Files
bambuddy/requirements.txt
T
maziggy 63b3cad8d8 chore(deps): bump python-multipart 0.0.22→0.0.26 and dompurify 3.3.3→3.4.0
python-multipart 0.0.26 closes CVE-2026-40347 (GHSA-mj87-hwqh-73pj), a
  DoS triggered by large preamble/epilogue data around a multipart
  boundary. Bambuddy consumes python-multipart transitively through
  FastAPI/Starlette for form and file-upload parsing, so multipart routes
  (backup restore, project thumbnail upload, etc.) were exposed.

  dompurify 3.4.0 picks up the fix for GHSA-39q2-94rc-95cp (function-form
  ADD_TAGS could bypass FORBID_TAGS). Bambuddy's two call sites use only
  array-form ALLOWED_TAGS/ALLOWED_ATTR, so the specific bypass was not
  reachable, but the bump still hardens the sanitizer and clears the
  audit warning.

  requirements.txt floor raised to python-multipart>=0.0.26;
  frontend/package.json caret pinned to ^3.4.0; npm audit and pip audit
  both report zero outstanding advisories after the bumps.
2026-04-16 08:47:40 +02:00

72 lines
1.3 KiB
Plaintext

# Web Framework
fastapi>=0.109.0
uvicorn[standard]>=0.27.0
# Database
sqlalchemy>=2.0.0
aiosqlite>=0.19.0
asyncpg>=0.29.0
greenlet>=3.0.0
# Pydantic
pydantic>=2.0.0
pydantic-settings>=2.0.0
# Bambu Lab Printer Communication
paho-mqtt>=2.0.0
aioftp>=0.22.0
# Virtual Printer (emulates Bambu printer for slicer uploads)
pyftpdlib>=2.0.0
cryptography>=46.0.7
# SpoolBuddy remote SSH updates (pure-Python SSH client; avoids the
# OpenSSH `ssh` binary which calls getpwuid() and fails in Docker when
# the container UID isn't in /etc/passwd)
asyncssh>=2.18.0
# 3MF Processing (standard zipfile is sufficient for Bambu 3MF files)
defusedxml>=0.7.0 # Safe XML parsing (prevents XXE attacks)
# Excel Export
openpyxl>=3.1.0
# Notifications
pywebpush>=2.0.0
# Utilities
python-multipart>=0.0.26
aiofiles>=23.0.0
# QR Code generation
qrcode[pil]>=7.4.0
# STL Thumbnail Generation
trimesh>=4.0.0
matplotlib>=3.8.0
fast-simplification>=0.1.0
# System monitoring
psutil>=6.0.0
# Authentication
PyJWT>=2.12.0
passlib[bcrypt]>=1.7.4
ldap3>=2.9.0
pyotp>=2.9.0
# HTTP client (used for OIDC token exchange)
httpx>=0.26.0
# Plate Detection (optional - enables build plate empty detection)
opencv-python-headless>=4.8.0
numpy>=1.24.0
# Development
pytest>=9.0.3
pytest-asyncio>=0.23.0
httpx>=0.26.0
ruff>=0.2.0
pillow>=12.2.0