Add a Poetry manifest (pyproject.toml) and lock file to manage the
development / standalone-CLI environment for the plugins. The plugins
themselves run inside calibre's bundled Python, so the project is set to
package-mode = false and the manifest documents the real third-party
dependency set rather than building a distributable package.
Declared dependencies:
- pycryptodomex (>=3.20): maintained crypto library exposing the
`Cryptodome` namespace that every crypto import already prefers. This
replaces the abandoned pycrypto (unmaintained since 2014,
CVE-2013-7459), which is no longer needed and is not declared.
- lxml (>=5.0): EPUB/PDF/ADEPT XML handling.
- apsw (>=3.46): optional `nook` group, only used by
ignoblekeyWindowsStore.py for Nook Windows Store key extraction.
calibre/calibre_lzma/PyQt are supplied by the calibre runtime and the
Python <3.3 lzma fallbacks (backports.lzma, pylzma) are unnecessary on
the supported Python 3.8+ range, so none are declared.
Also update the stale PyCrypto install instructions in
ignoblekeyGenPassHash.py to point at the maintained pycryptodomex.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This allows us to clean up the code a lot.
On Windows, it isn't installed by default and
most of the time not be found at all.
On M1 Macs, the kernel will kill the process instead.
Closes#33.