
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@pgsql/scripts
Advanced tools
Migration script generation for PostgreSQL — derive revert and verify scripts from classified statement facts
Migration script generation for PostgreSQL: derive revert and verify scripts from the classified statement facts of a deploy script (classifyStatements in @pgsql/transform).
import { classifyStatements } from '@pgsql/transform';
import { revertFor, verifyFor } from '@pgsql/scripts';
import { loadModule } from 'plpgsql-parser';
await loadModule();
const facts = classifyStatements(deploySql);
const { sql: revertSql, warnings } = revertFor(facts);
const { sql: verifySql } = verifyFor(facts);
revertFor(facts) — mechanical inverses in reverse topological order of the statement dependency graph, so dependents are dropped before their dependencies and no CASCADE is ever needed. Inverses are built as AST nodes and deparsed (pgsql-deparser), never string-templated.verifyFor(facts) — one existence check per created object, each raising on failure via SELECT 1/(CASE WHEN <exists> THEN 1 ELSE 0 END);.Nothing outside the supported vocabulary is ever guessed at: revertFor emits a -- revert not derivable: <reason> comment plus a warning; verifyFor emits nothing plus a warning. The list is exported as SUPPORTED_STATEMENTS (and SUPPORTED_NODE_TAGS).
| Statement | Revert | Verify |
|---|---|---|
CREATE SCHEMA | DROP SCHEMA | information_schema.schemata |
CREATE TABLE | DROP TABLE | to_regclass |
CREATE VIEW | DROP VIEW | to_regclass |
CREATE INDEX | DROP INDEX | to_regclass |
CREATE SEQUENCE | DROP SEQUENCE | to_regclass |
CREATE TYPE (composite, enum, range) | DROP TYPE | to_regtype |
CREATE DOMAIN | DROP DOMAIN | to_regtype |
CREATE FUNCTION / PROCEDURE | DROP FUNCTION / PROCEDURE with input signature (overload safe) | to_regprocedure |
CREATE TRIGGER | DROP TRIGGER ... ON table | pg_trigger |
CREATE POLICY | DROP POLICY ... ON table | pg_policies |
CREATE EXTENSION | DROP EXTENSION | pg_extension |
CREATE ROLE | DROP ROLE | pg_roles |
ALTER TABLE ... ADD COLUMN | DROP COLUMN | information_schema.columns |
ALTER TABLE ... ADD CONSTRAINT (named) | DROP CONSTRAINT | information_schema.table_constraints |
ALTER TABLE ... ENABLE / FORCE ROW LEVEL SECURITY | DISABLE / NO FORCE | pg_class.relrowsecurity / relforcerowsecurity |
GRANT privileges (tables, sequences, functions, schemas) | REVOKE same privileges | has_table_privilege / has_function_privilege / has_schema_privilege |
GRANT role TO role | REVOKE role FROM role | pg_auth_members |
COMMENT ON | COMMENT ON ... IS NULL | — |
Not derivable (warned, never guessed): REVOKE, unnamed constraints, ALTER ... SET with unknown prior value, arbitrary DML, dynamic SQL.
🛠 Built by the Constructive team — creators of modular Postgres tooling for secure, composable backends. If you like our work, contribute on GitHub.
pgsql-parser.pgsql-parser for parsing and deparsing SQL queries.AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.
No developer or entity involved in creating Software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the Software code or Software CLI, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.
FAQs
Migration script generation for PostgreSQL — derive revert and verify scripts from classified statement facts
The npm package @pgsql/scripts receives a total of 5,119 weekly downloads. As such, @pgsql/scripts popularity was classified as popular.
We found that @pgsql/scripts demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.