Changelog
For all changes, see the commit log on GitHub. DevDb uses descriptive commit messages, so the commit log is the full changelog.
4.0.0
Added
- Cloudflare D1 (local), free: DevDb finds
d1_databasesinwrangler.json/wrangler.jsonc/wrangler.tomland opens the local SQLite file of each binding (.wrangler/state, or--persist-tofrompackage.jsonscripts). See Cloudflare D1. - Cloudflare D1 (remote), Pro: connect with account ID, database ID and API token over the Cloudflare REST API.
- Turso / libSQL, Pro: detected from
TURSO_DATABASE_URLin.envor adrizzle.configwithdialect: 'turso', or added as a remote connection. See Turso / libSQL. - Pro: DynamoDB (AWS profiles incl. SSO, access keys, DynamoDB Local and LocalStack). Zero-config detection from
docker-compose.ymland.env. Query/Scan filters, edits and deletes by full key, PartiQL for MCP (read-only by default). See DynamoDB. - Zero-config detection from
DATABASE_URL(and similar variables), Prisma, Drizzle, docker-compose services, and Laravel SQL Server/Redis/MongoDB. Detected Redis and ClickHouse show as locked Pro rows without a license. See Zero-Config Detection.
Fixed
- SQLite works when the native driver cannot load (the universal Open VSX package on macOS, Windows or ARM, or Linux with glibc older than 2.29). DevDb then uses a WebAssembly SQLite; WAL-mode databases open read-only in that mode. Also, DevDb no longer fails to start when another window uses the MCP port. See Troubleshooting.
Changed
- New DevDb 4 launch notice (once, 4.x only; Pro users get a toast) and a refreshed DevWorkspace Pro showcase with the app's real UI mocks (once per showcase version, DDEV workspaces only). Both follow the VS Code theme and use a strict CSP.
3.2.0
Added
- Pro datastores: Redis / Valkey (namespaces, command console), ClickHouse (http/https), DuckDB (database files and Parquet/CSV/TSV/JSON/NDJSON, read-only by default), Neon (
.envdetection, verified TLS), and pgvector similarity search with OpenAI-compatible and Ollama embedding endpoints. Devdb.mcp.allowWritessetting: MCP queries are read-only unless you enable it. Each write asks for confirmation.- Per-platform VSIX packages include the correct DuckDB native binding. CI checks each VSIX.
Fixed
- Edit, delete, and set-null work on DuckDB, Redis, and ClickHouse.
- Column filters work again on MySQL, SQLite and MSSQL
varchar(n),char(n), enum and date columns. - Redis/Valkey and ClickHouse connections save, test and connect from the remote-connection dialog. Direct Postgres works on any port.
- Redis fails fast with the real error on a wrong password or a closed port. ClickHouse rejects a wrong password on connect.
- ClickHouse keeps Decimal precision. Cancel stops the query on the server, and queries have time and memory limits.
- DuckDB shows DECIMAL, UUID, DATE, TIMESTAMPTZ, MAP and BLOB values as readable text. SUMMARIZE works when one column fails. Raw queries stop at 10,000 rows. Cancel works.
- The new-datastores notice shows once, on 3.2.x only. Pro users get a short toast.
npm testruns the Mocha suite.- SQLite loads on linux-arm64, linux-armhf and Alpine. New win32-arm64 and alpine-arm64 packages.
Security
- The extension is disabled in untrusted workspaces.
Devdb.phpExecutablePathhas machine scope. - MCP server accepts localhost only, requires a token, and runs queries read-only at the database level.
- MCP clients must reconnect after the update: restart VS Code so the MCP server writes its new token.
- SSH tunnels check the host key against
~/.ssh/known_hostsand ask you to trust an unknown host. - Connection strings with passwords are stored in VS Code SecretStorage, keyed by connection id.
- DuckDB cannot read or write files outside the opened file and cannot load extensions.
- Embedding API keys are sent only to the origin they were saved for. Remote endpoints need https.
- Webviews use a strict Content Security Policy with random nonces.
- Updated dependencies: 0 high or critical
npm audit/bun auditfindings. Release tooling (@vscode/vsce,ovsx) is pinned and publish tokens are passed through the environment.
Earlier versions
See the commit log.