ambolt

CRA Index / PyPI / certifi

certifi and the Cyber Resilience Act

7 of 9 readable security signals are in place for certifi 2026.7.22 (PyPI). Data checked 2026-10-05.

certifi 2026.7.227 of 9 signals
Signals from public data, not a compliance assessment. A missing signal can mean the project keeps it elsewhere.

certifi 2026.7.22 is the current default version of this PyPI package, published on 2026-07-22. The registry lists 75 versions in total and the licence declared is MPL-2.0. The source repository is certifi/python-certifi with 1,001 stars.

The OpenSSF Scorecard for the repository was last computed on 2026-08-24 and gives an overall 6.3/10. Signals that are not in place today: code review before merge; automated security testing.

As of 2026-10-05, deps.dev lists no known advisories for this version. That is a snapshot and not a promise: new advisories can be published at any time.

If you ship a product that includes certifi, the Cyber Resilience Act expects you to know which components you ship, to follow their vulnerabilities and to exercise due diligence on third-party components (Annex I, Part II and Article 13). In practice: list certifi 2026.7.22 in your SBOM with its package URL pkg:pypi/[email protected], watch for new advisories, and keep the upstream security contact in your vulnerability handling process.

Put the badge in your README

CRA signals for certifi

Check your own project

Run the repository check on certifi/python-certifi, or check your own SBOM and create the licence notices.

More in the index

s3fs, six, platformdirs, filelock, google-auth, tomlkit · all PyPI packages

Sources and method

Package and version facts, licences, advisories and provenance: deps.dev (generated data under CC BY 4.0; advisories from OSV). Repository signals: the OpenSSF Scorecard. We read them on 2026-10-05 and show them without scoring the people behind a project. The nine signals are our selection; every signal could be read for this package.

Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.