Update the version to benefit from the fix for https://github.com/advisories/GHSA-pgww-xf46-h92r https://nvd.nist.gov/vuln/detail/CVE-2020-27783 This vulnerability is reproducible in Odoo with html_sanitize(..., sanitize_tags=False) which does NOT happen for user-facing content. Remove old compatibility check (lxml 3.1 was released in 2013) and cleanup global variables only used once closes odoo/odoo#64248 Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
48 lines
1.3 KiB
Plaintext
48 lines
1.3 KiB
Plaintext
Babel==2.6.0
|
|
chardet==3.0.4
|
|
decorator==4.4.2
|
|
docutils==0.16
|
|
ebaysdk==2.1.5
|
|
freezegun==0.3.11; python_version < '3.8'
|
|
freezegun==0.3.15; python_version >= '3.8'
|
|
gevent==1.5.0 ; python_version == '3.7'
|
|
gevent==20.9.0 ; python_version >= '3.8'
|
|
greenlet==0.4.15 ; python_version == '3.7'
|
|
greenlet==0.4.17 ; python_version > '3.7'
|
|
html2text==2020.1.16
|
|
idna==2.8
|
|
Jinja2==2.10.1; python_version < '3.8'
|
|
# bullseye version, focal patched 2.10
|
|
Jinja2==2.11.2; python_version >= '3.8'
|
|
libsass==0.18.0
|
|
lxml==4.6.2
|
|
MarkupSafe==1.1.0
|
|
num2words==0.5.6
|
|
ofxparse==0.19
|
|
passlib==1.7.2
|
|
Pillow==8.1.2 # could be 7.0.0 (Focal) when backported security patches are present
|
|
polib==1.1.0
|
|
psutil==5.6.6
|
|
psycopg2==2.7.7; sys_platform != 'win32' and python_version < '3.8'
|
|
psycopg2==2.8.6; sys_platform == 'win32' or python_version >= '3.8'
|
|
pydot==1.4.1
|
|
pyopenssl==19.0.0
|
|
PyPDF2==1.26.0
|
|
pypiwin32 ; sys_platform == 'win32'
|
|
pyserial==3.4
|
|
python-dateutil==2.7.3
|
|
python-ldap==3.2.0; sys_platform != 'win32'
|
|
python-stdnum==1.13
|
|
pytz==2019.3
|
|
pyusb==1.0.2
|
|
qrcode==6.1
|
|
reportlab==3.5.59 # version < 3.5.54 are not compatible with Pillow 8.1.2 and 3.5.59 is bullseye
|
|
requests==2.22.0
|
|
vobject==0.9.6.1
|
|
Werkzeug==0.16.1
|
|
xlrd==1.1.0; python_version < '3.8'
|
|
xlrd==1.2.0; python_version >= '3.8'
|
|
XlsxWriter==1.1.2
|
|
xlwt==1.3.*
|
|
zeep==3.4.0
|