Security¶
How stevin handles your workspace¶
- No credentials are stored. Authentication is delegated entirely to the Databricks
SDK's unified auth (
~/.databrickscfgprofiles, OAuth token cache, orDATABRICKS_*environment variables). stevin never writes a token anywhere. - No state file. Unity Catalog is the state. There is no local artefact holding a copy of your schema, and nothing to leak or drift.
- Plans are inert, and three commands write.
stevin planonly reads (information_schema,DESCRIBE DETAIL,DESCRIBE HISTORY,SHOW CREATE TABLE,SHOW TBLPROPERTIES), and so dodrift,import,adoptanddoctor. A statement that changes one of your tables is executed byapplyand nowhere else: from a saved plan that was reviewed first, or — without a plan file — from a plan it makes on the spot, shows, and asks about before it runs (--yesskips the question, so then nobody has read it).applyalso keeps its run history and its lock in thehistory_schema, whereforce-unlockcan release the lock.verifywrites too, in a scratch schema of its own and nowhere else: it creates the schema, makes tables, views and functions in it, and drops it. - Identifiers are always quoted. SQL is never assembled by concatenating raw
identifiers; one
quote_ident()helper handles every name that reaches a statement. - Safe by default. See the safety model: only managed tables can be
dropped, destructive steps need
--allow-destructive, and a stale plan is refused.
Plans and the history tables record the SQL that was run, including column names and table comments. Treat plan JSON as you would a schema dump — it can contain business-sensitive names. The one kind of data in it is a seed's rows: they are in the plan as they are in your repository.
Reporting a vulnerability¶
Please report security issues privately:
- Open a GitHub Security Advisory, or
- email info@kostavo.com.
Do not open a public issue for security reports.