# Tryton News February 2026

**URL:** https://discuss.tryton.org/t/tryton-news-february-2026/9076
**Category:** News
**Created:** [February 1, 2026, 7:00am UTC](https://discuss.tryton.org/t/tryton-news-february-2026/9076 "2026-02-01T07:00:22Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![udono](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/udono/32/2114_2.png) [@udono](https://discuss.tryton.org/u/udono)
#### Post date: [February 1, 2026, 7:00am UTC](https://discuss.tryton.org/t/tryton-news-february-2026/9076/1 "2026-02-01T07:00:22Z")

</div>

![A Group of Professionals Sharing Ideas](https://discuss-cdn.tryton.org/uploads/default/original/2X/3/3c0643c4b058ff5328c43e7666f73b4aeafcb63b.jpeg "Photo: Pexels, Canva Studio")

During the last month we focused on fixing bugs, improving the behaviour of things, speeding-up performance issues - building on the changes from [our release last month](https://discuss.tryton.org/t/tryton-release-7-8/). But we also added many new features which we would like to introduce to you in this newsletter.

For an in depth overview of the [Tryton issues please take a look at our issue tracker](https://bugs.tryton.org/) or see the issues and merge requests [filtered by label](https://code.tryton.org/tryton/-/labels).

## Changes for the User

### Sales, Purchases and Projects

We now [add the optional _gift card_ field to the list of products.](https://code.tryton.org/tryton/-/commit/f737c0027c664d6a5690039e3faee2ff7892d525) This helps to search gift card products.

Now we [clean the former quotation\_date when copy sale records](https://bugs.tryton.org/14358) as we already do with the sale\_date.

We now [display the `origin` field of requests in the purchase request list.](https://code.tryton.org/tryton/-/commit/5d0f5649ed67740cf73ac61614ad8f3efa8b19c7) When the _purchase request_ is not from a _stock supply_, it is useful for the user who takes action, to know the origin of the request.

### Accounting, Invoicing and Payments

[Now we support _allowance_ and _charge_ in UBL invoices.](https://bugs.tryton.org/14524)

We now [fill the buyer’s item identification (BuyersItemIdentification) in the UBL invoice](https://bugs.tryton.org/14470), when sale product customer is activated.  
On the invoice line we have properties like `product_name` to get related supplier and customer codes.

Now we [add a cron scheduler to reconcile account move lines.](https://bugs.tryton.org/14468) On larger setups the number of accounts and parties to reconcile can be very numerous. It would consume too much time to execute the _reconciliation wizard_, even with the _automatic_ option.  
In this cases it will be better to run the reconciliation process as a scheduled task in background.

We now add [support for payment references for incoming invoice](https://bugs.tryton.org/14465). As the invoice manages payment references, we support to fill it using information from the _incoming document_.

Now [Tryton warns the user before creating an overpayment](https://bugs.tryton.org/14457). Sometimes users book a payment directly as a move line but without creating a payment record. If the line is not yet reconciled (it can be a partial payment), the _line to pay_ stand still there showing the full amount to pay. This can lead to over pay a party without any notice for the user.  
So we now ensure that the amount being paid does not exceed the payable (or receivable) amount of the party.  
**There is no guarantee against overpayment** The proper way to avoid is to always use the _payments_ functionality. But the warning will catch most of the mistakes.

Now we [add support for Peppyrus webhooks](https://code.tryton.org/tryton/-/commit/b96191427ff3de6d68cc56fe10f5f4e74b3666a6) in Tryton’s document incoming functionality.

We now set [Belgian account 488 as deposit.](https://bugs.tryton.org/14148)

Now we [add `cy_vat` as _tax identifier type._](https://foss.heptapod.net/tryton/tryton/-/merge_requests/2778)

### Stock, Production and Shipments

We now [store the original _planned date_ of requested _internal shipments_ and _productions_.](https://bugs.tryton.org/14477)  
For _shipments_ created by _sales_ we already store the original _planned date_ to compute the _delay_. Now we do the same for the supplied shipments and productions.

Now we [use a `fields.Many2One` to display either the _product_ or the _variant_](https://bugs.tryton.org/14456) in the _stock reporting_ instead of the former _reference field_. With this change the user is able to search for product or variant specific attributes. But the reference field is still useful to build the domain, so we keep it invisible.

We now [add routings on BOM form](https://bugs.tryton.org/14367) to ease the setup.

Now we [use the default _warehouse_ when creating new product _locations_](https://code.tryton.org/tryton/-/commit/3bddb1b8f1e59a8b4584f0531f508b1616aeaf1c).

### User Interface

Now we [allow to reorder tabs in Sao](https://code.tryton.org/tryton/-/commit/5a0bd2eca011f16e392133c5ea40544ef8a0f825), the Tryton web client.

Now we [use the default digit value to calculate the width of the float widget](https://bugs.tryton.org/14153) in Sao.

## New Releases

We released bug fixes for the currently maintained [long term support series](https://discuss.tryton.org/t/release-process/395)  
[7.0](https://code.tryton.org/tryton/-/commits/branch/7.0) and [6.0](https://code.tryton.org/tryton/-/commits/branch/6.0), and for the penultimate series [7.8](https://code.tryton.org/tryton/-/commits/branch/7.8) and [7.6](https://code.tryton.org/tryton/-/commits/branch/7.6).

## Security
Please update your systems to take care of a security related bug we found last month. 

> [@Security Release for issue #14354](https://discuss.tryton.org/t/security-release-for-issue-14354/8950/):
>
> [Mahdi Afshar](https://foss.heptapod.net/Mahdi36) and [Abdulfatah Abdillahi](https://foss.heptapod.net/Abdul123) have found that [trytond](https://pypi.org/project/trytond/) [sends the trace-back to the clients for unexpected errors](https://bugs.tryton.org/14354). This trace-back may [leak information about the server setup](https://bugs.tryton.org/14355). Impact [CVSS v3.0 Base Score: 4.3](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C) Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Interaction: None Scope: Unchanged Confidentiality: Low Integrity: None Availability: None Workaround A possible workaround is to configure an error handler which would remove the trace-back from the respo…

> [@Security Release for issue #14363](https://discuss.tryton.org/t/security-release-for-issue-14363/8951/):
>
> [Abdulfatah Abdillahi](https://foss.heptapod.net/Abdul123) has found that [sao](https://www.npmjs.com/package/tryton-sao) [does not escape the completion values](https://bugs.tryton.org/14363). The content of completion is generally the record name which may be edited in many ways depending on the model. The content may include some JavaScript which is executed in the same context as sao which gives access to sensitive data such as the session. Impact [CVSS v3.0 Base Score: 7.3](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:H/RL:O/RC:C/CR:H/IR:H/MAV:N/MAC:L/MPR:L/MUI:R/MS:U/MC:H/MI:H/MA:N) Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Interaction: Required Scope: Unchanged Confidentiality…

> [@Security Release for issue #14364](https://discuss.tryton.org/t/security-release-for-issue-14364/8952/):
>
> [Mahdi Afshar](https://foss.heptapod.net/Mahdi36) has found that [trytond](https://pypi.org/project/trytond/) does not [enforce access rights for the route of the HTML editor](https://bugs.tryton.org/14364) (since version 6.0). Impact [CVSS v3.0 Base Score: 7.1](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:H/RL:O/RC:C) Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Interaction: None Scope: Unchanged Confidentiality: High Integrity: Low Availability: None Workaround A possible workaround is to block access to the html editor. Resolution All affected users should upgrade trytond to the latest version. Affected versions per ser…

> [@Security Release for issue #14366](https://discuss.tryton.org/t/security-release-for-issue-14366/8953/):
>
> [Cédric Krier](https://foss.heptapod.net/ced) has found that [trytond](https://pypi.org/project/trytond/) does not [enforce access rights for data export](https://bugs.tryton.org/14366) (since version 6.0). Impact [CVSS v3.0 Base Score: 6.5](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C) Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Interaction: None Scope: Unchanged Confidentiality: High Integrity: None Availability: None Workaround There is no workaround. Resolution All affected users should upgrade trytond to the latest version. Affected versions per series: trytond: 7.6: \<= 7.6.10 7.4: \<= 7.4.20 7.0: \<=…

## Changes for the System Administrator

Now we [allow filtering users to be notified by cron tasks.](https://bugs.tryton.org/14432) When notifying subscribing users of a cron task, messages may make sense only for some user. For example if the message is about a specific company, we want to notify only the users having access to this company.

We now [dump the `action value` of cron notification as JSON](https://bugs.tryton.org/14431) if it is not a string (aka JSON).

Now we log an [exception when the Binary field retrieval of a file ID from the file-store fails.](https://code.tryton.org/tryton/-/commit/d51a5bb9774616a4555dcda0db200ff44c08d0cb)

We now [support `0` as parameter of `max_tasks_per_child`](https://bugs.tryton.org/14349).  
The `ProcessPoolExecutor` requires a `positive number` or `None`. But when using an environment variable to configure a startup script, it is complicated to set _no value_ (which means skip the argument). Now it is easier because `0` is considered as `None`.

## Changes for Implementers and Developers

We now [log an exception when it fails to open the XML-file of a view (view arch).](https://code.tryton.org/tryton/-/commit/a84e4bae7609cca91c5c6efcb038cadc65f8de35)

Now we [format _dates_ used as _record names_ with the contextual language.](https://code.tryton.org/tryton/-/commit/5395d22d4a071c0485b0740b1e86283ac4da5477)

We now add the general [test `PartyCheckReplaceMixin` to check replaced fields of the replace party wizard.](https://code.tryton.org/tryton/-/commit/2376a541800e04e15fed0ebf12517e7507a759f7)

Authors: @dave @pokoli @udono

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [March 3, 2026, 7:01am UTC](https://discuss.tryton.org/t/tryton-news-february-2026/9076/2 "2026-03-03T07:01:18Z")

</div>

This topic was automatically closed after 30 days. New replies are no longer allowed.
