![Maven Central Adds Sigstore Signature Validation](https://cdn.sanity.io/images/cgdhsj6q/production/7da3bc8a946cfb5df15d7fcf49767faedc72b483-1024x1024.webp?w=400&fit=max&auto=format)
Security News
Maven Central Adds Sigstore Signature Validation
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
@ovotech/pg-sql-migrate
Advanced tools
A very small library for running sql migrations with postgres. It differs from the numerous other libs in this domain by being very minimal, using only raw timestamped sql files. No "down" migrations are provided by design, as that is usually a bad idea in production anyway.
yarn add @ovotech/pg-sql-migrate
add a configuration file, which by default is ./pg-sql-migrate.config.json
to configure the connection:
{
"client": "postgresql://postgres:dev-pass@0.0.0.0:5432/postgres",
"directory": "migrations",
"table": "migrations"
}
The default values for "directory" and "table" configuration is migrations
but you can override that if you need to.
Instead of a string you can use an object. This is passed directly to pg https://node-postgres.com/features/connecting
{
"client": {
"user": "postgres",
"password": "dev-pass",
"host": "0.0.0.0",
"database": "postgres",
"port": 5432
}
}
To create new migrations in the designated directory you can run:
yarn migrate create my_migration
This will create a file migrations/<timestamp>_my_migration.pgsql
that you can place raw sql into. After that, you can run the migration(s) by calling
yarn migrate execute
You can also specify the configuration as cli options
yarn migrate execute --config-directory ~/my/dir/migrations --config-table my-table --config-client postgresql://0.0.0.0:5432/my-database
In you code you can run it as a library
import { migrate } from '@ovotech/pg-sql-migrate';
await migrate();
In your config file you can use environment variables.
For example, if you have the env var PG_USER_PASS
setup, you can access it with:
{
"client": "postgresql://postgres:${PG_USER_PASS}@0.0.0.0:5432/postgres",
"directory": "migrations"
"table" "migrations"
}
You can choose a different location for the config file, or to just input its contents directly:
import { migrate } from '@ovotech/pg-sql-migrate';
import { createLogger } from 'winston';
await migrate();
await migrate({ config: 'custom-config.json' });
await migrate({
config: {
client: 'postgresql://postgres:dev-pass@0.0.0.0:5432/postgres',
// Custom table location
table: 'my_table',
// Custom directory for migration files
directory: 'migrations_dir',
},
});
// Custom logger
const logger = createLogger();
await migrate({ logger });
// Dry run
await migrate({ dryRun: true });
You can run the tests with:
yarn test
Style is maintained with prettier and eslint
yarn lint
Deployment is preferment by circleci automatically on merge / push to master, but you'll need to bump the package version numbers yourself.
Have a bug? File an issue with a simple example that reproduces this so we can take a look & confirm.
Want to make a change? Submit a PR, explain why it's useful, and make sure you've updated the docs (this file) and the tests (see test folder).
This project is licensed under Apache 2 - see the LICENSE file for details
FAQs
migrate db using postgres sql files
The npm package @ovotech/pg-sql-migrate receives a total of 0 weekly downloads. As such, @ovotech/pg-sql-migrate popularity was classified as not popular.
We found that @ovotech/pg-sql-migrate demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 333 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Security News
CISOs are racing to adopt AI for cybersecurity, but hurdles in budgets and governance may leave some falling behind in the fight against cyber threats.
Research
Security News
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.