NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3386 most downloaded on PyPI
Access your OS root certificates with utmost ease
Last release 1 months ago
27 Aug 2026
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 25 of 25 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
25 releases · first in 2023
One column per quarter.
CCADB embedded bundle is updated to latest version.
Postpone ssl import to whenever the user invoke create_default_ssl_context function.
ssl import to whenever the user invoke create_default_ssl_context function.CCADB embedded bundle is updated to latest version.
Guarded MacOS truststore access in process forks. Apple document as unsafe accessing some CoreFoundation/Security in forks. Previously could lead to a
unable to get local issuer certificate failures. Now extended with the embedded CCADB roots that the Windows AuthRootset_cache_ttl top level function to set, in seconds, how long the CA bundle will be valid for until re-polling from the OS.
set_cache_ttl top level function to set, in seconds, how long the CA bundle will be valid for until re-polling from the OS.hybrid_store boolean to force concatenate your OS CA bundle with the embedded CCADB bundle. E.g. wassima.generate_ca_bundle(hybrid_store=True).MacOS truststore implementation. A few tiny memory leaks and missing "trust" inspection when explicitly marked (i.e. CA) as "deny".
Unreasonable deep scan under FreeBSD causing a significant lag while loading trusted CAs. ( jawah/niquests#332 )
Rare unhandled PermissionError in Linux while in autodiscover of trusted CAs.
CCADB embedded bundle is updated to latest version.
CCADB embedded bundle is updated to latest version.
CCADB embedded bundle is updated to latest version. Include a new CA.
Native Rust extension in favor of a pure Python solution.
RUSTLS_LOADED.python -m wassima to debug platform support.generate_ca_bundle now integrate intermediate CA on Windows and MacOS.
You are responsible for trusting the bundle knowing that fact. It will no longer contain only trust anchors.
On Python defaults, OpenSSL will rebuild the chain and ensure the trust anchors (e.g. root CA/self-signed) is
there and valid. Passing VERIFY_PARTIAL_CHAIN will short circuit that insurance. (#16)pyo3 updated from 0.23.4 to 0.23.5
No longer fallback on certifi for Windows x86 CPython.
pyo3 updated from 0.23.3 to 0.23.4
pyo3 updated from 0.22.5 to 0.23.3
pyo3 updated from 0.20.3 to 0.22.5
Harmonized requirements in project metadata whether you fetch the pure Python wheel or not.
Bumped rustls-native-certs to version 0.7.3
rustls-native-certs to version 0.7.3certifi if native trust store access isn't supported on your platform.certifi fallback bundle is loaded even if stored inside a zip-like file.Bumped rustls-native-certs to version 0.7.1
rustls-native-certs to version 0.7.1Exception if the underlying rust library could not access the OS store
pyo3 to version 0.20.3Bumped rustls-native-certs to version 0.7.0
pyo3 to version 0.20.2rustls-native-certs to version 0.7.0maturin to version 1.4.0Function register_ca so that user may register their own custom CA (PEM, and DER accepted) in addition to the system trust store.
register_ca so that user may register their own custom CA (PEM, and DER accepted) in addition to the system trust store.SSL_CERT_FILE environment variable so that system CA is always returned.create_default_ssl_context now instantiates an SSLContext with the Mozilla Recommended Cipher Suite, instead of your system default.pyo3 to version 0.20.0Support for certifi fallback if you did not pick up a compatible wheel. Expose constant RUSTLS_LOADED as a witness.
__version__.certifi fallback if you did not pick up a compatible wheel. Expose constant RUSTLS_LOADED as a witness.Public functions root_der_certificates, root_pem_certificates, generate_ca_bundle, and create_default_ssl_context.
root_der_certificates, root_pem_certificates, generate_ca_bundle, and create_default_ssl_context.Your coding agent can read these notes before it upgrades. Set up the MCP server →