v0.5.6
0.5.6 (2026-10-02)
Bug Fixes
- isolate mutable test fixtures from shared temporary paths (#146) (2003a61)
- settle 0.x memory hardening and security backlog (#139) (194be9b)
Publication status
GitHub archives, SHA256 sidecars, SBOM and provenance are uploaded; the public linux-x64 binary passed actual live SQL/MCP verification. Public NuGet 0.5.6 installation is verified: a fresh-cache install reported 0.5.6.0 and validated a real SQL connection. npm 0.5.6 publication failed (E404 on the first platform package), so npm remains at 0.5.5 and the final Release smoke job was skipped. Maintainer credential/permission recovery and complete publication verification: #148. Do not treat this as a fully completed npm release.
Security clarification (added 2026-10-02)
- #52/#55/#56: bound query-row retention using a conservative serialized-JSON budget and refuse oversized raw SHOWPLAN XML through bounded reads. Early termination preserves truncation metadata; this is not a guarantee that every SQL-provider allocation is bounded. See memory-hardening issue #52 and fixing PR #139.
- CodeQL #18–#21: prevent the reproduced symlink overwrite through predictable shared temporary test-fixture paths by using an atomically created private temporary directory; PR #146. This finding affects the development/test fixture surface, not a proven production-server exploit.
The sequence-allocation, linked-parent/rotation and access-mode fixes merged in PR #150 are not included in v0.5.6. The npm publication limitation above remains unchanged.