Repository navigation
feat(bigquery): add native read-only session locking - #3851
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Code Review
This pull request updates the IsReadOnly method in the BigQuery source implementation to dynamically check if the write mode is blocked (WriteModeBlocked), rather than unconditionally returning false. It also adds a comprehensive unit test suite TestBigQuerySource_IsReadOnly to verify this behavior across various write modes. There are no review comments, and I have no additional feedback to provide.
anubhav756
force-pushed
the
anubhav-readonly-bigquery
branch
2 times, most recently
from
August 20, 2026 17:50
8e805ce to
c8c0a29
Compare
anubhav756
force-pushed
the
anubhav-readonly-cloudsqlmysql
branch
from
August 21, 2026 05:32
5cf614a to
c71c091
Compare
anubhav756
force-pushed
the
anubhav-readonly-bigquery
branch
5 times, most recently
from
August 21, 2026 11:11
84a5f99 to
3eaf4eb
Compare
anubhav756
marked this pull request as ready for review
August 21, 2026 12:04
anubhav756
changed the base branch from
anubhav-readonly-cloudsqlmysql
to
anubhav-readonly-annotation
August 21, 2026 12:04
anubhav756
force-pushed
the
anubhav-readonly-bigquery
branch
2 times, most recently
from
August 21, 2026 12:27
697eff4 to
778cc1e
Compare
3 tasks done
shobsi
reviewed
Aug 23, 2026
shobsi
requested changes
Aug 23, 2026
shobsi
reviewed
Aug 23, 2026
shobsi
reviewed
Aug 23, 2026
anubhav756
force-pushed
the
anubhav-readonly-bigquery
branch
from
August 24, 2026 10:15
778cc1e to
3b2e01c
Compare
anubhav756
force-pushed
the
anubhav-readonly-bigquery
branch
from
August 25, 2026 06:22
3b2e01c to
76039a3
Compare
anubhav756
force-pushed
the
anubhav-readonly-annotation
branch
from
August 26, 2026 21:06
adf943c to
e6f7564
Compare
anubhav756
force-pushed
the
anubhav-readonly-bigquery
branch
from
August 26, 2026 21:33
e3ad29a to
3faf198
Compare
shobsi
approved these changes
Aug 26, 2026
anubhav756
force-pushed
the
anubhav-readonly-bigquery
branch
from
August 27, 2026 06:11
3faf198 to
ff01292
Compare
anubhav756
force-pushed
the
anubhav-readonly-annotation
branch
2 times, most recently
from
August 27, 2026 06:48
a96d2ab to
0a4a063
Compare
anubhav756
force-pushed
the
anubhav-readonly-bigquery
branch
from
August 27, 2026 06:52
ff01292 to
a65f735
Compare
Contributor
|
🧨 Preview deployments removed. Cloudflare Pages environments for |
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.
## Changes
- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756
added a commit
that referenced
this pull request
Aug 27, 2026
…ions (#3872) ## Description This PR introduces end-to-end Read-Only mode support across Toolbox, spanning core framework tool suppression, source-aware dynamic MCP tool annotations, and protocol/session-level enforcement for database sources. When a data source is configured in read-only mode: 1. **Agent-Level Tool Suppression**: Write-capable tools bound to read-only sources are suppressed from tool registration and pruned from tool groups to save LLM context window space and prevent hallucinated write attempts. 2. **Dynamic Tool Annotations**: Multi-mode tools (such as SQL execution tools) dynamically advertise `readOnlyHint: true` and `destructiveHint: false` in MCP tool manifests when connected to read-only sources. 3. **Database Session-Level Enforcement**: Database drivers enforce strict, protocol-level session locking directly within the database engine/client driver, preventing prompt injection or multi-statement write breakouts. ## PRs Included - #3615 - #3816 - #3618 - #3851 - #3619 - #3617
github-actions Bot
pushed a commit
that referenced
this pull request
Aug 27, 2026
…amic tool annotations (#3872) ## Description This PR introduces end-to-end Read-Only mode support across Toolbox, spanning core framework tool suppression, source-aware dynamic MCP tool annotations, and protocol/session-level enforcement for database sources. When a data source is configured in read-only mode: 1. **Agent-Level Tool Suppression**: Write-capable tools bound to read-only sources are suppressed from tool registration and pruned from tool groups to save LLM context window space and prevent hallucinated write attempts. 2. **Dynamic Tool Annotations**: Multi-mode tools (such as SQL execution tools) dynamically advertise `readOnlyHint: true` and `destructiveHint: false` in MCP tool manifests when connected to read-only sources. 3. **Database Session-Level Enforcement**: Database drivers enforce strict, protocol-level session locking directly within the database engine/client driver, preventing prompt injection or multi-statement write breakouts. ## PRs Included - #3615 - #3816 - #3618 - #3851 - #3619 - #3617
