NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #124 most downloaded on PyPI
Verify certificates using native system trust stores
Last release 1 years ago
12 Aug 2025
Ships fairly regularly
a new release about every 4 months
Nearly every release is documented
notes for 15 of 15 stable releases
1 version withdrawn
withdrawn after publishing
5 years old
16 releases · first in 2022
One column per quarter.
Fixed a thread-safety issue when configuring the internal ssl.SSLContext object.
ssl.SSLContext object.Added support for the system certificate bundle in Fedora 43 and later.
Patch preloaded SSL context for requests library by @timo-reymann in #164
Full Changelog: v0.10.0...v0.10.1
Full Changelog: https://github.com/sethmlarson/truststore/compare/v0.10.0...v0.10.1
ssl.SSLContext
object to work automagically with truststore.inject_into_ssl()
regardless of import-order.Use the 'SecTrustEvaluate' API for macOS 10.13 and earlier by @sethmlarson and @illume in #157
Full Changelog: v0.9.2...v0.10.0
Full Changelog: https://github.com/sethmlarson/truststore/compare/v0.9.2...v0.10.0
SecTrustEvaluate API. Note that
this API doesn't return fine-grained errors like SecTrustEvaluateWithError (requires macOS 10.14+).SSLContext.set_default_verify_paths() method.SSLContext.check_hostname was False.
Now for both macOS and Windows the certificate verification policy is configured
to not check certificate hostname. This should have no effect on users.Raise an error if peer certificate chain APIs aren't available by @sethmlarson in #149
Full Changelog: v0.9.1...v0.9.2
Full Changelog: https://github.com/sethmlarson/truststore/compare/v0.9.1...v0.9.2
truststore module. The module
now raises an error immediately instead of on first handshake. This was added for the GraalPy
implementation specifically, but there may be others.Fixed an issue for CPython 3.13 where ssl.SSLSocket and ssl.SSLObject certificate chain APIs would return different types by @sethmlarson in #137
Full Changelog: v0.9.0...v0.9.1
Add explicit support for Python 3.13 by @sethmlarson in #132
Full Changelog: v0.8.0...v0.9.0
Full Changelog: https://github.com/sethmlarson/truststore/compare/v0.8.0...v0.9.0
IndexError, now is SSLCertVerificationError.Added support for PyPy 3.10 by @sethmlarson in https://github.com/sethmlarson/truststore/pull/113
Full Changelog: https://github.com/sethmlarson/truststore/compare/v0.7.0...v0.8.0
Full Changelog: v0.7.0...v0.8.0
Changed the error raised when using an unsupported macOS version (10.7 or earlier) from an OSError to an ImportError to match the error raised in othe
OSError to an ImportError to match the error raised in other situations where the module isn't supported.Fixed issue where a RecursionError that would be raised when setting SSLContext.minimum_version or .maximum_version.
RecursionError that would be raised when setting SSLContext.minimum_version or .maximum_version.Truststore is now beta! Truststore will be made the default in a future pip release.
Truststore is now beta! Truststore will be made the default in a future pip release.
inject_into_ssl() and extract_from_ssl() to enable Truststore for all packages using ssl.SSLContext automatically.check_hostname, verify_mode, and verify_flags.ssl.SSLContext methods like load_cert_chain(), set_alpn_protocols(), etc.Support for using truststore was released with pip v22.2! You can read more here about how to help us test truststore.
truststore with urllib3, Requests, aiohttp, and pip.ssl.SSLError with
message from the OS.:warning: This package is experimental and shouldn't be used in applications
:warning: This package is experimental and shouldn't be used in applications
ssl.SSLCertVerificationError determined by the OS on macOS and Windows.SSLContext.verify_flags for strictly checking CRLs instead of checking CRLs strictly by default.:warning: This package is experimental and shouldn't be used in applications
:warning: This package is experimental and shouldn't be used in applications
SSLContext.load_verify_locations().TruststoreSSLContext to SSLContext.:warning: This package is experimental and shouldn't be used in applications
:warning: This package is experimental and shouldn't be used in applications
:warning: This package is experimental and shouldn't be used in applications
:warning: This package is experimental and shouldn't be used in applications
Your coding agent can read these notes before it upgrades. Set up the MCP server →