Reporting to GitHub code scanning
A workflow that puts SQLens security findings in the Security tab, and the one property that decides how GitHub ranks them.
The privacy pack
An opt-in pack that reads column names and asks whether personal data is stored in the clear — and says out loud what a name cannot tell you.
The least-privilege audit role
A copy-paste role for each engine, the exact list of checks that go quiet without more, and the two-connection split that is the single most effective thing you can change.
Two connections, two roles — the setup that makes an injection cheaper
A runtime identity that cannot change the schema turns a successful injection into a smaller incident. Here is the Laravel configuration and the grant script for both engines, with the step everybody forgets.
MCP transport: the trust boundary, stated
What you are assuming when you start the SQLens MCP server, and which test holds each assumption.
MCP threat model: surface, countermeasures, residual risk
What an agent can reach through the SQLens MCP server, what stops it, and what this design does not protect you from.
Auditing a database that is not yours
Running SQLens against a client's database needs a documented engagement — what that means, what one should contain, and which commands touch a foreign system at all.