Yuan325
added a commit
that referenced
this pull request
Aug 27, 2026
🤖 I have created a release *beep* *boop* --- ## [1.10.0](v1.9.0...v1.10.0) (2026-08-27) ### Features * **falkordb:** Add FalkorDB source and tools ([#3692](#3692)) ([a94702c](a94702c)) * **firestore-mongodb:** Add firestore-execute-mql and firestore-get-… ([#3826](#3826)) ([4a85d75](4a85d75)) * **mcp:** Add Secure Parameters support as Toolbox experimental extension ([#3394](#3394)) ([9750d2d](9750d2d)) * **server/mcp:** Support com.google.cloud/toolbox.v1 extension in v20260728 ([#3801](#3801)) ([f4f7da6](f4f7da6)) * **skill:** Add fix-failing-tests skill for mcp-toolbox ([#3821](#3821)) ([168e69c](168e69c)) * **sources:** Support native read-only mode and dynamic tool annotations ([#3872](#3872)) ([c257022](c257022)), refs [#3615](#3615) [#3816](#3816) [#3618](#3618) [#3851](#3851) [#3619](#3619) [#3617](#3617) * **tool/mongodb:** Allow collection to be specified at runtime ([#3715](#3715)) ([7626eaf](7626eaf)) ### Bug Fixes * **cloud-storage:** Resolve symlinks when enforcing local path boundaries ([#3810](#3810)) ([c2ada64](c2ada64)) * **config:** Compare env var offsets in rune space when skipping comments ([#3856](#3856)) ([2e76934](2e76934)) * Merge prebuilt tools when reloading custom config ([#3864](#3864)) ([5a6d865](5a6d865)) * Normalize postgres UUIDs to strings ([#3806](#3806)) ([3b02f1d](3b02f1d)) * **postgres:** Filter background processes in postgres-list-active-queries ([#3885](#3885)) ([3d9e62a](3d9e62a)) * **test/alloydbainl:** Use explicit SQL alias prompts to stabilize AI… ([#3877](#3877)) ([50e45ed](50e45ed)) * **tests:** Prevent resource leaks by using context.WithoutCancel ([#3849](#3849)) ([f97a4f9](f97a4f9)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com> Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com>
github-actions Bot
pushed a commit
that referenced
this pull request
Aug 27, 2026
🤖 I have created a release *beep* *boop* --- ## [1.10.0](v1.9.0...v1.10.0) (2026-08-27) ### Features * **falkordb:** Add FalkorDB source and tools ([#3692](#3692)) ([a94702c](a94702c)) * **firestore-mongodb:** Add firestore-execute-mql and firestore-get-… ([#3826](#3826)) ([4a85d75](4a85d75)) * **mcp:** Add Secure Parameters support as Toolbox experimental extension ([#3394](#3394)) ([9750d2d](9750d2d)) * **server/mcp:** Support com.google.cloud/toolbox.v1 extension in v20260728 ([#3801](#3801)) ([f4f7da6](f4f7da6)) * **skill:** Add fix-failing-tests skill for mcp-toolbox ([#3821](#3821)) ([168e69c](168e69c)) * **sources:** Support native read-only mode and dynamic tool annotations ([#3872](#3872)) ([c257022](c257022)), refs [#3615](#3615) [#3816](#3816) [#3618](#3618) [#3851](#3851) [#3619](#3619) [#3617](#3617) * **tool/mongodb:** Allow collection to be specified at runtime ([#3715](#3715)) ([7626eaf](7626eaf)) ### Bug Fixes * **cloud-storage:** Resolve symlinks when enforcing local path boundaries ([#3810](#3810)) ([c2ada64](c2ada64)) * **config:** Compare env var offsets in rune space when skipping comments ([#3856](#3856)) ([2e76934](2e76934)) * Merge prebuilt tools when reloading custom config ([#3864](#3864)) ([5a6d865](5a6d865)) * Normalize postgres UUIDs to strings ([#3806](#3806)) ([3b02f1d](3b02f1d)) * **postgres:** Filter background processes in postgres-list-active-queries ([#3885](#3885)) ([3d9e62a](3d9e62a)) * **test/alloydbainl:** Use explicit SQL alias prompts to stabilize AI… ([#3877](#3877)) ([50e45ed](50e45ed)) * **tests:** Prevent resource leaks by using context.WithoutCancel ([#3849](#3849)) ([f97a4f9](f97a4f9)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com> Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com>
social4hyq
pushed a commit
to social4hyq/homebrew-core
that referenced
this pull request
Sep 20, 2026
mcp-toolbox 1.10.0 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.release notes
