From 2483b95541c6ce44f36ffafc37e169766138cc7f Mon Sep 17 00:00:00 2001 From: Mathieu Benoit Date: Fri, 25 Sep 2026 04:14:02 -0400 Subject: [PATCH 1/6] [UPD] todo external data: openpyxl 3.1.5, xlsxwriter 3.2.9 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The xlsx cleaning of Transform data reaches openpyxl private attributes (_external_links, _charts, _pivots, _images, _cf_rules), which is why openpyxl is pinned exactly and each bump has to pass the leak test. Checked: test_transform_external passes, 511 tests, none skipped, TestFuiteXlsx included, in a .venv.todo.external_data built from this file. --- FR --- [UPD] todo external data : openpyxl 3.1.5, xlsxwriter 3.2.9 Le nettoyage xlsx de Transform data touche des attributs privés d'openpyxl (_external_links, _charts, _pivots, _images, _cf_rules) : d'où une épingle exacte, et chaque montée doit passer le test de fuite. Vérifié : test_transform_external passe, 511 tests, aucun ignoré, TestFuiteXlsx compris, dans un .venv.todo.external_data bâti de ce fichier. Assisted-by: Claude Opus 5.5 --- requirement/todo_external_data.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirement/todo_external_data.txt b/requirement/todo_external_data.txt index d0dff53..abb7362 100644 --- a/requirement/todo_external_data.txt +++ b/requirement/todo_external_data.txt @@ -10,8 +10,8 @@ # conditional_formatting._cf_rules, qui n'ont pas d'équivalent public en # 3.1.2. Le test de fuite de test_transform_external.py est ce qui # surveille cette borne à la montée de version. -openpyxl==3.1.2 -xlsxwriter==3.1.9 +openpyxl==3.1.5 +xlsxwriter==3.2.9 xlrd==2.0.1 access-parser==0.0.6 chardet==5.2.0 From c290c7fd76ddf8470b164b55c2ea0ffac01a10eb Mon Sep 17 00:00:00 2001 From: Mathieu Benoit Date: Fri, 25 Sep 2026 04:14:18 -0400 Subject: [PATCH 2/6] [UPD] requirement: raise the factur-x floor to 6.8 outside s390x MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The lock already resolves factur-x 6.8 on every architecture but s390x, which keeps its <4 branch; >=4.2 let a regeneration fall back to a 4.x or 5.x that no install has run. The floor now matches what is locked, so no installed version changes. Checked: the lock changes only its content-hash; the calls OCA_edi makes (generate_from_file, xml_check_xsd, get_flavor, get_level, get_xml_namespaces, get_facturx_level) match the 6.8 signatures. --- FR --- [UPD] requirement : plancher de factur-x à 6.8 hors s390x Le lock résout déjà factur-x 6.8 sur toute architecture sauf s390x, qui garde sa branche <4 ; >=4.2 laissait une régénération retomber sur une 4.x ou 5.x qu'aucune installation n'a fait tourner. Le plancher suit désormais le lock : aucune version installée ne change. Vérifié : le lock ne change que son content-hash ; les appels d'OCA_edi (generate_from_file, xml_check_xsd, get_flavor, get_level, get_xml_namespaces, get_facturx_level) collent aux signatures de 6.8. Assisted-by: Claude Opus 5.5 --- requirement/poetry.odoo18.0_python3.12.10.lock | 2 +- requirement/pyproject.odoo18.0_python3.12.10.toml | 2 +- requirement/requirements.odoo18.0_python3.12.10.txt | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/requirement/poetry.odoo18.0_python3.12.10.lock b/requirement/poetry.odoo18.0_python3.12.10.lock index a5a8fea..ee4fd00 100644 --- a/requirement/poetry.odoo18.0_python3.12.10.lock +++ b/requirement/poetry.odoo18.0_python3.12.10.lock @@ -9565,4 +9565,4 @@ bindings = ["ghostscript"] [metadata] lock-version = "2.1" python-versions = ">=3.12.10,<3.13" -content-hash = "0d5f25bb32481ba8b3c917b42bbab385dba2d5f1b0142c05d69665e1febb7a93" +content-hash = "621f0b10ca2a376f1eba4545d51dff7c1c84718f6d29af463963f9a196c5201c" diff --git a/requirement/pyproject.odoo18.0_python3.12.10.toml b/requirement/pyproject.odoo18.0_python3.12.10.toml index d02ef2e..9670b79 100644 --- a/requirement/pyproject.odoo18.0_python3.12.10.toml +++ b/requirement/pyproject.odoo18.0_python3.12.10.toml @@ -208,7 +208,7 @@ xmltodict = "0.13.0" zeep = "4.2.1" zklib = "^0.1.1" [[tool.poetry.dependencies.factur-x]] -version = ">=4.2" +version = ">=6.8" markers = "platform_machine != \"s390x\"" [[tool.poetry.dependencies.factur-x]] diff --git a/requirement/requirements.odoo18.0_python3.12.10.txt b/requirement/requirements.odoo18.0_python3.12.10.txt