Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .bestpractices.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"tests_documented_added_status": "Met",
"tests_documented_added_justification": "The instructions for contributions document the policy of adding automated tests for major new functionality and explain acceptable regression coverage: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#verify-behavior",
"description_good_status": "Met",
"description_good_justification": "README describes the PostgreSQL stdio MCP server, nine tools, explicit database targeting and read-only defaults: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md",
"description_good_justification": "README describes the PostgreSQL stdio MCP server, nine tools, live database discovery, per-call physical database selection and default unrestricted access mode with read-only SQL calls unless writes are explicitly requested: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md",
"interact_status": "Met",
"interact_justification": "README documents installation and links CONTRIBUTING for bug reports, enhancement requests and pull requests: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md",
"contribution_requirements_status": "Met",
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -61,4 +61,5 @@ jobs:
node-version: '24'
- run: dotnet restore postgresql-sharp-mcp.slnx --locked-mode
- run: dotnet run --project tools/PostgreSqlMcp.Build -c Release -- package --output artifacts/packages
- run: dotnet run --project tools/PostgreSqlMcp.Verify -c Release -- packages --artifacts artifacts/packages
- name: Install and exercise native entrypoints without a database service
run: dotnet run --project tools/PostgreSqlMcp.Verify -c Release -- packages --artifacts artifacts/packages --installation-only
6 changes: 3 additions & 3 deletions .gitleaks.toml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ description = "README connection configuration placeholders"
condition = "AND"
paths = ['''^README\.md$''']
regexTarget = "match"
regexes = ['''^Password=<(?:database-password|other-password)>$''']
regexes = ['''^Password=<(?:database-password|other-password|YOUR_PASSWORD)>$''']

# The verifier creates its own loopback-only disposable PostgreSQL containers.
# These values must remain tied to these exact paths, not entire test files.
Expand All @@ -67,11 +67,11 @@ regexes = ['''^Password=(?:reader-disposable|writer-disposable|sensitive-configu

[[allowlists]]
targetRules = ["npgsql-keyword-password", "sqlserver-keyword-password"]
description = "Disposable package startup authentication marker"
description = "Disposable package startup and owned PostgreSQL fixture authentication markers"
condition = "AND"
paths = ['''^tools/PostgreSqlMcp\.Verify/Packages\.cs$''']
regexTarget = "match"
regexes = ['''^Password=disposable-package-secret$''']
regexes = ['''^Password=(?:disposable-package-secret|writer-disposable)$''']

# Default rules still run. Only these exact disposable values may be suppressed
# if the generic provider-independent rule also recognizes them.
Expand Down
15 changes: 14 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,20 @@
# Changelog

## Unreleased
## 0.3.1

- Make **0.3.1** the environment-first setup follow-on: use masked Bash/PowerShell input to set `POSTGRES_CONNECTION_STRING`, inherit it when launching the MCP client, and keep credentials and mandatory targets files out of the primary client configuration. Existing discovery works without a JSON file; retain protected profiles as an optional alternative.
- Explain process-only lifetime, child-process inheritance, full client restart, mutually exclusive file/environment configuration and plaintext storage/inspection risks. Do not treat environment variables as encrypted secret storage or put secrets in shell history, persistent profiles or literal MCP JSON.
- Document optional secret-free prompt functions in Bash `.bashrc` and Zsh `.zshrc`, their login/startup-file behavior and shell-specific input syntax. Prompt explicitly in the launching shell; do not persist credentials or invoke secret prompts automatically from rc files.
- Exercise environment-only live discovery, physical selection, read-only/write boundaries and installed npm/NuGet entrypoints against disposable PostgreSQL. Align npm/NuGet metadata at patch version 0.3.1 without claiming release or registry publication.
- Include the 0.3.0 database-agnostic PostgreSQL selection contract: `list_databases` queries the live accessible-database catalog; configured connections are bootstrap profiles, not mandatory per-database entries. Select physical names per call, optionally choose a `target` profile, and discover newly created/granted databases without changing the protected file or restarting. Preserve optional explicit database allowlists and PostgreSQL permissions.
- **Breaking:** omitted access mode now defaults to `unrestricted`; explicit `restricted` remains effective. SQL calls still default to read-only, and writes require `read_only=false`. The `list_databases` payload now contains a paged `databases` result instead of an alias-only `targets` list. Existing 0.2.0 binaries require an upgrade; this entry does not claim release or registry publication.
- Bound dynamic data-source retention to `256 / POSTGRES_POOL_SIZE` pools: equivalent normalized profiles reuse sources, idle pools are evicted, active pools retain ownership, and capacity waits share the original operation deadline. Preserve per-call database isolation, transaction boundaries and no fallback or write replay.
- Exercise immutable single-seed files, live creation/CONNECT revocation, concurrent database switching, punctuation-safe names, optional targets, explicit allowlists, default unrestricted writes, pool churn/capacity cancellation and disposal against disposable PostgreSQL. Install built npm/NuGet artifacts and exercise live discovery, physical selection and write commit/cleanup through their actual entrypoints.
- Keep the package fixture's exact `writer-disposable` synthetic password exception scoped to `tools/PostgreSqlMcp.Verify/Packages.cs`; other passwords and paths remain subject to scanning.
- Add explicit `packages --installation-only` verification for native Windows/macOS runners without a Docker database service; retain actual installed CLI/MCP/unavailable-endpoint checks and full live discovery/write package verification on Linux.
- Make unavailable-endpoint package verification portable by owning a listening loopback socket and rejecting each accepted handshake; do not rely on bound non-listening sockets producing immediate connection refusals on every OS.
- Rewrite first-time setup around one self-contained release path, explicit file locations and naming, a single `primary` target, complete Linux/macOS/Windows MCP configurations, client reload, connectivity checkpoints and troubleshooting. Keep alternative install methods separate and preserve existing installations. Extend the existing secret-scanner exception only to the exact new README password placeholder.
- Document verified local NuGet artifact installation when registry publication is unavailable, including checksum/attestation checks, an isolated local feed and installed MCP verification. Clarify protected conversion of PostgreSQL URI secrets without claiming registry availability.
- Add a NuGet-only manual release target that skips npm and GitHub Release publication while preserving main/tag validation, package verification, attestation and failure/cancellation gates. Keep the default all-target release behavior.
- Verify Best Practices enrollment as project 15155 (19%, not passing); add evidence-backed owner-review proposals and correct stale enrollment, secret-feature and Scorecard findings documentation without claiming hosted changes.
- Display the live OpenSSF Best Practices badge in README, including its in-progress state; distinguish the saved owner self-assessment from local answer proposals and security certification.
Expand Down
Loading
Loading