requirements.txt 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171
  1. # Web Framework
  2. # fastapi 0.136.x ships an undocumented `fastar` dep in its [standard]
  3. # extras group (MAL-2026-4750, surfaced by Amazon Inspector). `fastar`
  4. # is a Rust-tar binding package — no plausible reason for a web
  5. # framework to depend on it. Even if `fastar` is benign today, the
  6. # advisory's framing as a namespace-abuse / supply-chain vector is
  7. # valid: anyone controlling the `fastar` PyPI namespace gains code
  8. # execution at install time across every fastapi[standard] install.
  9. # Bambuddy doesn't request [standard], so we don't pull `fastar` in
  10. # practice, but pip-audit flags the package itself and breaks CI.
  11. # Hold to 0.135.x (which has all features we use, including SSE)
  12. # until upstream removes the dep or explains the rationale.
  13. fastapi>=0.109.0,<0.136.0
  14. uvicorn[standard]>=0.27.0
  15. # Database
  16. # 2.0.38 is a hard floor, not a preference: it changed the aiosqlite dialect's
  17. # default pool for file databases from NullPool to AsyncAdaptedQueuePool.
  18. # core/database._create_engine() passes pool_size/max_overflow on the SQLite
  19. # branch, which NullPool rejects — on <=2.0.37 every SQLite install (and the
  20. # test suite, which imports the module-level engine) dies at import with
  21. # "Invalid argument(s) 'pool_size','max_overflow' sent to create_engine()".
  22. sqlalchemy>=2.0.38
  23. aiosqlite>=0.19.0
  24. asyncpg>=0.29.0
  25. greenlet>=3.0.0
  26. # Pydantic
  27. pydantic>=2.0.0
  28. # 2.14.2 patches GHSA-4xgf-cpjx-pc3j (NestedSecretsSettingsSource follows
  29. # symlinks out of secrets_dir). Bambuddy does not use that source — pin
  30. # is precautionary so the audit stays clean.
  31. pydantic-settings>=2.14.2
  32. # Transitive of pydantic-settings, floor-pinned to patch CVE-2026-28684 (dotenv 1.2.1)
  33. python-dotenv>=1.2.2
  34. # Bambu Lab Printer Communication
  35. paho-mqtt>=2.0.0
  36. aioftp>=0.22.0
  37. # Virtual Printer (emulates Bambu printer for slicer uploads)
  38. pyftpdlib>=2.0.0
  39. # Upstream's X.509 / PKCS#7 surface is in our trust path via asyncssh,
  40. # pyOpenSSL and the virtual printer's certificates, so this floor tracks the
  41. # current fix release: 46.x had GHSA-537c-gmf6-5ccf (fixed in 48.0.1), and
  42. # 49.0.0 has PYSEC-2026-3552 (fixed in 50.0.0).
  43. cryptography>=50.0.0
  44. # Nothing in the app imports it, but it is installed, and it is the gate on
  45. # the line above: each pyOpenSSL release caps `cryptography` to a narrow
  46. # window (26.3.0 allows <50, 26.4.0 allows <51), so a stale pyOpenSSL
  47. # silently pins cryptography below its fix line -- pip cannot upgrade past
  48. # the cap even when asked.
  49. # Raise this floor in the same commit as any cryptography floor.
  50. pyopenssl>=26.4.0
  51. # SpoolBuddy remote SSH updates (pure-Python SSH client; avoids the
  52. # OpenSSH `ssh` binary which calls getpwuid() and fails in Docker when
  53. # the container UID isn't in /etc/passwd)
  54. asyncssh>=2.18.0
  55. # 3MF Processing (standard zipfile is sufficient for Bambu 3MF files)
  56. defusedxml>=0.7.0 # Safe XML parsing (prevents XXE attacks)
  57. # Excel Export
  58. openpyxl>=3.1.0
  59. # Utilities
  60. # 0.0.27 → 0.0.31 clears three CVEs in the parser surface that FastAPI
  61. # uses for multipart form bodies (CVE-2026-53538/53539/53540).
  62. python-multipart>=0.0.31
  63. aiofiles>=23.0.0
  64. # QR Code generation
  65. qrcode[pil]>=7.4.0
  66. # PDF generation (spool label printing — #809)
  67. reportlab>=4.0.0
  68. # PDF thumbnails for the file manager (#2976): renders page one with PDFium.
  69. # Wheels bundle the PDFium binary for every platform we ship (Linux x86_64 /
  70. # aarch64 / armv7, macOS, Windows), so no system package is needed.
