Releases: codegiveness/mssql-mcp
Release list
v0.5.7
Distribution status: GitHub archives and NuGet 0.5.7 are published. npm 0.5.7 is not published: registry publication failed with E404, and trusted-publisher inspection requires owner MFA. The workflow correctly withheld the main npm package. No token fallback or weakened publishing gate has been introduced.
Important authentication change
Microsoft Entra connection-string authentication is no longer supported in 0.5.7. The owner authorized removing the Azure/MSAL/native broker integration rather than seeking redistribution clearance or downgrading SqlClient security fixes. Use SQL password authentication, or Windows Integrated Authentication on Windows. SqlClient remains 7.1.1.
Native SNI assets are also explicitly excluded from application/tool publications, and SqlClient's documented managed Windows networking switch is enabled. The existing Windows .NET 10 runtime requirement remains. These removals address the known restrictions; they are not a general legal/licensing audit. Windows/macOS/ARM64 execution remains unverified.
Modernization
.NET SDK 10.0.401, runtime 10.0.12, fixed C# 14.0, Microsoft.Extensions 10.0.12, MCP SDK 2.2.0, and ScriptDom 180.117.0. Resource-ownership, cancellation/pool recovery, large-decimal output, row scratch allocation, and avoidable plan-accounting work are improved. See measured verification and limitations.
Final candidate verification: 452 unit / 479 live-SQL successes, zero failures, four existing skips; all three mandatory Inspector checks; all nine tools and clean EOF shutdown in the actual installed 0.5.7 tool and published Linux candidate; all 15 required protected-PR CI checks. Publication runs through the normal release workflow.
v0.5.6
0.5.6 (2026-10-02)
Bug Fixes
- isolate mutable test fixtures from shared temporary paths (#146) (2003a61)
- settle 0.x memory hardening and security backlog (#139) (194be9b)
Publication status
GitHub archives, SHA256 sidecars, SBOM and provenance are uploaded; the public linux-x64 binary passed actual live SQL/MCP verification. Public NuGet 0.5.6 installation is verified: a fresh-cache install reported 0.5.6.0 and validated a real SQL connection. npm 0.5.6 publication failed (E404 on the first platform package), so npm remains at 0.5.5 and the final Release smoke job was skipped. Maintainer credential/permission recovery and complete publication verification: #148. Do not treat this as a fully completed npm release.
Security clarification (added 2026-10-02)
- #52/#55/#56: bound query-row retention using a conservative serialized-JSON budget and refuse oversized raw SHOWPLAN XML through bounded reads. Early termination preserves truncation metadata; this is not a guarantee that every SQL-provider allocation is bounded. See memory-hardening issue #52 and fixing PR #139.
- CodeQL #18–#21: prevent the reproduced symlink overwrite through predictable shared temporary test-fixture paths by using an atomically created private temporary directory; PR #146. This finding affects the development/test fixture surface, not a proven production-server exploit.
The sequence-allocation, linked-parent/rotation and access-mode fixes merged in PR #150 are not included in v0.5.6. The npm publication limitation above remains unchanged.
v0.5.5
v0.5.4
v0.5.3
v0.5.2
0.5.2 (2026-07-25)
Bug Fixes
- correct release-please output name for dispatch (#100) (9c1d75d)
- security: harden 7 audit findings — npm shim, logging, cross-DB authz (#102) (7649383)
Security clarification (added 2026-10-02)
The public hardening report identifies these security fixes in this release:
- F1: reject archive traversal, absolute paths and symlink/hardlink entries before npm-shim extraction.
- F2: require database access in the database-parameter validation used by discovery tools. This does not turn Restricted mode into a database-authorization boundary.
- F3: reject log-path traversal and linked final log targets.
- F5: verify cached binary SHA-256 against its sidecar before reuse. This is integrity verification, not independent publisher authentication.
- F6: redact malformed credential values completely and return redaction rather than raw input on regex timeout.
- F7: reject download redirects outside the allowed GitHub hosts.
See the public hardening report and fixing PR #102. The identifiers above are those actually listed in the historical report; they are not CVE assignments. The later linked-parent/rotation hardening in PR #150 is not part of this release.
v0.5.1
v0.5.0
0.5.0 (2026-07-25)
Features
Bug Fixes
- ci: scope Scorecard write permissions to job level (#73) (79368ce)
- ci: use dereferenced commit SHA for scorecard-action (#74) (d3a4467)
- correct release-please manifest format + unified stamp sync (#88) (2f674cf), closes #78
- readme: update Scorecard badge URL to api.scorecard.dev (#76) (d00adef)
- skip version-consistency check for bot PRs (#90) (01dba32), closes #78
v0.4.2
What's Changed
- chore(release): bump version to 0.4.2 by @codegiveness in #71
Full Changelog: v0.4.1...v0.4.2
Security clarification (added 2026-10-02)
This release fixes public audit findings AHD-2 (credential leakage through transient connection errors) and AHD-3 (credential leakage through internal errors). Password obfuscation is applied at the error boundaries, including the connection-validation boundary. See the post-hardening audit and fixing changes. These are project audit identifiers, not CVE assignments. AHD-1 is not a data-isolation fix: Restricted mode does not replace SQL-principal permissions.
v0.4.1
What's Changed
- feat(cli): add --help/-h dispatch, graceful unknown-arg error, fix get_object_details by @codegiveness in #61
New Contributors
- @codegiveness made their first contribution in #61
Full Changelog: v0.4.0...v0.4.1