SQL Sage changelog
What changed in each version of SQL Sage, newest first. Entries marked Security or Privacy fix something that mattered for your data or your servers — we say plainly what was wrong before.
Updating: the SQL Sage panel checks for new versions and shows a banner; its Download button opens the latest signed installer. Close SSMS first, then run it. See Update & uninstall. Versions before 0.16.0 are not listed here; every release, with its installer, is also on GitHub.
0.24.0FeatureSecurity
- Safer AI agents. The AI can now use only SQL Sage's own tools. Before this version:
- Codex could run with its own shell and web search next to SQL Sage's tools — it now runs read-only, without a shell of its own and without web search;
- Claude Code turns could reach beyond SQL Sage's tools — they now have no file, shell or web access of their own.
- Bounded answers. The AI stops after 12 steps or 10 minutes per answer and tells you so. Ask it to continue and it picks up where it stopped.
- Copy diagnostics. A new button builds a support report that you preview before copying. It contains no SQL, no query results, no server or database names and no keys.
- This public changelog page.
0.23.0Feature
- Explain error in one click. When a query fails, SQL Sage first shows what your database's catalog proves — the missing column and the closest real name, the foreign key or CHECK constraint behind error 547, the key columns behind a duplicate, the column size behind a truncation, the parser position of a syntax error. With a licence, the AI then explains the cause and returns a fixed query. Values the server quotes in an error message are withheld before anything is shown or sent.
- Check this database on first run — a read-only check of about 10 seconds that lists the top findings with their numbers. Free for everyone, also after the trial.
- Subscription licences now always carry an expiry date and are refreshed online, so a renewal is picked up without pasting a new key.
0.22.0FeatureSecurity
- Choose how hard the AI thinks: a reasoning-effort selector next to the model picker (only the levels your model supports) and
/effortfor a single answer. - The model list now comes live from your Claude Code installation.
- Security fixes from an external audit. Before this version:
- queries that read through a linked server or from files and external sources (
OPENQUERY,OPENROWSET,OPENDATASOURCE, four-part names) were treated as plain reads and could run without asking — they now always ask for confirmation; - results you had agreed to share with one AI provider could be sent again to another provider after you switched — they now stay withheld until you choose “Share previous results”;
- Run could execute in a different query window than the one SQL Sage opened — it now checks the window, the exact SQL, the server and the database right before executing, and otherwise runs nothing;
- the audit log recorded a Run as executed before it was attempted — it now records approval, the attempt and the outcome separately;
- saved chats were plain files — chat history is now encrypted on disk, with a “Save chats” switch and a retention setting.
- queries that read through a linked server or from files and external sources (
- Fixed chats or model-list checks that could hang when the AI CLI left a helper process running.
0.21.0FeatureFix
- SQL Sage Free after the trial. When the 30-day trial ends, SQL Sage keeps working in a free mode: the F5 execution guard, JOIN suggestions from foreign keys, Expand wildcards, Qualify object names, Format and Execute current statement — with Redgate SQL Prompt compatible shortcuts that step aside when SQL Prompt is installed. AI features and the proof and audit tools need a licence.
- New “Show impact” link in the F5 guard.
- Installer fix: the setup program Windows unpacks during installation is now signed too. Earlier installers could be blocked by Smart App Control or App Control policies with “Error 4551”.
0.20.5Fix
- AI features now consistently require an active trial or licence on every path (chat, editor commands, AI inline completion), and a trial that ends while SSMS is open takes effect without a restart. Local safety features such as the F5 execution guard keep working.
- Support for required updates: a signed notice can ask older builds to update, with a grace period first. Only builds from 0.20.5 on can be asked this way.
0.20.4Fix
- Stop now reliably ends the whole AI process tree (Claude Code and Codex). Before, stopping a turn could leave the AI CLI running in the background when it was started through a
.cmdlauncher. - A clearer model picker grouped into Recommended, Latest and Specific versions, showing which model is actually running and where the list came from.
- Claude Sonnet 5.5 with your own API key; sending a message no longer waits for the model list; stricter verification of the signed model list.
0.20.3PrivacyFeature
- Privacy fix. Before this version, read-only queries the AI ran on your tables could return row values to the AI even when you had not agreed to share results. Now, without that consent, the AI runs nothing on your data and sees only column names and types.
- Literals and parameter values in query text and execution plans captured from the server (plan cache, Query Store, live requests) are masked before they reach the AI.
- Your consent to share results is tied to the exact server and database, and resets when either changes.
- A Buy licence button in the trial banner, with a gentle reminder in the last 10 days.
