Security
Report a vulnerability
Do not report security problems in public
Do not open a public issue or discussion for a security problem.
Report it privately:
- GitHub private vulnerability reporting (preferred). Go to the Security tab of the DevDb repository and click Report a vulnerability.
- Email. Contact damms005 through GitHub.
The maintainers fix security problems as soon as possible.
How DevDb protects your data
Workspace trust
DevDb does not run in untrusted workspaces. A project that you open cannot make DevDb run its tools until you trust the workspace.
Settings that can run programs or change data have machine scope: Devdb.phpExecutablePath and Devdb.mcp.allowWrites. A workspace .vscode/settings.json file cannot set them.
Secrets
- DevDb keeps passwords, connection strings and tokens of remote connections in the secret storage of your editor, including Cloudflare API tokens, Turso auth tokens and AWS access keys. It does not write them to settings files or logs.
- DevDb keeps embedding API keys in secret storage. It does not send them to the DevDb panel. It sends a key only to the origin that you saved it for.
.devdbrcis a plain file. Add it to.gitignore.
MCP server
- Listens on
127.0.0.1only. - Needs a per-session token on each request. DevDb keeps the token in
~/.devdb/mcp.json, which only your user can read. - Read-only by default. The database enforces it.
- Write queries need
Devdb.mcp.allowWritesand a confirmation for each query.
See MCP Server.
Network connections
- SSH tunnels check the host key against
~/.ssh/known_hosts. DevDb asks you to trust an unknown host and refuses a changed key. - Direct connections with TLS verify the server certificate unless you select Allow self-signed certificate.
- Neon connections always use TLS and verify the certificate.
- ClickHouse uses
httpsfor all hosts that are not local, unless you selecthttp. - Embedding endpoints must use
https, except onlocalhost.
DuckDB
DuckDB files open read-only by default. DuckDB queries cannot use the network, load extensions, attach other databases, or read or write other files.
Panel
The DevDb panel uses a strict Content Security Policy with a random nonce.
Data that leaves your computer
| Feature | Data sent | Sent to |
|---|---|---|
| Query explainer | Query, bindings, MySQL version, execution plan | api.mysqlexplain.com |
| Search by text | Search text | The embedding endpoint that you configure |
| License activation | License key, machine ID | DevDb license server |
| Remote D1 | Queries, API token | Cloudflare API |
DevDb does not send your database data anywhere else.