Release notes for pymetadata 0.7.0
Security
- Locations of COMBINE archive entries are validated: absolute locations and locations pointing outside of the archive, e.g.,
../model.xml, are rejected, so a manifest cannot write or delete files outside of the archive directory (#95). - The attributes of the
manifest.xmlare escaped, locations with&,"or<produced an unreadable manifest (#95). - ChEBI ids and InChIKeys are validated before they are used in request urls and cache file names; cache file names are derived with
pymetadata.cache.cache_fileand stay inside the cache directory (#95). Omex.from_urlonly accepts http and https urls, downloads with retries and a timeout, streams the archive to disk and removes the download afterwards (#95).
Fixes
- COMBINE archives (#95):
Omex.entries_by_formatmatches the names ofEntryFormat, e.g.,csvorSBML_L3V2.- Locations are normalized once when an entry is created; adding
model.xmltwice replaces the entry andget_path("model.xml")works. Omex.add_entryno longer modifies the entry passed by the caller.- The temporary directory of an archive is removed by the new
Omex.close, by the context manager, or at the latest when the archive is garbage collected. Omex.to_omexwrites atomically, a failing write does not destroy an existing archive.Omex.guess_formatdoes not depend on the encoding of.xmlfiles and handles.XML.
- Annotations (#95): terms of namespaces embedded in the LUI without their prefix (
chebi/33699,go/0005829), DOIs and other compact ids containing/, lowercase percent encoding inurn:miriamresources, upper case url schemes, query strings, fragments and trailing slashes in urls, registry patterns without anchors,RDFAnnotation.validatefor resources which cannot be parsed, and the mapping of legacy collections (obo.go,biomodels.sbo). - Web services (#95):
OLSQuery(cache=False)disabled the cache again; ChEBI and UniChem wrote the cache withcache=False; a corrupt cache file is treated as a cache miss; unknown ChEBI ids return{}; failed ontology downloads raise and downloads are written atomically. - Archives written by
Omex.to_omexand downloaded ontologies get regular file permissions instead of owner-only ones. - Canonical FMA IRIs for the OLS metadata resolution (#90).
Changes
- Invalid archive locations raise a
pydantic.ValidationError,Omex.from_omexraises aValueErrorfor a zip archive withoutmanifest.xml. Namespace.resourcesof the registry is alist[Resource], dictionaries are still converted.urllib3is a declared dependency.
Performance
- Reading and writing archives no longer copies every file twice.
- The registry compiles the patterns once and determines the dataclass fields once.
Your pymetadata team