Skip to content

Annif 1.4.2

Latest

Choose a tag to compare

@juhoinkinen juhoinkinen released this 14 Aug 14:34
· 165 commits to main since this release
Immutable release. Only release title and notes can be modified.
v1.4.2
b1f6e44

This is a patch release that fixes bugs arisen after the Annif 1.4.1 release and also includes some required maintenance work.

The fixes introduce a size limit to REST API requests: now requests larger than the limit will receive 413 error response (Content Too Large). By default the limit is 20 MB; it can be configured using an environment variable. Edit: See the Environment variables wiki page.

Before it was possibly to execute a Denial of Service attack by sending arbitrarily large requests to the REST API to exhaust available memory and make Annif process crash. Thanks to @EQSTLab for reporting this vulnerability in the case of /detect-language endpoint.

Please see the published advisory here: GHSA-p3qf-5mj7-hrcv

Note that it is still possible to send multiple requests at a high rate to achieve DoS. When exposing Annif to the public internet, it should always sit behind a proxy service that controls the traffic and possibly also includes authorization mechanisms. Please see this wiki page for details.

Bug fixes
#911/#933 Fix uploading nn-train.mdb directory to Hugging Face Hub
#915 Fix member paths in zip archive in Hugging Face uploads when using custom data directory
#930 Add guard to YAKE suggestions when using exclusions (credit: @mjsuhonos)
#941 Fix REST API 500 error and schemathesis flaky test
#948/#950 Limit API request size

Maintenance
7942838 Pin GH Action cache/restore with commit hash
#899 PyPI trusted publishing