Skip to content

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 13:49
18b6ed0

kpubdata 0.7.0 is mostly a security and correctness release. If you use 0.6.x, upgrade: several paths could leak your API key or send it somewhere it should not go.

pip install -U "kpubdata==0.7.0"

kpubdata-builder 0.4.0 is pinned to kpubdata<0.7 and still installs 0.6.x. The Builder release that moves to 0.7 will be 0.4.1.

Security

  • Your API key could reach logs, tracebacks and error trackers. When the key travelled as a query parameter (params=, used by datago, localdata, semas, sgis and every spec dataset), the exception chain kept the full URL with ?serviceKey=… (#486). bok carried its key in the URL path and law in a parameter named OC; neither was masked (#475). sgis tokens and consumer secrets were not masked either (#484).
  • lofin turned TLS certificate verification off. Every lofin request, including the key, would accept any certificate (#488). Verification is now on; only the cipher level is relaxed, which is all the server needs.
  • A spec could send your provider key to any host. The executor now refuses to attach a credential when endpoint.base_url is not a host listed for that provider (#532, #519).
  • Error responses and tokens were cached for 24 hours. Korean public APIs report quota and key errors in an HTTP 200 body, so a momentary quota breach was served from cache for a day (#490).

Behaviour changes — check before upgrading

  • Numeric columns cast differently. A declared numeric column is cast only if every value in it casts (#468). Thousands separators are understood: "1,200" becomes 1200, and datago.apt_trade.dealAmount is now an integer, not a string (#574). list_all() applies the rule across all pages at once, so page 1 and page 2 can no longer disagree on a column's type (#575).
  • An invalid license field in a spec now fails the load instead of being dropped silently (#476).
  • 4xx responses are no longer retried (#490). A Retry-After longer than TransportConfig.max_retry_delay (default 60 s) now raises a retryable RateLimitError instead of blocking (#477).
  • A credential sent to an unlisted host raises (#532) — only relevant if you wrote a spec that points somewhere unusual.
  • krx rejects raw operation names it does not have (#493). Previously any name returned the same listing.

Added

  • RecordBatch.validation — a typed report of which fields could not be cast, which were missing, and which were undeclared, with counts and sample values (#576, #582).
  • RecordBatch.meta["provenance"] — fetch time, SHA-256 of the raw response, content type, cache hit, and the masked URL and parameters (#583).
  • kpubdata probe — calls each dataset once with your key and sorts it into reachable, needs 활용신청 (403), needs parameters (400) or retired (#504).
  • Spec request parameters (type, required, description, example, enum) are exposed on DatasetRef metadata (#469, #376).
  • Spec datasets: 18 → 23, including the ocean buoy observation spec (#446, marked unstable until checked against the live API), and a license field in the spec schema (#443).

Fixed

  • data.go.kr gateway rejections are reported as what they are, on both the adapter and the spec path, instead of "malformed response envelope" (#478, #485).
  • The documented key names localdata / KPUBDATA_LOCALDATA_API_KEY and the semas equivalents now work; the shared datago key is still accepted (#492).
  • pip install kpubdata without pandas no longer breaks datasets.list() (#487).
  • HTTP errors carry status_code, and a 429 that exhausts retries raises RateLimitError (#484).
  • The response cache is written atomically, and keeps Content-Type across a hit (#484, #496).
  • localdata: resultCode "03" (no data) returns an empty result, empty wrappers no longer become a phantom row, and a trailing slash in base_url no longer produces // (#482, #483).
  • datago.g2b_catalog sends its required inqryDiv automatically (#421).

For contributors

Code comments and docstrings are now in English, with a CI gate against new Korean comments (#517). The project policy (docs/governance/POLICY.md), language policy (ADR 0003) and versioning policy (ADR 0004) were written down, and releases now run through a gated release pull request (#586, #588).

Full changelog: v0.6.0...v0.7.0