Files
DeDRM_tools/pyproject.toml
T
JMR-devandClaude Opus 4.8 815c621f01 Manage dependencies with Poetry; drop abandoned pycrypto
Add a Poetry manifest (pyproject.toml) and lock file to manage the
development / standalone-CLI environment for the plugins. The plugins
themselves run inside calibre's bundled Python, so the project is set to
package-mode = false and the manifest documents the real third-party
dependency set rather than building a distributable package.

Declared dependencies:
  - pycryptodomex (>=3.20): maintained crypto library exposing the
    `Cryptodome` namespace that every crypto import already prefers. This
    replaces the abandoned pycrypto (unmaintained since 2014,
    CVE-2013-7459), which is no longer needed and is not declared.
  - lxml (>=5.0): EPUB/PDF/ADEPT XML handling.
  - apsw (>=3.46): optional `nook` group, only used by
    ignoblekeyWindowsStore.py for Nook Windows Store key extraction.

calibre/calibre_lzma/PyQt are supplied by the calibre runtime and the
Python <3.3 lzma fallbacks (backports.lzma, pylzma) are unnecessary on
the supported Python 3.8+ range, so none are declared.

Also update the stale PyCrypto install instructions in
ignoblekeyGenPassHash.py to point at the maintained pycryptodomex.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 18:27:43 -05:00

41 lines
1.7 KiB
TOML

# Poetry-managed development environment for DeDRM_tools.
#
# Note: the DeDRM and Obok plugins are distributed as calibre plugin zips and
# run inside calibre's bundled Python interpreter -- they are NOT pip-installed.
# This manifest therefore manages the *development* / standalone-CLI environment
# (running the scripts outside calibre, testing, etc.) and documents the real
# third-party dependency set, rather than producing a distributable package.
# Hence `package-mode = false`.
#
# Dependencies provided by the calibre runtime (do not pip-install them here):
# calibre, calibre_plugins, calibre_lzma, PyQt5 / PyQt4
#
# Crypto: the code imports the `Cryptodome` namespace first (pycryptodomex,
# actively maintained) and only falls back to the `Crypto` namespace if it is
# missing. The legacy `Crypto` namespace is satisfied by the maintained
# pycryptodome package as well, so the abandoned `pycrypto` package (unmaintained
# since 2014, CVE-2013-7459) is not required and is intentionally not declared.
[tool.poetry]
package-mode = false
[tool.poetry.dependencies]
python = ">=3.8,<4.0"
# Actively-maintained crypto library, exposes the `Cryptodome` namespace that
# all crypto imports prefer. Replaces the abandoned `pycrypto`.
pycryptodomex = ">=3.20"
# XML handling for Adobe ADEPT / EPUB / PDF DRM (ineptepub, ineptpdf,
# epubfontdecrypt, epubwatermark, ignoblekey*).
lxml = ">=5.0"
# SQLite access for Nook (Barnes & Noble) Windows Store key extraction is only
# needed by DeDRM_plugin/ignoblekeyWindowsStore.py. Kept in an optional group so
# the base environment installs cleanly on platforms where it is not required.
[tool.poetry.group.nook]
optional = true
[tool.poetry.group.nook.dependencies]
apsw = ">=3.46"