
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@pgsql/transform
Advanced tools
AST-based SQL transformation, qualification, classification and closure analysis for PostgreSQL
AST-based SQL transformation, qualification, classification, and dependency-closure analysis for PostgreSQL. Works on plain SQL and inside PL/pgSQL function bodies (via plpgsql-parser hydration) — no regexes.
Looking for the PG13→17/18 version-upgrade AST transformer previously published under this name? It now lives at
@pgsql/transform-ast.
npm install @pgsql/transform
The parser runs on a WASM build of the real PostgreSQL parser; call loadModule() from plpgsql-parser once before using any synchronous API.
transformSql — schema-name rewritingRewrite schema names everywhere they can appear (DDL, DML, function bodies, trigger definitions, grants, policies, comments, type casts, string-embedded types inside PL/pgSQL, ...):
import { loadModule } from 'plpgsql-parser';
import { transformSql } from '@pgsql/transform';
await loadModule();
const mapping = new Map([['my-schema', 'my_schema']]);
const { sql } = transformSql(inputSql, mapping);
classifyStatements — per-statement AST factsimport { classifyStatements } from '@pgsql/transform';
const facts = classifyStatements(sql);
// per statement: kind (schema|table|view|index|type|function|trigger|policy|grant|...),
// creates, references (incl. inside PL/pgSQL bodies), referencedSchemas, roles,
// fkTargets, securityRelevant, securityDefiner, dynamicSql
qualifyUnqualified — add schema qualificationQualify unqualified object references against an inventory of known objects, with multi-schema routing support.
normalizeTree / cleanTree / validateRoundTrip — dependency-free AST normalization and mutation-aware parse→deparse→re-parse validation.
@pgsql/traverseThis package owns policy, not traversal. Every entry point above parses once,
then drives walk from @pgsql/traverse over the parsed script — statements and
hydrated PL/pgSQL bodies alike — with a visitor built here:
| Concern | Lives here |
|---|---|
| Which schema/role/extension a name maps to | SchemaRouter, RoleRouter, extension routes |
| What counts as a reference, a creation, a security-relevant statement | classifyStatements |
| When an unqualified name should be qualified | qualifyUnqualified |
| Whether the rewritten SQL still parses to the same tree | validateRoundTrip |
| How to reach every node of a SQL or PL/pgSQL AST | @pgsql/traverse |
So mapping logic never moves into the walker, and traversal logic never moves in
here. Some passes keep per-statement state (CTE names in qualifyUnqualified,
per-statement facts in classifyStatements) and drive the walkSqlAst /
walkPlpgsqlAst primitives directly with a visitor per statement.
Consequence for contributors: __fixtures__/output/ is the regression gate for
traversal changes made anywhere in the ecosystem. A walker change that alters
these golden files is a behavior change, not a refactor.
npm run fixtures — regenerate __fixtures__/output/ golden files from __fixtures__/input/npm run scan-corpus <dir> [dir...] — audit node-type coverage over a SQL corpus🛠 Built by the Constructive team — creators of modular Postgres tooling for secure, composable backends. If you like our work, contribute on GitHub.
pgsql-parser.pgsql-parser for parsing and deparsing SQL queries.AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.
No developer or entity involved in creating Software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the Software code or Software CLI, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.
FAQs
AST-based SQL transformation, qualification, classification and closure analysis for PostgreSQL
The npm package @pgsql/transform receives a total of 3,100 weekly downloads. As such, @pgsql/transform popularity was classified as popular.
We found that @pgsql/transform demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.