1545 Commits
Author SHA1 Message Date
Oliver a435738507 Fix 500 errors for transitions (#12678) 2026-08-22 00:51:51 +10:00
github-actions[bot]andgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> 6ca7160723 New Crowdin translations by GitHub Action (#12654)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-21 23:55:29 +10:00
Oliver 7fc36ac7bc Drop legacy user session tables (#12675) 2026-08-21 15:05:45 +10:00
Matthias MairandOliver 71787d4546 feat(frontend): Add filter navigation remove button (#12668)
* feat(frontend): Add filter navigation remove button

* extend docs

* extract and extend labels

* add spacer

* fix test

* small fix

* remove unneeded labels

* add mechanism for not triggering on viewsets

* reduce diff for now

* fix test

---------

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-21 09:34:11 +10:00
be9faff766 fix: trigger pricing recalculation when SupplierPart pack_quantity changes (#12421)
* fix: trigger pricing recalculation when SupplierPart is saved or deleted

When a SupplierPart's pack_quantity is updated after price breaks have
already been created, the Part's pricing (and BOM cost rollups for any
assemblies using that part) was not recalculated. This is because there
was no post_save or post_delete signal handler for the SupplierPart model
to trigger schedule_pricing_update on the linked Part.

Added post_save and post_delete signal handlers for SupplierPart that
mirror the existing SupplierPriceBreak signal handlers. The pricing
cascade (via update_assemblies) ensures BOM line costs in parent
assemblies are also updated.

Fixes #12285

* style: fix ruff format issues

* style: apply ruff format with --preview flag (matching project config)

* fix: resolve PartPricing.DoesNotExist in pack_quantity test

The test captured self.part.pricing before any PartPricing row existed,
yielding an unsaved instance; the later refresh_from_db() then raised
DoesNotExist. Re-fetch self.part.pricing after the price break creates
the row, matching the pattern in test_supplier_part_pricing.

---------

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
Co-authored-by: Aman Jain <jainamn@amazon.com>
2026-08-21 08:44:09 +10:00
Matthias Mair a48ba58ee9 refactor PurchaseOrder APIs to viewset (#12317)
* refactor PurchaseOrder APIs to viewser

* reduce diff/api change

* replicate legacy api return codes

* fix serializer

* fix return code

* fix viewsets

* clean up docstrings

* ensure stuff is cleaned correctly

* distribute CleanMixin better down MRO

* move for mro reasons

* add prefetching

* update APISearchView to support viewsets

* fix apiserch for modelviewsets

* fix names

* Apply suggestions from code review

Co-authored-by: Matthias Mair <code@mjmair.com>

* add test for hold
2026-08-20 19:54:46 +10:00
Bhumin PaladiyaandOliver 501efdcb6e Fix admin search fields and misc code quality issues (#12525)
* Fix admin search for StockItemTracking and StockItemTestResult

Add search_fields to StockTrackingAdmin and StockItemTestResultAdmin

- item__part__name: search tracking by part name
- item__serial: search tracking by serial number
- notes: search tracking notes
- stock_item__part__name: search test results by part name
- stock_item__serial: search test results by serial number
- template__test_name: search test results by test template name
- value: search test results by output value
- notes: search test result notes

Also adds a unit test to verify search_fields configuration.

* Fix admin search for PartPricing, PartStocktake, PartRelated, and PartTestTemplate

Add search_fields to PartPricingAdmin, PartStocktakeAdmin, PartRelatedAdmin,
and PartTestTemplateAdmin.

- part__name, part__IPN, part__description: search PartPricing
- part__name, part__IPN: search PartStocktake
- part_1__name, part_2__name: search PartRelated
- part__name, test_name, description: search PartTestTemplate

Also adds unit test assertions to verify search_fields configuration.

* Fix admin search for SalesOrderAllocation and ReturnOrderLineItem

Add search_fields to SalesOrderAllocationAdmin and ReturnOrderLineItemAdmin.

