NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1810 by repository stars
Last release 5 days ago
03 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Some releases are documented
notes for 15 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
159 releases · first in 2022
One column per quarter.
Nothing published for this version
Breaking change: describe_resource MCP tool retired
Full Changelog: v0.12.718...v0.12.732
describe_resource MCP tool retiredThe describe_resource MCP tool has been removed (#796). It wrapped DESCRIBE provider.service.resource, which reports the schema of one select method resolved without WHERE parameters, while a SELECT routes by its parameters and can land on a method with a different shape.
describe_method is now the single column source for MCP clients. It returns the exact contract for the method a query routes to: inputs with param_type, and the output fields a SELECT can reference. The discovery path is list_providers -> list_services -> list_resources -> list_methods -> describe_method.
describe_resource need to be updated to call list_methods followed by describe_method.DESCRIBE statement is unchanged.describe_method output fields.--mcp.protocol.version)The MCP server now builds against github.com/modelcontextprotocol/go-sdk v1.8.0 (previously v1.7.0) and the newest protocol revision it advertises can be pinned (#796, issue #784). The setting is available as the --mcp.protocol.version flag, which overrides server.protocol_version in mcp.config.
| Value | Advertised | Effect |
|---|---|---|
auto (default) or absent |
every SDK revision | negotiation per client: the highest revision both sides speak |
2026-07-28 |
2026-07-28 only |
sessionless only; implies stateless for Streamable HTTP |
2025-11-25 (or any older revision) |
that revision and everything before it | handshake lifecycle only; a 2026-07-28 request is answered with JSON-RPC error -32022 whose data.supported lists the advertised revisions, so the client can renegotiate |
stackql mcp --mcp.server.type=http --mcp.protocol.version=2026-07-28 --mcp.config '{"server": {"transport": "http", "address": "127.0.0.1:9992"} }'
stackql mcp --mcp.server.type=stdio --mcp.protocol.version=2025-11-25Any other value fails config validation at startup with invalid server.protocol_version, naming the legal values.
Behaviour changes that come with SDK v1.8.0:
2026-07-28 request is now answered with JSON-RPC error -32022 (UnsupportedProtocolVersion) rather than a plain HTTP 400.413 beyond it), and JSON nested deeper than 1000 levels is rejected before parsing. These limits are not configurable in mcp.config.See docs/mcp.md for the full transport and negotiation detail.
DESC classed as read-only by the MCP policy gateThe MCP policy gate now classes DESC (and DESC EXTENDED) as read-only, the same as DESCRIBE (#795, issue #773). The parser already accepted DESC on every other path; previously the gate treated a statement beginning with DESC as an unknown query class.
--output otel--output otel can now push records to an OTLP/HTTP logs endpoint in addition to writing them to stdout (#795, issue #755 phase 2). The exporter is configured through the new --otel.config flag, which takes a JSON or YAML string:
stackql exec --output otel \
--otel.config '{"exporter": {"endpoint": "http://localhost:4318/v1/logs", "headers": {"authorization": "<token>"}}}' \
"select name, location from google.storage.buckets where project = 'my-project';"| Key | Required | Default | Description |
|---|---|---|---|
exporter.endpoint |
yes | Full OTLP/HTTP logs URL, for example http://collector:4318/v1/logs |
|
exporter.headers |
no | Headers sent on every export request, for example an ingestion token or API key | |
exporter.timeout_ms |
no | 10000 |
Per-request timeout in milliseconds |
exporter.batch_size |
no | 512 |
Number of log records per export request |
batch_size; the remainder is shipped when the statement completes.429 and 5xx responses, and transport errors, are retried up to 4 attempts, honouring a delay-seconds Retry-After header (capped at 30 seconds) or otherwise an exponential backoff starting at 500 ms.OTEL_EXPORTER_OTLP_* environment variables are read; all exporter settings come from --otel.config. A malformed value, or an exporter without an endpoint, fails startup.JOIN without an ON clauseA JOIN with no ON clause crashed plan building with a nil pointer dereference (#794, fixes #793). A condition-less inner join is now treated as a CROSS JOIN, which both the SQLite and Postgres backends accept, so a query that joins two provider tables with the join condition in WHERE now runs.
Preview functionality is not stable. Behaviour, syntax and output may change or break between releases without notice. Do not rely on it in production.
The opt-in preview query path (--preview='{"unstable":true}') has been extended (#797). Statements over relations named stackql_unstable_<provider>.<service>.<resource> are resolved and run by omnisdk directly from the provider documents, with rows streamed to the output as they are produced rather than staged in the SQL backend.