index 59bec8c..af1f9bb 100644 --- a/requirement/requirements.odoo18.0_python3.12.10.txt +++ b/requirement/requirements.odoo18.0_python3.12.10.txt @@ -96,7 +96,7 @@ boto3==1.43.49 # en amont, GraalVM Native Image ne ciblant pas s390x. # La 3.x n'exige que lxml et pypdf. On y retombe là où saxonche n'existe pas, # au prix de la validation Schematron. -factur-x>=4.2 ; platform_machine != 's390x' +factur-x>=6.8 ; platform_machine != 's390x' factur-x<4 ; platform_machine == 's390x' # PyMuPDF (OCA_edi) : MuPDF ne se construit pas sur s390x. On l'y écarte, au From 3316f7022383d48b7dffb526761751f49b15c137 Mon Sep 17 00:00:00 2001 From: Mathieu Benoit Date: Fri, 25 Sep 2026 04:14:33 -0400 Subject: [PATCH 3/6] [UPD] requirement: aiobotocore 3.9.1 with botocore and boto3 1.43.75 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit aiobotocore 3.9.1 accepts botocore only in >=1.43.66,<1.43.76, so botocore 1.43.49 failed the resolution against it. botocore and boto3 move to 1.43.75, the highest release in that range; boto3 1.43.75 needs botocore>=1.43.75 and s3transfer <0.20, which the lock already holds. Checked: poetry lock resolves, only the three AWS packages change version. --- FR --- [UPD] requirement : aiobotocore 3.9.1 avec botocore et boto3 1.43.75 aiobotocore 3.9.1 n'accepte botocore que dans >=1.43.66,<1.43.76 : botocore 1.43.49 faisait échouer la résolution. botocore et boto3 passent à 1.43.75, la plus haute version de cette plage ; boto3 1.43.75 exige botocore>=1.43.75 et s3transfer <0.20, que le lock porte déjà. Vérifié : poetry lock résout, seuls les trois paquets AWS changent de version. Assisted-by: Claude Opus 5.5 --- .../poetry.odoo18.0_python3.12.10.lock | 26 +++++++++---------- .../pyproject.odoo18.0_python3.12.10.toml | 6 ++--- .../requirements.odoo18.0_python3.12.10.txt | 6 ++--- 3 files changed, 19 insertions(+), 19 deletions(-) diff --git a/requirement/poetry.odoo18.0_python3.12.10.lock b/requirement/poetry.odoo18.0_python3.12.10.lock index ee4fd00..4a69254 100644 --- a/requirement/poetry.odoo18.0_python3.12.10.lock +++ b/requirement/poetry.odoo18.0_python3.12.10.lock @@ -14,20 +14,20 @@ files = [ [[package]] name = "aiobotocore" -version = "3.9.0" +version = "3.9.1" description = "Async client for aws services using botocore and aiohttp" optional = false python-versions = ">=3.10" groups = ["main"] files = [ - {file = "aiobotocore-3.9.0-py3-none-any.whl", hash = "sha256:7354659eac9ba6034675b3ea178330b7de97c45989d6fda1bf01d3da167b6135"}, - {file = "aiobotocore-3.9.0.tar.gz", hash = "sha256:5d344e97c518b010bea167c7f7ba4f9e785f9d2b8ac7af4fd00846c62f2c0a10"}, + {file = "aiobotocore-3.9.1-py3-none-any.whl", hash = "sha256:23aa448b4daff3fdce0714c962a2050b63c0222b5f2b5c17d0c874eb76a50ac0"}, + {file = "aiobotocore-3.9.1.tar.gz", hash = "sha256:617d4a78da5adb6ae7d532835727ad388f73555f2ef129b9de1b1add73a43ee6"}, ] [package.dependencies] aiohttp = ">=3.14.0,<4.0.0" aioitertools = ">=0.5.1,<1.0.0" -botocore = ">=1.43.3,<1.43.57" +botocore = ">=1.43.66,<1.43.76" jmespath = ">=0.7.1,<2.0.0" multidict = ">=6.0.0,<7.0.0" python-dateutil = ">=2.1,<3.0.0" @@ -658,18 +658,18 @@ xyzservices = ">=2021.09.1" [[package]] name = "boto3" -version = "1.43.49" +version = "1.43.75" description = "The AWS SDK for Python" optional = false python-versions = ">=3.10" groups = ["main"] files = [ - {file = "boto3-1.43.49-py3-none-any.whl", hash = "sha256:2b31ab1a0eb1cee01d0363b8ee5e68b45dff2c8f99e7b53aca11c9f7b591a794"}, - {file = "boto3-1.43.49.tar.gz", hash = "sha256:e58e0704805f720b94e40a56588eadd6da05d3693bde78b573116b11ae56710f"}, + {file = "boto3-1.43.75-py3-none-any.whl", hash = "sha256:08a79edb68e6a0d65d305eb90188639313650e155aed015e86eef59d8475dde0"}, + {file = "boto3-1.43.75.tar.gz", hash = "sha256:86da93d3d5b46a58b03fa51b598ffa4aeaff485a3000affacf78491c105e44f0"}, ] [package.dependencies] -botocore = ">=1.43.49,<1.44.0" +botocore = ">=1.43.75,<1.44.0" jmespath = ">=0.7.1,<2.0.0" s3transfer = ">=0.19.0,<0.20.0" @@ -678,14 +678,14 @@ crt = ["botocore[crt] (>=1.21.0,<2.0a0)"] [[package]] name = "botocore" -version = "1.43.49" +version = "1.43.75" description = "Low-level, data-driven core of boto 3." optional = false python-versions = ">=3.10" groups = ["main"] files = [ - {file = "botocore-1.43.49-py3-none-any.whl", hash = "sha256:16b6838ac2fbbab85fb265c1f2e37906527aca07f461b1d293d3f8ab82f992dc"}, - {file = "botocore-1.43.49.tar.gz", hash = "sha256:7de02863c95b8008b1400c92a1a00996f25ad38944c07f7b620949f8798d1fdf"}, + {file = "botocore-1.43.75-py3-none-any.whl", hash = "sha256:121abc8b0b529bc4e29a28d1e8b096b20f26708cabe3d5ae4b3446747712aece"}, + {file = "botocore-1.43.75.tar.gz", hash = "sha256:e8ed6b0f3cd398dfb9e08d7ca3a0b964152166a317a04e89c45ec91003327ffe"}, ] [package.dependencies] @@ -694,7 +694,7 @@ python-dateutil = ">=2.1,<3.0.0" urllib3 = ">=1.25.4,<2.2.0 || >2.2.0,<3" [package.extras] -crt = ["awscrt (==0.32.2)"] +crt = ["awscrt (==0.36.0)"] [[package]] name = "cachecontrol" @@ -9565,4 +9565,4 @@ bindings = ["ghostscript"] [metadata] lock-version = "2.1" python-versions = ">=3.12.10,<3.13" -content-hash = "621f0b10ca2a376f1eba4545d51dff7c1c84718f6d29af463963f9a196c5201c" +content-hash = "12a1d5b0492e1090c4a85b9a7d0cad722328cd94200827e066a2518aa3de5a7c" diff --git a/requirement/pyproject.odoo18.0_python3.12.10.toml b/requirement/pyproject.odoo18.0_python3.12.10.toml index 9670b79..86d861a 100644 --- a/requirement/pyproject.odoo18.0_python3.12.10.toml +++ b/requirement/pyproject.odoo18.0_python3.12.10.toml @@ -20,7 +20,7 @@ authors = [ "Mathieu Benoit ",] [tool.poetry.dependencies] python = ">=3.12.10,<3.13" a2wsgi = ">=1.10.6" -aiobotocore = "3.9.0" +aiobotocore = "3.9.1" altcha = ">=2.0.0" ansi2html = "^1.9.5" apispec = "^6.10.0" @@ -32,8 +32,8 @@ bandit = "^1.9.4" base64io = "^1.0.3" beautifulsoup4 = "4.13.5" bokeh = "3.6.3" -boto3 = "1.43.49" -botocore = "1.43.49" +boto3 = "1.43.75" +botocore = "1.43.75" cachetools = "^7.2.0" cairosvg = "^2.9.1" caldav = "1.3.9" diff --git a/requirement/requirements.odoo18.0_python3.12.10.txt b/requirement/requirements.odoo18.0_python3.12.10.txt index af1f9bb..b0f7128 100644 --- a/requirement/requirements.odoo18.0_python3.12.10.txt +++ b/requirement/requirements.odoo18.0_python3.12.10.txt @@ -86,9 +86,9 @@ pillow==12.3.0 # exigée par s3fs (>=2.19.0,<4.0.0). s3fs==2026.9.0 fsspec==2026.9.0 -aiobotocore==3.9.0 -botocore==1.43.49 -boto3==1.43.49 +aiobotocore==3.9.1 +botocore==1.43.75 +boto3==1.43.75 # factur-x >= 4.0 dépend de saxonche, qui encapsule SaxonC. Saxonica ne publie # de roue que pour x86_64, aarch64, macOS et Windows — aucune pour s390x, et From 46acd94a290cc2627fbce7de944fcec441089ac6 Mon Sep 17 00:00:00 2001 From: Mathieu Benoit Date: Fri, 25 Sep 2026 04:14:51 -0400 Subject: [PATCH 4/6] [UPD] requirement: pin requests 2.32.4 over the 2.31.0 of Odoo 18 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Odoo 18 pins requests 2.31.0, affected by CVE-2024-35195 and CVE-2024-47081, both fixed in 2.32.4. Left to the generated resolution, the version followed whatever an addon repository declared, down to an example requirements file under a doc/ directory. The ERPLibre pin now wins the conflict and states its reason. Checked: poetry lock resolves, requests is the only package that moves. --- FR --- [UPD] requirement : requests 2.32.4 plutôt que le 2.31.0 d'Odoo 18 Odoo 18 épingle requests 2.31.0, touchée par CVE-2024-35195 et CVE-2024-47081, toutes deux corrigées en 2.32.4. Livrée à la résolution générée, la version suivait ce qu'un dépôt d'addons déclarait, jusqu'à un requirements d'exemple sous un répertoire doc/. L'épingle d'ERPLibre l'emporte désormais et dit sa raison. Vérifié : poetry lock résout, requests est le seul paquet qui bouge. Assisted-by: Claude Opus 5.5 --- requirement/poetry.odoo18.0_python3.12.10.lock | 12 ++++++------ requirement/pyproject.odoo18.0_python3.12.10.toml | 2 +- requirement/requirements.odoo18.0_python3.12.10.txt | 3 +++ 3 files changed, 10 insertions(+), 7 deletions(-) diff --git a/requirement/poetry.odoo18.0_python3.12.10.lock b/requirement/poetry.odoo18.0_python3.12.10.lock index 4a69254..48181d2 100644 --- a/requirement/poetry.odoo18.0_python3.12.10.lock +++ b/requirement/poetry.odoo18.0_python3.12.10.lock @@ -7593,19 +7593,19 @@ renderpm = ["rl-renderPM (>=4.0.3,<4.1)"] [[package]] name = "requests" -version = "2.31.0" +version = "2.32.4" description = "Python HTTP for Humans." optional = false -python-versions = ">=3.7" +python-versions = ">=3.8" groups = ["main"] files = [ - {file = "requests-2.31.0-py3-none-any.whl", hash = "sha256:58cd2187c01e70e6e26505bca751777aa9f2ee0b7f4300988b709f44e013003f"}, - {file = "requests-2.31.0.tar.gz", hash = "sha256:942c5a758f98d790eaed1a29cb6eefc7ffb0d1cf7af05c3d2791656dbd6ad1e1"}, + {file = "requests-2.32.4-py3-none-any.whl", hash = "sha256:27babd3cda2a6d50b30443204ee89830707d396671944c998b5975b031ac2b2c"}, + {file = "requests-2.32.4.tar.gz", hash = "sha256:27d0316682c8a29834d3264820024b62a36942083d52caf2f14c0591336d3422"}, ] [package.dependencies] certifi = ">=2017.4.17" -charset-normalizer = ">=2,<4" +charset_normalizer = ">=2,<4" idna = ">=2.5,<4" urllib3 = ">=1.21.1,<3" @@ -9565,4 +9565,4 @@ bindings = ["ghostscript"] [metadata] lock-version = "2.1" python-versions = ">=3.12.10,<3.13" -content-hash = "12a1d5b0492e1090c4a85b9a7d0cad722328cd94200827e066a2518aa3de5a7c" +content-hash = "e7342912cea361d2e2ad2c9d9510f446208096ebcf99b8514e3ad9b1471ffc3e" diff --git a/requirement/pyproject.odoo18.0_python3.12.10.toml b/requirement/pyproject.odoo18.0_python3.12.10.toml index 86d861a..82b6b9a 100644 --- a/requirement/pyproject.odoo18.0_python3.12.10.toml +++ b/requirement/pyproject.odoo18.0_python3.12.10.toml @@ -173,7 +173,7 @@ radon = "^6.0.1" redis = "^8.1.0" regex = "^2026.9.10" reportlab = "4.1.0" -requests = "2.31.0" +requests = "2.32.4" requests-oauthlib = "^2.0.0" requests-toolbelt = "^1.0.0" responses = "^0.26.3" diff --git a/requirement/requirements.odoo18.0_python3.12.10.txt b/requirement/requirements.odoo18.0_python3.12.10.txt index b0f7128..c80c28b 100644 --- a/requirement/requirements.odoo18.0_python3.12.10.txt +++ b/requirement/requirements.odoo18.0_python3.12.10.txt @@ -18,6 +18,9 @@ googletrans-py==4.0.0 #chardet==3.0.4 openai==2.54.0 idna==3.20 +# Odoo 18 épingle requests 2.31.0, touchée par CVE-2024-35195 et +# CVE-2024-47081, corrigées en 2.32.4. L'épingle d'ERPLibre l'emporte. +requests==2.32.4 # Module infobip_whatsapp_integration # Ignore it, need another version of requests From 222613ee72c8ce9e1b59a6852b938ce2a53ecb3f Mon Sep 17 00:00:00 2001 From: Mathieu Benoit Date: Fri, 25 Sep 2026 04:17:56 -0400 Subject: [PATCH 5/6] [FIX] poetry update: skip requirements under doc and examples dirs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit poetry_update.py read every requirements.txt of the addon repositories, illustrations included: an example file declaring a loose ">=" moved a dependency for the whole environment, past the pin Odoo sets. A path with a directory named doc, docs, example or examples, compared by exact name, is now skipped for requirements and manifests alike; the ERPLibre requirements file is still added without filtering. Checked on a tree with the extra repositories: 70 requirements and 4016 manifests found, the one example file skipped, no manifest lost. --- FR --- [FIX] poetry update : ignorer les requirements sous doc et examples poetry_update.py lisait tout requirements.txt des dépôts d'addons, illustrations comprises : un fichier d'exemple déclarant un « >= » lâche déplaçait une dépendance pour tout l'environnement, par-delà l'épingle d'Odoo. Un chemin dont un répertoire s'appelle doc, docs, example ou examples, comparé au nom exact, est désormais écarté, requirements comme manifestes ; le requirements d'ERPLibre reste ajouté sans filtre. Vérifié sur une arborescence avec les dépôts extra : 70 requirements et 4016 manifestes trouvés, le seul fichier d'exemple écarté, aucun manifeste perdu. Assisted-by: Claude Opus 5.5 --- script/poetry/poetry_update.py | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/script/poetry/poetry_update.py b/script/poetry/poetry_update.py index 7354531..f9e2d4b 100755 --- a/script/poetry/poetry_update.py +++ b/script/poetry/poetry_update.py @@ -113,12 +113,24 @@ def get_lst_manifest_py(config, ignore_dir_startswith: list = None): ) +# A file under one of these directories documents or illustrates, it does not +# declare what an addon needs: an example requirements.txt with a loose +# ">=" would otherwise override a pin for the whole environment. +IGNORED_DIR_NAMES = {"doc", "docs", "example", "examples"} + + def get_file_from_glob( config, glob_txt, ignore_dir_startswith: list = None, force_add_item: list = None, ): + """Files matching glob_txt under the Odoo tree of the active version. + + A path is skipped when a directory of it is named in IGNORED_DIR_NAMES, + compared by exact name, or when it starts with one of + ignore_dir_startswith. force_add_item is appended without filtering. + """ lst_v = [] # TODO take all groups odoo##.