SalesOrderAllocationAdmin:
- line__order__reference: search by Sales Order reference
- line__part__name: search by ordered Part name
- item__part__name: search by allocated Stock Item part name
- item__part__IPN: search by allocated Stock Item IPN
- item__serial: search by Stock Item serial number

ReturnOrderLineItemAdmin:
- order__reference: search by Return Order reference
- order__customer__name: search by Customer name
- item__part__name: search by returned Item part name
- item__serial: search by returned Item serial number
- reference: search by line item reference

Also adds list_display improvements and unit tests to verify
search_fields configuration.

* Fix incorrect identity comparison for status validation

Use '!=' (value comparison) instead of 'is not' (identity comparison)
when comparing custom_status.logical_key with self.instance.status.

Python only caches small integers (-5 to 256). For status codes > 256,
'is not' can return True even when values are equal, causing valid
custom status keys to be incorrectly rejected.

Per PEP 8: always use '==' or '!=' for value comparisons.

* Fix wrong super() method call in DataImportColumnMapAdmin

The formfield_for_dbfield method was incorrectly calling
super().formfield_for_choice_field() instead of super().formfield_for_dbfield().

These are different Django admin methods with different expectations.
formfield_for_choice_field expects choice-type fields, but the 'column'
field is a plain CharField. This could cause incorrect form rendering
or errors when viewing DataImportSession detail in Django Admin.

Fix: call the correct parent method formfield_for_dbfield().

* Fix broken delete() method signature on EmailMessage model

The delete() method used '*kwargs' which collects positional arguments
into a tuple named 'kwargs'. This breaks Django's Model.delete()
contract which expects keyword arguments (using=None, keep_parents=False).

When super().delete(*kwargs) was called, keyword arguments passed by
Django internals would be unpacked incorrectly as positional args.

Fix: use standard '*args, **kwargs' signature and pass both to super().

* Fix bare except clause in order status validation

Replace bare 'except:' with 'except Exception:' in
validate_status_custom_key method.

Bare except catches all BaseException subclasses including SystemExit,
KeyboardInterrupt, and MemoryError which should never be silenced.
The get_logical_value() function performs a database .get() call that
can raise ObjectDoesNotExist or MultipleObjectsReturned, both of which
are subclasses of Exception.

This follows PEP 8 (E722: do not use bare except).

* Fix bare except clauses in machine registry and barcode mixins

Replace bare 'except:' with 'except Exception:' in two locations:

- machine/registry.py: hash computation catches AttributeError or
  DoesNotExist when a machine config no longer exists
- plugin/base/barcodes/mixins.py: has_barcode_generation property
  catches any error from calling generate(None) on a plugin

Bare except catches all BaseException subclasses including SystemExit
and KeyboardInterrupt which should never be silenced.

This follows PEP 8 (E722: do not use bare except).

* Fix readonly_fields typos and add search_fields in admin classes

* Remove redundant admin field test assertions per review feedback

* Fix file formatting and end-of-file newlines per prek style check

---------

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-20 19:52:08 +10:00
Matthias Mair 36d21fe640 feat(frontend): add user setting to control navigation behaviour (#12669)
follow up to https://github.com/inventree/InvenTree/pull/12585
2026-08-20 11:23:12 +10:00
dependabot[bot]dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>Matthias Mair
dc9a277478 chore(deps): bump sqlparse from 0.5.5 to 0.6.0 in /src/backend (#12653)
* chore(deps): bump sqlparse from 0.5.5 to 0.6.0 in /src/backend

Bumps [sqlparse](https://github.com/andialbrecht/sqlparse) from 0.5.5 to 0.6.0.
- [Changelog](https://github.com/andialbrecht/sqlparse/blob/master/CHANGELOG)
- [Commits](https://github.com/andialbrecht/sqlparse/compare/0.5.5...0.6.0)

---
updated-dependencies:
- dependency-name: sqlparse
  dependency-version: 0.6.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-19 09:05:35 +10:00
dependabot[bot]dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>Matthias Mair
34732f0afa chore(deps): bump the dependencies group across 1 directory with 14 updates (#12642)
* chore(deps): bump the dependencies group across 1 directory with 14 updates

