Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@gwax/sql-formatter
Advanced tools
SQL Formatter is a JavaScript library and command line tool for pretty-printing SQL queries. It started as a Javascript port of a PHP Library, but has diverged considerably, and been forked/joined multiple times in the past. The current formatter (@gwax/sql-formatter) forked from zeroturnaround/sql-formatter with code consolidated from kufii/sql-formatter-plus and a number of other forks scattered around GitHub.
SQL Formatter supports Standard SQL, Couchbase N1QL, IBM DB2, Oracle PL/SQL, Amazon Redshift, and Spark dialects.
Get the latest version from NPM:
npm install @gwax/sql-formatter
The CLI tool will be installed under @gwax/sql-formatter
and under
sql-formatter
and may be invoked via npx @gwax/sql-formatter
:
npx @gwax/sql-formatter -h
usage: sql-formatter [-h] [-v] [-f FILE] [-o OUTPUT]
[-l {db2,n1ql,pl/sql,plsql,redshift,spark,sql}]
[-i N | -t] [-u] [--lines-between-queries N]
SQL Formatter
Optional arguments:
-h, --help Show this help message and exit.
-v, --version Show program's version number and exit.
-f FILE, --file FILE Input SQL file (defaults to stdin)
-o OUTPUT, --output OUTPUT
File to write SQL output (defaults to stdout)
-l {db2,n1ql,pl/sql,plsql,redshift,spark,sql}, --langauge {db2,n1ql,pl/sql,plsql,redshift,spark,sql}
SQL Formatter dialect (defaults to basic sql)
-i N, --indent N Number of spaces to indent query blocks (defaults to
2)
-t, --tab-indent Indent query blocks with tabs instead of spaces
-u, --uppercase Capitalize language keywords
--lines-between-queries N
How many newlines to insert between queries
(separated by ";")
By default, the tool takes queries from stdin and processes them to stdout but
the -f
/--file
and -o
/--output
flags can be used to alter this behavior.
echo 'select * from tbl where id = 3' | npx @gwax/sql-formatter -u
SELECT
*
FROM
tbl
WHERE
id = 3
import sqlFormatter from '@gwax/sql-formatter';
console.log(sqlFormatter.format('SELECT * FROM tbl'));
This will output:
SELECT
*
FROM
tbl
You can also pass in configuration options:
sqlFormatter.format('SELECT * FROM tbl', {
language: 'spark', // Defaults to "sql"
indent: ' ', // Defaults to two spaces
uppercase: bool, // Defaults to false
linesBetweenQueries: 2, // Defaults to 1
});
Currently just six SQL dialects are supported:
// Named placeholders
sqlFormatter.format('SELECT * FROM tbl WHERE foo = @foo', {
params: { foo: "'bar'" },
});
// Indexed placeholders
sqlFormatter.format('SELECT * FROM tbl WHERE foo = ?', {
params: ["'bar'"],
});
Both result in:
SELECT
*
FROM
tbl
WHERE
foo = 'bar'
If you don't use a module bundler, clone the repository, run npm install
and grab a file from /dist
directory to use inside a <script>
tag.
This makes SQL Formatter available as a global variable window.sqlFormatter
.
Make sure to run all checks:
npm run check
...and you're ready to poke us with a pull request.
FAQs
Format whitespace in a SQL query to make it more readable
The npm package @gwax/sql-formatter receives a total of 55 weekly downloads. As such, @gwax/sql-formatter popularity was classified as not popular.
We found that @gwax/sql-formatter demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.