Skip to content

v0.3.2

Choose a tag to compare

@github-actions github-actions released this 07 Oct 04:25
· 3 commits to main since this release
6fea234

Published and verified

Version 0.3.2 is available on all three destinations:

  • GitHub Release assets: five self-contained platform archives, npm/NuGet package files, CycloneDX SBOM and checksums.
  • npm, with latest=0.3.2.
  • NuGet.

Easy installation

Choose one method. Both registry packages require .NET 10; npx also requires Node.js 22+. Installing a .NET tool requires the .NET 10 SDK. Self-contained archives need no separate .NET installation.

npx:

npx -y --allow-scripts=@codegiveness/postgresql-sharp-mcp @codegiveness/postgresql-sharp-mcp@0.3.2 --version

.NET tool:

dotnet tool install --global codegiveness.postgresql-sharp-mcp --version 0.3.2
postgresql-sharp-mcp --version

The package-specific npm flag approves the C# installer on npm 12. The README covers MCP registration, protected connection input, validation, runtime/PATH requirements and upgrades. Database-access behavior is unchanged.

Observed verification

  • All eight release checksums and all nine GitHub attestations passed with exact source/workflow identity enforced.
  • npm's registry tarball is byte-identical to the attested release asset; fresh-cache standard npx version/help passed.
  • NuGet fresh-cache tool-path and isolated global installation passed. Installed version/help passed locally and in the successful hosted recovery run.
  • NuGet's repository signature verified, and all 60 non-signature package entries match the attested original.
  • Installed release package assets passed actual MCP discovery, database selection, read-only/write boundaries and shutdown against disposable PostgreSQL. Windows/macOS native package installation passed CI; other platform archives were not run locally.

Publication recovery

npm completed through owner-approved local browser authentication, without CI npm provenance. The npm Actions job subsequently passed by skipping the existing immutable version.

NuGet completed through an owner-authorized isolated sibling GitHub OIDC job. It verified the original PostgreSQL attestation before authentication and skipped ordinary MSSQL release jobs. The hosted install check passed after NuGet indexing. The temporary sibling branch was deleted; sibling main was unchanged. No secret was copied or exposed and no policy scope was widened.

The initial target all-release run retains its NuGet policy-mismatch failure; registry recovery is separate from that historical run. Future direct target-repository publishing requires a matching policy or another explicitly authorized publisher use.

Original build source: 6fea234b11dd88cea5fa0a66f2b8301252c2e44a.