[UPD] requirement: refresh Odoo 18 lock, pin openai, idna and fsspec

Unpinned, openai and fsspec float to releases that break resolution:
openai 3.x needs idna>=3.18 against the idna==3.6 of Odoo, and s3fs
wants fsspec at its own exact version. openai stays on 2.x, fsspec moves
with s3fs, idna 3.20 overrides Odoo (3.6 carries CVE-2024-3651).
meteostat returns to 1.x, every 2.x caps pytz below 2024. The s390x
exclusion of PyMuPDF now lives in the requirements, so it survives.
Checked: no dependency leaves the pyproject (194 to 196) or the lock.
Not tested: majors ujson 6, plotly 7, python-slugify 9, sqlalchemy 2.1.

--- FR ---

[UPD] requirement : lock Odoo 18 à jour, épingles openai, idna et fsspec

Sans borne, openai et fsspec dérivent vers des versions qui cassent la
résolution : openai 3.x exige idna>=3.18 contre l'idna==3.6 d'Odoo, et
s3fs veut fsspec à sa propre version exacte. openai reste en 2.x, fsspec
suit s3fs, idna 3.20 supplante Odoo (la 3.6 porte CVE-2024-3651).
meteostat revient en 1.x, toute 2.x plafonne pytz sous 2024. L'exclusion
s390x de PyMuPDF vit désormais dans les requirements : elle survit.
Vérifié : aucune dépendance ne quitte le pyproject (194 à 196) ni le lock.
Non testé : majeures ujson 6, plotly 7, python-slugify 9, sqlalchemy 2.1.

Assisted-by: Claude Opus 5.5
This commit is contained in:
Mathieu Benoit 2026-09-25 03:15:58 -04:00
parent 409c8a57bd
commit 113353d2d3
3 changed files with 1102 additions and 1007 deletions

