Skip to content

Upgrade pyexiv2 to v2.16.0 - #1605

Merged
danlamanna merged 2 commits into
masterfrom
upgrade-pyexiv2
Sep 30, 2026
Merged

danlamanna merged 2 commits into
masterfrom
upgrade-pyexiv2

Conversation

@danlamanna

@danlamanna danlamanna commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

pyexiv2 2.16.0 bundles exiv2 0.28.8. That version writes a plain string for Xmp.xmpRights.UsageTerms as simple text instead of an rdf:Alt. The IPTC spec requires a Lang Alt value for this field, and test_iptc_metadata_embedding failed on the upgrade. The fix passes an explicit x-default entry, which writes the same XMP on 2.15.5 and 2.16.0.

Split out of #1587.

Summary by CodeRabbit

  • Improvements
    • Rights usage terms in published image metadata are now provided as a default-language alternative, supporting metadata consumers that expect language-qualified values.

pyexiv2 2.16.0 bundles exiv2 0.28.8. That version writes a plain
string for Xmp.xmpRights.UsageTerms as simple text. The IPTC photo
metadata spec requires a Lang Alt value for this field. Pass an
explicit x-default entry so that exiv2 writes an rdf:Alt.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 59529322-3397-4c44-a6df-f70bdfaec3a3

📥 Commits

Reviewing files that changed from the base of the PR and between ff5b086 and 51326a9.

⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • isic/ingest/services/publish/__init__.py
  • pyproject.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The publish code now supplies Xmp.xmpRights.UsageTerms as an x-default language alternative. The pinned pyexiv2 version changes from 2.15.5 to 2.16.0.

Changes

Publish metadata

Layer / File(s) Summary
UsageTerms representation and dependency
isic/ingest/services/publish/__init__.py, pyproject.toml
UsageTerms changes from a plain string to an x-default language alternative. The pyexiv2 pin changes from 2.15.5 to 2.16.0.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 51326

The published license terms are represented as an x-default language alternative, with an existing test checking the output. No actionable merge-blocking risk is evident.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 51326

The change preserves the expected license format and existing publishing controls. No introduced security issue was identified, but the upgraded library's runtime behavior and storage failure recovery were not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly evidenced output scope is an accession's original image and thumbnail. The supplied public-api classification does not establish external invocation, attacker control of accession inputs, or a maximum independently attackable service or tenant scope.

Trust Boundaries and Controls

  • inferred — The reviewed delta does not add callers, change metadata input authority, or bypass the existing public-image guard. It changes the value representation passed into the existing pyexiv2 processing boundary; broader library behavior remains unverified.

Resilience and Maintainability Implications

  • inferred — A failure while generating either replacement occurs before the caller replaces persisted blob references. Later storage-save failure, interruption, concurrent replacement, and recovery cleanup are not proven atomic. These uncertainties concern the pre-existing persistence sequence, not a demonstrated regression from this PR.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary change: upgrading the pinned pyexiv2 dependency to version 2.16.0.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@danlamanna
danlamanna merged commit 43d8639 into master Sep 30, 2026
3 checks passed
@danlamanna
danlamanna deleted the upgrade-pyexiv2 branch September 30, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant