Dependencies
Runtime packages#
| Package | Used for |
|---|---|
| PyQt6 | Qt 6 widgets, networking, multimedia, printing |
| PyQt6-WebEngine | Qt WebEngine (Chromium) and QWebEngineView |
| pywinstyles | small Windows styling helpers |
| requests | background downloads of the filter and threat lists |
| cryptography | AES-GCM and Scrypt for the password vault |
The Qt and Chromium binaries come with PyQt6-Qt6 and PyQt6-WebEngine-Qt6, which pip installs as dependencies.
Chromium security fixes therefore reach JBrowser through new PyQt6-WebEngine releases.
Build and developer tools#
requirements-build.txt adds PyInstaller (the build) and pyflakes (the lint
check) to the runtime packages.
tools/update_deps.py#
tools/update_deps.py is the one tool for the environment:
| Command | Does |
|---|---|
py -3.14 tools\update_deps.py |
creates .venv if needed, upgrades pip and every package in requirements-build.txt to its newest version (--upgrade-strategy eager), then verifies |
… --check |
verifies only: imports every module, runs pyflakes; installs nothing (this is what CI runs) |
… --runtime-only |
installs requirements.txt only, without PyInstaller and pyflakes |
… --lock |
also writes requirements.lock.txt with the exact installed versions |
"Verify" means: import every Qt module JBrowser uses and every module of the jbrowser package in a subprocess
(with QT_QPA_PLATFORM=offscreen), then run pyflakes over jbrowser, tools and main.py. A missing or broken
package fails here, not when a user opens a rarely used dialog. The versions of the main packages are printed at the
end.
Adding a package#
- Prefer the standard library and Qt. Every package ends up in the installer and in the licence notices.
- Add it to
requirements.txt(runtime) orrequirements-build.txt(tools only) with a minimum version, and add its top-level module toREQUIRED_IMPORTSintools/update_deps.pyif the app imports it. - Check the licence is compatible with the GPL v3 and list it in the README's licence section.
- Run
tools\update_deps.py, then build the app and check the package is bundled (PyInstaller hooks usually handle it; otherwise add it tohiddenimportsinJBrowser.spec).
Security updates#
Run tools\update_deps.py before every release (master.ps1 does it automatically), and watch
PyQt6-WebEngine releases for Chromium security fixes; a new
PyQt6-WebEngine is a reason for a patch release on its own.