPGP* EdDSA/ed25519 keys and signatures
Remove unnecessary python-dateutil==2.8.0 version pinning to not cause downstream dependency conflicts
python-dateutil==2.8.0 version pinning to not cause downstream dependency conflicts (#192)Fix stream duplication race conditions in subprocess interface
Remove data serialization in create_signature and verify_signature
create_signature and verify_signature (#162)TempFile utility with single helper function (#181)Provide option to normalize line endings (\r\n -> \n, \r -> \n) when calculating the hash of a file (default: do not normalize).
\r\n -> \n, \r -> \n) when
calculating the hash of a file (default: do not normalize).No (en|de)cryption of ed25519 key files when given empty password (pr #148).
No (en|de)cryption of ed25519 key files when given empty password (pr #148).
Support ed25519 crypto in pure python with default installation (pr #149).
Update installation instructions to indicate commands needed to install optional dependencies for RSA and ECDSA support (pr #150).
Edit setup.py's license classifier to OSI LIcense :: MIT (pr #151).
Convert \r\n newline characters to \n, so that the same KEYID is generated for key data regardless of the newline style used (pr #146).
\r\n newline characters to \n, so that the same KEYID is
generated for key data regardless of the newline style used (pr #146).Add prompt parameter to interface.import_rsa_privatekey_from_file() (pr #124).
Add prompt parameter to interface.import_rsa_privatekey_from_file() (pr #124).
Update dependencies.
Note: This is a backwards-incompatible release.
Replace deprecated cryptography methods. signer() and verifier() should be replaced with sign() and verify(), respectively.
Replace deprecated cryptography methods. signer() and verifier()
should be replaced with sign() and verify(), respectively.
Update dependencies.
Enable password confirmation in all generate_and_write_XXX_keypair() functions.
Add get_password() to API.
Enable password confirmation in all generate_and_write_XXX_keypair()
functions.
Minor:
Fix broken link in comment (recommended # of bits for RSA keys).
Add TEXT_SCHEMA.
Remove obsolete function (check_crypto_libaries) from .coveragerc.
Add debian directory (and files) that can be used to package a .deb file.
Add debian directory (and files) that can be used to package a .deb file.
Modify functions that generate or import keys so that the key file's path is shown if the function prompts for a password.
Add colorama dependency. It is used to colorize some of the prompts.
Update dependencies to their latest version.
Support KEYID filenames for generated key files. KEYID filenames are used if a filename is not specified.
Minor edits to comments, indentation, whitespace, etc.
Modify generate_rsa_key() so that leading and trailing newline characters are stripped before generating the KEYID. This is done so that the KEYID generated from imported keys match. Imported PEM keys are stripped of any leading and trailing newline characters before the KEYID is generated.
Drop support for Python 2.6 and 3.3
Drop support for Python 2.6 and 3.3
Add support for Python 3.6
Fix bug in PEM parser. See https://github.com/secure-systems-lab/securesystemslib/issues/54
Drop PyCrypto and multiple-library support
Update dependencies
Verify that the arguments to verify_signature() have matching KEYIDs
Add a changelog file (this one :)
@vladimir-v-diaz vladimir-v-diaz released this on Aug 23 · 79 commits to master since this release
@vladimir-v-diaz vladimir-v-diaz released this on Aug 23 · 79 commits to master since this release
Fix bug in _get_keyid(), where the hash_algorithm argument to _get_keyid() wasn't correctly being used.
hash_algorithm argument to _get_keyid() wasn't correctly being used.@vladimir-v-diaz vladimir-v-diaz released this on Jul 17 · 127 commits to master since this release
Bump cryptography dependency to v1.9.0
@vladimir-v-diaz vladimir-v-diaz released this on Jun 14 · 130 commits to master since this release
Bump cryptography dependency to v1.9.0
Fix backwards-incompatible change introduced by v1.9.0 of cryptography (dependency)
Add PUBLIC_KEY_SCHEMA and PUBLIC_KEYVAL_SCHEMA
@vladimir-v-diaz vladimir-v-diaz released this on Jan 23 · 146 commits to master since this release
Add PUBLIC_KEY_SCHEMA and PUBLIC_KEYVAL_SCHEMA
Remove ssl_crypto/ssl_commons relics in docstrings
@vladimir-v-diaz vladimir-v-diaz released this on Jan 19 · 152 commits to master since this release
@vladimir-v-diaz vladimir-v-diaz released this on Jan 19 · 152 commits to master since this release
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →