Jeremy Stretch před 14 hodinami
rodič
revize
251458b89a
37 změnil soubory, kde provedl 3030 přidání a 2700 odebrání
  1. 160 102
      contrib/openapi.json
  2. 17 12
      docs/release-notes/version-4.7.md
  3. 2 2
      netbox/release.yaml
  4. binární
      netbox/translations/cs/LC_MESSAGES/django.mo
  5. 180 161
      netbox/translations/cs/LC_MESSAGES/django.po
  6. binární
      netbox/translations/da/LC_MESSAGES/django.mo
  7. 176 161
      netbox/translations/da/LC_MESSAGES/django.po
  8. binární
      netbox/translations/de/LC_MESSAGES/django.mo
  9. 178 161
      netbox/translations/de/LC_MESSAGES/django.po
  10. binární
      netbox/translations/es/LC_MESSAGES/django.mo
  11. 178 161
      netbox/translations/es/LC_MESSAGES/django.po
  12. binární
      netbox/translations/fr/LC_MESSAGES/django.mo
  13. 179 162
      netbox/translations/fr/LC_MESSAGES/django.po
  14. binární
      netbox/translations/it/LC_MESSAGES/django.mo
  15. 178 161
      netbox/translations/it/LC_MESSAGES/django.po
  16. binární
      netbox/translations/ja/LC_MESSAGES/django.mo
  17. 174 161
      netbox/translations/ja/LC_MESSAGES/django.po
  18. binární
      netbox/translations/ko/LC_MESSAGES/django.mo
  19. 174 161
      netbox/translations/ko/LC_MESSAGES/django.po
  20. binární
      netbox/translations/lv/LC_MESSAGES/django.mo
  21. 175 158
      netbox/translations/lv/LC_MESSAGES/django.po
  22. binární
      netbox/translations/nl/LC_MESSAGES/django.mo
  23. 177 161
      netbox/translations/nl/LC_MESSAGES/django.po
  24. binární
      netbox/translations/pl/LC_MESSAGES/django.mo
  25. 180 161
      netbox/translations/pl/LC_MESSAGES/django.po
  26. binární
      netbox/translations/pt/LC_MESSAGES/django.mo
  27. 178 161
      netbox/translations/pt/LC_MESSAGES/django.po
  28. binární
      netbox/translations/ru/LC_MESSAGES/django.mo
  29. 184 161
      netbox/translations/ru/LC_MESSAGES/django.po
  30. binární
      netbox/translations/tr/LC_MESSAGES/django.mo
  31. 176 161
      netbox/translations/tr/LC_MESSAGES/django.po
  32. binární
      netbox/translations/uk/LC_MESSAGES/django.mo
  33. 180 161
      netbox/translations/uk/LC_MESSAGES/django.po
  34. binární
      netbox/translations/zh/LC_MESSAGES/django.mo
  35. 174 161
      netbox/translations/zh/LC_MESSAGES/django.po
  36. 4 4
      pyproject.toml
  37. 6 6
      requirements.txt

Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 160 - 102
contrib/openapi.json


+ 17 - 12
docs/release-notes/version-4.7.md

@@ -1,23 +1,28 @@
 # NetBox v4.7
 # NetBox v4.7
 
 
-## v4.7.2 (FUTURE)
+## v4.7.2 (2026-09-29)
 
 
 !!! warning "API Tokens Created by Background Bulk Requests"
 !!! warning "API Tokens Created by Background Bulk Requests"
-    NetBox v4.7.0 and v4.7.1 accepted `background=true` on a bulk write to the `/api/users/tokens/` endpoint, and recorded each created token's plaintext in the job's result. Any user permitted to view those jobs (`core.view_job`, subject to object permissions) could read it.
+    NetBox v4.7.0 and v4.7.1 recorded the plaintext of API tokens created via background bulk requests in the job results, where they were readable by any user permitted to view jobs. This release rejects such requests; any tokens created this way should be considered exposed and replaced. See [#23196](https://github.com/netbox-community/netbox/issues/23196) for details.
 
