- Mailing Lists
- Contributors
- OCA pip module loaded by external organization on pypi.org
Archives
- By thread 1419
-
By date
- August 2019 59
- September 2019 118
- October 2019 165
- November 2019 97
- December 2019 35
- January 2020 58
- February 2020 204
- March 2020 121
- April 2020 172
- May 2020 50
- June 2020 158
- July 2020 85
- August 2020 94
- September 2020 193
- October 2020 277
- November 2020 100
- December 2020 159
- January 2021 38
- February 2021 87
- March 2021 146
- April 2021 73
- May 2021 90
- June 2021 86
- July 2021 123
- August 2021 50
- September 2021 68
- October 2021 66
- November 2021 74
- December 2021 75
- January 2022 98
- February 2022 77
- March 2022 68
- April 2022 31
- May 2022 59
- June 2022 87
- July 2022 141
- August 2022 38
- September 2022 73
- October 2022 152
- November 2022 39
- December 2022 50
- January 2023 93
- February 2023 49
- March 2023 106
- April 2023 47
- May 2023 69
- June 2023 92
- July 2023 64
- August 2023 103
- September 2023 91
- October 2023 101
- November 2023 94
- December 2023 46
- January 2024 75
- February 2024 79
- March 2024 104
- April 2024 63
- May 2024 40
- June 2024 160
- July 2024 80
- August 2024 70
- September 2024 62
- October 2024 121
- November 2024 117
- December 2024 89
- January 2025 59
- February 2025 104
- March 2025 96
- April 2025 107
- May 2025 52
- June 2025 72
- July 2025 60
- August 2025 81
- September 2025 124
- October 2025 63
- November 2025 22
Contributors
Request for Guidance on Migrating from POS UI API v15 to v16
Aletrnative to mrp_workorder (MRP II) Shop Floor application?
OCA pip module loaded by external organization on pypi.org
In tests done on github is used the "non-OCA" version too:
while the current OCA version is "version": "14.0.1.0.1",
by Sergio Corato - 05:36 - 24 Jan 2025
Follow-Ups
-
Re: OCA pip module loaded by external organization on pypi.org
Hi Stéphane,thanks very much for the clarification.I've managed to install the OCA module version as we use a private distributor of pip packages: this is used by forcing the 14.0.1.0.1 version.Warmest regards,Sergio CoratoIl giorno sab 25 gen 2025 alle ore 12:06 Stéphane Bidoul <notifications@odoo-community.org> ha scritto:Hi Sergio,Thanks for reporting this.In this case, what happened is that odoo12-addon-stock_move_backdating is owned by OCA, but another company published odoo14-addon-stock_move_backdating before it was migrated in OCA.When later merged in OCA, the publishing to PyPI failed because OCA did not own the package.We were alerted by the monitoring and attempted to contact that company to resolve the issue, without success so far.From PyPI perspective, there is nothing wrong with that because odoo12-addon-stock_move_backdating and odoo14-addon-stock_move_backdating are two different packages.Since Odoo 15, the Odoo version is not part of the package name, so this kind of confusion cannot happen anymore.We are currently aware of 2 situations where an addon is merged in OCA and not owned by OCA on PyPI: odoo14-addon-stock_move_backdating and odoo14-addon-pos_sale_order_load.It is nevertheless important to keep in mind that anyone can publish new packages to PyPI, including Odoo addons, and when installing from PyPI (as from anywhere on the internet) one must be careful to assert the trust one places in the package owners.Additionally, since Nov 2024, to avoid merging in OCA when the name is not available on PyPI, the bot checks that the name is available before accepting the merge.In OCA CI, there is a mechanism in place to test only with OCA addons.Best regards,-StéphaneOn Fri, Jan 24, 2025 at 6:37 PM Pierre Verkest <notifications@odoo-community.org> wrote:Hi,I suppose the https://pypi.org/user/ssi-bot/ user own the pypi project before OCA bot try to create it so it's certainly a best practice to first get OCA package from the OCA wheelhouse https://wheelhouse.odoo-community.org/regards,Le ven. 24 janv. 2025 à 17:38, Sergio Corato <notifications@odoo-community.org> a écrit :Hi all,I am writing this mail even if I've already written it in OCA Discord, because I think this is a security issue, I apologize whether it's not.I found installed in an instance a pip from pypi.org of an OCA module upgraded there from a company outside OCA: https://pypi.org/project/odoo14-addon-stock-move-backdating/14.0.1.2.0/They pushed the module changed and with a different logo (almost this change made me notice it) and a link to their website. It's a bad thing that someone can put a pip there with a random code.I'll stop taking this pip from pypi.org or I'll take the OCA version, but what about other instances installed in this way? Or is it a deprecated way of deployment?
