Files
odoo_source/requirements.txt
T
Martin Trigaux aa07f93ef7 [IMP] package: update lxml version
Update the version to benefit from the fix for
https://github.com/advisories/GHSA-pgww-xf46-h92r
https://nvd.nist.gov/vuln/detail/CVE-2020-27783

This vulnerability is reproducible in Odoo with
html_sanitize(..., sanitize_tags=False) which does NOT happen for
user-facing content.

Remove old compatibility check (lxml 3.1 was released in 2013)
and cleanup global variables only used once

closes odoo/odoo#64248

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2021-12-01 14:07:47 +00:00

48 lines
1.3 KiB
Plaintext

Babel==2.6.0
chardet==3.0.4
decorator==4.4.2
docutils==0.16
ebaysdk==2.1.5
freezegun==0.3.11; python_version < '3.8'
freezegun==0.3.15; python_version >= '3.8'
gevent==1.5.0 ; python_version == '3.7'
gevent==20.9.0 ; python_version >= '3.8'
greenlet==0.4.15 ; python_version == '3.7'
greenlet==0.4.17 ; python_version > '3.7'
html2text==2020.1.16
idna==2.8
Jinja2==2.10.1; python_version < '3.8'
# bullseye version, focal patched 2.10
Jinja2==2.11.2; python_version >= '3.8'
libsass==0.18.0
lxml==4.6.2
MarkupSafe==1.1.0
num2words==0.5.6
ofxparse==0.19
passlib==1.7.2
Pillow==8.1.2 # could be 7.0.0 (Focal) when backported security patches are present
polib==1.1.0
psutil==5.6.6
psycopg2==2.7.7; sys_platform != 'win32' and python_version < '3.8'
psycopg2==2.8.6; sys_platform == 'win32' or python_version >= '3.8'
pydot==1.4.1
pyopenssl==19.0.0
PyPDF2==1.26.0
pypiwin32 ; sys_platform == 'win32'
pyserial==3.4
python-dateutil==2.7.3
python-ldap==3.2.0; sys_platform != 'win32'
python-stdnum==1.13
pytz==2019.3
pyusb==1.0.2
qrcode==6.1
reportlab==3.5.59 # version < 3.5.54 are not compatible with Pillow 8.1.2 and 3.5.59 is bullseye
requests==2.22.0
vobject==0.9.6.1
Werkzeug==0.16.1
xlrd==1.1.0; python_version < '3.8'
xlrd==1.2.0; python_version >= '3.8'
XlsxWriter==1.1.2
xlwt==1.3.*
zeep==3.4.0