File diff suppressed because it is too large Load diff

View file

@ -20,22 +20,22 @@ authors = [ "Mathieu Benoit <mathben@technolibre.ca>",]
[tool.poetry.dependencies]
python = ">=3.12.10,<3.13"
a2wsgi = ">=1.10.6"
aiobotocore = "3.1.2"
aiobotocore = "3.1.3"
altcha = ">=2.0.0"
ansi2html = "^1.9.2"
ansi2html = "^1.9.5"
apispec = "^6.10.0"
asn1crypto = "1.5.1"
astor = "^0.8.1"
avalara = "^26.7.3"
avalara = "^26.9.0"
babel = "2.10.3"
bandit = "^1.9.4"
base64io = "^1.0.3"
beautifulsoup4 = "4.13.5"
bokeh = "3.6.3"
boto3 = "1.42.42"
botocore = "1.42.42"
cachetools = "^7.1.7"
cairosvg = "^2.9.0"
boto3 = "1.42.49"
botocore = "1.42.49"
cachetools = "^7.2.0"
cairosvg = "^2.9.1"
caldav = "1.3.9"
cbor2 = "5.6.2"
cerberus = "^1.3.8"
@ -43,37 +43,38 @@ chardet = "5.2.0"
code-writer = "^1.3.0"
colorama = "^0.4.6"
contextvars = "^2.4"
cryptography = "46.0.5"
cryptography = "46.0.7"
cssselect = "^1.5.0"
cython = "^3.2.9"
dateparser = "^1.4.2"
cython = "^3.3.0"
dateparser = "^1.4.3"
decorator = "5.1.1"
dnspython = "^2.8.0"
docutils = "0.20.1"
dropbox = "^12.2.1"
dropbox = "^12.2.2"
easypost = "7.15.0"
email-validator = "^2.3.0"
extendable = ">=0.0.4"
extendable-pydantic = ">=1.2.0"
extract-msg = "^0.56.0"
extract-msg = "^0.56.1"
extruct = "^0.18.0"
ezdxf = "^1.4.4"
fastapi = ">=0.110.0"
filetype = "^1.2.0"
flake8 = "^7.3.0"
flake8 = "^7.4.1"
fonttools = "^4.66.0"
formio-data = "^2.1.7"
freezegun = "1.2.1"
geocoder = "^1.38.1"
geoip2 = "2.9.0"
geojson = "^3.3.0"
gevent = "24.2.1"
gitpython = "^3.1.59"
gitpython = "^3.1.62"
giturlparse = "0.12.0"
googletrans-py = "4.0.0"
greenlet = "3.0.3"
httpagentparser = "^1.9.9"
icalendar = "5.0.13"
idna = "3.6"
idna = "3.20"
img2pdf = "^0.6.3"
isort = "7.0.0"
itsdangerous = "^2.2.0"
@ -83,31 +84,31 @@ libsass = "0.22.0"
lottie = "^0.7.2"
lxml = "5.2.1"
lxml-html-clean = "<0.4.5"
mako = "^1.4.1"
mako = "^1.4.3"
markdown2 = "2.5.1"
markdownify = "0.13.1"
markupsafe = "2.1.5"
matplotlib = "^3.11.1"
meteostat = "1.6.8"
matplotlib = "^3.11.2"
meteostat = "1.7.6"
mock = "^5.2.0"
mpld3 = "0.5.10"
msgraphfs = "^0.5"
mysqlclient = "^2.2.8"
mysqlclient = "^2.3.0"
nextcloud-api-wrapper = "^0.2.3"
num2words = "0.5.13"
numpy = ">=1.15"
numpy-financial = "<=1.0.0"
numpy-stl = "^4.0.0"
numpy-stl = "^4.0.1"
oauthlib = "^3.3.1"
odoo-test-helper = "^2.1.3"
odoorpc = "^0.10.1"
ofxparse = "0.21"
ollama = "^0.6.2"
openai = "^2.53.0"
openai = "2.54.0"
openpyxl = "3.1.2"
openupgradelib = "^3.13.6"
openupgradelib = "^3.13.7"
openwebui-client = ">=0.3.0"
orjson = "^3.11.9"
orjson = "^3.12.0"
ovh = "^1.2.0"
pandas = "2.3.3"
paramiko = "<4.0.0"
@ -117,10 +118,10 @@ pathspec = "^1.1.1"
pdf2image = "^1.17.0"
pdfminer-six = "20260107"
pexpect = "^4.9.0"
phonenumbers = "^9.0.36"
phonenumbers = "^9.0.40"
pillow = "12.2.0"
plaid-python = "^42.0.0"
plotly = "^6.9.0"
plaid-python = "^44.0.0"
plotly = "^7.1.0"
polib = "1.1.1"
pre-commit = "^4.6.2"
premailer = "^3.10.0"
@ -135,16 +136,16 @@ pycups = "^2.0.4"
pydantic = ">=2.0.0"
pydevd-odoo = "^1.2.2"
pyftpdlib = "^2.2.0"
pygithub = "^2.9.1"
pygithub = "^2.10.0"
pyjsparser = "^2.7.1"
pyjwt = "^2.13.0"
pylint = "^4.0.7"
pylint-odoo = "^10.0.9"
pyjwt = "^2.15.0"
pylint = "^4.0.9"
pylint-odoo = "^10.0.11"
pyncclient = "^0.7"
pyopenssl = "26.0.0"
pypdf = ">=3.1.0"
pypdf2 = "2.12.1"
pyproj = "^3.7.2"
pyproj = "^3.8.0"
pyquerystring = "^1.1"
pyserial = "3.5"
pysftp = "^0.2.9"
@ -153,15 +154,15 @@ python-dateutil = "2.8.2"
python-docx = "^1.2.0"
python-dotenv = ">=1.0.0"
python-jose = "^3.5.0"
python-json-logger = "^4.1.0"
python-json-logger = "^4.2.0"
python-ldap = "3.4.4"
python-multipart = "^0.0.32"
python-pptx = "^1.0.2"
python-resize-image = "^1.1.20"
python-slugify = "^8.0.4"
python-slugify = "^9.1.1"
python-stdnum = "1.19"
python-telegram-bot = "^22.8"
pytz = "^2026.3.post1"
pytz = "^2026.4"
pyusb = "1.2.1"
pyyaml = "^6.0.3"
pyzbar = "^0.1.9"
@ -170,27 +171,27 @@ qifparse = "^0.5"
qrcode = "7.4.2"
radon = "^6.0.1"
redis = "^8.1.0"
regex = "^2026.7.19"
regex = "^2026.9.10"
reportlab = "4.1.0"
requests = "2.31.0"
requests-oauthlib = "^2.0.0"
requests-toolbelt = "^1.0.0"
responses = "^0.26.2"
responses = "^0.26.3"
rjsmin = "1.2.0"
roulier = "^1.1.1"
s3fs = "2026.7.0"
s3fs = "2026.9.0"
schwifty = "2024.4.0"
sentry-sdk = ">=2.0.0,<=2.22.0"
setuptools = "80.10.2"
shapely = "^2.1.2"
sqlalchemy = "^2.0.51"
sqlalchemy = "^2.1.0"
statsd = "^4.0.1"
tldextract = "^5.3.2"
to-3mf = "^0.1.0"
tweepy = "^4.17.0"
twilio = "^9.10.9"
twilio = "^9.11.1"
typing-extensions = "^4.16.0"
ujson = "^5.13.0"
ujson = "^6.0.0"
unidecode = "^1.4.0"
urllib3 = "2.0.7"
uvloop = "^0.22.1"
@ -205,7 +206,7 @@ xlsxwriter = "3.1.9"
xlwt = "1.3.0"
xmltodict = "0.13.0"
zeep = "4.2.1"
zklib = "^0.1.1"
[[tool.poetry.dependencies.pymupdf]]
version = "^1.28.2"
markers = "platform_machine != \"s390x\""
@ -228,7 +229,7 @@ rev = "update_imghdr_python3"
[tool.poetry.dependencies.fsspec]
extras = [ "s3",]
version = "^2026.7.0"
version = "^2026.9.0"
[tool.poetry.dependencies.pysaml2]
git = "https://github.com/prauscher/pysaml2.git"

