
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@pgsql/semantics
Advanced tools
AST-derived semantic facts for PostgreSQL statements: what each statement creates, references, and touches
AST-derived semantic facts for PostgreSQL statements: given a SQL script,
extract what each statement is, what it creates, and what it references —
including references reached inside PL/pgSQL function bodies (via plpgsql-parser
hydration). Read-only: the input is never modified.
This is the fact-extraction layer that grew up inside @pgsql/transform.
It extracts semantics (which relations/functions/types a statement reads and
creates, which namespaces it touches), independent of any transformation.
@pgsql/transform re-exports the same symbols, so existing consumers are
unaffected.
npm install @pgsql/semantics
The parser runs on a WASM build of the real PostgreSQL parser; call loadModule()
from plpgsql-parser once before using any synchronous API.
import { loadModule } from 'plpgsql-parser';
import { classifyStatements } from '@pgsql/semantics';
await loadModule();
const facts = classifyStatements(sql);
// per statement: kind (schema|table|view|index|type|function|trigger|policy|grant|...),
// creates, references (incl. inside PL/pgSQL bodies), bodyReferences,
// referencedSchemas, roles, fkTargets, extension, securityRelevant,
// securityDefiner, dynamicSql, span, stmt
classifyStatements(sql) — classify each top-level statement into StatementFacts[].StatementFacts, StatementKind, QualifiedName, ExtensionFact, ExtensionAction, StatementSpan.🛠 Built by the Constructive team — creators of modular Postgres tooling for secure, composable backends. If you like our work, contribute on GitHub.
pgsql-parser.pgsql-parser for parsing and deparsing SQL queries.AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.
No developer or entity involved in creating Software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the Software code or Software CLI, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.
FAQs
AST-derived semantic facts for PostgreSQL statements: what each statement creates, references, and touches
We found that @pgsql/semantics demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.