Update each action to its current latest release and pin to the full commit SHA (supply-chain hardening), with the version in a trailing comment: * actions/checkout v4 -> v7.0.0 * Swatinem/rust-cache v2 -> v2.9.1 * actions/upload-artifact v4 -> v7.0.1 * actions/download-artifact v4 -> v8.0.1 * softprops/action-gh-release v2 -> v3.0.1 * dtolnay/rust-toolchain pinned to master @ 2026-06-20 (no tagged releases); add explicit `toolchain: stable` since the channel can no longer be inferred from the @ref once pinned to a SHA. Verified upload-artifact v7 (zips by default) and download-artifact v8 interoperate, and that every input still exists in the new majors. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
DRMLibre
A standalone, single-binary command-line tool (written in Rust, no runtime dependencies) for removing DRM from Amazon Kindle and Adobe Digital Editions ebooks. The decryption logic is ported from DeDRM_tools; DRMLibre is therefore licensed GPL-3.0-or-later. See CREDITS.md.
Use DRMLibre only on books you own, to exercise your own rights (format shifting, backup, accessibility). Respect the law in your jurisdiction.
Status
Under active development. Supported / planned formats:
| Capability | Status |
|---|---|
| Adobe ADEPT EPUB (+ hardening, B&N PassHash, font de-obfuscation) | ✅ done |
| Kindle MOBI / AZW / AZW3 | ✅ done |
| Adobe key auto-extraction from installed ADE (Windows, DPAPI) | ✅ done |
Kindle-for-PC key (.kinf) / Android / macOS auto-extraction |
planned |
| Kindle KFX-ZIP | planned |
| Adobe PDF, Kindle Topaz, eReader, Kobo, LCP | out of scope |
On Windows with Adobe Digital Editions activated, ADEPT EPUBs decrypt with no extra arguments — the key is extracted from the local install and cached in the config for later offline use.
Usage
drmlibre remove <files...> [options] # remove DRM
drmlibre passhash ... # generate/extract Adobe/B&N PassHashes
drmlibre config # summarize keys in the config file
Common remove options: -o/--output, --outputdir, -f/--force,
--overwrite, --serial, --pid, --key, --passphrase, --android-backup,
--config (default ./drmlibre.toml).
Examples:
# Adobe EPUB, using an exported Adobe key:
drmlibre remove "My Book.epub" --key adobe.der -o "My Book (no DRM).epub"
# Kindle eInk book, using the device serial:
drmlibre remove "My Book.azw" --serial 0123456789ABCDEF
Architecture
A Cargo workspace:
crates/drmlibre-core— the UI-agnostic engine (format detection, key management, decryptors). No printing or process exits; everything is aResultand progress goes throughtracing. This is what a future GUI links.crates/drmlibre-cli— thedrmlibrebinary (argument parsing, file I/O policy, exit codes).
Building
cargo build --release # binary at target/release/drmlibre
cargo test # run the test suite