{"id":15155,"user_id":57083,"name":"postgresql-sharp-mcp","description":"Token-efficient PostgreSQL MCP server in C# with Npgsql, explicit multi-database targeting and bounded results","homepage_url":"","repo_url":"https://github.com/codegiveness/postgresql-sharp-mcp","license":"MIT","homepage_url_status":"?","homepage_url_justification":null,"sites_https_status":"Met","sites_https_justification":"Given only https: URLs.","description_good_status":"Met","description_good_justification":"README describes the PostgreSQL stdio MCP server, nine tools, explicit database targeting and read-only defaults: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md","interact_status":"Met","interact_justification":"README documents installation and links CONTRIBUTING for bug reports, enhancement requests and pull requests: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md","contribution_status":"Met","contribution_justification":"Non-trivial contribution file in repository: \u003chttps://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md\u003e.","contribution_requirements_status":"Met","contribution_requirements_justification":"Contribution guidance specifies dependency direction, supported tooling, meaningful regression evidence, confidentiality and review requirements: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md","license_location_status":"Met","license_location_justification":"Non-trivial licenses directory file in repository: \u003chttps://github.com/codegiveness/postgresql-sharp-mcp/tree/main/LICENSES\u003e.","floss_license_status":"Met","floss_license_justification":"The MIT license is approved by the Open Source Initiative (OSI).","floss_license_osi_status":"Met","floss_license_osi_justification":"The MIT license is approved by the Open Source Initiative (OSI).","documentation_basics_status":"Met","documentation_basics_justification":"Some documentation basics file contents found.","documentation_interface_status":"Met","documentation_interface_justification":"README documents CLI/configuration inputs, all nine MCP tools, structured rowset outputs, pagination, clipping and error envelopes: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#tools","repo_public_status":"Met","repo_public_justification":"Repository on GitHub, which provides public git repositories with URLs.","repo_track_status":"Met","repo_track_justification":"Repository on GitHub, which uses git. git can track the changes, who made them, and when they were made.","repo_interim_status":"Met","repo_interim_justification":"Public-source evidence: released v0.2.0 identifies 1595dc1683c709e4265027048567c06216751afa; subsequent public commits a9f4ec3fdac162e0ce7a1e5e7dbb5d5e13cb3b38, e0572221bb3f3a6c4a8bce2791435f558fbf20db and bde167e95e0fb3ff74b895db55c87f4b04d69b0c expose interim maintenance between releases: https://github.com/codegiveness/postgresql-sharp-mcp/compare/v0.2.0...bde167e95e0fb3ff74b895db55c87f4b04d69b0c","repo_distributed_status":"Met","repo_distributed_justification":"Repository on GitHub, which uses git. git is distributed.","version_unique_status":"Met","version_unique_justification":"Public releases use unique version tags v0.1.0 and v0.2.0: https://github.com/codegiveness/postgresql-sharp-mcp/releases","version_semver_status":"Met","version_semver_justification":"Release identifiers use major.minor.patch numbering: https://github.com/codegiveness/postgresql-sharp-mcp/releases","version_tags_status":"Met","version_tags_justification":"Public releases identify their corresponding Git tags: https://github.com/codegiveness/postgresql-sharp-mcp/releases","release_notes_status":"Met","release_notes_justification":"Non-trivial release notes file in repository: \u003chttps://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CHANGELOG.md\u003e.","release_notes_vulns_status":"N/A","release_notes_vulns_justification":"API-verified evidence (checked 2026-10-10 12:53 UTC): 0 repository security advisories, and 0 GitHub Advisory Database entries and 0 OSV records for the published npm package @codegiveness/postgresql-sharp-mcp and NuGet package codegiveness.postgresql-sharp-mcp; no CVE or similar identifier has been assigned to a vulnerability in this project's results. The criterion directs N/A when there have been no publicly known vulnerabilities and applies only to project results, not dependencies. The release notes record no project vulnerability fix; the 0.3.1 entry's base-image OpenSSL update for CVE-2026-84782 concerns a dependency of the source-built container: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/CHANGELOG.md","report_url_status":"?","report_url_justification":null,"report_tracker_status":"Met","report_tracker_justification":"Contribution instructions direct actionable bug reports and enhancements to GitHub issues: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#issues-pull-requests-and-reviews","report_process_status":"Met","report_process_justification":"Non-trivial SECURITY[.md] file found file in repository: \u003chttps://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md\u003e. [osps_do_02_01]","report_responses_status":"Met","report_responses_justification":"API-verified evidence (GitHub REST and GraphQL, checked 2026-10-10 12:53 UTC): the repository has received 0 issues ever (all 29 issue-API entries are pull requests), has GitHub Discussions disabled and has 0 repository security advisories, so there is no bug report to acknowledge. It was created on 2026-10-02, so the 2-12 month window contains no reports. This criterion offers no N/A, so the answer is met only vacuously and must be re-evaluated once bug reports arrive: https://github.com/codegiveness/postgresql-sharp-mcp/issues?q=is%3Aissue","enhancement_responses_status":"Met","enhancement_responses_justification":"API-verified evidence (GitHub REST and GraphQL, checked 2026-10-10 12:53 UTC): 0 issues ever and GitHub Discussions disabled, so no enhancement request has been submitted; the 29 pull requests are maintainer and Dependabot changes, not outstanding requests. The repository was created on 2026-10-02, so the 2-12 month window contains no requests. This criterion offers no N/A, so the answer is met only vacuously and must be re-evaluated once requests arrive: https://github.com/codegiveness/postgresql-sharp-mcp/issues?q=is%3Aissue","report_archive_status":"Met","report_archive_justification":"GitHub issues and pull requests provide searchable, URL-addressable public reports and responses: https://github.com/codegiveness/postgresql-sharp-mcp/issues","vulnerability_report_process_status":"Met","vulnerability_report_process_justification":"SECURITY documents private reporting, sanitized reproduction requirements and fallback contact requests: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#reporting-a-vulnerability","vulnerability_report_private_status":"Met","vulnerability_report_private_justification":"GitHub private vulnerability reporting is enabled (repository API verified 2026-10-02); SECURITY links the HTTPS reporting route: https://github.com/codegiveness/postgresql-sharp-mcp/security","vulnerability_report_response_status":"N/A","vulnerability_report_response_justification":"API-verified evidence (GitHub REST, checked 2026-10-10 12:53 UTC): 0 repository security advisories, which include drafts opened by private vulnerability reports, and 0 issues; no vulnerability report has been received since the repository was created on 2026-10-02. The criterion directs N/A when no vulnerabilities were reported in the last 6 months. Reporting route: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#reporting-a-vulnerability","build_status":"Met","build_justification":"Public-source evidence: the .NET build is documented in CONTRIBUTING, and CI run 36975816424 on bde167e95e0fb3ff74b895db55c87f4b04d69b0c successfully restored locked dependencies, built and exercised PostgreSQL integration, and built packages: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/36975816424 . This does not verify the unmerged candidate.","build_common_tools_status":"Met","build_common_tools_justification":"The source build uses the .NET SDK and MSBuild: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#build-from-source","build_floss_tools_status":"Met","build_floss_tools_justification":"Public-source evidence: the documented source build uses dotnet build without requiring a proprietary IDE or hosted service: https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/CONTRIBUTING.md#build-from-source . The .NET SDK and MSBuild are MIT-licensed FLOSS: https://github.com/dotnet/sdk/blob/main/LICENSE.TXT and https://github.com/dotnet/msbuild/blob/main/LICENSE . Docker and npm are needed for separate verification/package paths, not the source executable build.","test_status":"Met","test_justification":"The public MIT-licensed .NET verifier exercises actual MCP calls against a disposable PostgreSQL fixture; CONTRIBUTING documents invocation: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#verify-behavior","test_invocation_status":"Met","test_invocation_justification":"The suite is invoked using dotnet run --project tools/PostgreSqlMcp.Verify -c Release -- integration: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#verify-behavior","test_most_status":"Unmet","test_most_justification":"Public-source evidence: the repository measures no statement or branch coverage, so it cannot show that the suite covers most code branches. The integration verifier exercises MCP tool calls, configuration inputs, permissions/RLS, target isolation, rollback, bounded results, sanitized errors and installed package entrypoints against disposable PostgreSQL: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/CONTRIBUTING.md#verify-behavior . CI passed on main revision fbbe5aa0c2abea5d48d58fa282d84204921c8e19: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38052409295 . FsCheck properties and the libFuzzer campaign add varied SQL inputs. This shows breadth of functional and input testing, not measured branch coverage; Met would require a coverage measurement.","test_policy_status":"Met","test_policy_justification":"The CONTRIBUTING.md Verify behavior section explicitly requires automated consumer-visible behavior coverage for major new functionality, with meaningful boundaries, transitions and errors: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#verify-behavior","tests_are_added_status":"Met","tests_are_added_justification":"Released-source evidence: v0.2.0 replaced the npm launcher and delivery tooling with .NET, as summarized in https://github.com/codegiveness/postgresql-sharp-mcp/blob/v0.2.0/CHANGELOG.md . The same release commit added the maintained verifier, including offline installation, native entrypoints, missing-.NET prerequisite failure and real MCP initialization/tool calls/shutdown checks: https://github.com/codegiveness/postgresql-sharp-mcp/commit/1595dc1683c709e4265027048567c06216751afa and https://github.com/codegiveness/postgresql-sharp-mcp/blob/v0.2.0/tools/PostgreSqlMcp.Verify/Packages.cs . Successful later CI run 36975816424 exercised these distributions on Linux, macOS and Windows; this is evidence of functionality testing, not branch-coverage measurement.","tests_documented_added_status":"Met","tests_documented_added_justification":"The instructions for contributions document the policy of adding automated tests for major new functionality and explain acceptable regression coverage: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#verify-behavior","warnings_status":"Met","warnings_justification":"Shared build settings enable nullable checking and TreatWarningsAsErrors: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Directory.Build.props","warnings_fixed_status":"Met","warnings_fixed_justification":"Public-source evidence: CI run 36975816424 passed its real integration/build and package jobs on bde167e95e0fb3ff74b895db55c87f4b04d69b0c with shared TreatWarningsAsErrors enabled: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/36975816424 and https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/Directory.Build.props . This is not evidence about an unmerged candidate.","warnings_strict_status":"Met","warnings_strict_justification":"All projects inherit nullable checking and TreatWarningsAsErrors: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Directory.Build.props","know_secure_design_status":"Met","know_secure_design_justification":"Owner attestation: the project owner, a primary developer, attests to knowing how to design secure software, including the Saltzer and Schroeder principles this criterion lists. The repository does not prove that knowledge; it shows design choices made with it. Tool calls cross an explicit stdio trust boundary and cannot supply connection strings or change host, login or TLS settings: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#trust-boundary . Least-privilege PostgreSQL roles are the authorization authority; SQL defaults to server-owned read-only transactions and writes require explicit opt-in: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#postgresql-permissions-are-the-authority and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/src/PostgreSqlMcp.Core/SqlExecutor.cs#L30-L35 . An optional database lock refuses out-of-lock databases before connecting and verifies PostgreSQL grants at startup: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#database-lock-hardening . Server-owned connection settings disable error-detail and parameter logging: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/src/PostgreSqlMcp.Core/DatabaseRegistry.cs#L30-L36","know_common_errors_status":"Met","know_common_errors_justification":"Owner attestation: the project owner, a primary developer, attests to knowing the common kinds of errors that lead to vulnerabilities in database-access servers, including SQL injection, missing authorization, credential and information exposure and resource exhaustion, and at least one mitigation for each. The repository does not prove that knowledge; it shows those mitigations applied. Catalog tools pass caller values as Npgsql parameters rather than SQL text: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/src/PostgreSqlMcp.Tools/DatabaseTools.cs#L62-L66 and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/src/PostgreSqlMcp.Core/SqlExecutor.cs#L75-L76 . A statement-boundary guard accepts one statement and rejects transaction/session control, while PostgreSQL permissions and read-only transactions, not the lexer, enforce access: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/src/PostgreSqlMcp.Core/SqlGuard.cs and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#postgresql-permissions-are-the-authority . Errors and logs withhold PostgreSQL messages, parameters and connection strings, and results, pools and deadlines are bounded: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#credentials-and-diagnostics and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#connection-and-resource-settings . FsCheck properties against PostgreSQL and a SharpFuzz/libFuzzer campaign on the SQL guard exercise input handling: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/tools/PostgreSqlMcp.Verify/FuzzChecks.cs and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/.github/workflows/fuzzing.yml","crypto_published_status":"Met","crypto_published_justification":"Public-source evidence: database connections delegate to Npgsql 10.0.3, whose authentication uses published PostgreSQL protocols (including SCRAM-SHA-256) and whose TLS implementation delegates to .NET SslStream: https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/src/PostgreSqlMcp.Core/DatabaseRegistry.cs and https://github.com/npgsql/npgsql/blob/v10.0.3/src/Npgsql/Internal/NpgsqlConnector.Auth.cs and https://github.com/npgsql/npgsql/blob/v10.0.3/src/Npgsql/Internal/NpgsqlConnector.cs . No project-specific cryptographic protocol is implemented. Published protocols do not establish safe negotiated algorithms, key lengths, certificate validation or forward secrecy; those stronger criteria remain unresolved.","crypto_call_status":"Met","crypto_call_justification":"Public-source evidence: the application delegates PostgreSQL authentication and TLS to Npgsql rather than implementing cryptographic primitives. Npgsql delegates TLS to .NET SslStream and SCRAM primitives to System.Security.Cryptography (SHA256, HMACSHA256, PBKDF2 and RandomNumberGenerator): https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/src/PostgreSqlMcp.Core/DatabaseRegistry.cs and https://github.com/npgsql/npgsql/blob/v10.0.3/src/Npgsql/Internal/NpgsqlConnector.Auth.cs and https://github.com/npgsql/npgsql/blob/v10.0.3/src/Npgsql/Internal/NpgsqlConnector.cs","crypto_floss_status":"Met","crypto_floss_justification":"Public-source evidence: the cryptographic functionality can run with FLOSS Npgsql and .NET on Linux, using their open authentication/TLS implementations; no proprietary cryptographic service is required. The repository distributes their permissive Npgsql and MIT .NET licenses: https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/LICENSES/Npgsql.txt and https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/LICENSES/DotNet.txt . Implementation: https://github.com/npgsql/npgsql/blob/v10.0.3/src/Npgsql/Internal/NpgsqlConnector.Auth.cs","crypto_keylength_status":"Met","crypto_keylength_justification":"Public-source evidence: the application selects no key sizes and contains no cryptographic APIs: https://github.com/codegiveness/postgresql-sharp-mcp/tree/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/src . Its security mechanisms are delegated. Npgsql 10.0.3 SCRAM-SHA-256 authentication uses SHA-256, HMAC-SHA-256 and PBKDF2-SHA-256 with 256-bit outputs: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.Auth.cs#L150-L284 . TLS uses .NET SslStream with EnabledSslProtocols=None and no cipher override, so the operating system's TLS policy chooses protocol versions, cipher suites and key-exchange groups: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.cs#L1229-L1239 and https://learn.microsoft.com/dotnet/core/extensions/sslstream-best-practices . Smaller key lengths can be completely disabled through that OS policy (for example the OpenSSL security level on Linux or SChannel settings on Windows); the application has no separate key-length option. Negotiated key sizes also depend on the operator's PostgreSQL server certificate and TLS settings, and TLS is used only when the operator's SSL Mode and server enable it (Npgsql defaults to Prefer): https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#connection-and-resource-settings . This is not a guarantee for every platform or server.","crypto_working_status":"Met","crypto_working_justification":"Public-source evidence: the application implements no algorithm or cipher mode and contains no cryptographic APIs: https://github.com/codegiveness/postgresql-sharp-mcp/tree/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/src . By default Npgsql 10.0.3 authenticates with SCRAM-SHA-256, trying SCRAM-SHA-256-PLUS channel binding first over TLS, whenever the server requests SASL, as PostgreSQL 14 and later do by default: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.Auth.cs#L50-L58 . TLS uses .NET SslStream with OS-chosen protocols and cipher suites, which .NET documents as letting the OS block versions it no longer considers secure: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.cs#L1229-L1239 and https://learn.microsoft.com/dotnet/core/extensions/sslstream-best-practices . Npgsql still performs PostgreSQL's legacy MD5 challenge-response if an operator's server is configured to request it; operators can refuse it with the Require Auth connection-string setting (for example ScramSHA256): https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/NpgsqlConnectionStringBuilder.cs#L724-L731 . The role-hardening guide configures hostssl with scram-sha-256: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#hardening-the-role . TLS use and certificate validation remain operator-controlled: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#connection-and-resource-settings","crypto_pfs_status":"Met","crypto_pfs_justification":"Public-source evidence: the only key-agreement protocol is TLS, implemented by .NET SslStream and the operating system's TLS provider with OS-selected protocols and suites: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.cs#L1229-L1239 . Full TLS 1.3 handshakes, used when the OS and the operator's PostgreSQL server support TLS 1.3, always use ephemeral (EC)DHE key exchange and so provide forward secrecy; with TLS 1.2, forward secrecy depends on the OS policy and the server preferring ECDHE or DHE suites. TLS use, certificate validation and server TLS settings are operator-controlled, and the server does not force TLS: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#connection-and-resource-settings . SCRAM authentication is not a key-agreement protocol. This is not a guarantee for every deployment.","crypto_password_storage_status":"N/A","crypto_password_storage_justification":"The passing criterion explicitly excludes outbound authentication credentials. This stdio MCP server does not authenticate external MCP users or store their password verifiers; configured PostgreSQL credentials authenticate outbound database connections. Public trust-boundary and credential documentation: https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/SECURITY.md#trust-boundary and https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/src/PostgreSqlMcp.Core/ServerOptions.cs . This exemption does not waive protecting outbound secrets or database TLS.","crypto_random_status":"Met","crypto_random_justification":"Public-source evidence: the application generates no cryptographic keys or nonces itself and contains no cryptographic or random-number APIs: https://github.com/codegiveness/postgresql-sharp-mcp/tree/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/src . Npgsql 10.0.3 generates the SCRAM client nonce with System.Security.Cryptography.RandomNumberGenerator, a cryptographically secure generator: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.Auth.cs#L194-L201 . TLS session keys and nonces are generated by the operating system's TLS provider used by .NET SslStream: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.cs#L1229-L1239 . Neither the application nor Npgsql uses System.Random for these values.","delivery_mitm_status":"Met","delivery_mitm_justification":"Distribution channels use HTTPS exclusively. [osps_br_03_02]","delivery_unsigned_status":"Met","delivery_unsigned_justification":"Public-source evidence: the project never retrieves a cryptographic hash over HTTP. CI, build and release tooling download third-party binaries only over HTTPS and compare them with SHA-256 or SHA-512 digests committed in the repository: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/.github/workflows/secrets.yml#L23-L35 and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/.github/workflows/release.yml#L193-L202 and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/tools/PostgreSqlMcp.Fuzz/FuzzCampaign.cs#L8-L9 and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/tools/PostgreSqlMcp.Build/Program.cs#L16-L17 . Outside bundled third-party license texts, no http:// URL appears in the repository at this revision. Release SHA256SUMS manifests are delivered with the assets over HTTPS from GitHub Releases and covered by GitHub build attestations: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/docs/security-posture.md#supply-chain-evidence . npm and NuGet also deliver packages over HTTPS.","vulnerabilities_fixed_60_days_status":"Met","vulnerabilities_fixed_60_days_justification":"API-verified evidence (checked 2026-10-10 12:53 UTC): no vulnerability in the project's results is publicly known, so none is unpatched: 0 repository security advisories, and 0 GitHub Advisory Database and 0 OSV entries for the published npm and NuGet packages. Dependency monitoring reports 0 Dependabot alerts in any state and 0 open CodeQL alerts; the dependency-audit and container HIGH/CRITICAL gates passed on main revision fbbe5aa0c2abea5d48d58fa282d84204921c8e19: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38052409352 and https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38052409308 . Releases bundle the .NET runtime from pinned SDK 10.0.401, which matched Microsoft's latest .NET 10 servicing release (runtime 10.0.12) when checked: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/global.json . These are point-in-time results, not a vulnerability-free guarantee.","vulnerabilities_critical_fixed_status":"Met","vulnerabilities_critical_fixed_justification":"API-verified evidence (checked 2026-10-10 12:53 UTC): no critical vulnerability has been reported or detected: 0 repository security advisories (including private reports), 0 issues, 0 Dependabot alerts in any state and 0 open CodeQL alerts. Private reporting is enabled: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#reporting-a-vulnerability . SECURITY guarantees no response time, so this records the absence of critical reports rather than a demonstrated fix time; re-evaluate when one is reported.","static_analysis_status":"Met","static_analysis_justification":"Public-source evidence: GitHub CodeQL (CLI bundle 2.27.1) runs the security-extended query suite over a real Release build of the C# solution and over