Skip to content

Security ​

Report a vulnerability ​

Do not report security problems in public

Do not open a public issue or discussion for a security problem.

Report it privately:

  1. GitHub private vulnerability reporting (preferred). Go to the Security tab of the DevDb repository and click Report a vulnerability.
  2. Email. Contact damms005 through GitHub.

The maintainers fix security problems as soon as possible.

How DevDb protects your data ​

Workspace trust ​

DevDb does not run in untrusted workspaces. A project that you open cannot make DevDb run its tools until you trust the workspace.

Settings that can run programs or change data have machine scope: Devdb.phpExecutablePath and Devdb.mcp.allowWrites. A workspace .vscode/settings.json file cannot set them.

Secrets ​

  • DevDb keeps passwords, connection strings and tokens of remote connections in the secret storage of your editor, including Cloudflare API tokens, Turso auth tokens and AWS access keys. It does not write them to settings files or logs.
  • DevDb keeps embedding API keys in secret storage. It does not send them to the DevDb panel. It sends a key only to the origin that you saved it for.
  • .devdbrc is a plain file. Add it to .gitignore.

MCP server ​

  • Listens on 127.0.0.1 only.
  • Needs a per-session token on each request. DevDb keeps the token in ~/.devdb/mcp.json, which only your user can read.
  • Read-only by default. The database enforces it.
  • Write queries need Devdb.mcp.allowWrites and a confirmation for each query.

See MCP Server.

Network connections ​

  • SSH tunnels check the host key against ~/.ssh/known_hosts. DevDb asks you to trust an unknown host and refuses a changed key.
  • Direct connections with TLS verify the server certificate unless you select Allow self-signed certificate.
  • Neon connections always use TLS and verify the certificate.
  • ClickHouse uses https for all hosts that are not local, unless you select http.
  • Embedding endpoints must use https, except on localhost.

DuckDB ​

DuckDB files open read-only by default. DuckDB queries cannot use the network, load extensions, attach other databases, or read or write other files.

Panel ​

The DevDb panel uses a strict Content Security Policy with a random nonce.

Data that leaves your computer ​

FeatureData sentSent to
Query explainerQuery, bindings, MySQL version, execution planapi.mysqlexplain.com
Search by textSearch textThe embedding endpoint that you configure
License activationLicense key, machine IDDevDb license server
Remote D1Queries, API tokenCloudflare API

DevDb does not send your database data anywhere else.

DevDb - Zero-config database client for VS Code