MetaKavita

Security and operations work merged into a metadata enrichment tool for the Kavita reading server: authentication, a hardened container and dependency fixes.

Status
Merged upstream
Timeline
July 2026 to 30 July 2026
Built with
Python, Docker, Kavita

MetaKavita fills in metadata for large Kavita libraries. Before putting it on my network I read it closely, and sent back what I found as seven merged pull requests:

  • a full user and password authentication system
  • a non-root container with configurable user ids, a health check and a /healthz endpoint
  • a size cap on proxied images, a token on the webhook, and a private config file
  • a prominent warning that custom scrapers can run arbitrary code
  • dependency bumps for gunicorn and requests, and a test that no longer touched the real database