0.20.2Fix
- Longer replies no longer cut off on thinking models (own API key); prompt caching for own-API-key chat.
- Inline completions never spend their budget thinking; tool descriptions state their real limits; no invented table names in completion prompts.
0.20.1Fix
- A slow or unresponsive source (the local model catalog, the CLI version check or the model policy) can no longer hold up choosing a model beyond its time budget.
0.20.0Feature
- Models follow the CLIs installed on your machine. The Codex channel reads Codex's own local model catalog, so model retirements are handled without an extension update; a clear “update Codex CLI” message when a newer model needs it; SQL Sage never switches you to a costlier model on its own.
- A “Recommended” row in the model picker, reasoning effort shown for Codex, inline completions choose their model automatically.
- Audit records now name the exact model that acted. Stricter validation of model names passed to the CLIs.
0.19.4Fix
- Model list refresh: the OpenAI (Codex) channel defaults to GPT-5.5 and offers GPT-5.6 / GPT-6; Claude Fable uses the version-independent alias; model names show relative cost instead of marketing labels.
- Fixed inline completions on the Codex channel.
0.19.3Feature
- See what is sent to the AI (schema metadata and query text), a live token-usage counter, a warning before large operations, and a guided first run. (A gap in how results were withheld was found later and fixed in 0.20.3.)
0.19.2Feature
- Evidence-first code reasoning. When reading your code, SQL Sage looks at call sites before claiming something is absent, says where to check instead of guessing a dependency it cannot resolve, and labels every claim Proven, Inferred or Unresolved.
0.19.1Feature
- Connect a repository reads your live repository through SQL Sage's own read and search tools: connecting is instant, with no size limit. Secret files are refused and secret values are redacted when they are read.
- “Connect repository” appears without a manual refresh.
0.19.0Security
- Connect a repository is hard-fenced. While a repository is connected, the assistant's own file, shell and search tools are switched off; it reaches your code only through SQL Sage's tools, which leave secret files out. (Claude channel. In this version the tools worked on a filtered snapshot of the repository; 0.19.1 replaced the snapshot with reading the live repository under the same rules.)
0.18.0Feature
- Query-tuning skill: evidence-first analysis of code and database that verifies key claims before making them, classifying findings as Proven, Inferred or Gated.
- Execution plans now show implicit conversions (and which side is converted), seek versus residual predicates, missing indexes and plan warnings. Compiled parameter values in plans are masked.
0.17.2Fix
- The extension loads across SSMS 22 builds: fixed a machine-specific load failure (assembly binding redirects), plus clear diagnostics if start-up fails.
0.17.1Fix
- The attached-query chip shows the query editor's name instead of a placeholder.
0.17.0Feature
- Connect a repository (preview, opt-in, Claude): the assistant reasons about your application code alongside the database, with secret files fenced off.
- The model list can be refreshed from a list we publish, so new Claude and ChatGPT models can appear without an extension release (since 0.20.0 the list comes from your CLIs, with a signed policy on top).
- Reliability and security hardening.
0.16.4Feature
- Lighter long chats. Older turns are compacted automatically: your recent turns and the full toolset stay verbatim, bulky older tool results become a short summary of their shape (never your row data), and safety-critical context stays pinned — your connection and any ALTER/DROP still awaiting confirmation.
- Clicking Download in the update banner now sends an anonymous download count (no identifier).
0.16.3Fix
- The chat can no longer hang: if the AI backend goes silent, a watchdog ends the turn with “The AI stopped responding — try again” (Claude and OpenAI/Codex), and New chat interrupts a stuck turn.
- The assistant follows a facts-over-guesses rule: claims about schema, plans, row counts, impact or equivalence are grounded in a real tool result, and it says so when it cannot verify something.
0.16.2Feature
- Select and copy text directly in the chat (click-drag, Ctrl+C, right-click Copy), with formatting and T-SQL highlighting preserved.
0.16.1Fix
- The “new version available” banner kept showing right after installing the latest build, because the extension reported an outdated internal version. It now reports its real version.
0.16.0Feature
- Prove-It. When a query is rewritten, one click checks that the rewrite returns the same rows as the original — a server-side fingerprint of the row multiset (order-independent, duplicate-aware) plus the logical-reads difference — and answers EQUIVALENT, DIFFERENT or UNDECIDABLE (for example with
GETDATE()orNEWID()). Read-only in a rolled-back transaction, no AI tokens, written to the local audit log. Honest limit: the proof covers your current data, not all possible data.
AI usage not included: SQL Sage needs your own AI access (Claude Code on a paid Claude plan, the Codex CLI with a ChatGPT account, or your own Anthropic API key). See pricing