- Sources: migration guide, httpx2, discussion
- Summary: The migration guide names a break that reaches applications using the SDK's default client and changing nothing else. HTTPX verified certificates against the certifi bundle, HTTPX2 uses the operating-system trust store, and the SDK no longer installs certifi, so verification can fail in minimal container images with no system CA certificates, behind TLS-inspecting corporate proxies, and anywhere a modified certifi bundle was relied on. The stated fix is installing CA certificates in the OS trust store or setting
SSL_CERT_FILE or SSL_CERT_DIR, the SDK also stops installing httpx transitively, custom transports, auth classes, event hooks and mocking must target httpx2 types, and a RESPX version that patches only legacy HTTPX cannot intercept the default client. - Why it matters: A dependency upgrade that changes the trust store fails at request time in exactly the deployment shapes that carry no system CA bundle.
- Follow-up: Track whether the documented legacy HTTPX escape hatch, which is runtime-only and fails static type checking without a cast, is discontinued.
send feedback on this story