v0.7.0
kpubdata 0.7.0 is mostly a security and correctness release. If you use 0.6.x, upgrade: several paths could leak your API key or send it somewhere it should not go.
pip install -U "kpubdata==0.7.0"kpubdata-builder 0.4.0 is pinned to kpubdata<0.7 and still installs 0.6.x. The Builder release that moves to 0.7 will be 0.4.1.
Security
- Your API key could reach logs, tracebacks and error trackers. When the key travelled as a query parameter (
params=, used by datago, localdata, semas, sgis and every spec dataset), the exception chain kept the full URL with?serviceKey=…(#486). bok carried its key in the URL path and law in a parameter namedOC; neither was masked (#475). sgis tokens and consumer secrets were not masked either (#484). - lofin turned TLS certificate verification off. Every lofin request, including the key, would accept any certificate (#488). Verification is now on; only the cipher level is relaxed, which is all the server needs.
- A spec could send your provider key to any host. The executor now refuses to attach a credential when
endpoint.base_urlis not a host listed for that provider (#532, #519). - Error responses and tokens were cached for 24 hours. Korean public APIs report quota and key errors in an HTTP 200 body, so a momentary quota breach was served from cache for a day (#490).
Behaviour changes — check before upgrading
- Numeric columns cast differently. A declared numeric column is cast only if every value in it casts (#468). Thousands separators are understood:
"1,200"becomes1200, anddatago.apt_trade.dealAmountis now an integer, not a string (#574).list_all()applies the rule across all pages at once, so page 1 and page 2 can no longer disagree on a column's type (#575). - An invalid
licensefield in a spec now fails the load instead of being dropped silently (#476). - 4xx responses are no longer retried (#490). A
Retry-Afterlonger thanTransportConfig.max_retry_delay(default 60 s) now raises a retryableRateLimitErrorinstead of blocking (#477). - A credential sent to an unlisted host raises (#532) — only relevant if you wrote a spec that points somewhere unusual.
- krx rejects raw operation names it does not have (#493). Previously any name returned the same listing.
Added
RecordBatch.validation— a typed report of which fields could not be cast, which were missing, and which were undeclared, with counts and sample values (#576, #582).RecordBatch.meta["provenance"]— fetch time, SHA-256 of the raw response, content type, cache hit, and the masked URL and parameters (#583).kpubdata probe— calls each dataset once with your key and sorts it into reachable, needs 활용신청 (403), needs parameters (400) or retired (#504).- Spec request parameters (type, required, description, example, enum) are exposed on
DatasetRefmetadata (#469, #376). - Spec datasets: 18 → 23, including the ocean buoy observation spec (#446, marked unstable until checked against the live API), and a
licensefield in the spec schema (#443).
Fixed
- data.go.kr gateway rejections are reported as what they are, on both the adapter and the spec path, instead of "malformed response envelope" (#478, #485).
- The documented key names
localdata/KPUBDATA_LOCALDATA_API_KEYand the semas equivalents now work; the shared datago key is still accepted (#492). pip install kpubdatawithout pandas no longer breaksdatasets.list()(#487).- HTTP errors carry
status_code, and a 429 that exhausts retries raisesRateLimitError(#484). - The response cache is written atomically, and keeps
Content-Typeacross a hit (#484, #496). - localdata:
resultCode "03"(no data) returns an empty result, empty wrappers no longer become a phantom row, and a trailing slash inbase_urlno longer produces//(#482, #483). datago.g2b_catalogsends its requiredinqryDivautomatically (#421).
For contributors
Code comments and docstrings are now in English, with a CI gate against new Korean comments (#517). The project policy (docs/governance/POLICY.md), language policy (ADR 0003) and versioning policy (ADR 0004) were written down, and releases now run through a gated release pull request (#586, #588).
Full changelog: v0.6.0...v0.7.0