# from manifest, will create a dependency # Hardcode logic from manifest @@ -131,6 +143,8 @@ def get_file_from_glob( a_dirname = os.path.dirname(a) if a_dirname.startswith(".repo/") or a_dirname.startswith(".venv"): continue + if IGNORED_DIR_NAMES.intersection(Path(a_dirname).parts): + continue if ignore_dir_startswith: ignore_it = False for item_ignore_dir in ignore_dir_startswith: From aaefae033c990b280647bd818051243e04287a99 Mon Sep 17 00:00:00 2001 From: Mathieu Benoit Date: Fri, 25 Sep 2026 04:21:57 -0400 Subject: [PATCH 6/6] [UPD] changelog: aws 1.43.75, requests 2.32.4, doc examples skipped MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Unreleased entry named botocore 1.43.49 with aiobotocore 3.9.0, which the branch replaces by 1.43.75 with 3.9.1; the entry now matches what installs. Added: openpyxl and xlsxwriter for Transform data and the factur-x floor under Changed, the doc and examples filter of poetry_update.py under Fixed, requests 2.32.4 under Security. Checked: make doc_markdown regenerates both files, each language only in its own. --- FR --- [UPD] changelog : aws 1.43.75, requests 2.32.4, exemples doc écartés L'entrée Unreleased nommait botocore 1.43.49 avec aiobotocore 3.9.0, que la branche remplace par 1.43.75 avec 3.9.1 ; l'entrée colle désormais à ce qui s'installe. Ajoutés : openpyxl et xlsxwriter pour Transform data et le plancher de factur-x sous Modifié, le filtre doc et examples de poetry_update.py sous Corrigé, requests 2.32.4 sous Sécurité. Vérifié : make doc_markdown régénère les deux fichiers, chaque langue dans le sien seulement. Assisted-by: Claude Opus 5.5 --- CHANGELOG.base.md | 12 ++++++++++-- CHANGELOG.fr.md | 6 +++++- CHANGELOG.md | 6 +++++- 3 files changed, 20 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.base.md b/CHANGELOG.base.md index e7ea36d..7debfaf 100644 --- a/CHANGELOG.base.md +++ b/CHANGELOG.base.md @@ -174,8 +174,10 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - TODO menus: the language is set only from Configuration, the duplicate entry in Execute is gone, and Fork moves from the main menu to Configuration. The main menu now numbers Telemetry 4 and Configuration 5. The language chooser shows a flag per language - Odoo 18 dependencies refreshed. `openai` is pinned to 2.x, whose 3.x requires an `idna` that Odoo 18 forbids; `fsspec` is pinned beside `s3fs`, which demands it at its own exact version, so the two move together; `meteostat` returns to 1.x, every 2.x capping `pytz` below 2024. PyMuPDF stays excluded on s390x, now declared in the requirements so a regeneration keeps it. Major bumps of `ujson` 6, `plotly` 7, `python-slugify` 9 and `sqlalchemy` 2.1 are not yet tested - Dependabot ignores the major versions of `meteostat` -- Odoo 18 moves to pandas 3.0.6, cryptography 50 with pyopenssl 26.4, Pillow 12.3 and botocore/boto3 1.43.49 with aiobotocore 3.9.0 — the only aiobotocore whose botocore range holds 1.43.49. The seven modules that import pandas run their pandas calls unchanged; `freq='d'` in a Cybro attendance dashboard now warns and will break with pandas 4 +- Odoo 18 moves to pandas 3.0.6, cryptography 50 with pyopenssl 26.4, Pillow 12.3 and botocore/boto3 1.43.75 with aiobotocore 3.9.1, the highest botocore its narrow range accepts. The seven modules that import pandas run their pandas calls unchanged; `freq='d'` in a Cybro attendance dashboard now warns and will break with pandas 4 - Dependabot groups `aiobotocore`, `botocore` and `boto3` into one pull request, since each aiobotocore accepts only a narrow botocore range; security fixes still arrive on their own +- `TODO › Transform data` reads Excel with openpyxl 3.1.5 and xlsxwriter 3.2.9; the leak test that guards openpyxl's exact pin passes on them +- factur-x requires 6.8 outside s390x, the version already locked, so a regeneration can no longer fall back to an untested 4.x or 5.x @@ -206,8 +208,10 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - Menus de TODO : la langue se règle