# Dependencies are listed alphabetically by package name.
# Multiple entries for the same package (with different version constraints) are grouped together.

aiohttp>=3.13.5,<3.14.0; python_version < '3.10'
aiohttp>=3.14.2; python_version >= '3.10'
certifi>=2026.5.20
cffi>=2.0.0
# cheroot 8.5.2 fails to build with modern setuptools due to setuptools_scm_git_archive dependency
cheroot>=11.1.2
cherrypy>=18.10.0
# We need contextvars for salt-ssh
contextvars
croniter!=0.3.22,>=6.2.2; sys_platform != 'win32'
# cryptography 48.0.0 drops support for Python 3.9.0 and 3.9.1
# (only >3.9.1 is accepted), but the py3.9 lock files are compiled
# with --python-version=3.9 which includes those releases. Cap at the
# last 46.x release for Python 3.9 so uv pip compile can still resolve;
# Python 3.10+ takes the 48.x line.
cryptography>=46.0.7,<48.0.0; python_version < '3.10'
# cryptography 49+ dropped Windows x86 (win32) wheels. 3006.x still
# builds a Windows x86 onedir and the salt-onedir Windows build path
# does not pass --no-binary (unlike Linux/macOS), so pip falls through
# to the sdist and the Rust openssl-sys build fails for
# i686-pc-windows-msvc. Cap Windows at the last release that ships
# cp3X-abi3-win32 wheels (48.0.1). Non-Windows takes the 48.x floor
# and can float forward to 50.x.
cryptography>=48.0.1,<49.0.0; python_version >= '3.10' and sys_platform == 'win32'
cryptography>=48.0.1; python_version >= '3.10' and sys_platform != 'win32'
distro>=1.9.0
frozenlist>=1.8.0; python_version < '3.11'
frozenlist>=1.5.0; python_version >= '3.11'
gitpython>=3.1.62
immutables>=0.21
importlib-metadata>=8.7.0
# jaraco.functools 4.5.0 and jaraco.context 6.1.2 drop Python 3.9; keep the
# last 3.9-compatible releases there and let py>=3.10 float forward.
jaraco.functools>=4.4.0,<4.5.0; python_version < '3.10'
jaraco.functools>=4.4.0; python_version >= '3.10'
jaraco.context>=6.1.1,<6.1.2; python_version < '3.10'
jaraco.context>=6.1.1; python_version >= '3.10'
jaraco.text>=4.2.0
Jinja2>=3.1.6
jmespath>=1.1.0
looseversion
lxml>=6.1.1; sys_platform == 'win32'
MarkupSafe<4.0.0
# multidict 6.0.4 fails to source-build under clang 17+ with strict int/pointer
# conversion checks (macOS 15 onedir builds compile from sdist via
# --no-binary=:all:). 6.6+ fixed the C source compatibility.
multidict>=6.6.0
# msgpack 1.2.1 drops Python 3.9; keep the last 3.9-compatible release there.
msgpack>=1.1.2,<1.2.1; python_version < '3.10'
msgpack>=1.2.0; python_version >= '3.10'
# Packaging 24.1+ imports annotations from __future__ which breaks
# salt-ssh on target hosts with older Python versions (Amazon Linux 2
# still ships Python 3.7). 26.x additionally uses positional-only
# `/` parameter syntax which is a SyntaxError on Python <3.8. Keep at
# 24.0 to preserve salt-ssh compatibility against legacy target
# Pythons; salt 3006.x still promises this matrix.
packaging==24.0
psutil<6.0.0; python_version <= '3.9'
psutil>=5.0.0; python_version >= '3.10'
# pymssql 2.3.12+ dropped win32 (32-bit Windows) wheels; salt 3006.x
# still builds a Windows x86 onedir, so pin to the last release that
# ships cp3X-win32 wheels.
pymssql==2.3.11; sys_platform == 'win32'
pymysql>=1.2.0; sys_platform == 'win32'
# pyopenssl 26.2 dropped X509Extension and add_extensions(); salt/modules/tls.py
# now guards the missing symbol and lets the extension feature degrade cleanly.
pyopenssl>=26.0.0
python-dateutil>=2.9.0.post0
python-gnupg>=0.5.6
# pythonnet 3.1.0 drops Python 3.9; keep the last 3.9-compatible release there.
pythonnet>=3.0.5,<3.1.0; sys_platform == 'win32' and python_version < '3.10'
pythonnet>=3.0.5; sys_platform == 'win32' and python_version >= '3.10'
tzdata; sys_platform == 'win32'
pywin32>=312; sys_platform == 'win32'
pycryptodomex>=3.23.0
PyYAML>=6.0.3
requests>=2.32.5 ; python_version < '3.10'
requests>=2.34.2 ; python_version >= '3.10'
setproctitle>=1.3.7
# pyzmq 27 dropped its tornado runtime dep; pyzmq.eventloop submodules
# (zmqstream, future) still import tornado.ioloop at module load. Pin
# tornado explicitly so onedir lockfiles keep shipping it.
tornado>=6.5.5
# Python 3.9 stays on urllib3 1.26.x because botocore on py3.9 hard
# requires urllib3 < 2 and Salt 3006.x still builds a py3.9 onedir.
# The Python 3.10+ floor carries the urllib3 2.6.3 CVE backports
# (CVE-2025-66418, CVE-2026-21441).
urllib3>=1.26.20,<2.0.0; python_version < '3.10'
urllib3>=2.7.0; python_version >= '3.10'
# virtualenv 21.5.1 drops Python 3.9; keep the last 3.9-compatible release there.
virtualenv>=21.4.2,<21.5.1; python_version < '3.10'
virtualenv>=21.4.2; python_version >= '3.10'
# Transitive of virtualenv; some uv resolver caches pin a stale 3.25
# version that conflicts with the CI floor of 3.29.1 on Python 3.10+.
filelock>=3.29.1; python_version >= '3.10'
filelock>=3.19.1,<3.29.0; python_version < '3.10'
wmi>=1.5.1; sys_platform == 'win32'
xmltodict>=1.0.4; sys_platform == 'win32'
# zipp 4.1.0 drops Python 3.9; keep the last 3.9-compatible release there.
zipp>=3.23.1,<4.1.0; python_version < '3.10'
zipp>=3.23.1; python_version >= '3.10'
apache-libcloud>=3.8.0,<3.9.1; python_version < '3.10'
apache-libcloud>=3.9.1; python_version >= '3.10'
idna>=3.18
# attrs and charset-normalizer are pulled in transitively by aiohttp/requests.
# Explicit floors on py>=3.10 keep them at the current CVE-patched line.
attrs>=26.1.0; python_version >= '3.10'
charset-normalizer>=3.4.7; python_version >= '3.10'
# more-itertools 11.0.0 drops Python 3.9; keep the last 3.9-compatible release there.
more-itertools>=10.8.0,<11.0.0; python_version < '3.10'
more-itertools>=10.8.0; python_version >= '3.10'
pyasn1>=0.6.4
# pycparser 3.0 drops Python 3.9; keep the last 3.9-compatible release there.
pycparser>=2.23,<3.0; python_version < '3.10'
pycparser>=2.23; python_version >= '3.10'
