
Security News
npm Introduces minimumReleaseAge and Bulk OIDC Configuration
npm rolls out a package release cooldown and scalable trusted publishing updates as ecosystem adoption of install safeguards grows.
@prisma/sqlcommenter
Advanced tools
Type definitions for SQL commenter plugins in Prisma Client.
This package provides TypeScript types for creating SQL commenter plugins that add metadata to SQL queries as comments. The comments follow the sqlcommenter format developed by Google.
SQL comments are useful for:
traceparentnpm install @prisma/sqlcommenter
A SQL commenter plugin is a function that receives query context and returns key-value pairs to be added as comments:
import type { SqlCommenterPlugin, SqlCommenterContext } from '@prisma/sqlcommenter'
const myPlugin: SqlCommenterPlugin = (context: SqlCommenterContext) => {
return {
application: 'my-app',
version: '1.0.0',
}
}
Pass your plugins to the comments option when creating a PrismaClient instance:
import { PrismaClient } from '@prisma/client'
import { PrismaPg } from '@prisma/adapter-pg'
const adapter = new PrismaPg({ connectionString: `${process.env.DATABASE_URL}` })
const prisma = new PrismaClient({
adapter,
comments: [myPlugin],
})
@prisma/sqlcommenter-query-tags: appends arbitrary tags to all queries within an async context.@prisma/sqlcommenter-trace-context: appends traceparent comments to SQL queries for distributed tracing.@prisma/sqlcommenter-query-insights: enables query insights for Prisma Postgres.Plugins receive a SqlCommenterContext object with information about the query being executed.
See API Reference for more details.
Plugins return a SqlCommenterTags object where keys can have undefined values. Keys with undefined values are automatically filtered out from the final comment:
import type { SqlCommenterPlugin } from '@prisma/sqlcommenter'
const conditionalPlugin: SqlCommenterPlugin = (context) => ({
model: context.query.modelName, // undefined for raw queries, automatically omitted
action: context.query.action,
// Include SQL length only when available (not available with Accelerate)
sqlLength: context.sql ? String(context.sql.length) : undefined,
})
import type { SqlCommenterPlugin } from '@prisma/sqlcommenter'
const applicationTags: SqlCommenterPlugin = (context) => ({
application: 'my-service',
environment: process.env.NODE_ENV ?? 'development',
operation: context.query.action,
model: context.query.modelName, // automatically omitted if undefined
})
import { AsyncLocalStorage } from 'node:async_hooks'
import type { SqlCommenterPlugin } from '@prisma/sqlcommenter'
const routeStorage = new AsyncLocalStorage<{ route: string }>()
const routeContext: SqlCommenterPlugin = () => ({
route: routeStorage.getStore()?.route,
})
The plugin outputs are merged, sorted by key, URL-encoded, and formatted according to the sqlcommenter specification:
SELECT "id", "name" FROM "User" /*application='my-app',environment='production',model='User'*/
SqlCommenterTagstype SqlCommenterTags = { readonly [key: string]: string | undefined }
Key-value pairs to add as SQL comments. Keys with undefined values are automatically filtered out and will not appear in the final comment.
SqlCommenterPlugininterface SqlCommenterPlugin {
(context: SqlCommenterContext): SqlCommenterTags
}
A function that receives query context and returns key-value pairs. Return an empty object to add no comments for a particular query. Keys with undefined values are automatically omitted.
SqlCommenterContextinterface SqlCommenterContext {
query: SqlCommenterQueryInfo
sql?: string
}
Context provided to plugins containing information about the query.
query: Information about the Prisma query being executed. See SqlCommenterQueryInfo.sql: The SQL query being executed. It is only available when using driver adapters but not when using Accelerate.SqlCommenterQueryInfotype SqlCommenterQueryInfo =
| ({ type: 'single' } & SqlCommenterSingleQueryInfo)
| ({ type: 'compacted' } & SqlCommenterCompactedQueryInfo)
Information about the query or queries being executed.
type: 'single': A single Prisma query is being executedtype: 'compacted': Multiple queries have been batched into a single SQL statement (e.g., automatic findUnique batching)SqlCommenterSingleQueryInfointerface SqlCommenterSingleQueryInfo {
modelName?: string
action: SqlCommenterQueryAction
query: unknown
}
Information about a single Prisma query.
modelName: The model being queried (e.g., "User", "Post"). Undefined for raw queries.action: The Prisma operation (e.g., "findMany", "createOne", "queryRaw")query: The full query object with selection and arguments. Specifics of the query representation are not part of the public API yet.SqlCommenterCompactedQueryInfointerface SqlCommenterCompactedQueryInfo {
modelName?: string
action: SqlCommenterQueryAction
queries: unknown[]
}
Information about a compacted batch query.
modelName: The model being queried (e.g., "User", "Post").action: The Prisma operation (e.g., "findUnique")queries: The full query objects with selections and arguments. Specifics of the query representation are not part of the public API yet.undefined values are filtered out (they do not remove keys set by earlier plugins)\'Apache-2.0
FAQs
SQL commenter types for Prisma
We found that @prisma/sqlcommenter demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
npm rolls out a package release cooldown and scalable trusted publishing updates as ecosystem adoption of install safeguards grows.

Security News
AI agents are writing more code than ever, and that's creating new supply chain risks. Feross joins the Risky Business Podcast to break down what that means for open source security.

Research
/Security News
Socket uncovered four malicious NuGet packages targeting ASP.NET apps, using a typosquatted dropper and localhost proxy to steal Identity data and backdoor apps.