Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .bestpractices.json
Original file line number Diff line number Diff line change
Expand Up @@ -67,5 +67,5 @@
"dynamic_analysis_unsafe_justification": "The passing criterion explicitly permits N/A when the project does not produce software written in a memory-unsafe language. Maintained first-party application and tooling sources are C# without unsafe blocks or AllowUnsafeBlocks; the public source tree contains no first-party C/C++ implementation: https://github.com/codegiveness/postgresql-sharp-mcp/tree/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/src and https://github.com/codegiveness/postgresql-sharp-mcp/tree/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/tools . Native runtime/dependency code is not a claim of memory-safety certification.",
"dynamic_analysis_enable_assertions_status": "Met",
"dynamic_analysis_enable_assertions_justification": "Public-source evidence: the verification configuration runs deterministic varied-input SQL checks with always-enabled Check.Equal/Check.That and expected-error assertions, including exact PostgreSQL literal round trips, no unexpected truncation and second-statement/control-statement rejection: https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/tools/PostgreSqlMcp.Verify/FuzzChecks.cs . These assertions belong to the test verifier, not the production server, and integration succeeded in https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/36975816424 . This does not establish release-specific pre-release analysis or any branch-coverage percentage.",
"general_comments": "Repository-maintained answer proposals only; this file does not save hosted answers for https://www.bestpractices.dev/en/projects/15155 . Human-readable question text, choices and paste-ready explanations are provided in docs/best-practices-checklist.md. Default-branch policy evidence applies when this revision is published on main. No answers are proposed from subjective developer-knowledge attestations, presumed report-response histories, an absence of scanner findings, assumed credential cleanliness, unmeasured branch coverage or unverified release-specific pre-release analysis."
"general_comments": "Evidence-backed project metadata for https://www.bestpractices.dev/en/projects/15155 . Proposed answers require review and saving on the badge website. Developer-knowledge attestations, report-response histories, credential cleanliness, branch coverage and release-specific analysis are not inferred."
}
1 change: 0 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@

- Verify Best Practices enrollment as project 15155 (19%, not passing); add evidence-backed owner-review proposals and correct stale enrollment, secret-feature and Scorecard findings documentation without claiming hosted changes.
- Display the live OpenSSF Best Practices badge in README, including its in-progress state; distinguish the saved owner self-assessment from local answer proposals and security certification.
- Provide a Best Practices owner checklist using the questionnaire's exact visible question text, answer choices and copy-ready explanations instead of requiring manual interpretation of internal JSON identifiers.
- Harden solo-maintainer release execution: require a manual main-branch dispatch and an existing tag reachable from main; compile trusted orchestration in read-only preflight and use digest-checked immutable artifacts in checkout-free attestation/publishing jobs. Replace source discovery in publishers with an explicit publication context.
- Preserve zero required approvals while enabling resolved review conversations, enforced full-SHA Actions pins, a restricted action-publisher allowlist and owner approval for external fork workflows. Restrict the release environment to main; document unchanged optional secret controls and that hosted badge answers still require owner authentication.
- Replace the coverage-guided SQL fuzz Bash launcher with checksum-verified, deadline-bounded C# orchestration and fail-closed seed replay; keep portable corpus names and repair the asynchronous FsCheck verifier entrypoint. Document distinct PostgreSQL property and lexer fuzzing layers.
Expand Down
2 changes: 0 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,6 @@ A PostgreSQL MCP server built with C#/.NET 10 and Npgsql. One stdio server expos

The server, npm installation helper, packaging, verification and release automation are C#/.NET. No maintained JavaScript, Python or Bash implementation is required. npm itself requires Node.js for installation; the installed server runs directly as a .NET executable, without a Node process. Workflow badges and Scorecard report checks and practices, not certifications or profile achievements. Best Practices shows the saved owner self-assessment, which may still be in progress. See [Security posture](docs/security-posture.md) for supply-chain evidence and limits.

For the Best Practices questionnaire, use the [exact website questions and copy-ready answers](docs/best-practices-checklist.md). Repository proposals do not save the website's answers; the project owner must review and save them.

## Quick start

### 1. Install or run
Expand Down
Loading
Loading