View file

@ -16,7 +16,8 @@ setuptools==80.10.2
googletrans-py==4.0.0
#googletrans==4.0.0-rc1
#chardet==3.0.4
openai
openai==2.54.0
idna==3.20
# Module infobip_whatsapp_integration
# Ignore it, need another version of requests
@ -57,7 +58,7 @@ orjson
#python-dateutil>=2.8.2
# Extra module
meteostat==1.6.8
meteostat==1.7.6
# Fix build
beautifulsoup4==4.13.5
@ -68,7 +69,7 @@ isort==7.0.0
git+https://github.com/mathben/flanker.git@update_imghdr_python3
# Fix some OS
cryptography==46.0.5
cryptography==46.0.7
pyopenssl==26.0.0
# This will ignore pyopenssl from pysaml2==7.5.4
git+https://github.com/prauscher/pysaml2.git@replace-pyopenssl
@ -78,14 +79,16 @@ git+https://github.com/prauscher/pysaml2.git@replace-pyopenssl
pandas==2.3.3
pillow==12.2.0
# OCA_storage amène « fsspec[s3] » sans borne : l'extra s3 de fsspec 2026.7.0
# exige s3fs>=2026.6.0, incompatible avec l'épingle 2026.4.0. On aligne s3fs sur
# fsspec ; aiobotocore 3.1.2 reste dans la plage exigée (>=2.19.0,<4.0.0), donc
# le trio botocore/boto3 n'a pas à bouger.
s3fs==2026.7.0
aiobotocore==3.1.2
botocore==1.42.42
boto3==1.42.42
# s3fs exige fsspec à sa propre version exacte, alors qu'OCA_storage amène
# « fsspec[s3] » sans borne : laissé libre, fsspec prendrait la dernière version
# publiée et casserait la résolution à chaque sortie. Les deux sont épinglés à
# la même version et se montent ensemble. aiobotocore doit rester dans la plage
# exigée par s3fs (>=2.19.0,<4.0.0).
s3fs==2026.9.0
fsspec==2026.9.0
aiobotocore==3.1.3
botocore==1.42.49
boto3==1.42.49
# factur-x >= 4.0 dépend de saxonche, qui encapsule SaxonC. Saxonica ne publie
# de roue que pour x86_64, aarch64, macOS et Windows — aucune pour s390x, et
@ -96,6 +99,10 @@ boto3==1.42.42
factur-x>=4.2 ; platform_machine != 's390x'
factur-x<4 ; platform_machine == 's390x'
# PyMuPDF (OCA_edi) : MuPDF ne se construit pas sur s390x. On l'y écarte, au
# prix des fonctions PDF qui en dépendent sur cette architecture.
pymupdf>=1.28.2 ; platform_machine != 's390x'
# lxml-html-clean 0.4.5 (2026-05-20) exige lxml>=6.1.1, alors qu'Odoo 18 épingle
# lxml==5.2.1 : le solveur poetry n'a plus de solution. Les versions jusqu'à
# 0.4.4 n'imposent aucune borne sur lxml — vérifié sur PyPI, release par