SELECT over these relations is now handed to omnisdk as a whole: INNER JOIN and LEFT JOIN between document-driven relations are supported, as are IN list filters. omnisdk decides which conditions become request parameters, which become edges between relations, and which become row filters.LIMIT without ORDER BY is pushed down and stops the requests early. ORDER BY, GROUP BY, HAVING, DISTINCT and aggregates are refused on these relations.INSERT, UPDATE and DELETE against a document-driven relation are routed through omnisdk; a RETURNING list streams back the affected resource. INSERT and UPDATE are covered by the functional test suite in this release.omnisdk.SHOW METHODS on these relations reports each method's SQL verb (SELECT, INSERT, UPDATE, ...), with EXEC for a method no verb maps to.--output jsonl or --output otel to have each row written as it arrives; the default table output holds every row until the query completes.stackql exec --preview='{"unstable":true}' --output jsonl \
"select b.name as bucket, i.role, i.members
from stackql_unstable_google.storage.buckets b
inner join stackql_unstable_google.storage.buckets_iam_policies i on i.bucket = b.name
where b.project = 'my-project';"Developer documentation, including audit query examples for AWS, Azure and Google, is in docs/preview.md.
github.com/modelcontextprotocol/go-sdk v1.7.0 -> v1.8.0github.com/stackql-labs/omnisdk v0.1.2-beta02 -> v0.1.3-alpha05@stackql/mcp-server) and PyPI (stackql-mcp-server) aligned to the 0.12.x lineNothing published for this version
retire describe_resource MCP tool; discovery via list_methods -> describe_method
mcp updates
retire describe_resource MCP tool; discovery via list_methods -> describe_method
The MCP describe_resource tool wrapped DESCRIBE provider.service.resource,
which reports the schema of one select method resolved without WHERE
parameters, while a SELECT routes by its parameters and can land on a
method with a different shape. describe_method is the exact contract
(inputs with param_type, output fields) for the method a query routes to,
so it is now the single column source.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Co-authored-by: Claude Fable 5.1 noreply@anthropic.com
Nothing published for this version
ci: bump Node20-deprecated actions to Node24; cut runner costs by @jeffreyaven in #781
Full Changelog: v0.11.673...v0.12.718
The embedded SQLite backend is now
modernc.org/sqlite(pure Go). All binaries are built withCGO_ENABLED=0and are statically linked; no C toolchain is involved anywhere in the build.
The custom extension functions (
split_part,regexp_like,regexp_substr,regexp_replace,json_equal,aws_policy_equal) are ported to pure Go inany-sdk; documented behaviour divergences (RE2 regexp limits) are listed in any-sdkpublic/sqlfuncs/DIVERGENCES.md.
Library embedders now inherit the
modernc.org/sqlitedependency tree instead ofmattn/go-sqlite3/cgo.
External loadable SQLite extensions (
.load) are no longer supported.
Rollback anchor: the tag
v0.11.707-final-cgomarks the last cgo commit onmain.
migrate-embedded-sqlite-to-pure-go-modernc
modernc sqlite migration prep
migrate-embedded-sqlite-to-pure-go-modernc (#783)
docs(sqlfuncs): mirror CLAUDE.md as AGENTS.md for all agent sessions
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: copilot-swe-agent[bot] 198982749+Copilot@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
finalize-pure-go-sqlite-migration-cleanup (#785)
retire remaining cgo configuration and stale migration artifacts
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: copilot-swe-agent[bot] 198982749+Copilot@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Rename docs/stackql release process.md to
docs/stackql_release_process.md per review, and update the three
references to it (two workflow header comments and the mcpb packaging
notes) so nothing points at the old name.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Remove the six workflow-level extension function smoke steps from
build.yml per review. The check lives in the robot scenario
Sqlite Extension Functions Smoke Working, which now carries the
stronger aws_policy_equal comparison the workflow steps used (Version
plus scalar-vs-array Resource), so nothing is lost in the move.
The scenario runs wherever the functional suite runs: winbuild,
linuxtest, linuxarmbuild, macosbuild, wsltest and the docker sqlite leg.
winarmsmoke and macosarmbuild have no robot harness, so the check is no
longer exercised in those two jobs.
Also drop the stale "cgo" wording from the winarmsmoke comment.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Sharding splits one robot run across several dockertest legs, so no
single leg can attest that the whole suite ran. Add a dockertestverify
job that runs once all legs conclude and fails unless, for each
(platform, db backend) group, the shards together account for every
functional test exactly once.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Per review: now that GitHub hosts arm64 macOS and Windows runners, run
the robot functional suite on both rather than leaving the extension
function check unexercised there.
brew --prefix because homebrew's prefixCo-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Co-authored-by: Copilot 198982749+Copilot@users.noreply.github.com
Co-authored-by: jeffreyaven 5146499+jeffreyaven@users.noreply.github.com
Co-authored-by: Claude Fable 5.1 noreply@anthropic.com
modernc sqlite migration prep
modernc sqlite migration prep
reload_credentials: report installed providers, invalidate doc auth contexts, changed flag, actionable credential errors
The reload_credentials MCP tool read the lazily populated auth context
registry, so an unscoped call before any query returned no rows and a
scoped call for an installed, credentialed provider errored with
"cannot find AUTH context" (after the env re-source had already run).
