Skip to content

v0.5.6

Choose a tag to compare

@github-actions github-actions released this 02 Oct 04:42
f8c882e

0.5.6 (2026-10-02)

Bug Fixes

  • isolate mutable test fixtures from shared temporary paths (#146) (2003a61)
  • settle 0.x memory hardening and security backlog (#139) (194be9b)

Publication status

GitHub archives, SHA256 sidecars, SBOM and provenance are uploaded; the public linux-x64 binary passed actual live SQL/MCP verification. Public NuGet 0.5.6 installation is verified: a fresh-cache install reported 0.5.6.0 and validated a real SQL connection. npm 0.5.6 publication failed (E404 on the first platform package), so npm remains at 0.5.5 and the final Release smoke job was skipped. Maintainer credential/permission recovery and complete publication verification: #148. Do not treat this as a fully completed npm release.

Security clarification (added 2026-10-02)

  • #52/#55/#56: bound query-row retention using a conservative serialized-JSON budget and refuse oversized raw SHOWPLAN XML through bounded reads. Early termination preserves truncation metadata; this is not a guarantee that every SQL-provider allocation is bounded. See memory-hardening issue #52 and fixing PR #139.
  • CodeQL #18–#21: prevent the reproduced symlink overwrite through predictable shared temporary test-fixture paths by using an atomically created private temporary directory; PR #146. This finding affects the development/test fixture surface, not a proven production-server exploit.

The sequence-allocation, linked-parent/rotation and access-mode fixes merged in PR #150 are not included in v0.5.6. The npm publication limitation above remains unchanged.