seulement depuis Configuration, l'entrée en double dans Execute disparaît, et Fork quitte le menu principal pour Configuration. Le menu principal numérote désormais Télémétrie 4 et Configuration 5. Le choix de la langue montre un drapeau par langue - Dépendances d'Odoo 18 rafraîchies. `openai` est épinglé en 2.x, dont la 3.x exige un `idna` qu'Odoo 18 interdit ; `fsspec` est épinglé à côté de `s3fs`, qui l'exige à sa propre version exacte, si bien que les deux se montent ensemble ; `meteostat` revient en 1.x, toute 2.x plafonnant `pytz` sous 2024. PyMuPDF reste écarté sur s390x, désormais déclaré dans les requirements pour qu'une régénération le garde. Les montées majeures de `ujson` 6, `plotly` 7, `python-slugify` 9 et `sqlalchemy` 2.1 ne sont pas encore testées - Dependabot ignore les versions majeures de `meteostat` -- Odoo 18 passe à pandas 3.0.6, cryptography 50 avec pyopenssl 26.4, Pillow 12.3 et botocore/boto3 1.43.49 avec aiobotocore 3.9.0 — le seul aiobotocore dont la plage de botocore contient 1.43.49. Les sept modules qui importent pandas exécutent leurs appels pandas sans changement ; `freq='d'` dans un tableau de bord de présence Cybro avertit désormais et cassera avec pandas 4 +- Odoo 18 passe à pandas 3.0.6, cryptography 50 avec pyopenssl 26.4, Pillow 12.3 et botocore/boto3 1.43.75 avec aiobotocore 3.9.1, le plus haut botocore que sa plage étroite accepte. Les sept modules qui importent pandas exécutent leurs appels pandas sans changement ; `freq='d'` dans un tableau de bord de présence Cybro avertit désormais et cassera avec pandas 4 - Dependabot réunit `aiobotocore`, `botocore` et `boto3` dans une seule demande de fusion, chaque aiobotocore n'acceptant qu'une plage étroite de botocore ; les correctifs de sécurité arrivent toujours seuls +- `TODO › Transform data` lit Excel avec openpyxl 3.1.5 et xlsxwriter 3.2.9 ; le test de fuite qui garde l'épingle exacte d'openpyxl passe sur eux +- factur-x exige 6.8 hors s390x, la version déjà verrouillée : une régénération ne peut plus retomber sur une 4.x ou 5.x non testée ## Fixed @@ -280,6 +284,7 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - Dependabot no longer opens pull requests against the frozen requirements of Odoo 12 to 17: its security updates scan `requirement/` as its own directory, which the exclusions did not cover - `poetry_update.py` stops on a missing `pyproject.toml` with the command that creates it, `make switch_odoo_XX` for the active version, and offers to run it then restart when launched from a terminal - `poetry_update.py` runs Poetry in the Odoo venv even from a shell under `.venv.erplibre`, whose Python made it fail on « InvalidCurrentPythonVersionError » +- `poetry_update.py` skips requirements and manifests under a `doc`, `docs`, `example` or `examples` directory: an example file declaring a loose `>=` no longer moves a dependency for the whole environment @@ -348,6 +353,7 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - Dependabot n'ouvre plus de demandes de fusion sur les requirements figés d'Odoo 12 à 17 : ses mises à jour de sécurité lisent `requirement/` comme un répertoire à part, que les exclusions ne couvraient pas - `poetry_update.py` s'arrête sur un `pyproject.toml` absent en nommant la commande qui le crée, `make switch_odoo_XX` pour la version active, et propose de la lancer puis de se relancer quand il tourne dans un terminal - `poetry_update.py` fait tourner Poetry dans le venv Odoo même depuis un shell sous `.venv.erplibre`, dont le Python le faisait échouer sur « InvalidCurrentPythonVersionError » +- `poetry_update.py` écarte les requirements et manifestes sous un répertoire `doc`, `docs`, `example` ou `examples` : un fichier d'exemple déclarant un `>=` lâche ne déplace plus une dépendance pour tout l'environnement ## Removed @@ -370,12 +376,14 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - An API key and a bearer token are redacted too before a command is displayed, logged or reprinted: `OPENAI_API_KEY=` went out in the clear, and a header token escaped by construction, carrying neither an option name nor a variable name - Following a redirect, the cache no longer forwards the client's credentials (Authorization, Cookie, Proxy-Authorization) to another host - Odoo 18 installs `idna` 3.20 instead of the 3.6 its own requirements pin, which is affected by CVE-2024-3651 +- Odoo 18 installs `requests` 2.32.4 instead of the 2.31.0 its own requirements pin, which is affected by CVE-2024-35195 and CVE-2024-47081 - Une clé d'API et un jeton Bearer sont caviardés eux aussi avant qu'une commande soit affichée, journalisée ou réimprimée : `OPENAI_API_KEY=` partait en clair, et un jeton d'en-tête échappait par construction, ne portant ni nom d'option ni nom de variable - En suivant une redirection, le cache ne transmet plus les identifiants du client (Authorization, Cookie, Proxy-Authorization) à un autre hôte - Odoo 18 installe `idna` 3.20 au lieu de la 3.6 qu'épinglent ses propres requirements, touchée par CVE-2024-3651 +- Odoo 18 installe `requests` 2.32.4 au lieu du 2.31.0 qu'épinglent ses propres requirements, touché par CVE-2024-35195 et CVE-2024-47081 diff --git a/CHANGELOG.fr.md b/CHANGELOG.fr.md index fb4d441..aca6f7d 100644 --- a/CHANGELOG.fr.md +++ b/CHANGELOG.fr.md @@ -94,8 +94,10 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - Menus de TODO : la langue se règle seulement depuis Configuration, l'entrée en double dans Execute disparaît, et Fork quitte le menu principal pour Configuration. Le menu principal numérote désormais Télémétrie 4 et Configuration 5. Le choix de la langue montre un drapeau par langue - Dépendances d'Odoo 18 rafraîchies. `openai` est épinglé en 2.x, dont la 3.x exige un `idna` qu'Odoo 18 interdit ; `fsspec` est épinglé à côté de `s3fs`, qui l'exige à sa propre version exacte, si bien que les deux se montent ensemble ; `meteostat` revient en 1.x, toute 2.x plafonnant `pytz` sous 2024. PyMuPDF reste écarté sur s390x, désormais déclaré dans les requirements pour qu'une régénération le garde. Les montées majeures de `ujson` 6, `plotly` 7, `python-slugify` 9 et `sqlalchemy` 2.1 ne sont pas encore testées - Dependabot ignore les versions majeures de `meteostat` -- Odoo 18 passe à pandas 3.0.6, cryptography 50 avec pyopenssl 26.4, Pillow 12.3 et botocore/boto3 1.43.49 avec aiobotocore 3.9.0 — le seul aiobotocore dont la plage de botocore contient 1.43.49. Les sept modules qui importent pandas exécutent leurs appels pandas sans changement ; `freq='d'` dans un tableau de bord de présence Cybro avertit désormais et cassera avec pandas 4 +- Odoo 18 passe à pandas 3.0.6, cryptography 50 avec pyopenssl 26.4, Pillow 12.3 et botocore/boto3 1.43.75 avec aiobotocore 3.9.1, le plus haut botocore que sa plage étroite accepte. Les sept modules qui importent pandas exécutent leurs appels pandas sans changement ; `freq='d'` dans un tableau de bord de présence Cybro avertit désormais et cassera avec pandas 4 - Dependabot réunit `aiobotocore`, `botocore` et `boto3` dans une seule demande de fusion, chaque aiobotocore n'acceptant qu'une plage étroite de botocore ; les correctifs de sécurité arrivent toujours seuls +- `TODO › Transform data` lit Excel avec openpyxl 3.1.5 et xlsxwriter 3.2.9 ; le test de fuite qui garde l'épingle exacte d'openpyxl passe sur eux +- factur-x exige 6.8 hors s390x, la version déjà verrouillée : une régénération ne peut plus retomber sur une 4.x ou 5.x non testée ## Corrigé @@ -164,6 +166,7 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - Dependabot n'ouvre plus de demandes de fusion sur les requirements figés d'Odoo 12 à 17 : ses mises à jour de sécurité lisent `requirement/` comme un répertoire à part, que les exclusions ne couvraient pas - `poetry_update.py` s'arrête sur un `pyproject.toml` absent en nommant la commande qui le crée, `make switch_odoo_XX` pour la version active, et propose de la lancer puis de se relancer quand il tourne dans un terminal - `poetry_update.py` fait tourner Poetry dans le venv Odoo même depuis un shell sous `.venv.erplibre`, dont le Python le faisait échouer sur « InvalidCurrentPythonVersionError » +- `poetry_update.py` écarte les requirements et manifestes sous un répertoire `doc`, `docs`, `example` ou `examples` : un fichier d'exemple déclarant un `>=` lâche ne déplace plus une dépendance pour tout l'environnement ## Retiré @@ -174,6 +177,7 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - Une clé d'API et un jeton Bearer sont caviardés eux aussi avant qu'une commande soit affichée, journalisée