[1.31.2]
Update navidrome to 0.64.2
Full Changelog
Sanitize user-controlled names (playlists, albums, artists, track titles) in the Content-Disposition header of downloads, so a crafted name cannot change the name of the downloaded file. (#5895 by @zapisanchez)
Stop writing the admin password to the log when the initial admin user cannot be created. (#5897 by @zapisanchez)
Fix database is locked errors, UI freezes and failed scans on slow storage. The artwork worker now pauses during scans, ANALYZE runs one index at a time, @eaDir thumbnail folders are ignored, and folder saves are retried when the database is busy. (#6201 by @deluan)
Fix scans failing with value out of range on 32-bit builds when a file has an invalid track number, disc number or BPM. A migration resets existing invalid values. (#6202 by @deluan)
Fix a failed initial admin creation that marked the initial setup as done, leaving the server without an admin user. Also fix invalid JSON in some delete responses and the missing Content-Type on shared playlist (M3U) downloads. (#5897 by @zapisanchez)
Honor the IsPublic flag when creating a playlist. Before, all playlists created through the Jellyfin API were private. (#6204 by @deluan)