Changes:

  • Install supported Odoo 19 Community from its official daily package channel with an exact package digest and bound repository key. Preserve the upstream payload while restoring its source-declared Trixie PDF dependency alternative in package control metadata.
  • Install Odoo's required patched wkhtmltopdf 0.12.6 series from an exact upstream package digest for PDF report rendering.
  • Bridge Odoo's stale python3-pypdf2 package dependency to Trixie's maintained python3-pypdf implementation without modifying Odoo's payload.
  • Use a non-superuser PostgreSQL application role and keep generated database and firstboot credentials out of process arguments and traces.
  • Add a non-mutating update check, v19 acceptance coverage, and README evidence crosswalk. Prepare supervised updates through the same verified, payload-preserving control correction used at build time.
  • Upgrade the base distribution to Debian 13 Trixie.

Links