## [1.10.0](googleapis/mcp-toolbox@v1.9.0...v1.10.0) (2026-08-27) ### Features * **falkordb:** Add FalkorDB source and tools ([#3692](googleapis/mcp-toolbox#3692)) ([a94702c](googleapis/mcp-toolbox@a94702c)) * **mcp:** Add Secure Parameters support as Toolbox experimental extension ([#3394](googleapis/mcp-toolbox#3394)) ([9750d2d](googleapis/mcp-toolbox@9750d2d)) * **server/mcp:** Support com.google.cloud/toolbox.v1 extension in v20260728 ([#3801](googleapis/mcp-toolbox#3801)) ([f4f7da6](googleapis/mcp-toolbox@f4f7da6)) * **skill:** Add fix-failing-tests skill for mcp-toolbox ([#3821](googleapis/mcp-toolbox#3821)) ([168e69c](googleapis/mcp-toolbox@168e69c)) * **sources:** Support native read-only mode and dynamic tool annotations ([#3872](googleapis/mcp-toolbox#3872)) ([c257022](googleapis/mcp-toolbox@c257022)), refs [#3615](googleapis/mcp-toolbox#3615) [#3816](googleapis/mcp-toolbox#3816) [#3618](googleapis/mcp-toolbox#3618) [#3851](googleapis/mcp-toolbox#3851) [#3619](googleapis/mcp-toolbox#3619) [#3617](googleapis/mcp-toolbox#3617) * **tools/firestore-mongodb:** Add tools for execute mql and get schema ([#3826](googleapis/mcp-toolbox#3826)) ([4a85d75](googleapis/mcp-toolbox@4a85d75)) * **tool/mongodb:** Allow collection to be specified at runtime ([#3715](googleapis/mcp-toolbox#3715)) ([7626eaf](googleapis/mcp-toolbox@7626eaf)) ### Bug Fixes * **cloud-storage:** Resolve symlinks when enforcing local path boundaries ([#3810](googleapis/mcp-toolbox#3810)) ([c2ada64](googleapis/mcp-toolbox@c2ada64)) * **config:** Compare env var offsets in rune space when skipping comments ([#3856](googleapis/mcp-toolbox#3856)) ([2e76934](googleapis/mcp-toolbox@2e76934)) * Merge prebuilt tools when reloading custom config ([#3864](googleapis/mcp-toolbox#3864)) ([5a6d865](googleapis/mcp-toolbox@5a6d865)) * Normalize postgres UUIDs to strings ([#3806](googleapis/mcp-toolbox#3806)) ([3b02f1d](googleapis/mcp-toolbox@3b02f1d)) * **postgres:** Filter background processes in postgres-list-active-queries ([#3885](googleapis/mcp-toolbox#3885)) ([3d9e62a](googleapis/mcp-toolbox@3d9e62a)) | **OS/Architecture** | **Description** | **SHA256 Hash** | | --------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------- | | [linux/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/linux/amd64/toolbox) ([Signature](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/linux/amd64/toolbox.asc)) | For **Linux** systems running on **Intel/AMD 64-bit processors**. | 7e15dba09e6f957f64ce5924a0aa06b12cdf83ab26119813b0fa40edab566dd4 | | [darwin/arm64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/darwin/arm64/toolbox) | For **macOS** systems running on **Apple Silicon** (M1, M2, M3, etc.) processors. | c994f06781462abba4171cb4844776c45605e391c57dc96adb3e130c81b53825 | | [darwin/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/darwin/amd64/toolbox) | For **macOS** systems running on **Intel processors**. | 12ebf78d9d05e8f3fe90c5d02ae14f2ccd96cf036f3dfba430bc32e3cfeadfd4 | | [windows/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/windows/amd64/toolbox.exe) | For **Windows** systems running on **Intel/AMD 64-bit processors**. | 734783941cb5864c0e5d4d78be625f8b12be23b01d94781d7fa7db9b3c25aac6 | | [windows/arm64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/windows/arm64/toolbox.exe) | For **Windows** systems running on **ARM 64-bit processors**. | d9be7c2ce1d2e29c20f2974cbac4cde857adad836cee565d2584f3fbcc97f096 |View the full release notes at https://github.com/googleapis/mcp-toolbox/releases/tag/v1.10.0">https://github.com/googleapis/mcp-toolbox/releases/tag/v1.10.0.
>
See merge request: Harmonybrew/homebrew-core!17982
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
Add support for BigQuery in Toolbox's Read-Only architecture.
When BigQuery is configured with
writeMode: "blocked", the source is recognized as read-only (IsReadOnly() == true).bigquery-execute-sqlremains available to AI agents forSELECTqueries as a single polymorphic tool, dynamically updating its MCP annotations toreadOnlyHint: trueanddestructiveHint: false. Any dedicated mutating tools without read-only annotations are automatically suppressed.Changes
BigQuerySource.IsReadOnly()to returntruewhenWriteMode == "blocked".writeModestates (blocked,allowed,protected, empty default).ShouldSuppress(ctx, source) bool { return false }soexecute_sqlremains exposed to agents forSELECTqueries on read-only sources.GetAnnotations(src)to dynamically returnreadOnlyHint: trueanddestructiveHint: falsewhen connected to awriteMode: "blocked"source, preserving custom hints.TestGetAnnotations,TestShouldSuppress).writeMode: ${BIGQUERY_WRITE_MODE:allowed}onbigquery-sourceso prebuilt images can be launched in read-only mode via environment variables (BIGQUERY_WRITE_MODE=blocked ./toolbox --prebuilt bigquery).TestBigQuery_ReadOnlyVulnerabilityBlockverifying that if a custom tool is falsely annotated withreadOnlyHint: trueon awriteMode: "blocked"source, BigQuery dry-run validation catches and rejects mutating SQL statements (likeCREATE TABLE) before execution.writeModereference table to document coordination with MCP read-only annotations and tool suppression.