In tests done on github is used the "non-OCA" version too:Requirement already satisfied: odoo14-addon-stock-move-backdating in /opt/odoo-venv/src/odoo14-addon-stock-move-backdating/setup/stock_move_backdating (from -r test-requirements.txt (line 6)) (14.0.1.0.2.dev2)
while the current OCA version is "version": "14.0.1.0.1",Sergio Corato_______________________________________________
Mailing-List: https://odoo-community.org/groups/contributors-15
Post to: mailto:contributors@odoo-community.org
Unsubscribe: https://odoo-community.org/groups?unsubscribe
--Pierre_______________________________________________
Mailing-List: https://odoo-community.org/groups/contributors-15
Post to: mailto:contributors@odoo-community.org
Unsubscribe: https://odoo-community.org/groups?unsubscribe
_______________________________________________
Mailing-List: https://odoo-community.org/groups/contributors-15
Post to: mailto:contributors@odoo-community.org
Unsubscribe: https://odoo-community.org/groups?unsubscribe
by Sergio Corato - 03:51 - 25 Jan 2025 -
Re: OCA pip module loaded by external organization on pypi.org
Hi Sergio,Thanks for reporting this.In this case, what happened is that odoo12-addon-stock_move_backdating is owned by OCA, but another company published odoo14-addon-stock_move_backdating before it was migrated in OCA.When later merged in OCA, the publishing to PyPI failed because OCA did not own the package.We were alerted by the monitoring and attempted to contact that company to resolve the issue, without success so far.From PyPI perspective, there is nothing wrong with that because odoo12-addon-stock_move_backdating and odoo14-addon-stock_move_backdating are two different packages.Since Odoo 15, the Odoo version is not part of the package name, so this kind of confusion cannot happen anymore.We are currently aware of 2 situations where an addon is merged in OCA and not owned by OCA on PyPI: odoo14-addon-stock_move_backdating and odoo14-addon-pos_sale_order_load.It is nevertheless important to keep in mind that anyone can publish new packages to PyPI, including Odoo addons, and when installing from PyPI (as from anywhere on the internet) one must be careful to assert the trust one places in the package owners.Additionally, since Nov 2024, to avoid merging in OCA when the name is not available on PyPI, the bot checks that the name is available before accepting the merge.In OCA CI, there is a mechanism in place to test only with OCA addons.Best regards,-StéphaneOn Fri, Jan 24, 2025 at 6:37 PM Pierre Verkest <notifications@odoo-community.org> wrote:Hi,I suppose the https://pypi.org/user/ssi-bot/ user own the pypi project before OCA bot try to create it so it's certainly a best practice to first get OCA package from the OCA wheelhouse https://wheelhouse.odoo-community.org/regards,Le ven. 24 janv. 2025 à 17:38, Sergio Corato <notifications@odoo-community.org> a écrit :Hi all,I am writing this mail even if I've already written it in OCA Discord, because I think this is a security issue, I apologize whether it's not.I found installed in an instance a pip from pypi.org of an OCA module upgraded there from a company outside OCA: https://pypi.org/project/odoo14-addon-stock-move-backdating/14.0.1.2.0/They pushed the module changed and with a different logo (almost this change made me notice it) and a link to their website. It's a bad thing that someone can put a pip there with a random code.I'll stop taking this pip from pypi.org or I'll take the OCA version, but what about other instances installed in this way? Or is it a deprecated way of deployment?
In tests done on github is used the "non-OCA" version too:Requirement already satisfied: odoo14-addon-stock-move-backdating in /opt/odoo-venv/src/odoo14-addon-stock-move-backdating/setup/stock_move_backdating (from -r test-requirements.txt (line 6)) (14.0.1.0.2.dev2)
while the current OCA version is "version": "14.0.1.0.1",Sergio Corato_______________________________________________
Mailing-List: https://odoo-community.org/groups/contributors-15
Post to: mailto:contributors@odoo-community.org
Unsubscribe: https://odoo-community.org/groups?unsubscribe
--Pierre_______________________________________________
Mailing-List: https://odoo-community.org/groups/contributors-15
Post to: mailto:contributors@odoo-community.org
Unsubscribe: https://odoo-community.org/groups?unsubscribe
by Stéphane Bidoul - 11:57 - 25 Jan 2025 -
Re: OCA pip module loaded by external organization on pypi.org
Hi,I suppose the https://pypi.org/user/ssi-bot/ user own the pypi project before OCA bot try to create it so it's certainly a best practice to first get OCA package from the OCA wheelhouse https://wheelhouse.odoo-community.org/regards,Le ven. 24 janv. 2025 à 17:38, Sergio Corato <notifications@odoo-community.org> a écrit :Hi all,I am writing this mail even if I've already written it in OCA Discord, because I think this is a security issue, I apologize whether it's not.I found installed in an instance a pip from pypi.org of an OCA module upgraded there from a company outside OCA: https://pypi.org/project/odoo14-addon-stock-move-backdating/14.0.1.2.0/They pushed the module changed and with a different logo (almost this change made me notice it) and a link to their website. It's a bad thing that someone can put a pip there with a random code.I'll stop taking this pip from pypi.org or I'll take the OCA version, but what about other instances installed in this way? Or is it a deprecated way of deployment?
In tests done on github is used the "non-OCA" version too:Requirement already satisfied: odoo14-addon-stock-move-backdating in /opt/odoo-venv/src/odoo14-addon-stock-move-backdating/setup/stock_move_backdating (from -r test-requirements.txt (line 6)) (14.0.1.0.2.dev2)
while the current OCA version is "version": "14.0.1.0.1",Sergio Corato_______________________________________________
Mailing-List: https://odoo-community.org/groups/contributors-15
Post to: mailto:contributors@odoo-community.org
Unsubscribe: https://odoo-community.org/groups?unsubscribe
--Pierre
by Pierre Verkest - 06:36 - 24 Jan 2025