From d2605bccdba1838db5700a6ae0dd12ca9f9b20c7 Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Tue, 14 Aug 2018 14:54:55 +0200 Subject: [PATCH] [FIX] requirements: bump up pillow,jinja2 reqs Recommended by GitHub's repository alerts. We normally stick as close as possible to the version we depend on in the official DEB packages. This in turn depends on the version of Debian stable at the time of release - for 9.0 that would be Debian 8 (jessie) and thus Pillow 2.6.1. However Pillow versions before 3.3.2 and Jinja2 before 2.8.1 suffer from a few issues that could lead to crashes of Odoo workers. The bugfixes have been backported in the DEB packages for Pillow, so users of Debian/Ubuntu LTS versions won't be affected if they are keeping their systems updated. However it's worth an exception to our rule for pip users. --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 92be4fcd468..3121790d291 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,8 +1,8 @@ Babel==1.3 -Jinja2==2.7.3 +Jinja2==2.8.1 Mako==1.0.1 MarkupSafe==0.23 -Pillow==3.1.1 +Pillow==3.3.2 Python-Chart==1.39 PyYAML==3.11 Werkzeug==0.9.6