MetaKavita
Security and operations work merged into a metadata enrichment tool for the Kavita reading server: authentication, a hardened container and dependency fixes.
- Status
- Merged upstream
- Timeline
- July 2026 to 30 July 2026
- Built with
- Python, Docker, Kavita
- Links
- Source on GitHub
MetaKavita fills in metadata for large Kavita libraries. Before putting it on my network I read it closely, and sent back what I found as seven merged pull requests:
- a full user and password authentication system
- a non-root container with configurable user ids, a health check and a
/healthzendpoint - a size cap on proxied images, a token on the webhook, and a private config file
- a prominent warning that custom scrapers can run arbitrary code
- dependency bumps for gunicorn and requests, and a test that no longer touched the real database