Bumps the dependencies group with 14 updates in the /src/backend directory:

| Package | From | To |
| --- | --- | --- |
| [cffi](https://github.com/python-cffi/cffi) | `2.1.0` | `2.1.1` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.15.2` | `7.15.4` |
| [django-stubs](https://github.com/typeddjango/django-stubs) | `6.0.7` | `6.0.9` |
| [django-stubs-ext](https://github.com/typeddjango/django-stubs) | `6.0.6` | `6.0.9` |
| [django-test-migrations](https://github.com/wemake-services/django-test-migrations) | `1.5.0` | `1.6.0` |
| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |
| [pip](https://github.com/pypa/pip) | `26.2` | `26.2.1` |
| [prek](https://github.com/j178/prek) | `0.4.11` | `0.4.12` |
| [pytest-django](https://github.com/pytest-dev/pytest-django) | `4.12.0` | `4.13.0` |
| [blessed](https://github.com/jquast/blessed) | `1.47.0` | `1.48.0` |
| [boto3](https://github.com/boto/boto3) | `1.43.61` | `1.43.66` |
| [botocore](https://github.com/boto/botocore) | `1.43.61` | `1.43.66` |
| [djangorestframework](https://github.com/encode/django-rest-framework) | `3.17.1` | `3.18.0` |
| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.75.0` | `1.75.1` |



Updates `cffi` from 2.1.0 to 2.1.1
- [Release notes](https://github.com/python-cffi/cffi/releases)
- [Commits](https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1)

Updates `coverage` from 7.15.2 to 7.15.4
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](https://github.com/coveragepy/coveragepy/compare/7.15.2...7.15.4)

Updates `django-stubs` from 6.0.7 to 6.0.9
- [Release notes](https://github.com/typeddjango/django-stubs/releases)
- [Commits](https://github.com/typeddjango/django-stubs/compare/6.0.7...6.0.9)

Updates `django-stubs-ext` from 6.0.6 to 6.0.9
- [Release notes](https://github.com/typeddjango/django-stubs/releases)
- [Commits](https://github.com/typeddjango/django-stubs/compare/6.0.6...6.0.9)

Updates `django-test-migrations` from 1.5.0 to 1.6.0
- [Release notes](https://github.com/wemake-services/django-test-migrations/releases)
- [Changelog](https://github.com/wemake-services/django-test-migrations/blob/master/CHANGELOG.md)
- [Commits](https://github.com/wemake-services/django-test-migrations/compare/1.5.0...1.6.0)

Updates `packaging` from 26.2 to 26.3
- [Release notes](https://github.com/pypa/packaging/releases)
- [Changelog](https://github.com/pypa/packaging/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pypa/packaging/compare/26.2...26.3)

Updates `pip` from 26.2 to 26.2.1
- [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst)
- [Commits](https://github.com/pypa/pip/compare/26.2...26.2.1)

Updates `prek` from 0.4.11 to 0.4.12
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](https://github.com/j178/prek/compare/v0.4.11...v0.4.12)

Updates `pytest-django` from 4.12.0 to 4.13.0
- [Release notes](https://github.com/pytest-dev/pytest-django/releases)
- [Changelog](https://github.com/pytest-dev/pytest-django/blob/main/docs/changelog.rst)
- [Commits](https://github.com/pytest-dev/pytest-django/compare/v4.12.0...v4.13.0)

Updates `blessed` from 1.47.0 to 1.48.0
- [Release notes](https://github.com/jquast/blessed/releases)
- [Changelog](https://github.com/jquast/blessed/blob/master/docs/history.rst)
- [Commits](https://github.com/jquast/blessed/commits/1.48)

Updates `boto3` from 1.43.61 to 1.43.66
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.61...1.43.66)

Updates `botocore` from 1.43.61 to 1.43.66
- [Commits](https://github.com/boto/botocore/compare/1.43.61...1.43.66)

Updates `djangorestframework` from 3.17.1 to 3.18.0
- [Release notes](https://github.com/encode/django-rest-framework/releases)
- [Commits](https://github.com/encode/django-rest-framework/compare/3.17.1...3.18.0)

Updates `googleapis-common-protos` from 1.75.0 to 1.75.1
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-python/compare/googleapis-common-protos-v1.75.0...googleapis-common-protos-v1.75.1)

---
updated-dependencies:
- dependency-name: cffi
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: coverage
  dependency-version: 7.15.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-stubs
  dependency-version: 6.0.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-stubs-ext
  dependency-version: 6.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-test-migrations
  dependency-version: 1.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: packaging
  dependency-version: '26.3'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: pip
  dependency-version: 26.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: prek
  dependency-version: 0.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: pytest-django
  dependency-version: 4.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: blessed
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: boto3
  dependency-version: 1.43.66
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: botocore
  dependency-version: 1.43.66
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: djangorestframework
  dependency-version: 3.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: googleapis-common-protos
  dependency-version: 1.75.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-18 08:50:58 +10:00
github-actions[bot]andgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> 90b72c194b New Crowdin translations by GitHub Action (#12625)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-16 23:02:10 +10:00
Oliver af74f1abf6 Improve error handling for unit registry (#12643) 2026-08-16 11:46:40 +10:00
amanjain57-gifandAman Jain ee4ad7fd10 feat: add piece_count and piece_size fields to BomItem for cut-to-length parts (#12422)
* feat: add piece_count and piece_size fields to BomItem for cut-to-length parts

Manufacturing BOMs frequently require multiple pieces of a specific size
cut from continuous stock (cables, tubing, structural profiles). Currently
the only way to express "10 pieces of 250mm cable" is to enter the total
length (2.5m) as quantity, which loses the piece-count information that
purchasing and production need.

This adds two optional fields to BomItem:
- piece_count: number of discrete pieces required (default: 1)
- piece_size: size/length of each piece (e.g. "250 mm")

When piece_size is specified, the total quantity is auto-calculated as
piece_count × piece_size, maintaining full backward compatibility (existing
items effectively have piece_count=1 and empty piece_size).

Changes:
- Backend: new model fields, migration, updated recalculate_quantity()
  logic, hash_fields for BOM validation
- API: serializer exposes piece_count and piece_size
- Frontend: BOM form includes the new fields, BOM table shows them as
  optional columns

Addresses #10274

* refactor: simplify to single piece_count field per reviewer feedback

Remove the piece_size field entirely. The existing quantity field already
represents the per-piece size/length, so piece_count multiplied by
quantity gives the total material requirement.

Example: quantity=200mm, piece_count=10 → total 2m of wire in 10 pieces.

Changes:
- Remove piece_size model field, serializer field, and frontend column/form
- Update migration to only add piece_count
- Update get_required_quantity() to multiply by piece_count
- Restore original recalculate_quantity() without piece_size logic

* test/docs: add unit tests and documentation for piece_count field

* style: replace ambiguous × with x to fix RUF002 lint error

* Address review feedback: api_version bump, changelog, style fix

- Bump INVENTREE_API_VERSION to 531 with entry for piece_count field
- Add CHANGELOG.md entry under Unreleased > Added
- Fix RUF001: replace ambiguous × with x in serializers.py help_text

* fix: align piece_count migration help_text with model (RUF001)

The 0153 AddField recorded help_text with a Unicode multiplication sign
(×), while the model field uses plain 'x' after the RUF001 fix. This
mismatch made makemigrations --check flag an unstaged
0154_alter_bomitem_piece_count migration, failing the DB test CI jobs.

Update the original migration's help_text (and docstring) to plain 'x'
so the field definition matches the model, keeping a single clean
migration instead of add-then-alter.

* fix: use set_quantity() in piece_count tests

BomItem.quantity is a derived field, recalculated from raw_amount on
every save() via recalculate_quantity(). Setting item.quantity directly
was overwritten back to the fixture value on save, so the tests computed
against quantity=3 and failed. Use set_quantity() (which sets raw_amount)
to match how quantity is meant to be updated.

* ci: re-trigger CI to confirm Firefox E2E failures are transient

---------

Co-authored-by: Aman Jain <jainamn@amazon.com>
2026-08-16 09:43:42 +10:00
Oliver 9844a4805e Allow bulk-edit for ReturnOrderLineItem (#12635)
* Allow bulk-edit for ReturnOrderLineItem

- Allow bulk change of line item outcome

* Update API version documentation with pull request links
2026-08-13 20:10:10 +10:00
Oliver 695b9c1dc2 [bug] Fix ReturnOrder event registration (#12633) 2026-08-13 16:43:22 +10:00
ribseyandOliver f5c4bbc6a8 reset errors on update (#12550)
* reset errors on update

* add empty line

---------

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-12 16:38:46 +10:00
Oliver 2b3283d5d2 [bug] OptionalField race condition (#12627)
* [bug] OptionalField race condition

Fixes subtle bug where OptionalField entries can be  silenty dropped from an API request due to concurrent requests / race conditions

* Additional unit tests

* Additional guard in metadata.py

* include extra kwargs

* Adjust import/exporting options

* Fix attribute sharing across class instances
2026-08-12 16:38:04 +10:00
FurinaDogandFurinaDog 55a193e5d7 fix: support UUID notification references (#12616)
* fix: support UUID notification references

* test: update notification uid expectation

---------

Co-authored-by: FurinaDog <FurinaDog@users.noreply.github.com>
2026-08-12 07:47:25 +10:00
Matthias Mair 1c86102d82 refactor fail limit to match allauth defaults more closely (#12623) 2026-08-12 07:46:45 +10:00
Matthias Mair 40c528164f feat(backend): switch to a more formal FSM approach (#12507)
* full fsm implementation

closes https://github.com/inventree/InvenTree/issues/12314

based on https://github.com/matmair/InvenTree/pull/721

* update assertations

* refactor to reduce duplication

* move for cleaner diff

* more moving stuff around

* fix assingment

* remove skip

* merge test classes

* re-enable transition plugin tests

* fix docstrings

* add depreciation warning

* fix type

* nitpicks

* small cleanup

* ensure we alwas pass a str

* add backport

* fix marker position

* full fsm implementation

closes https://github.com/inventree/InvenTree/issues/12314

based on https://github.com/matmair/InvenTree/pull/721

* update assertations

* refactor to reduce duplication

* move for cleaner diff

* more moving stuff around

* fix assingment

* remove skip

* merge test classes

* re-enable transition plugin tests

* fix docstrings

* add depreciation warning

* fix type

* nitpicks

* small cleanup

* ensure we alwas pass a str

* add backport

* fix marker position

* fix ty issue

* ignore this corner case

* ensure invalid transitions can raise a nice validation error

* compact code

* add depreciation mark

* make raise_error default (#754)

* fix merge

* adjust test as this is now not a no-op but a raised error

* fix assertations

* fix test to not take a broken path

* remove unused test statements

* converge

* add test branch for actually working transition

* reduce uneeded code

* ignore depreceated methods

* fix missing coverage

* add prefetch

* reduce diff
2026-08-12 07:45:43 +10:00
Matthias Mair 7cb3d78a5f refactor(backend): remove network dep from test (#12624) 2026-08-12 07:44:49 +10:00
Oliver 77d8470141 [bug] Handle duplicate email addresses for magic links (#12621) 2026-08-11 23:49:53 +10:00
github-actions[bot]andgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> f054a487ef New Crowdin translations by GitHub Action (#12535)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-11 18:47:12 +10:00
Oliver 1020ed3009 Fix for API exception_handler (#12604)
- Only log unhandled exceptions to sentry.io
- Check for valid handling first
- Report second
2026-08-10 23:23:07 +10:00
Oliver e7503684d0 Bump version number to 1.6.0-rev (#12603)
* Bump version number to 1.6.0-rev

* Add release date

* Add next version entry
2026-08-10 21:58:40 +10:00
dependabot[bot]dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>Matthias Mair
c622a65661 chore(deps): bump the dependencies group across 1 directory with 10 updates (#12561)
* chore(deps): bump the dependencies group across 1 directory with 10 updates

Bumps the dependencies group with 10 updates in the /src/backend directory:

| Package | From | To |
| --- | --- | --- |
| [boto3](https://github.com/boto/boto3) | `1.43.55` | `1.43.61` |
| [botocore](https://github.com/boto/botocore) | `1.43.55` | `1.43.61` |
| [django-anymail](https://github.com/anymail/django-anymail) | `15.0` | `15.1` |
| [feedparser](https://github.com/kurtmckee/feedparser) | `6.0.12` | `6.0.14` |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.2` | `3.10.3` |
| [redis](https://github.com/redis/redis-py) | `8.0.1` | `8.1.0` |
| [tablib](https://github.com/jazzband/tablib) | `3.9.0` | `3.10.0` |
| [tqdm](https://github.com/tqdm/tqdm) | `4.69.1` | `4.70.0` |
| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.2.2` | `2.3.0` |
| [pip](https://github.com/pypa/pip) | `26.1.2` | `26.2` |



Updates `boto3` from 1.43.55 to 1.43.61
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.55...1.43.61)

Updates `botocore` from 1.43.55 to 1.43.61
- [Commits](https://github.com/boto/botocore/compare/1.43.55...1.43.61)

Updates `django-anymail` from 15.0 to 15.1
- [Release notes](https://github.com/anymail/django-anymail/releases)
- [Changelog](https://github.com/anymail/django-anymail/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/anymail/django-anymail/compare/v15.0...v15.1)

Updates `feedparser` from 6.0.12 to 6.0.14
- [Release notes](https://github.com/kurtmckee/feedparser/releases)
- [Changelog](https://github.com/kurtmckee/feedparser/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/kurtmckee/feedparser/compare/v6.0.12...v6.0.14)

Updates `markdown` from 3.10.2 to 3.10.3
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](https://github.com/Python-Markdown/markdown/compare/3.10.2...3.10.3)

Updates `redis` from 8.0.1 to 8.1.0
- [Release notes](https://github.com/redis/redis-py/releases)
- [Changelog](https://github.com/redis/redis-py/blob/master/CHANGES)
- [Commits](https://github.com/redis/redis-py/compare/v8.0.1...v8.1.0)

Updates `tablib` from 3.9.0 to 3.10.0
- [Release notes](https://github.com/jazzband/tablib/releases)
- [Changelog](https://github.com/jazzband/tablib/blob/master/HISTORY.md)
- [Commits](https://github.com/jazzband/tablib/compare/v3.9.0...v3.10.0)

Updates `tqdm` from 4.69.1 to 4.70.0
- [Release notes](https://github.com/tqdm/tqdm/releases)
- [Commits](https://github.com/tqdm/tqdm/compare/v4.69.1...v4.70.0)

Updates `wrapt` from 2.2.2 to 2.3.0
- [Release notes](https://github.com/GrahamDumpleton/wrapt/releases)
- [Changelog](https://github.com/GrahamDumpleton/wrapt/blob/develop/docs/changes.rst)
- [Commits](https://github.com/GrahamDumpleton/wrapt/compare/2.2.2...2.3.0)

Updates `pip` from 26.1.2 to 26.2
- [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst)
- [Commits](https://github.com/pypa/pip/compare/26.1.2...26.2)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.61
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: botocore
  dependency-version: 1.43.61
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-anymail
  dependency-version: '15.1'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: feedparser
  dependency-version: 6.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: markdown
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: redis
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: tablib
  dependency-version: 3.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: tqdm
  dependency-version: 4.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: wrapt
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: pip
  dependency-version: '26.2'
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-10 21:28:29 +10:00
Matthias Mair 324b0ca012 feat(backend): add throtteling by default (#11951)
* feat(backend): add throtteling by default

* add changelog entry

* ignore throtetling in debug mode

* increase threshold
2026-08-10 18:41:15 +10:00
Oliver 1b20920e4a [security] Additional SSRF protections (#12595)
Tighten SSRF protections when fetching from external URLs
2026-08-10 18:32:49 +10:00
dependabot[bot]dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>Matthias Mair
edae156439 chore(deps): bump pypdf from 6.14.2 to 6.15.0 in /src/backend (#12594)
* chore(deps): bump pypdf from 6.14.2 to 6.15.0 in /src/backend

Bumps [pypdf](https://github.com/py-pdf/pypdf) from 6.14.2 to 6.15.0.
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](https://github.com/py-pdf/pypdf/compare/6.14.2...6.15.0)

---
updated-dependencies:
- dependency-name: pypdf
  dependency-version: 6.15.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-10 16:13:05 +10:00
siddhartha28andSiddhartha Ravilla 76bce6a7b1 Fix Install Stock Items shows only selected parts (#12596)
* Bug Fix Install Stock Item showing variant stock when BOM disallows variants