ou réimprimée : `OPENAI_API_KEY=` partait en clair, et un jeton d'en-tête échappait par construction, ne portant ni nom d'option ni nom de variable - En suivant une redirection, le cache ne transmet plus les identifiants du client (Authorization, Cookie, Proxy-Authorization) à un autre hôte - Odoo 18 installe `idna` 3.20 au lieu de la 3.6 qu'épinglent ses propres requirements, touchée par CVE-2024-3651 +- Odoo 18 installe `requests` 2.32.4 au lieu du 2.31.0 qu'épinglent ses propres requirements, touché par CVE-2024-35195 et CVE-2024-47081 ## [1.8.0] - 2026-09-04 diff --git a/CHANGELOG.md b/CHANGELOG.md index 0707a8b..486a2ad 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -94,8 +94,10 @@ to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - TODO menus: the language is set only from Configuration, the duplicate entry in Execute is gone, and Fork moves from the main menu to Configuration. The main menu now numbers Telemetry 4 and Configuration 5. The language chooser shows a flag per language - Odoo 18 dependencies refreshed. `openai` is pinned to 2.x, whose 3.x requires an `idna` that Odoo 18 forbids; `fsspec` is pinned beside `s3fs`, which demands it at its own exact version, so the two move together; `meteostat` returns to 1.x, every 2.x capping `pytz` below 2024. PyMuPDF stays excluded on s390x, now declared in the requirements so a regeneration keeps it. Major bumps of `ujson` 6, `plotly` 7, `python-slugify` 9 and `sqlalchemy` 2.1 are not yet tested - Dependabot ignores the major versions of `meteostat` -- Odoo 18 moves to pandas 3.0.6, cryptography 50 with pyopenssl 26.4, Pillow 12.3 and botocore/boto3 1.43.49 with aiobotocore 3.9.0 — the only aiobotocore whose botocore range holds 1.43.49. The seven modules that import pandas run their pandas calls unchanged; `freq='d'` in a Cybro attendance dashboard now warns and will break with pandas 4 +- Odoo 18 moves to pandas 3.0.6, cryptography 50 with pyopenssl 26.4, Pillow 12.3 and botocore/boto3 1.43.75 with aiobotocore 3.9.1, the highest botocore its narrow range accepts. The seven modules that import pandas run their pandas calls unchanged; `freq='d'` in a Cybro attendance dashboard now warns and will break with pandas 4 - Dependabot groups `aiobotocore`, `botocore` and `boto3` into one pull request, since each aiobotocore accepts only a narrow botocore range; security fixes still arrive on their own +- `TODO › Transform data` reads Excel with openpyxl 3.1.5 and xlsxwriter 3.2.9; the leak test that guards openpyxl's exact pin passes on them +- factur-x requires 6.8 outside s390x, the version already locked, so a regeneration can no longer fall back to an untested 4.x or 5.x ## Fixed @@ -164,6 +166,7 @@ to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - Dependabot no longer opens pull requests against the frozen requirements of Odoo 12 to 17: its security updates scan `requirement/` as its own directory, which the exclusions did not cover - `poetry_update.py` stops on a missing `pyproject.toml` with the command that creates it, `make switch_odoo_XX` for the active version, and offers to run it then restart when launched from a terminal - `poetry_update.py` runs Poetry in the Odoo venv even from a shell under `.venv.erplibre`, whose Python made it fail on « InvalidCurrentPythonVersionError » +- `poetry_update.py` skips requirements and manifests under a `doc`, `docs`, `example` or `examples` directory: an example file declaring a loose `>=` no longer moves a dependency for the whole environment ## Removed @@ -174,6 +177,7 @@ to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - An API key and a bearer token are redacted too before a command is displayed, logged or reprinted: `OPENAI_API_KEY=` went out in the clear, and a header token escaped by construction, carrying neither an option name nor a variable name - Following a redirect, the cache no longer forwards the client's credentials (Authorization, Cookie, Proxy-Authorization) to another host - Odoo 18 installs `idna` 3.20 instead of the 3.6 its own requirements pin, which is affected by CVE-2024-3651 +- Odoo 18 installs `requests` 2.32.4 instead of the 2.31.0 its own requirements pin, which is affected by CVE-2024-35195 and CVE-2024-47081 ## [1.8.0] - 2026-09-04