The linter would miss / fail to warn on injection of *local variables* in some cases. Try to improve it to be stricter and more reliable, after discussion with odo, sql which is "correctly" dynamic should use psycopg2's sql package in order to bypass the linter (bonus: it should also properly escape & quote identifiers). closes odoo/odoo#53938 Related: odoo/enterprise#11718 Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>