The handler is now three ordered phases: re-source the configured env
file (a configured file that has gone missing is an explicit error
naming the path), invalidate auth contexts registered lazily from
provider documents (--auth contexts are retained; the cached provider
object is dropped with its context because doc auth only registers on
provider creation), then report every installed provider against the
now-current environment. Scoping is a filter; an unknown provider name
is the only scoped error. Each row carries a new changed field: a
sha256 comparison of the resolved credential material (successor chain
included) before and after the re-source, never emitted.
Query tools: credential resolution failures on run_select_query,
run_mutation_query and run_lifecycle_operation now name the provider
(parsed from the statement) and the recovery sequence (fix the env
file, call reload_credentials, retry). execQuery propagates statement
errors, which mutation, lifecycle and pull_provider previously
swallowed into an empty success payload.
Tool description rewritten to forbid preemptive calls and to make
changed: false after a failure the stop signal.
Tests: scripted stdio harness (run_stdio_credential_script) driving the
stackql_auth_testing dummy-credential provider; robot scenarios for
fresh-session scoped/unscoped/unknown, rotation after a registered
context (stale key rejected by the mock, new key used post-reload),
rotation before first query, recovery from failed resolution (select
and mutation error text, no-op reload), missing env file. The
pull_provider scenario now runs against a mocked HTTP registry server
(9927) so the install is real rather than a swallowed local-mode error.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Tool descriptions were inline Go string literals spread across server.go
and query_library.go while instructions, prompts and resources were
already authored as markdown under pkg/mcp_server/content. Move the 16
descriptions to content/tools/<tool_name>.md (frontmatter name, body
is the description prose; soft line breaks collapse to spaces, blank
lines keep paragraph breaks) and load them through the same embedded
content framework.
addToolWithGate attaches the mastered description and returns an error
when a registered tool has none, so registration failures surface at
server construction like prompt and resource failures do. Published
bytes are unchanged for every tool. The build-time gate test now checks
coverage in both directions: every published tool has a file and every
file names a published tool.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Reads content/tools/run_select_query.md from disk independently of the
loader, strips the frontmatter and joins the wrapped lines, then compares
with the description returned by an in-process tools/list.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
The 2026-07-28 stateless roundtrip now opens with server/discover, the
SEP-2575 replacement for the initialize handshake, and the 9926
scenario asserts the response lists the revision and carries the
embedded content/instructions text. Closes the black-box gap where the
new-revision instructions path was only covered by the in-process unit
test.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
tool descriptions
mcp: align server instructions with the on-demand tool descriptions
server_info and reload_credentials are on-demand recovery and
diagnostic tools, never session-start steps; the instructions said
otherwise. Session guidance now states the defaults (sqlite3, safe),
that credentials resolve at query time with no preceding step, and the
fail -> fix file -> reload -> retry sequence with changed: false as the
stop signal. The 401 recovery rule gates the retry on changed: true.
Discovery points at the query library before the drill-down, dialect
rules describe validate_select_query as an on-demand pre-flight rather
than a routine step, and the mutation shapes gain the EXEC statement
form behind run_lifecycle_operation.
validate_select_query: the "no credentials required" claim was checked
against the binary and is false (EXPLAIN resolves credentials and fails
before reporting a bad column when they are missing); the description
now says so. Trailing newlines restored on the tool files.
The stateless discover scenario anchors on the "# Discovery workflow"
heading rather than a sentence that the rewrite reworded.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
The Sources Env File Mid Session scenario now runs through
run_stdio_credential_script like the other reload scenarios, and the
superseded run_stdio_credential_reload_roundtrip helper is removed. This
also clears the CodeQL clear-text-storage alert (pre-existing on main)
that the helper's secret_value write carried.
Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
Co-authored-by: Claude Fable 5.1 noreply@anthropic.com
Nothing published for this version
mirror-publish-git-ident by @jeffreyaven in #721
LIKE and NOT LIKE by @Roshan931 in #723Full Changelog: v0.10.605...v0.11.669
Nothing published for this version
embedded-mcp-packaging by @jeffreyaven in #718
Full Changelog: v0.10.601...v0.10.605
preview-provider by @general-kroll-4-life in #711
Full Changelog: v0.10.591...v0.10.601
Nothing published for this version
fix: stdio malformed-frame resilience, JSON() param fan-out, window/CTE test coverage by @jeffreyaven in #702
Full Changelog: v0.10.582...v0.10.591
Install doc updates by @jeffreyaven in #693
Full Changelog: v0.10.559...v0.10.582
Nothing published for this version
Install doc updates by @jeffreyaven in #690
Full Changelog: v0.10.557...v0.10.559
feat: mcp credential (re)sourcing via server.env_file + reload_credentials tool ( #688 ) by @jeffreyaven in #689
Full Changelog: v0.10.542...v0.10.557
identity-federation by @general-kroll-4-life in #667
Full Changelog: v0.10.500...v0.10.542
claude code perms update by @jeffreyaven in #662
Full Changelog: v0.10.489...v0.10.500
Nothing published for this version
shell-fail-eager by @general-kroll-4-life in #646
Full Changelog: v0.10.426...v0.10.489
shell-fail-eager by @general-kroll-4-life in #646
Full Changelog: v0.10.426...v0.10.474
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →