Repository navigation
This is a patch release that fixes bugs arisen after the Annif 1.4.1 release and also includes some required maintenance work.
The fixes introduce a size limit to REST API requests: now requests larger than the limit will receive 413 error response (Content Too Large). By default the limit is 20 MB; it can be configured using an environment variable. Edit: See the Environment variables wiki page.
Before it was possibly to execute a Denial of Service attack by sending arbitrarily large requests to the REST API to exhaust available memory and make Annif process crash. Thanks to @EQSTLab for reporting this vulnerability in the case of /detect-language endpoint.
Please see the published advisory here: GHSA-p3qf-5mj7-hrcv
Note that it is still possible to send multiple requests at a high rate to achieve DoS. When exposing Annif to the public internet, it should always sit behind a proxy service that controls the traffic and possibly also includes authorization mechanisms. Please see this wiki page for details.
Bug fixes
#911/#933 Fix uploading nn-train.mdb directory to Hugging Face Hub
#915 Fix member paths in zip archive in Hugging Face uploads when using custom data directory
#930 Add guard to YAKE suggestions when using exclusions (credit: @mjsuhonos)
#941 Fix REST API 500 error and schemathesis flaky test
#948/#950 Limit API request size
Maintenance
7942838 Pin GH Action cache/restore with commit hash
#899 PyPI trusted publishing