Assessment: Met
Justification
The project uses TLS exclusively through the requests library for HTTPS fetching. TLS 1.2+ compliance is guaranteed by the combination of the requests version floor, its dependency chain, and the absence of any downgrade configuration in the project code.
How TLS is used
The sole TLS code path is HTTPSFetcher._do_fetch(), which calls requests.get() (cache.py:355–362):
response = requests.get(
self._url,
auth=auth,
verify=verify, # defaults to True (cert validation on)
timeout=30,
allow_redirects=False,
stream=...,
)
There is no ssl_context, ssl_version, or PROTOCOL_* override anywhere in the codebase — TLS negotiation is fully delegated to the requests/urllib3/OpenSSL stack.
Why that stack enforces TLS 1.2+
- requests >= 2.32.2 (pyproject.toml:53)
requests 2.32.x depends on urllib3 >= 2.0. urllib3 2.0 dropped support for TLS 1.0 and TLS 1.1 entirely, setting SSLContext.minimum_version = TLSVersion.TLSv1_2 by default. This means TLS 1.2 is the minimum regardless of the system OpenSSL default.
- cryptography >= 46.0.7 (pyproject.toml:38)
The cryptography 46.x series requires OpenSSL 1.1.1 or later and PyCA cryptography itself enforces TLS 1.2+ in all contexts it manages. This underpins the paramiko SSH transport as well.
- paramiko == 5.0.0 (pyproject.toml:39)
Paramiko 5.x requires cryptography >= 3.3 and exclusively uses SSHv2 — there is no SSHv1 support in any supported paramiko release. The SFTP transport carries no TLS but does carry SSHv2, which is a listed approved protocol in the requirement.
- Certificate verification on by default
verify=None in the requests.get() call means True (verify against the system CA bundle) unless the user has set REQUESTS_CA_BUNDLE or CURL_CA_BUNDLE to a valid path (cache.py:342–350). Setting those env vars to an invalid path raises a TrestleError — it is impossible to silently disable certificate verification.
Key source locations
File Relevance
pyproject.toml:53 requests>=2.32.2 — floor that pulls in urllib3>=2.0, which enforces TLS 1.2 minimum
pyproject.toml:38 cryptography>=46.0.7 — modern TLS stack, OpenSSL 1.1.1+ required
pyproject.toml:39 paramiko==5.0.0 — SSHv2 only, no SSHv1
trestle/core/remote/cache.py:334–380 Only TLS call site — no version override, cert verify on by default
trestle/core/remote/cache.py:340–350 CA bundle handling — invalid path raises error, cannot be used to disable TLS verification
trestle/core/remote/security.py:159–160 Scheme allowlist enforces https or sftp only — plain HTTP cannot reach the TLS layer at all
Key external references
urllib3 2.0 changelog (drops TLS <1.2): https://urllib3.readthedocs.io/en/stable/changelog.html
requests 2.32 release (urllib3 2.x dependency): https://github.com/psf/requests/releases/tag/v2.32.0
paramiko 5.x (SSHv2 only): https://www.paramiko.org/changelog.html