the GitHub Actions workflows on every main push, on every pull request to main (base and candidate scans with a trusted-base severity gate) and weekly: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/.github/workflows/codeql.yml . Releases are dispatched only from main for tags reachable from main, and main branch protection requires the pull-request-analysis check, enforced for administrators (repository API verified 2026-10-10). Release v0.4.0 commit 51f1514393abbc374160ef33f8ad0b06453a8351 passed CodeQL before publication, and every release commit since v0.2.0 has a successful push CodeQL run; v0.1.0 predates the workflow: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38030109803 . Current main fbbe5aa0c2abea5d48d58fa282d84204921c8e19 passed https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38052409383","static_analysis_common_vulnerabilities_status":"Met","static_analysis_common_vulnerabilities_justification":"CodeQL runs security-extended queries for C# and GitHub Actions; run 36975816274 succeeded on revision bde167e95e0fb3ff74b895db55c87f4b04d69b0c: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/36975816274","static_analysis_fixed_status":"Met","static_analysis_fixed_justification":"API-verified evidence (GitHub code-scanning API, checked 2026-10-10 12:53 UTC): CodeQL has raised one default-branch alert, #7 actions/untrusted-checkout/medium in the release workflow, dismissed on 2026-10-02 as a false positive with a recorded rationale (manual main-only preflight validates tag ancestry, packaging is read-only and publishers are checkout-free): https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/docs/security-posture.md#release-execution-boundary . No CodeQL alert is open and no medium or higher vulnerability found by static analysis has been confirmed. The 4 open code-scanning alerts are OpenSSF Scorecard repository-practice findings, not source vulnerabilities.","static_analysis_often_status":"Met","static_analysis_often_justification":"CodeQL is configured on main pushes and pull requests, with a weekly schedule: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/.github/workflows/codeql.yml","dynamic_analysis_status":"Met","dynamic_analysis_justification":"Public-source evidence: a SharpFuzz/libFuzzer coverage-guided campaign instruments the production SQL guard, replays checked-in regression seeds and mutates UTF-8/UTF-16 inputs for 60 seconds on every main push and pull request and 300 seconds daily, failing on crashes and replay errors: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/.github/workflows/fuzzing.yml and https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/tools/PostgreSqlMcp.Fuzz/Program.cs . It has run for every release commit since v0.3.1; release v0.4.0 commit 51f1514393abbc374160ef33f8ad0b06453a8351 passed it before publication, and current main passed 453,020 runs in 61 seconds: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38030109759 and https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38052409305 . Deterministic FsCheck properties also vary SQL literals against real PostgreSQL in the integration suite: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/tools/PostgreSqlMcp.Verify/FuzzChecks.cs . This is neither exhaustive fuzzing nor OSS-Fuzz enrollment.","dynamic_analysis_unsafe_status":"N/A","dynamic_analysis_unsafe_justification":"The passing criterion explicitly permits N/A when the project does not produce software written in a memory-unsafe language. Maintained first-party application and tooling sources are C# without unsafe blocks or AllowUnsafeBlocks; the public source tree contains no first-party C/C++ implementation: https://github.com/codegiveness/postgresql-sharp-mcp/tree/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/src and https://github.com/codegiveness/postgresql-sharp-mcp/tree/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/tools . Native runtime/dependency code is not a claim of memory-safety certification.","dynamic_analysis_enable_assertions_status":"Met","dynamic_analysis_enable_assertions_justification":"Public-source evidence: the verification configuration runs deterministic varied-input SQL checks with always-enabled Check.Equal/Check.That and expected-error assertions, including exact PostgreSQL literal round trips, no unexpected truncation and second-statement/control-statement rejection: https://github.com/codegiveness/postgresql-sharp-mcp/blob/bde167e95e0fb3ff74b895db55c87f4b04d69b0c/tools/PostgreSqlMcp.Verify/FuzzChecks.cs . These assertions belong to the test verifier, not the production server, and integration succeeded in https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/36975816424 . This does not establish release-specific pre-release analysis or any branch-coverage percentage.","dynamic_analysis_fixed_status":"Met","dynamic_analysis_fixed_justification":"API-verified evidence (checked 2026-10-10 12:53 UTC): dynamic analysis runs as described under dynamic_analysis, and no medium or higher vulnerability discovered by it has been confirmed. Of 66 recorded fuzzing workflow runs, 65 succeeded, 1 was cancelled and none failed, and there are 0 repository security advisories: https://github.com/codegiveness/postgresql-sharp-mcp/actions/workflows/fuzzing.yml . A future confirmed finding must be fixed under this criterion.","general_comments":"","created_at":"2026-10-02T07:08:01.122Z","updated_at":"2026-10-11T15:33:42.469Z","crypto_weaknesses_status":"Met","crypto_weaknesses_justification":"Public-source evidence: the delegated default mechanisms do not depend on SHA-1 or on CBC modes chosen by this project. SCRAM-SHA-256 uses only SHA-256-family primitives, and SCRAM channel binding hashes SHA-1- or MD5-signed server certificates with SHA-256: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.Auth.cs#L150-L284 . TLS algorithms come from the operating system's default policy through SslStream rather than an application default: https://github.com/npgsql/npgsql/blob/d3768398c17877b3a916c3c4d87e8e11698991fc/src/Npgsql/Internal/NpgsqlConnector.cs#L1229-L1239 and https://learn.microsoft.com/dotnet/core/extensions/sslstream-best-practices . TLS 1.3, negotiated when the OS and the operator's PostgreSQL server support it, offers only AEAD cipher suites. Whether a legacy TLS 1.2 CBC or SHA-1 suite could be negotiated depends on that OS policy and the operator's server configuration: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/SECURITY.md#connection-and-resource-settings . Legacy MD5 authentication is covered under crypto_working.","test_continuous_integration_status":"Met","test_continuous_integration_justification":"CI runs integration and native package installation on pushes and pull requests; run 36975816424 succeeded on revision bde167e95e0fb3ff74b895db55c87f4b04d69b0c: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/36975816424","cpe":"","discussion_status":"Met","discussion_justification":"GitHub supports discussions on issues and pull requests.","no_leaked_credentials_status":"Met","no_leaked_credentials_justification":"Scanner evidence: GitHub secret scanning with push protection is enabled and reports 0 alerts (repository API checked 2026-10-10 12:53 UTC). Checksum-verified Gitleaks 8.30.1 scans every branch, tag and pull-request commit with default rules plus PostgreSQL URI, Npgsql and SQL Server password rules, ignoring inline allow comments and repository ignore files: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/.github/workflows/secrets.yml . Its exceptions are limited to exact synthetic placeholder and disposable-fixture values tied to paths, and historical ones also to exact commits: https://github.com/codegiveness/postgresql-sharp-mcp/blob/fbbe5aa0c2abea5d48d58fa282d84204921c8e19/.gitleaks.toml . The full-history scan passed on main in https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38052409410 , and a local run of the same configuration on 2026-10-10 scanned 62 commits with no leaks. Scanners can miss credential formats; this is evidence, not proof of absence.","english_status":"Met","english_justification":"README and contribution/reporting instructions are in English: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md","hardening_status":"Met","hardening_justification":"The software is managed, memory-safe C# with no unsafe code or native interop in src; nullable reference types and warnings-as-errors remove classes of undefined behavior (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Directory.Build.props ); the server bounds results, statements, concurrency and pools and forces safe Npgsql settings so defects are less likely to become vulnerabilities (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/assurance-case.md#4-argument-that-the-requirements-are-met ). The project has no HTTP interface, so CSP and similar headers do not apply. Least privilege (non-root container, narrow tokens) is counted separately and not claimed as hardening. This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","crypto_used_network_status":"Met","crypto_used_network_justification":"Met. The server's only network protocol is the PostgreSQL connection, and by default it is encrypted: a profile without SSL Mode uses VerifyFull for every non-loopback host, so a remote server that offers no TLS is refused with tls_unavailable instead of falling back to plaintext. Unencrypted connections happen only to loopback/Unix-socket hosts or when the operator explicitly sets SSL Mode=Disable/Allow/Prefer, which is warned about on stderr for remote hosts: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#connection-and-resource-settings . These files are changed by the pull request that proposes these answers; the URLs show the described state once that change is merged to main.","crypto_tls12_status":"Met","crypto_tls12_justification":"TLS is performed by Npgsql through .NET SslStream; the server does not restrict protocol versions and leaves negotiation to the operating system, which on supported platforms offers TLS 1.2 and later: https://learn.microsoft.com/dotnet/core/extensions/sslstream-best-practices and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#connection-and-resource-settings . Whether TLS is used at all is the operator's SSL Mode choice (see crypto_used_network).","crypto_certificate_verification_status":"Met","crypto_certificate_verification_justification":"Met. A connection profile that omits SSL Mode gets SSL Mode=VerifyFull for any non-loopback host (certificate chain and host name verified, no plaintext or unverified fallback) and Disable only for loopback and Unix sockets; this is applied to every profile at startup. An explicit unverified mode is the operator's documented opt-out and is warned about on stderr for remote hosts. The verifier's TLS scenarios against a disposable throwaway-CA PostgreSQL show that an untrusted certificate is refused with tls_verification_failed, a configured Root Certificate connects, and a trusted chain with a host-name mismatch is rejected: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#connection-and-resource-settings and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#connection-string-quoting-and-tls . These files are changed by the pull request that proposes these answers; the URLs show the described state once that change is merged to main.","crypto_verification_private_status":"Met","crypto_verification_private_justification":"Met. Under the default (VerifyFull for non-loopback hosts) Npgsql verifies the server certificate during the TLS handshake, before the startup packet (user name) or any password is sent. The verifier's TLS scenario asserts that after a failed verification the PostgreSQL server log contains no login attempt for the configured role. Operators who explicitly set Prefer, Allow, Require or Disable opt out; that opt-out is documented and warned about for remote hosts: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#connection-and-resource-settings . These files are changed by the pull request that proposes these answers; the URLs show the described state once that change is merged to main.","hardened_site_status":"Met","hardened_site_justification":"The repository, issue tracker and release downloads are served by github.com, which sent Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options: nosniff and X-Frame-Options: deny in responses to curl -I on 2026-10-11 for https://github.com/codegiveness/postgresql-sharp-mcp and the v0.5.0 release asset URL (the asset itself is then served from a GitHub-controlled redirect target that was not separately checked). The package registries are third-party sites: npmjs.com returned HSTS, a CSP, nosniff and X-Frame-Options; the nuget.org package page returned HSTS, nosniff and X-Frame-Options but its CSP was report-only.","installation_common_status":"Met","installation_common_justification":"Installation and uninstallation use commonly used package managers: npm (npx, npm install -g/uninstall) and the .NET tool (dotnet tool install/uninstall), plus verified archives and a Dockerfile: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#1-install-or-run and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#other-installation-methods","build_reproducible_status":"Unmet","build_reproducible_justification":"Not yet shown for every release output. On 2026-10-11 an independent local rebuild of the v0.5.0 source produced a linux-x64 npm tarball with the same SHA-256 as the asset built by the release workflow, and the archives and npm tarballs are documented as reproducible. The .nupkg and SBOM became deterministic only after v0.5.0 (see build_repeatable), so no published release yet shows them reproduced independently. Rebuilding the next release locally and matching every SHA256SUMS entry except the per-run provenance bundle would change this.","badge_percentage_0":100,"achieved_passing_at":"2026-10-10T13:37:58.285Z","lost_passing_at":null,"implementation_languages":"C#, Dockerfile","badge_percentage_1":98,"dco_status":"Unmet","dco_justification":"This SHOULD criterion is not adopted. Contributions are accepted under the project's MIT license, stated in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#issues-pull-requests-and-reviews , but no Developer Certificate of Origin sign-off or contributor license agreement is required or enforced. A documented DCO policy with sign-off enforcement would change this.","governance_status":"Met","governance_justification":"GOVERNANCE.md documents the single-maintainer governance model, how proposals are made, decided and recorded, and how disputes are handled: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/GOVERNANCE.md#governance-model and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/GOVERNANCE.md#how-decisions-are-made . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","code_of_conduct_status":"Met","code_of_conduct_justification":"The repository adopts the Contributor Covenant 2.1 in the standard location, with an enforcement contact and enforcement guidelines: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CODE_OF_CONDUCT.md . CONTRIBUTING links it: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#issues-pull-requests-and-reviews","roles_responsibilities_status":"Met","roles_responsibilities_justification":"GOVERNANCE.md defines the Maintainer, Contributor, Reviewer, Security reporter, Automation and AI-agent roles with their responsibilities and says who holds each (the maintainer role is held by the GitHub user codegiveness): https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/GOVERNANCE.md#roles-and-responsibilities . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","access_continuity_status":"Unmet","access_continuity_justification":"Not met on 2026-10-11. Nobody but the maintainer can currently merge, release or publish: GitHub admin, npm package maintainer and NuGet package ownership rest with one account, and no lockbox arrangement is recorded. What exists (public MIT source, written release procedure, no stored credentials, verifiable artifacts) and the two routes that would change the answer (a second maintainer, or the criterion's lockbox-and-will route for an individual maintainer) are recorded in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/GOVERNANCE.md#continuity-if-the-maintainer-is-unavailable . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","bus_factor_status":"Unmet","bus_factor_justification":"The bus factor is 1: the GitHub contributors API reported one human contributor (58 commits) and Dependabot (3) on 2026-10-11. See https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/GOVERNANCE.md#continuity-if-the-maintainer-is-unavailable for the steps that would raise it. This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","documentation_roadmap_status":"Met","documentation_roadmap_justification":"docs/roadmap.md describes what the project intends to do and not do for the twelve months from 2026-10-11 and says it is direction, not a promise: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/roadmap.md . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","documentation_architecture_status":"Met","documentation_architecture_justification":"docs/architecture.md describes the components, dependency direction, request flow, configuration model and verification structure: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/architecture.md . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","documentation_security_status":"Met","documentation_security_justification":"SECURITY.md states the trust boundary, what PostgreSQL permissions must enforce, credential and diagnostic handling, TLS responsibility and limits: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#trust-boundary . docs/assurance-case.md lists the security requirements and the expectations the software deliberately does not meet: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/assurance-case.md#1-security-requirements . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","documentation_quick_start_status":"Met","documentation_quick_start_justification":"README has a three-step quick start (install or run, prepare the connection environment, validate and start): https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#quick-start","documentation_current_status":"Met","documentation_current_justification":"Documentation is updated with the change that alters it. This is required by AGENTS.md and the pull-request checklist (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/AGENTS.md , https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/.github/pull_request_template.md ), a documentation-versus-help mismatch was tracked as issue 41 and fixed in 0.5.0 (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CHANGELOG.md ), and documents that carry release-specific claims state the version and date they were checked against. This is an effort, not a guarantee of perfection.","documentation_achievements_status":"Met","documentation_achievements_justification":"The README front page hyperlinks the Best Practices entry and Scorecard and explains what they do and do not certify: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#development-and-licensing . The Project badges table shows the badges: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#project-badges","accessibility_best_practices_status":"Met","accessibility_best_practices_justification":"The software has no graphical interface; the project documents its command-line, MCP-client and documentation accessibility, known limitations and a barrier-reporting route: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/ACCESSIBILITY.md . CLI output is plain text without colors or control codes.","internationalization_status":"Unmet","internationalization_justification":"The software produces English-only text (--help, startup warnings, tool summaries and error messages) with no resource files or localization mechanism. Tool results are structured JSON with SQLSTATE codes, and parsing and sorting use invariant or ordinal rules, but the user-facing strings are not externalized for translation. SHOULD criterion; not planned in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/roadmap.md .","sites_password_security_status":"N/A","sites_password_security_justification":"The project sites are GitHub, npmjs.com and nuget.org. The project operates no site that stores passwords of external users; the criterion notes that use of GitHub meets it.","maintenance_or_update_status":"Met","maintenance_or_update_justification":"The project is 0.x and ships fixes as new releases from main; older releases are not patched, so an upgrade path is provided and documented: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#upgrading-an-existing-installation , upgrade notes in the https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CHANGELOG.md entries where behavior changes (for example the breaking database-lock note in 0.4.0 and the upgrade notes in 0.5.0), and the upgrade boundary in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/security-posture.md#runtime-boundaries . https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#how-reports-are-handled states that affected users upgrade. SECURITY.md is changed by the pull request that proposes these answers; its new section's URL resolves once that change is merged to main.","vulnerability_report_credit_status":"N/A","vulnerability_report_credit_justification":"No vulnerability reports have been resolved in the last 12 months: the GitHub API showed 0 repository security advisories and 0 Dependabot alerts on 2026-10-11. The credit practice (advisory and CHANGELOG credit unless anonymity is requested) is documented in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#how-reports-are-handled . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","vulnerability_response_process_status":"Met","vulnerability_response_process_justification":"SECURITY.md documents the response process: private receipt, triage, fix with regression coverage, release, advisory and credit: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#how-reports-are-handled . It guarantees no response time, which is stated. This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","coding_standards_status":"Met","coding_standards_justification":"CONTRIBUTING identifies Microsoft's C# coding conventions and the .NET naming guidelines as the style guides, requires contributions to comply and lists repository-specific rules and the exception policy: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#coding-standards . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","coding_standards_enforced_status":"Met","coding_standards_enforced_justification":"The repository's .editorconfig defines C# style rules (unused usings, using placement, file-scoped namespaces, accessibility modifiers, PascalCase naming, I-prefixed interfaces) and the CI verify job runs dotnet format style --verify-no-changes --severity warn, which fails on any violation; the compiler also treats all warnings, including obsolete API use, as errors: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/.editorconfig , https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/.github/workflows/ci.yml , https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Directory.Build.props . Brace and line-layout conventions are deliberately not prescribed (documented in CONTRIBUTING); no style exceptions exist. The step and files are added by the pull request that proposes these answers.","build_standard_variables_status":"N/A","build_standard_variables_justification":"The project does not build native binaries with a C or C++ compiler or linker. It is managed C# built by the .NET SDK and MSBuild, so CC, CFLAGS, CXXFLAGS and LDFLAGS do not apply.","build_preserve_debug_status":"Unmet","build_preserve_debug_justification":"SHOULD criterion. Source builds with dotnet build keep the SDK's debug-information defaults and the project sets no override (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Directory.Build.props ). The release packaging tool, however, forces DebugType=None and DebugSymbols=false for the shipped archives and packages and rejects archives containing .pdb files (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/tools/PostgreSqlMcp.Build/Program.cs ), so debug information cannot be requested for release artifacts.","build_non_recursive_status":"Met","build_non_recursive_justification":"The build is an MSBuild solution whose projects declare explicit ProjectReference dependencies (Core \u003c- Tools \u003c- App); no recursive make or per-directory build scripts exist: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/postgresql-sharp-mcp.slnx and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#build-from-source","build_repeatable_status":"Met","build_repeatable_justification":"Met. Rebuilding the same source produces byte-identical release outputs: the five archives, the six npm tarballs, the .nupkg (NuGet's DeterministicTimestamp fixes every entry time at 1980-01-01) and the CycloneDX SBOM (serial number derived from the content, timestamp from the release commit time), and therefore SHA256SUMS. On 2026-10-11 two clean rebuilds under different time zones gave identical hashes for all of them. The offline release-regressions verifier (repeated dotnet pack of a probe project and SBOM normalization) and the packages verifier (fixed .nupkg