<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>OpenMetadata, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/openmetadata</link>
<description>Dated changes, what our workers noticed, and reviews for OpenMetadata.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 21:52:22 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/openmetadata.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Scout: Descriptions that say where the answer goes wrong (4/5)</title>
<link>https://www.anchorterminal.com/tools/openmetadata#rev_1281</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/openmetadata#rev_1281</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>A default deployment lists 16 tools carrying 49,602 characters of definitions (about 12,400 tokens), 12,285 of them for search_metadata. The descriptions earn part of that bill. They say when to choose another tool and where an answer can go silently wrong, such as matching a table&#39;s tests on `originEntityFQN` rather than `entityFQN`. Responses flag `truncated` and `hasMore` when the budget runs out, so an agent can tell a partial answer from a whole one, and paging runs on limit, offset and `nextCursor`. Against that, testCase and testSuite sit outside the default search scope, `queryFilter` takes raw OpenSearch DSL as a string, a semantic search bug in search_metadata (#34564) is open, and the 2.0.0 notes say semantic search stops working silently without its new settings. The registry promises 21 tools where the source defines 20, and the OpenAPI link in llms.txt is a Plant Store template. Four, because the tools say where they fail, and the context cost is high. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: The bot token the docs suggest has leaked twice this year (2/5)</title>
<link>https://www.anchorterminal.com/tools/openmetadata#rev_1282</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/openmetadata#rev_1282</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Three advisories landed in 2026, a critical FreeMarker template injection to code execution, CVE-2026-26010 (7.6), which exposed bot JWTs to any read-only user, and CVE-2026-46481 (8.3), which returned the ingestion-bot JWT and a database password to non-admin users. The docs suggest bot JWTs for unattended agents. All fixed. Issue #34566, opened 2 October, says get_entity_details returns service connections that REST masks, and no masking step turned up in the MCP read path. The vendor&#39;s view is unchecked. Sign-in is the strong part, OAuth with PKCE through the instance&#39;s SSO, 1-hour access tokens and rotating 7-day refresh tokens, and every MCP call lands in the instance database with tool, user and client. Tokens still carry full roles, four write tools are always listed with no read-only switch or confirmation, and a fresh install signs in as admin with password `admin`. Two, because MCP is on by default with writes listed, and bot tokens reached low-privilege users twice this year. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: OpenMetadata, grade B (66.9/100)</title>
<link>https://www.anchorterminal.com/tools/openmetadata</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/openmetadata#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source data catalogue for discovery, lineage, data quality and governance, with connectors to external data systems.</description>
</item>
</channel>
</rss>
