Security fixes are provided for the latest version published to the Visual Studio Marketplace. Earlier versions are unsupported; upgrade to the latest release before reporting a vulnerability.
Do not open a public GitHub issue for security vulnerabilities.
Report via GitHub Security Advisories or contact the maintainer via LinkedIn.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- The extension parses SQL object definitions but does not execute object DDL
.dacpacparsing is fully offline- Live database import runs configured catalog / DMV queries through the MSSQL
extension connection API only when the user starts an import. Built-in
queries are read-only; custom DMV SQL is trusted local configuration and is
executed as configured (with
{{SCHEMAS}}expansion for Phase 2) - Table profiling runs row-count and aggregate
SELECTqueries only after an explicit profiling click - YAML scaffolding commands write fixed filenames in the first workspace root and preserve existing files. Draw.io export uses a save dialog. Import does not modify database objects or user source code
- Strict Content Security Policy on the webview
- Custom YAML DMV queries, AI templates, and parse-rule regexes are trusted local configuration; avoid loading untrusted YAML files
@lineageuses the model selected in VS Code. When invoked, the selected model receives the user's prompt, native@lineagechat history, and lineage metadata or DDL returned by local snapshot tools. The AI runtime cannot connect to a database, execute SQL, start an import, or start profiling- AI trace logging is disabled by default. Enabling it for a session writes full model and tool diagnostics under the VS Code extension log directory. These files can contain database identifiers, SQL, prompts, responses, and tool payloads; review them before sharing
- Copy Debug Info can include project/source/schema names, filter state, GUI state, database-model metadata, and AI session metadata. Review and redact identifiers before sharing it