 
-    This release rejects background bulk creations, updates, and deletions on that endpoint with an `HTTP 400` response. A token job queued before the upgrade is rejected the same way when an upgraded worker picks it up. Integrations which set `background=true` on these operations must drop the parameter. Synchronous writes are unaffected.
-
-    This does not remove the plaintexts already recorded, and it does not revoke the affected tokens. Treat a token created this way as potentially exposed. After upgrading and restarting the workers, revoke and replace the affected tokens, then delete the job records which captured them.
+### Enhancements
 
 
-    Job names are localized to the requesting user's language, so identify candidate records by their stored result instead:
+* [#21879](https://github.com/netbox-community/netbox/issues/21879) - Introduce the `Cable.update_dependent_objects()` hook to rebuild cable paths and related attributes after writes which bypass `save()`
+* [#22886](https://github.com/netbox-community/netbox/issues/22886) - Include VLANs assigned via VLAN groups scoped to a site (or its site group) among the site's related objects
+* [#22949](https://github.com/netbox-community/netbox/issues/22949) - Focus and scroll to the first field with a validation error when a form fails validation
+* [#23095](https://github.com/netbox-community/netbox/issues/23095) - Display the compatible module types for a module bay type in a dedicated, sortable, and paginated table
 
 
-    ```no-highlight
-    SELECT id, name, created
-    FROM core_job
-    WHERE jsonb_path_exists(data, '$.data[*].token ? (@ != null)');
-    ```
+### Bug Fixes
 
 
-    The query returns job metadata only, never the stored values. Confirm that a match really holds an API token response before deleting it, as an unrelated result may also carry a `token` field. An empty result does not rule out earlier exposure, because the affected records may already have been deleted. Deleting the records does not invalidate the tokens.
+* [#23122](https://github.com/netbox-community/netbox/issues/23122) - Prevent the failure to automatically sync one object from skipping the sync of subsequent objects
+* [#23150](https://github.com/netbox-community/netbox/issues/23150) - Preserve the parent device type assignment when using "Create & Add Another" to add component templates
+* [#23160](https://github.com/netbox-community/netbox/issues/23160) - Record a change log entry for each terminating object when a cable is deleted
+* [#23181](https://github.com/netbox-community/netbox/issues/23181) - Restore the display of the cluster group in the virtual machine detail view
+* [#23187](https://github.com/netbox-community/netbox/issues/23187) - Permit the assignment of a data file when creating an export template via the REST API
+* [#23195](https://github.com/netbox-community/netbox/issues/23195) - Validate the `return_url` parameter used for the cancel button on the IP address assignment view
+* [#23196](https://github.com/netbox-community/netbox/issues/23196) - Ensure plaintext API tokens are never recorded in background job results (see the warning above)
+* [#23197](https://github.com/netbox-community/netbox/issues/23197) - Enforce object permission constraints on the REST API `sync` action for synced data models
+* [#23203](https://github.com/netbox-community/netbox/issues/23203) - Fix the population of the related objects panel for owners
 
 
 ---
 ---
 
 

+ 2 - 2
netbox/release.yaml

@@ -1,3 +1,3 @@
-version: "4.7.1"
+version: "4.7.2"
 edition: "Community"
 edition: "Community"
-published: "2026-09-15"
+published: "2026-09-29"

binární
netbox/translations/cs/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 180 - 161
netbox/translations/cs/LC_MESSAGES/django.po


binární
netbox/translations/da/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 176 - 161
netbox/translations/da/LC_MESSAGES/django.po


binární
netbox/translations/de/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 178 - 161
netbox/translations/de/LC_MESSAGES/django.po


binární
netbox/translations/es/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 178 - 161
netbox/translations/es/LC_MESSAGES/django.po


binární
netbox/translations/fr/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 179 - 162
netbox/translations/fr/LC_MESSAGES/django.po


binární
netbox/translations/it/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 178 - 161
netbox/translations/it/LC_MESSAGES/django.po


binární
netbox/translations/ja/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 174 - 161
netbox/translations/ja/LC_MESSAGES/django.po


binární
netbox/translations/ko/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 174 - 161
netbox/translations/ko/LC_MESSAGES/django.po


binární
netbox/translations/lv/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 175 - 158
netbox/translations/lv/LC_MESSAGES/django.po


binární
netbox/translations/nl/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 177 - 161
netbox/translations/nl/LC_MESSAGES/django.po


binární
netbox/translations/pl/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 180 - 161
netbox/translations/pl/LC_MESSAGES/django.po


binární
netbox/translations/pt/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 178 - 161
netbox/translations/pt/LC_MESSAGES/django.po


binární
netbox/translations/ru/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 184 - 161
netbox/translations/ru/LC_MESSAGES/django.po


binární
netbox/translations/tr/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 176 - 161
netbox/translations/tr/LC_MESSAGES/django.po


binární
netbox/translations/uk/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 180 - 161
netbox/translations/uk/LC_MESSAGES/django.po


binární
netbox/translations/zh/LC_MESSAGES/django.mo


Rozdílová data souboru nebyla zobrazena, protože soubor je příliš velký
+ 174 - 161
netbox/translations/zh/LC_MESSAGES/django.po


+ 4 - 4
pyproject.toml

@@ -33,15 +33,15 @@ swift = ["django-storage-swift"]
 s3 = ["boto3"]
 s3 = ["boto3"]
 git = ["dulwich"]
 git = ["dulwich"]
 # NetBox Labs plugins (proprietary, opt-in). Minor-bounded to the tested series.
 # NetBox Labs plugins (proprietary, opt-in). Minor-bounded to the tested series.
-branching = ["netboxlabs-netbox-branching>=1.1.0,<1.2.0"]
-custom-objects = ["netboxlabs-netbox-custom-objects>=0.5.0,<0.6.0"]
+branching = ["netboxlabs-netbox-branching>=1.2.0,<1.3.0"]
+custom-objects = ["netboxlabs-netbox-custom-objects>=0.7.0,<1.0.0"]
 # Convenience aggregate of the recommended NetBox Labs plugins (NOT a catch-all of every extra).
 # Convenience aggregate of the recommended NetBox Labs plugins (NOT a catch-all of every extra).
 # The component pins are duplicated literally, as remote-auth duplicates ldap and saml2;
 # The component pins are duplicated literally, as remote-auth duplicates ldap and saml2;
 # scripts/verify_wheel_metadata.py verifies in CI that this aggregate equals the union of the
 # scripts/verify_wheel_metadata.py verifies in CI that this aggregate equals the union of the
 # branching and custom-objects extras, guarding the duplication against drift.
 # branching and custom-objects extras, guarding the duplication against drift.
 recommended-plugins = [
 recommended-plugins = [
-    "netboxlabs-netbox-branching>=1.1.0,<1.2.0",
-    "netboxlabs-netbox-custom-objects>=0.5.0,<0.6.0",
+    "netboxlabs-netbox-branching>=1.2.0,<1.3.0",
+    "netboxlabs-netbox-custom-objects>=0.7.0,<1.0.0",
 ]
 ]
 dev = [
 dev = [
     "build",
     "build",

+ 6 - 6
requirements.txt

@@ -21,25 +21,25 @@ feedparser==6.0.14
 gunicorn==26.2.0
 gunicorn==26.2.0
 Jinja2==3.1.6
 Jinja2==3.1.6
 jsonschema==4.26.0
 jsonschema==4.26.0
-Markdown==3.10.3
+Markdown==3.11
 mkdocs==1.6.1
 mkdocs==1.6.1
 mkdocs-material==9.7.7
 mkdocs-material==9.7.7
 mkdocstrings==1.0.6
 mkdocstrings==1.0.6
-mkdocstrings-python==2.0.8
+mkdocstrings-python==2.0.9
 netaddr==1.3.0
 netaddr==1.3.0
 nh3==0.3.7
 nh3==0.3.7
 Pillow==12.3.0
 Pillow==12.3.0
-psycopg[c,pool]==3.3.5
+psycopg[c,pool]==3.3.6
 PyYAML==6.0.3
 PyYAML==6.0.3
 redis==8.1.0
 redis==8.1.0
 requests==2.34.2
 requests==2.34.2
 rq==2.12.0
 rq==2.12.0
 social-auth-app-django==6.0.1
 social-auth-app-django==6.0.1
-social-auth-core==5.1.0
+social-auth-core==5.1.1
 sorl-thumbnail==13.1.0
 sorl-thumbnail==13.1.0
 strawberry-graphql==0.327.7
 strawberry-graphql==0.327.7
-strawberry-graphql-django==0.89.2
+strawberry-graphql-django==0.90.0
 svgwrite==1.4.3
 svgwrite==1.4.3
 tablib==3.10.0
 tablib==3.10.0
 tzdata==2026.4
 tzdata==2026.4
-zensical==0.0.62
+zensical==0.0.66

Některé soubory nejsou zobrazeny, neboť je v těchto rozdílových datech změněno mnoho souborů