mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 14:25:08 +00:00
- Plugin-supplied widgets load as /static/plugin-widgets/...js?v=<plugin version>, so an update isn't hidden behind the year-long immutable cache. - Fire-and-forget loadInstalledPlugins() calls catch the rejection it has already reported, so the global handler no longer adds a second toast. - Timezone picker renders again when the General partial is re-injected. - Remove dead code: executePluginAction's six plugin-id fallbacks and [DEBUG] logging, window.currentPluginConfig and every read of it, the file-upload JSON delete branch, unused PluginAPI / PluginInstallManager / PluginStateManager helpers, loadPluginWidgetsFromManifest, the stale install_manager.js and LEDVisibility fallbacks, error_handler.js's global escapeHtml, 13 unused CSS rules, and stale comments/no-op returns. - pytz < 2027, psutil < 7 in requirements-test.txt, pytest-cov < 8. - Pin anthropics/claude-code-action to the commit v1 resolves to. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
79 lines
3.8 KiB
Plaintext
79 lines
3.8 KiB
Plaintext
# LEDMatrix Core Dependencies
|
|
# Compatible with Python 3.10, 3.11, 3.12, and 3.13
|
|
# Tested on Raspbian OS 12 (Bookworm) and 13 (Trixie)
|
|
|
|
# Image processing
|
|
Pillow>=12.2.0,<13.0.0
|
|
numpy>=1.24.0 # For fast array operations in ScrollHelper (compatible with 2.x)
|
|
|
|
# Timezone handling
|
|
pytz>=2024.2,<2027.0 # Updated for latest timezone data
|
|
|
|
# HTTP requests
|
|
requests>=2.33.0,<3.0.0
|
|
urllib3>=2.7.0,<3.0.0 # requests transitive, but imported directly (urllib3.util.retry.Retry); floor is a security floor, not the API floor — 1.26.x carries ~10 CVEs
|
|
|
|
# Google API integration
|
|
|
|
# Font rendering
|
|
freetype-py>=2.5.1,<3.0.0
|
|
|
|
# Spotify integration (used by web_interface/blueprints/api_v3.py OAuth endpoints)
|
|
spotipy>=2.25.2,<3.0.0
|
|
|
|
# Flask web framework
|
|
Flask>=3.1.3,<4.0.0
|
|
|
|
# WebSocket support: intentionally NOT declared here. Plugins that need
|
|
# it (e.g. ledmatrix-music's Socket.IO client) declare it in their own
|
|
# requirements.txt, which the plugin store installs.
|
|
|
|
# JSON Schema validation
|
|
jsonschema>=4.20.0,<5.0.0
|
|
|
|
# Requirement specifier parsing (plugin dependency satisfaction checks)
|
|
packaging>=23.0,<27.0
|
|
|
|
# Testing dependencies live in requirements-test.txt:
|
|
# pip install -r requirements.txt -r requirements-test.txt
|
|
|
|
# ───────────────────────────────────────────────────────────────────────
|
|
# Optional dependencies — the code imports these inside try/except
|
|
# blocks and gracefully degrades when missing. Install them for the
|
|
# full feature set, or skip them for a minimal install.
|
|
# ───────────────────────────────────────────────────────────────────────
|
|
#
|
|
# scipy — nothing, as of #570. It was listed for the sub-pixel
|
|
# interpolation path in src/common/scroll_helper.py, but
|
|
# get_visible_portion never consulted HAS_SCIPY, so that
|
|
# path was dead before it was deleted. The blend that
|
|
# replaced it is numpy-only. Do not install it expecting
|
|
# smoother scrolling: sub-pixel blending is off by default
|
|
# because it reads worse on a coarse panel, not because it
|
|
# is missing a library. See docs/SCROLL_PERFORMANCE.md.
|
|
#
|
|
# psutil — per-plugin resource monitoring in
|
|
# src/plugin_system/resource_monitor.py. The monitor
|
|
# silently no-ops when missing (PSUTIL_AVAILABLE = False).
|
|
# Note: web_interface/requirements.txt requires this
|
|
# range as a hard dependency — keep the two in sync.
|
|
# pip install 'psutil>=6.0.0,<7.0.0'
|
|
#
|
|
# orjson — faster JSON for the disk cache
|
|
# (src/cache/disk_cache.py). Encoding a ~1MB cache
|
|
# record drops from ~12ms to ~1.6ms on a Pi 4, which
|
|
# matters because that work holds the GIL and stalls
|
|
# the render thread mid-scroll. Falls back to the
|
|
# stdlib json when missing — see docs/SCROLL_PERFORMANCE.md.
|
|
# The 3.11.6 floor is CVE-2025-67221: orjson.dumps did not
|
|
# limit recursion on deeply nested documents, and the disk
|
|
# cache encodes payloads parsed straight from third-party
|
|
# APIs. 3.11.6 covers the Python range above.
|
|
# pip install 'orjson>=3.11.6,<4.0'
|
|
#
|
|
# Flask-Limiter — request rate limiting in web_interface/app.py
|
|
# (accidental-abuse protection, not security). The
|
|
# web interface starts without rate limiting when
|
|
# this is missing.
|
|
# pip install 'Flask-Limiter>=3.5.0,<4.0.0'
|