$npx skillfedfor your agent

securesystemslib

A library that provides cryptographic and general-purpose routines for Secure Systems Lab projects at NYU

Worth itPyPI Software DevelopmentReleased May 20261.1M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — securesystemslib-1.4.0-py3-none-any.whl
v1.4.0 · released 2026-05-27 · Python ~=3.10

Yes. Securesystemslib is worth installing if you need to sign or verify digital signatures in a supply-chain or software-integrity context. It is actively maintained, has no base dependencies, carries a permissive MIT license, and is purpose-built for TUF and in-toto workflows. Install with extras (`[crypto]` or `[hsm]`) only if you need signature creation or hardware key support.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Default installation supports ed25519 verification only; other schemes require optional dependencies via extras.
  • Low install friction with no runtime dependencies; actively maintained with a release 79 days ago and recent commits.

License · maintenance · safety

MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and proprietary projects.

last release 2026-05-27 (79 days) · last repo commit 2026-08-12 · 56 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,065,950 downloads/mo, #4,415 on PyPI

Verify before relying

pip install securesystemslib

from securesystemslib.signer import SSlibSigner

# Basic usage requires importing from the signer module
# For RSA, ECDSA, or HSM support, install with extras:
# pip install securesystemslib[crypto]
# pip install securesystemslib[hsm]
  • Whether the package's cryptographic implementations have undergone independent security audits.
  • Performance characteristics when handling large numbers of signatures or keys.
  • Specific cloud-based key management systems supported beyond the general mention.
Same gist for agents: .md · .json

What it is and what it does

Securesystemslib is a cryptography interface library that abstracts digital signing and verification operations. It sits between your application and various cryptographic backends—pure-Python ed25519, the cryptography library for RSA and ECDSA, and hardware security modules like Yubikeys—allowing you to work with a unified API regardless of which signing system you choose. The library was built specifically for TUF (The Update Framework) and in-toto projects, so its key and signature containers are compatible with those projects' metadata formats.

The default installation provides ed25519 signature verification only. To enable signature creation or other schemes (RSA, ECDSA), you install with extras like `[crypto]` or `[hsm]`. It has no runtime dependencies in its base form, making it lightweight to add to a project. The library is actively maintained, supports modern Python versions (3.10 through 3.14), and carries an MIT license.

Use it for

  • Verify software package authenticity in supply-chain security tools by checking TUF or in-toto metadata signatures.
  • Sign and verify release artifacts or deployment manifests in CI/CD pipelines using a unified cryptographic interface.
  • Integrate hardware security module keys (e.g., Yubikeys) into applications without writing HSM-specific code.
  • Build secure update frameworks that need to support multiple signature schemes without tight coupling to any one backend.
  • Migrate legacy key formats to a standard format compatible with modern signing workflows.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Securesystemslib is worth installing if you need to sign or verify digital signatures in a supply-chain or software-integrity context. It is actively maintained, has no base dependencies, carries a permissive MIT license, and is purpose-built for TUF and in-toto workflows. Install with extras (`[crypto]` or `[hsm]`) only if you need signature creation or hardware key support.

Install

securesystemslib on PyPI

Before you install

Low install friction with no runtime dependencies; actively maintained with a release 79 days ago and recent commits. Supports Python 3.10 through 3.14.

Requires Python 3.10 or later. Default installation supports ed25519 verification only; other schemes require optional dependencies via extras.

License in practice

MIT license permits free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and proprietary projects.

Quickstart

pip install securesystemslib

from securesystemslib.signer import SSlibSigner

# Basic usage requires importing from the signer module
# For RSA, ECDSA, or HSM support, install with extras:
# pip install securesystemslib[crypto]
# pip install securesystemslib[hsm]

Verify before relying

  • Whether the package's cryptographic implementations have undergone independent security audits.
  • Performance characteristics when handling large numbers of signatures or keys.
  • Specific cloud-based key management systems supported beyond the general mention.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release ~=3.10
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 79 days since the last release
Last repo commit
First released
Downloads1,065,950 / month, #4,415 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersNatural Language :: EnglishOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXOperating System :: POSIX :: LinuxProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonTopic :: SecurityTopic :: Software Development

Evidence: securesystemslib-1.4.0-py3-none-any.whl

Tags

Capabilities
digital signature verificationcryptographic signing libraryed25519 rsa ecdsa signaturestuf in-toto metadatahardware security module keyskey management cryptographysignature verification python
Topics
supply-chain-securitytuf-in-totohardware-keys
PyPI keywords
cryptographyecdsaed25519keysrsasignatures

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ed25519 rsa ecdsa signatures”

  • securesystemslibSecuresystemslib provides a cryptography interface for creating and…
  • lightdsaLightDSA provides digital signature generation and verification using…
  • ECPyECPy is a pure Python elliptic curve library providing ECDSA, EdDSA…

Give your agent the search over MCP, or paste the wish link into any chat.

More Software Development packages

typing-extensions Worth it
PyPI · Software Development · released Jul 2026

Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.

PSF-2.0pure Python · 3.9+
1.9Bdownloads / mo
numpy Worth it
PyPI · Software Development · released Aug 2026

NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.

BSD-3-Clause AND 0BSD AND MIT AND Zlib AND CC0-1.0compiled wheel · 3.12+
1.1Bdownloads / mo
fastapi Worth it
PyPI · Software Development · released Jul 2026

FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.

MITpure Python · 3.10+
568.6Mdownloads / mo
annotated-doc With conditions
PyPI · Software Development · released Jul 2026

Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.

MITpure Python · 3.9+
456.2Mdownloads / mo
typer Worth it
PyPI · Software Development · released Aug 2026

Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.

Install it if you are building CLIs in Python.

MITpure Python · 3.10+
369.3Mdownloads / mo
distlib With conditions
PyPI · Software Development · released Jun 2026

Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.

permissive licensepure Python
323.3Mdownloads / mo

See also ckzg · lightdsa · tuf · hsms · PGPy13 · endesive · ed25519-blake2b-fork · xmlsec · py-ed25519-zebra-bindings · pyas2lib