Skip to content

Releases: codegiveness/mssql-mcp

v0.5.7

Choose a tag to compare

@github-actions github-actions released this 02 Oct 14:55
0c31b28

Distribution status: GitHub archives and NuGet 0.5.7 are published. npm 0.5.7 is not published: registry publication failed with E404, and trusted-publisher inspection requires owner MFA. The workflow correctly withheld the main npm package. No token fallback or weakened publishing gate has been introduced.

Important authentication change

Microsoft Entra connection-string authentication is no longer supported in 0.5.7. The owner authorized removing the Azure/MSAL/native broker integration rather than seeking redistribution clearance or downgrading SqlClient security fixes. Use SQL password authentication, or Windows Integrated Authentication on Windows. SqlClient remains 7.1.1.

Native SNI assets are also explicitly excluded from application/tool publications, and SqlClient's documented managed Windows networking switch is enabled. The existing Windows .NET 10 runtime requirement remains. These removals address the known restrictions; they are not a general legal/licensing audit. Windows/macOS/ARM64 execution remains unverified.

Modernization

.NET SDK 10.0.401, runtime 10.0.12, fixed C# 14.0, Microsoft.Extensions 10.0.12, MCP SDK 2.2.0, and ScriptDom 180.117.0. Resource-ownership, cancellation/pool recovery, large-decimal output, row scratch allocation, and avoidable plan-accounting work are improved. See measured verification and limitations.

Final candidate verification: 452 unit / 479 live-SQL successes, zero failures, four existing skips; all three mandatory Inspector checks; all nine tools and clean EOF shutdown in the actual installed 0.5.7 tool and published Linux candidate; all 15 required protected-PR CI checks. Publication runs through the normal release workflow.


v0.5.6

Choose a tag to compare

@github-actions github-actions released this 02 Oct 04:42
f8c882e

0.5.6 (2026-10-02)

Bug Fixes

  • isolate mutable test fixtures from shared temporary paths (#146) (2003a61)
  • settle 0.x memory hardening and security backlog (#139) (194be9b)

Publication status

GitHub archives, SHA256 sidecars, SBOM and provenance are uploaded; the public linux-x64 binary passed actual live SQL/MCP verification. Public NuGet 0.5.6 installation is verified: a fresh-cache install reported 0.5.6.0 and validated a real SQL connection. npm 0.5.6 publication failed (E404 on the first platform package), so npm remains at 0.5.5 and the final Release smoke job was skipped. Maintainer credential/permission recovery and complete publication verification: #148. Do not treat this as a fully completed npm release.

Security clarification (added 2026-10-02)

  • #52/#55/#56: bound query-row retention using a conservative serialized-JSON budget and refuse oversized raw SHOWPLAN XML through bounded reads. Early termination preserves truncation metadata; this is not a guarantee that every SQL-provider allocation is bounded. See memory-hardening issue #52 and fixing PR #139.
  • CodeQL #18–#21: prevent the reproduced symlink overwrite through predictable shared temporary test-fixture paths by using an atomically created private temporary directory; PR #146. This finding affects the development/test fixture surface, not a proven production-server exploit.

The sequence-allocation, linked-parent/rotation and access-mode fixes merged in PR #150 are not included in v0.5.6. The npm publication limitation above remains unchanged.

v0.5.5

Choose a tag to compare

@github-actions github-actions released this 04 Sep 11:56
d625a6b

0.5.5 (2026-09-04)

Bug Fixes

  • speed up startup and update dependencies (#127) (f8ec6a6)

v0.5.4

Choose a tag to compare

@github-actions github-actions released this 25 Jul 17:25
5fac4ac

0.5.4 (2026-07-25)

Bug Fixes

  • ci: sync version stamps before dotnet publish in release.yml (#105) (#110) (8e02ed3)

v0.5.3

Choose a tag to compare

@github-actions github-actions released this 25 Jul 15:28
f71ff72

0.5.3 (2026-07-25)

Bug Fixes

  • sync version stamps to 0.5.2 (manifest was ahead of csproj/npm/server.json) (#107) (88f6f11), closes #106
  • update stale docs to reflect current code (ADRs, versions, test counts) (#109) (665e145)

v0.5.2

Choose a tag to compare

@github-actions github-actions released this 25 Jul 13:37
926598c

0.5.2 (2026-07-25)

Bug Fixes

  • correct release-please output name for dispatch (#100) (9c1d75d)
  • security: harden 7 audit findings — npm shim, logging, cross-DB authz (#102) (7649383)

Security clarification (added 2026-10-02)

The public hardening report identifies these security fixes in this release:

  • F1: reject archive traversal, absolute paths and symlink/hardlink entries before npm-shim extraction.
  • F2: require database access in the database-parameter validation used by discovery tools. This does not turn Restricted mode into a database-authorization boundary.
  • F3: reject log-path traversal and linked final log targets.
  • F5: verify cached binary SHA-256 against its sidecar before reuse. This is integrity verification, not independent publisher authentication.
  • F6: redact malformed credential values completely and return redaction rather than raw input on regex timeout.
  • F7: reject download redirects outside the allowed GitHub hosts.

See the public hardening report and fixing PR #102. The identifiers above are those actually listed in the historical report; they are not CVE assignments. The later linked-parent/rotation hardening in PR #150 is not part of this release.

v0.5.1

Choose a tag to compare

@github-actions github-actions released this 25 Jul 04:47
97d8d4f

0.5.1 (2026-07-25)

Bug Fixes

  • dispatch release.yml on release-please tag creation (#99) (02663d1)
  • sync version stamps to 0.5.0 + skip consistency on release merges (#96) (a73c277)
  • use PAT for release-please to trigger downstream workflows (#98) (5302979)

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 25 Jul 03:46
bce733e

0.5.0 (2026-07-25)

Features

  • release-please automated version stamping + consistency guard (#86) (7f660a8), closes #78

Bug Fixes

  • ci: scope Scorecard write permissions to job level (#73) (79368ce)
  • ci: use dereferenced commit SHA for scorecard-action (#74) (d3a4467)
  • correct release-please manifest format + unified stamp sync (#88) (2f674cf), closes #78
  • readme: update Scorecard badge URL to api.scorecard.dev (#76) (d00adef)
  • skip version-consistency check for bot PRs (#90) (01dba32), closes #78

v0.4.2

Choose a tag to compare

@github-actions github-actions released this 24 Jul 05:26
2458379

What's Changed

Full Changelog: v0.4.1...v0.4.2

Security clarification (added 2026-10-02)

This release fixes public audit findings AHD-2 (credential leakage through transient connection errors) and AHD-3 (credential leakage through internal errors). Password obfuscation is applied at the error boundaries, including the connection-validation boundary. See the post-hardening audit and fixing changes. These are project audit identifiers, not CVE assignments. AHD-1 is not a data-isolation fix: Restricted mode does not replace SQL-principal permissions.

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 23 Jul 17:39
eef5312

What's Changed

  • feat(cli): add --help/-h dispatch, graceful unknown-arg error, fix get_object_details by @codegiveness in #61

New Contributors

Full Changelog: v0.4.0...v0.4.1