entry times) enforce this; the only per-run asset is the signed provenance attestation bundle: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#automation-and-releases . These files are changed by the pull request that proposes these answers; the URLs show the described state once that change is merged to main.","installation_standard_variables_status":"N/A","installation_standard_variables_justification":"The project ships no DESTDIR-style installer. Installation locations are controlled by the standard conventions of the package managers used (npm prefix, dotnet tool --tool-path) or by where the user extracts an archive.","installation_development_quick_status":"Met","installation_development_quick_justification":"CONTRIBUTING gives the clone, restore, build and run commands for developers and the single command that builds and runs the full verifier against a disposable PostgreSQL fixture (Docker required): https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#build-from-source and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#verify-behavior","external_dependencies_status":"Met","external_dependencies_justification":"Dependencies are listed in machine-readable form: central NuGet versions in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Directory.Packages.props , committed lock files per project and runtime identifier (for example https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/src/PostgreSqlMcp.Core/packages.lock.json ), and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/npm/package.json for the npm packages.","dependency_monitoring_status":"Met","dependency_monitoring_justification":"Dependabot tracks NuGet, GitHub Actions, Docker and .NET SDK updates weekly (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/.github/dependabot.yml ); Dependabot alerts and security updates are enabled (0 open alerts on 2026-10-11); the Dependency audit workflow runs NuGet audit over direct and transitive packages on pushes, pull requests and weekly (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/.github/workflows/security.yml , success: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38102103499 ); Trivy scans the built container's OS and application packages (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/.github/workflows/container-security.yml ).","updateable_reused_components_status":"Met","updateable_reused_components_justification":"Reused components are NuGet packages with central version management, locked restore and Dependabot updates, so a vulnerable component is identified and updated in one place: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Directory.Packages.props . The container's base images are pinned by digest and tracked by Dependabot (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Dockerfile ). Bundled licenses and versions are listed in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/THIRD-PARTY-NOTICES.md","interfaces_current_status":"Met","interfaces_current_justification":"TreatWarningsAsErrors makes use of an obsolete or deprecated .NET API a build failure (compiler warning CS0618), and the project targets the current .NET 10 SDK pinned in global.json: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/Directory.Build.props and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/global.json","automated_integration_testing_status":"Met","automated_integration_testing_justification":"The CI workflow runs the real PostgreSQL integration suite and package installation checks on every push to main and every pull request and reports success or failure per job: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/.github/workflows/ci.yml . Example: https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/38102103515 succeeded on 2026-10-11.","regression_tests_added50_status":"Met","regression_tests_added50_justification":"Checked with git history on 2026-10-11: 9 of the 11 fix: commits on main (all since the repository was created on 2026-10-02) changed the automated test scenarios, either the C# verifier in tools/PostgreSqlMcp.Verify (pull requests 11, 25, 45, 46, 49, 51 and 60) or the earlier smoke script it replaced (two earlier fixes). The other two changed release workflows, release tooling and documentation only. The contribution policy requires regression coverage for fixes: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#verify-behavior . The window is nine days, so this is a small sample and changed scenarios are not individually proven to be regression tests for each bug.","test_statement_coverage80_status":"Met","test_statement_coverage80_justification":"Met. The verifier's coverage command runs the integration scenarios against a disposable PostgreSQL with the FLOSS coverlet console tool instrumenting the three shipped assemblies, writes a Cobertura report and fails below 80% total line (statement) coverage; the CI verify job runs it and uploads the report as the coverage artifact. The first measurement on 2026-10-11 was 89.41% lines (1073/1200), 84.84% branches and 98.38% methods; only compiler-generated [GeneratedRegex] code is excluded: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#measure-test-coverage . These files are changed by the pull request that proposes these answers; the URLs show the described state once that change is merged to main.","test_policy_mandated_status":"Met","test_policy_mandated_justification":"CONTRIBUTING and AGENTS.md require consumer-visible automated coverage for major new functionality and for plausible consumer-visible regressions, extending the maintained verifier: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#verify-behavior and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/AGENTS.md#implementation-and-evidence","implement_secure_design_status":"Met","implement_secure_design_justification":"docs/assurance-case.md applies each Saltzer and Schroeder principle, plus allowlist input validation and limited attack surface, to the design with code and test evidence: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/assurance-case.md#5-secure-design-principles . It records the exceptions (default unrestricted access mode and unverified default TLS). This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","input_validation_status":"Met","input_validation_justification":"Tool arguments, options and configuration are validated against allowlists, ranges and length limits and rejected otherwise; values reach PostgreSQL only as bound parameters or fixed SQL: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/assurance-case.md#4-argument-that-the-requirements-are-met (R6). The SQL guard is additionally fuzzed (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/tools/PostgreSqlMcp.Fuzz/Program.cs ) and covered by FsCheck properties (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/tools/PostgreSqlMcp.Verify/FuzzChecks.cs ). This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","crypto_algorithm_agility_status":"Met","crypto_algorithm_agility_justification":"The project implements no cryptography; algorithm and protocol selection is delegated to Npgsql, .NET and the operating system's TLS and to the PostgreSQL server (SCRAM-SHA-256, other methods, TLS versions and cipher suites), so operators can switch algorithms through server, OS or connection-string settings without code changes: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/assurance-case.md#3-trust-boundaries and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#connection-and-resource-settings","crypto_credential_agility_status":"Met","crypto_credential_agility_justification":"Credentials are never hard-coded: they come from the environment, an owner-protected targets file or CLI options, separate from other configuration, and can be replaced by restarting the server without recompiling: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/README.md#2-prepare-the-connection-environment and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/SECURITY.md#credentials-and-diagnostics","signed_releases_status":"Met","signed_releases_justification":"Releases from v0.2.0 carry GitHub build attestations (Sigstore keyless signatures bound to the release.yml workflow identity and the exact source commit) for every archive, package, the SBOM and SHA256SUMS; since v0.5.0 the signed bundle is also published as the provenance.sigstore.json release asset (gh release view v0.5.0 listed it on 2026-10-11), and on 2026-10-11 the existing bundles of