* Add regression test for include_variants stock filter

---------

Co-authored-by: Siddhartha Ravilla <ravilla.si@northeastern.edu>
2026-08-09 17:57:18 +10:00
214f472ec9 Fix test result ordering by test timestamps (#12533)
* Fix test result ordering by test timestamps

* Refractor test result comparison helper

* Apply formatting fixes

* Fix frontend formatting

* Avoid mutating test result records

* Add migration for test result ordering

* Retry documentation build

---------

Co-authored-by: jayasree723 <confidentlehmann@tomorjerry.com>
Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-09 09:56:48 +10:00
Oliver afcc89ecfb Data import fix (#12568)
* Specify JSON encoder for data import fields

- Fixes encoding issues when importing from XLSX file

* Add regression test

* Fix faulty error handler

* Fix for unit test
2026-08-09 08:19:19 +10:00
Oliver 901dc024c0 [bug] Fix for plugin fetching (#12590)
- Prevent operation on stale plugin
2026-08-09 08:19:01 +10:00
Oliver 61fe3c9ce5 [bug] Fix PartStocktakeSerializer (#12587)
Closes https://github.com/inventree/InvenTree/issues/12555
2026-08-09 07:26:37 +10:00
OliverandMatthias Mair 94024ad23e [bug] Validate location when completing build outputs (#12570)
* [bug] Validate location when completing build outputs

- Cannot be structural

* Fix unit test

---------

Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-08 23:27:53 +10:00
Oliver c0ed42549f [API] Restrict barcode scan history (#12569)
- A non-staff user can only view their own results
2026-08-08 21:56:47 +10:00
Oliver 28fea388f6 [bug] Handle deleted Part (#12578) 2026-08-08 21:56:25 +10:00
Oliver 6cdc21c308 [sentry] Do not report MethodNotAllowed (#12584) 2026-08-08 20:51:21 +10:00
Oliver 21819ebc78 Fix flaky test on sqlite (#12582) 2026-08-08 20:27:50 +10:00
Oliver 5c798f4237 [bug] Fix part duplicate checks (#12574)
* [bug] Fix part duplicate checks

* Additional unit tests
2026-08-08 19:11:46 +10:00
Oliver cf2f64c83a [bug] Fix getLogoImage helper (#12577)
* [bug] Fix getLogoImage helper

- Do not return a file:// URI

* cleanup code
2026-08-08 19:11:32 +10:00
Oliver f1e6ec249d [bug] Fix post-delete actions (#12575)
- Check that underlying part is still available
2026-08-08 17:58:21 +10:00
Oliver 9b5c69da26 [bug] excel encoding for data import (#12576)
- Handle different encoding types for excel import
- Fail cleanly if cannot read file
2026-08-08 17:58:01 +10:00
Oliver fe82ff1f9e [refactor] Improve efficiency of check_missing_pricing (#12572) 2026-08-08 17:17:20 +10:00
Oliver 66b95cde5b [API] Handle AppRegistryNotReady (#12571)
Explicit handling for AppRegistryNotReady error
2026-08-08 16:11:30 +10:00
Oliver 358c464349 Barcode API bugs (#12565)
* Add explicit permission checks for barcode scanning

- Previous role_required attribute did not do anything

* Additional unit tests
2026-08-08 14:17:50 +10:00
Oliver ad818889df Deduplicate part pricing updates per session (#12564) 2026-08-08 12:27:32 +10:00
Oliver badf7ab300 Handle missing part (#12566)
Part instance may have already been deleted in post_delete hook for related models.
2026-08-08 12:27:19 +10:00
Oliver 02ee7ca2a1 Fix permissions for group and RuleSet endpoints (#12563)
- Require StaffRole in addition to is_staff
2026-08-08 10:43:15 +10:00
dependabot[bot]dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>Matthias Mair
4a7970b61f chore(deps): bump cryptography from 49.0.0 to 50.0.0 in /src/backend (#12546)
* chore(deps): bump cryptography from 49.0.0 to 50.0.0 in /src/backend

Bumps [cryptography](https://github.com/pyca/cryptography) from 49.0.0 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/49.0.0...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-05 21:27:27 +12:00