Truststore is a Python library that provides an ssl.SSLContext-like API backed by your operating system’s native certificate trust stores, so apps can verify TLS certificates using system-managed CA updates and related features. It is useful for developers who want to avoid relying on certifi, and it has been integrated into pip 24.2+ as the default HTTPS certificate verification method (with a certifi fallback).
Project status
- The upstream GitHub activity shows a recent push on 2026-09-29 (relative to 2026-10-02), which suggests the repository is still being actively worked on, even though no newer tagged updates than v0.10.4 are reflected in the provided release summaries.
- The documented version updates in the provided history are sparse (v0.10.4 on 2025-09-02, then v0.10.3 and v0.10.2 in late July 2025), indicating a low release cadence relative to today.
AI summary generated
Recent updates
v0.10.4
Version 0.10.4 primarily addresses a thread-safety issue related to configuring the internal ssl.SSLContext used by truststore.SSLContext. The fix adds synchronization around the context configuration step during wrap_socket.
v0.10.3
Release v0.10.3 appears to be primarily a build and release pipeline adjustment. The only library code change is the package version bump, with CI workflow changes to use a pinned build dependency set.
v0.10.2
Release v0.10.2 was published on 2025-07-29, but the publisher did not provide any release notes. Without documented changes, it is not possible to identify specific feature additions, bug fixes, breaking changes, or security updates from the release information alone.
v0.10.1
This patch release adds a fix to how truststore patches Python SSL contexts so that Requests can use the patched SSL context even when Requests has a globally preloaded SSL context. The release notes only mention the Requests preloaded SSL context change, but the diff also includes runtime detection logic changes aimed at speeding up imports.
v0.10.0
v0.10.0 adds improved macOS trust evaluation support for older systems, including macOS 10.13 and earlier by using SecTrustEvaluate. It also adds SSLContext.set_default_verify_paths and changes how hostname verification is disabled on macOS and Windows by configuring the underlying trust policy rather than post-filtering hostname errors.
Featuresv0.9.2
Release 0.9.2 adds a runtime check intended to fail fast when the underlying Python SSL stack does not expose peer certificate chain APIs. The release notes describe raising an error when those APIs are unavailable, and the diff also updates documentation and CI/tests accordingly.
Breakingv0.9.1
v0.9.1 is a small patch release focused on CPython 3.13 compatibility for SSL certificate chain handling. The release notes state it fixes a type mismatch where certificate chain APIs on ssl sockets return different types.
v0.9.0
Release v0.9.0 adds explicit Python 3.13 support, fixes macOS behavior when loading additional certificates, and improves the Windows error raised when the peer provides no certificates. It also updates CI and packaging metadata to include Python 3.13 and adjusts documentation to warn against using `inject_into_ssl()` in libraries.
BreakingFeaturesv0.8.0
Release 0.8.0 claims to add support for PyPy 3.10. While the release notes are minimal, the code changes show a non-CPython specific implementation strategy for SSLContext to preserve compatibility with libraries that do isinstance checks.
BreakingFeaturesv0.7.0
Release v0.7.0 primarily adjusts the exception type raised when the library is imported on unsupported macOS versions (10.7 and earlier). The code change is accompanied by documentation and test updates.
Breakingv0.6.1
Release 0.6.1 primarily addresses a RecursionError occurring when setting `SSLContext.minimum_version` or `SSLContext.maximum_version`. The code change works by delegating those setters to the original `ssl.SSLContext` implementation instead of assigning directly to the proxied context.
v0.6.0
Release 0.6.0 (marked beta) expands Truststore's SSLContext integration by adding functions to inject Truststore SSLContext into Python's stdlib ssl module, plus additional SSLContext method pass-throughs. It also documents the ability to control verification behavior via check_hostname and verify_mode (and verify_flags).
BreakingFeatures