chore(deps): remove packages nothing imports, declare direct imports, move mypy to test deps

Removed from requirements.txt: python-socketio, python-engineio,
websockets, websocket-client — zero imports anywhere in this repo, and
the one store plugin that needs Socket.IO (ledmatrix-music) declares it
in its own requirements.txt, which the plugin store installs. Removed
the same quartet plus timezonefinder, geopy, google-auth-oauthlib,
google-auth-httplib2, google-api-python-client, unidecode, icalevents,
python-dateutil, flask-wtf and the werkzeug pin from
web_interface/requirements.txt — all leftovers from the deleted built-in
weather/calendar/music displays (flask-wtf was doubly dead: app.py
explicitly disables CSRF and sets csrf=None). scripts/
install_dependencies_apt.py, which mirrors these lists for the
first-time installer, drops the same packages.

Added: urllib3 (imported directly in four core modules), jinja2 and
markupsafe (imported directly in pages_v3.py) — previously reachable
only as transitives. mypy moves from runtime requirements to
requirements-test.txt.

Verified in a fresh venv: all four requirements files co-install, pip
check is clean, the full CI-enrolled suite (907 tests) and a Flask boot
smoke pass with the trimmed dependency set.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SXb4mKcAkVaxkeTb3YnAdr
This commit is contained in:
Claude
2026-08-06 00:06:36 +00:00
parent 45032f96e1
commit 1ec22db2d1
4 changed files with 22 additions and 56 deletions
+10 -26
View File
@@ -4,20 +4,15 @@
# Web framework
flask>=3.1.3,<4.0.0
werkzeug>=3.1.6,<4.0.0
flask-wtf>=1.2.0 # CSRF protection (optional for local-only, but recommended)
flask-limiter>=3.5.0,<4.0.0 # Rate limiting (prevent accidental abuse)
flask-compress>=1.14 # gzip/brotli response compression (big win for the large JS/HTML over WiFi)
jinja2>=3.1.0,<4.0.0 # Flask transitive, but imported directly (TemplateNotFound)
markupsafe>=2.1.0,<4.0.0 # Flask transitive, but imported directly (escape)
# WebSocket support for plugins
# Note: Web interface uses Server-Sent Events (SSE) for real-time updates, not WebSockets
# However, plugins may need websocket support to connect to external services
# (e.g., music plugin connecting to YTM Companion server via Socket.IO)
# These packages are required for plugin compatibility
python-socketio>=5.14.0,<6.0.0
python-engineio>=4.9.0,<5.0.0
websockets>=12.0,<14.0
websocket-client>=1.8.0,<2.0.0
# WebSocket support: intentionally NOT declared here. The web interface
# uses Server-Sent Events, and plugins that need Socket.IO (e.g.
# ledmatrix-music) declare it in their own requirements.txt, which the
# plugin store installs.
# Image processing
Pillow>=12.2.0,<13.0.0
@@ -35,24 +30,13 @@ numpy>=1.24.0
# HTTP requests
requests>=2.33.0,<3.0.0
# Date/time utilities
python-dateutil>=2.9.0,<3.0.0
# Timezone handling (must match main requirements)
pytz>=2024.2,<2025.0
timezonefinder>=6.5.0,<7.0.0
geopy>=2.4.1,<3.0.0
# Google API integration (must match main requirements)
google-auth-oauthlib>=1.2.0,<2.0.0
google-auth-httplib2>=0.2.0,<1.0.0
google-api-python-client>=2.147.0,<3.0.0
# Spotify integration (must match main requirements)
spotipy>=2.25.2,<3.0.0
# Text processing (must match main requirements)
unidecode>=1.3.8,<2.0.0
# Calendar integration (must match main requirements)
icalevents>=0.1.27,<1.0.0
# Plugin-era note: timezonefinder, geopy, the google-api client stack,
# unidecode, icalevents and python-dateutil used to live here for the
# built-in weather/calendar/music displays. Those are store plugins now
# and declare their own dependencies, which the plugin store installs.