v0.3.1, v0.3.2, v0.3.3 and v0.4.0 were attached the same way after each verified with gh attestation verify against every asset of its release. No long-lived private signing key exists on the distribution sites. The documented verification process, which checks repository, signer workflow and subject digest with gh attestation verify, is in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/security-posture.md#supply-chain-evidence (the release verification commands near the end of that section). v0.1.0 predates attestations.","version_tags_signed_status":"Unmet","version_tags_signed_justification":"Release tags are annotated but not cryptographically signed: GitHub's tag API reported verified=false (reason unsigned) for v0.1.0, v0.2.0, v0.3.1, v0.3.2, v0.4.0 and v0.5.0 on 2026-10-11, and v0.3.3 is a lightweight tag. Signed tags (git tag -s with a signing key registered on GitHub) would change this.","badge_percentage_2":61,"contributors_unassociated_status":"Unmet","contributors_unassociated_justification":"The project has one human contributor; no second unassociated significant contributor exists (GitHub contributors API, 2026-10-11).","copyright_per_file_status":"Met","copyright_per_file_justification":"Every tracked .cs source file begins with SPDX-FileCopyrightText: 2026 codegiveness, matching the LICENSE copyright holder; CONTRIBUTING requires the header for new files: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#coding-standards . Added to all 39 .cs files by the pull request that proposes these answers.","license_per_file_status":"Met","license_per_file_justification":"Every tracked .cs source file begins with SPDX-License-Identifier: MIT (for example https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/src/PostgreSqlMcp.Core/SqlGuard.cs ); the license text is https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/LICENSE . Added to all 39 .cs files by the pull request that proposes these answers. Non-source data files such as fuzz corpus seeds are not annotated, because changing their bytes would change the corpus.","small_tasks_status":"Unmet","small_tasks_justification":"The good first issue and help wanted labels exist and CONTRIBUTING explains them (https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#small-tasks-for-new-contributors ), but on 2026-10-11 the repository had no open issues at all (0 open, 133 closed), so none carries either label. Labeling real small tasks when they arise would change this.","require_2FA_status":"Met","require_2FA_justification":"GitHub requires 2FA as of March 2023. [osps_ac_01_01]","secure_2FA_status":"?","code_review_standards_status":"Met","code_review_standards_justification":"CONTRIBUTING documents how review is conducted, what must be checked and what makes a change acceptable: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#code-review-standards , with the self-review procedure in https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/git-workflow.md#6-review . This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","two_person_review_status":"Unmet","two_person_review_justification":"Every human change is authored by the sole maintainer, and GitHub does not let an author approve their own pull request; the main ruleset requires zero approvals. Scorecard reported 0 of 27 approved changesets on 2026-10-11. A different person must review at least half of proposed modifications to change this.","test_statement_coverage90_status":"Unmet","test_statement_coverage90_justification":"Not met: total statement coverage measured on 2026-10-11 was 89.41%, below 90%. The least-covered file is src/PostgreSqlMcp/Program.cs (the --help, --version and invalid --log-level paths); a scenario for those paths would change this. See test_statement_coverage80 and https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#measure-test-coverage .","test_branch_coverage80_status":"Met","test_branch_coverage80_justification":"Met. Total branch coverage of the shipped assemblies under the integration scenarios was 84.84% (907/1069) on 2026-10-11, measured with the FLOSS coverlet console tool by the verifier's coverage command, which CI runs on every pull request (its gate is on line coverage; branch coverage is reported alongside): https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/CONTRIBUTING.md#measure-test-coverage . These files are changed by the pull request that proposes these answers; the URLs show the described state once that change is merged to main.","security_review_status":"?","assurance_case_status":"Met","assurance_case_justification":"docs/assurance-case.md contains the threat model, the trust boundaries, an argument that secure design principles were applied, an argument that common weaknesses are countered, and the residual risks and gaps: https://github.com/codegiveness/postgresql-sharp-mcp/blob/main/docs/assurance-case.md . It is a self-assessment drafted by an AI agent for the maintainer and says so; its review record shows the maintainer's review as pending until the maintainer records it. This file is added by the pull request that proposes these answers; its URL resolves once that change is merged to main.","achieve_passing_status":"Met","achieve_silver_status":"Unmet","tiered_percentage":198,"repo_url_updated_at":null,"achieved_silver_at":null,"lost_silver_at":null,"achieved_gold_at":null,"lost_gold_at":null,"first_achieved_passing_at":"2026-10-10T13:37:58.285Z","first_achieved_silver_at":null,"first_achieved_gold_at":null,"maintained_status":"Met","maintained_justification":"Public-source evidence: the non-archived repository has substantive recent maintenance, including runtime-resource/security verification fixes in e0572221bb3f3a6c4a8bce2791435f558fbf20db and real-build/secret/container security gates in bde167e95e0fb3ff74b895db55c87f4b04d69b0c, with successful integration CI: https://github.com/codegiveness/postgresql-sharp-mcp/commit/e0572221bb3f3a6c4a8bce2791435f558fbf20db and https://github.com/codegiveness/postgresql-sharp-mcp/actions/runs/36975816424 . These demonstrate meaningful maintenance, not a measured report-response history.","OSPS-AC-01.01_status":"?","OSPS-AC-02.01_status":"?","OSPS-AC-03.01_status":"?","OSPS-AC-03.02_status":"?","OSPS-BR-01.01_status":"?","OSPS-BR-01.02_status":0,"OSPS-BR-01.02_justification":null,"OSPS-BR-03.01_status":"?","OSPS-BR-03.02_status":"?","OSPS-BR-07.01_status":"?","OSPS-DO-01.01_status":"?","OSPS-DO-02.01_status":"?","OSPS-GV-02.01_status":"?","OSPS-GV-03.01_status":"?","OSPS-LE-02.01_status":"?","OSPS-LE-02.02_status":"?","OSPS-LE-03.01_status":"?","OSPS-LE-03.02_status":"?","OSPS-QA-01.01_status":"?","OSPS-QA-01.02_status":"?","OSPS-QA-02.01_status":"?","OSPS-QA-04.01_status":"?","OSPS-QA-05.01_status":"?","OSPS-QA-05.02_status":"?","OSPS-VM-02.01_status":"?","OSPS-AC-04.01_status":"?","OSPS-BR-02.01_status":"?","OSPS-BR-04.01_status":"?","OSPS-BR-05.01_status":"?","OSPS-BR-06.01_status":"?","OSPS-DO-06.01_status":"?","OSPS-GV-01.01_status":"?","OSPS-GV-01.02_status":"?","OSPS-GV-03.02_status":"?","OSPS-LE-01.01_status":"?","OSPS-QA-03.01_status":"?","OSPS-QA-06.01_status":"?","OSPS-SA-01.01_status":"?","OSPS-SA-02.01_status":"?","OSPS-SA-03.01_status":"?","OSPS-VM-01.01_status":"?","OSPS-VM-03.01_status":"?","OSPS-VM-04.01_status":"?","OSPS-AC-04.02_status":"?","OSPS-BR-02.02_status":"?","OSPS-BR-07.02_status":"?","OSPS-DO-03.01_status":"?","OSPS-DO-03.02_status":"?","OSPS-DO-04.01_status":"?","OSPS-DO-05.01_status":"?","OSPS-GV-04.01_status":"?","OSPS-QA-02.02_status":"?","OSPS-QA-04.02_status":"?","OSPS-QA-06.02_status":"?","OSPS-QA-06.03_status":"?","OSPS-QA-07.01_status":"?","OSPS-SA-03.02_status":"?","OSPS-VM-04.02_status":"?","OSPS-VM-05.01_status":"?","OSPS-VM-05.02_status":"?","OSPS-VM-05.03_status":"?","OSPS-VM-06.01_status":"?","OSPS-VM-06.02_status":"?","badge_percentage_baseline_1":0,"badge_percentage_baseline_2":0,"badge_percentage_baseline_3":0,"achieved_baseline_1_at":null,"achieved_baseline_2_at":null,"achieved_baseline_3_at":null,"lost_baseline_1_at":null,"lost_baseline_2_at":null,"lost_baseline_3_at":null,"first_achieved_baseline_1_at":null,"first_achieved_baseline_2_at":null,"first_achieved_baseline_3_at":null,"baseline_tiered_percentage":0,"entry_locale":"en","OSPS-BR-01.03_status":"?","OSPS-DO-07.01_status":"?","OSPS-BR-01.04_status":"?","badge_level":"passing","additional_rights":[],"project_entry_attribution":"Please credit AG and the CII Best Practices badge contributors.","project_entry_license":"CC-BY-3.0+"}