Repository navigation
v0.3.2
Published and verified
Version 0.3.2 is available on all three destinations:
- GitHub Release assets: five self-contained platform archives, npm/NuGet package files, CycloneDX SBOM and checksums.
- npm, with
latest=0.3.2. - NuGet.
Easy installation
Choose one method. Both registry packages require .NET 10; npx also requires Node.js 22+. Installing a .NET tool requires the .NET 10 SDK. Self-contained archives need no separate .NET installation.
npx:
npx -y --allow-scripts=@codegiveness/postgresql-sharp-mcp @codegiveness/postgresql-sharp-mcp@0.3.2 --version.NET tool:
dotnet tool install --global codegiveness.postgresql-sharp-mcp --version 0.3.2
postgresql-sharp-mcp --versionThe package-specific npm flag approves the C# installer on npm 12. The README covers MCP registration, protected connection input, validation, runtime/PATH requirements and upgrades. Database-access behavior is unchanged.
Observed verification
- All eight release checksums and all nine GitHub attestations passed with exact source/workflow identity enforced.
- npm's registry tarball is byte-identical to the attested release asset; fresh-cache standard npx version/help passed.
- NuGet fresh-cache tool-path and isolated global installation passed. Installed version/help passed locally and in the successful hosted recovery run.
- NuGet's repository signature verified, and all 60 non-signature package entries match the attested original.
- Installed release package assets passed actual MCP discovery, database selection, read-only/write boundaries and shutdown against disposable PostgreSQL. Windows/macOS native package installation passed CI; other platform archives were not run locally.
Publication recovery
npm completed through owner-approved local browser authentication, without CI npm provenance. The npm Actions job subsequently passed by skipping the existing immutable version.
NuGet completed through an owner-authorized isolated sibling GitHub OIDC job. It verified the original PostgreSQL attestation before authentication and skipped ordinary MSSQL release jobs. The hosted install check passed after NuGet indexing. The temporary sibling branch was deleted; sibling main was unchanged. No secret was copied or exposed and no policy scope was widened.
The initial target all-release run retains its NuGet policy-mismatch failure; registry recovery is separate from that historical run. Future direct target-repository publishing requires a matching policy or another explicitly authorized publisher use.
Original build source: 6fea234b11dd88cea5fa0a66f2b8301252c2e44a.