  71. pypdfium2>=5.0.0
  72. # STL Thumbnail Generation
  73. trimesh>=4.0.0
  74. matplotlib>=3.8.0
  75. fast-simplification>=0.1.0
  76. # trimesh's 3MF loader uses networkx for scene-graph traversal and lxml
  77. # for the model.xml parse. Required by plate_thumbnail.py to render the
  78. # model out of a sliced .gcode.3mf when the BS/Orca CLI didn't embed
  79. # Metadata/plate_N.png. Not strictly transitive — trimesh imports both
  80. # lazily inside the 3MF code path, so the load call fails at runtime
  81. # ("No module named 'networkx'" / "No module named 'lxml'") if absent.
  82. networkx>=3.0
  83. lxml>=5.0
  84. # System monitoring
  85. psutil>=6.0.0
  86. # IANA tz database for Windows. The stdlib ``zoneinfo`` module reads the
  87. # system tz database on Linux/macOS, but Windows has none — and the
  88. # embedded Python in our Windows installer doesn't carry one either, so
  89. # even ``ZoneInfo("UTC")`` raises ``ZoneInfoNotFoundError`` and any
  90. # endpoint that resolves a tz (e.g. /api/local-backup/status) 500s.
  91. # ``tzdata`` is the official PyPI package that fills the gap.
  92. tzdata>=2024.1; sys_platform == "win32"
  93. # Authentication
  94. PyJWT>=2.13.0
  95. passlib[bcrypt]>=1.7.4
  96. ldap3>=2.9.0
  97. pyotp>=2.9.0
  98. # Transitive dep pin: idna<3.15 has CVE-2026-45409 (ReDoS on encode() with
  99. # crafted Unicode). Pulled in by anyio/httpx/requests/yarl; pin the floor
  100. # so we don't regress when a downstream loosens its constraint.
  101. idna>=3.15
  102. # HTTP client (used for OIDC token exchange)
  103. httpx>=0.26.0
  104. # CA bundle. Already a transitive dep of httpx, but services/makerworld.py
  105. # imports it directly to pin the S3 presigned download's urllib opener to the
  106. # same trust store httpx uses — the Windows OS store lacks the Amazon root
  107. # until CryptoAPI lazily caches it (#2562). Declared explicitly so a future
  108. # httpx release that drops certifi can't silently break that import.
  109. certifi>=2024.2.2
  110. # HTTP client with browser TLS-fingerprint impersonation. Used only for
  111. # the bambulab.com firmware-download page in services/firmware_check.py:
  112. # Bambu's Cloudflare WAF gates the page behind a JA3/TLS-fingerprint
  113. # challenge that plain httpx/requests can't pass (#1666). curl_cffi
  114. # replays Chrome's ClientHello bytes so the TLS handshake clears CF;
  115. # the HTTP-layer User-Agent stays honest Bambuddy/1.0 per our compliance
  116. # commitment. Soft dependency — if it fails to import (rare platforms,
  117. # constrained installs), firmware_check degrades gracefully to wiki-only
  118. # version detection and logs a warning at startup.
  119. curl_cffi>=0.7.0
  120. # Transitive pin: urllib3 2.6.3 has CVE-2026-44431 and CVE-2026-44432;
  121. # 2.7.0+ is the fixed release. Direct pin here because none of our
  122. # top-level deps require >=2.7.0 yet, so without this the resolver
  123. # would silently keep installing the vulnerable 2.6.x line.
  124. urllib3>=2.7.0
  125. # Transitive of fastapi. starlette 1.0.0 has PYSEC-2026-161; 1.1.x has
  126. # CVE-2026-54282/54283; 1.3.1 is the fixed release. fastapi's range still
  127. # admits the vulnerable builds, so we pin the floor directly to stop the
  128. # resolver from picking them.
  129. starlette>=1.3.1
  130. # Used directly by services/external_camera.py (ClientSession, ClientTimeout,
  131. # ClientError, iter_chunked). The floor keeps the resolver off vulnerable
  132. # lines: 3.13.5 has CVE-2026-34993 and CVE-2026-47265 (fixed in 3.14.0), and
  133. # 3.14.1 has PYSEC-2026-3545/3546/3547 (3.14.3 clears all three).
  134. aiohttp>=3.14.3
  135. # Plate Detection (optional - enables build plate empty detection)
  136. opencv-python-headless>=4.8.0
  137. numpy>=1.24.0
  138. # Development
  139. pytest>=9.0.3
  140. pytest-asyncio>=0.23.0
  141. httpx>=0.26.0
  142. # Lint/format is pinned exactly in requirements-dev.txt — that file is the
  143. # source of truth for the version CI enforces. This floor only keeps `ruff`
  144. # importable for anyone who installs the runtime file alone.
  145. ruff>=0.8.0
  146. pillow>=12.2.0