🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@database-mcp/mariadb

Package Overview
Dependencies
Maintainers
1
Versions
6
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@database-mcp/mariadb - npm Package Compare versions

Comparing version
0.2.0
to
0.3.0
+3
-3
package.json
{
"name": "@database-mcp/mariadb",
"version": "0.2.0",
"version": "0.3.0",
"description": "MCP server for MariaDB with read-only guardrails, row caps, and statement timeouts",

@@ -33,4 +33,4 @@ "license": "MIT",

"dependencies": {
"@database-mcp/core": "^0.2.1",
"@database-mcp/mysql": "^0.2.1"
"@database-mcp/core": "^0.3.0",
"@database-mcp/mysql": "^0.3.0"
},

@@ -37,0 +37,0 @@ "devDependencies": {

@@ -5,4 +5,5 @@ # @database-mcp/mariadb

Two tools, guardrails on by default. MariaDB is MySQL wire-compatible, so
this is a thin package over the [`@database-mcp/mysql`](https://www.npmjs.com/package/@database-mcp/mysql)
adapter — identical behavior, MariaDB-flavored configuration.
this is a thin package over the
[`@database-mcp/mysql`](https://www.npmjs.com/package/@database-mcp/mysql)
adapter with MariaDB-flavored configuration.

@@ -20,3 +21,3 @@ ## Quick start (Claude Desktop / Claude Code / Cursor)

"MARIADB_USER": "readonly_user",
"MARIADB_PASSWORD": "...",
"MARIADB_PASSWORD": "your-password",
"MARIADB_DATABASE": "mydb"

@@ -29,10 +30,74 @@ }

Alternatives: `MARIADB_PASSWORD_FILE=/run/secrets/...`, a YAML file via
`--config` (`${VAR}` expansion supported), or `--dsn`. `--print-config`
shows the resolved config with the password redacted.
## Configuration
Use whichever method fits your setup. When methods are combined, flags win
over the YAML file, and the YAML file wins over environment variables.
### Environment variables
`MARIADB_HOST`, `MARIADB_PORT`, `MARIADB_USER`, `MARIADB_PASSWORD`,
`MARIADB_DATABASE`, as in the quick start above.
### Mounted secret file (Docker, Kubernetes)
Keeps the password out of the environment and out of every config file.
Point `MARIADB_PASSWORD_FILE` at a file that contains only the password:
```json
"env": {
"MARIADB_HOST": "127.0.0.1",
"MARIADB_USER": "readonly_user",
"MARIADB_PASSWORD_FILE": "/run/secrets/mariadb_password",
"MARIADB_DATABASE": "mydb"
}
```
### YAML config file
Keeps the client entry down to two lines. Pass an absolute path, since the
working directory at launch is unpredictable:
```json
"args": ["-y", "@database-mcp/mariadb", "--config", "/absolute/path/database-mcp.yaml"]
```
```yaml
# /absolute/path/database-mcp.yaml
connection:
host: 127.0.0.1
port: 3306
user: readonly_user
password: ${MARIADB_PASSWORD} # expanded from the environment at load time
# or read it from a mounted file instead:
# password_file: /run/secrets/mariadb_password
database: mydb
guardrails:
readOnly: true
maxRows: 1000
queryTimeoutMs: 30000
```
Never write a literal password into the YAML file. Use `${VAR}` expansion or
`password_file` as shown.
### Connection string
```json
"args": ["-y", "@database-mcp/mariadb", "--dsn", "mysql://readonly_user@127.0.0.1:3306/mydb"]
```
MariaDB uses the MySQL URI scheme. Putting the password inside the DSN works
but is discouraged. If you do it anyway, the server redacts it from any log
output.
### Checking the result
Run the server with `--print-config` to see exactly what it resolved. The
password always prints as `***`.
## Tools
- **`execute_sql`** `{ sql }` — run a single SQL statement.
- **`search_objects`** `{ table? }` — list tables, or describe one (columns,
- **`execute_sql`** `{ sql }` runs a single SQL statement.
- **`search_objects`** `{ table? }` lists tables, or describes one (columns,
indexes, foreign keys).

@@ -39,0 +104,0 @@