
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
ng-sql-parser
Advanced tools
SQL Parser is a lexer, grammar and parser for SQL written in JS. Currently it is only capable of parsing fairly basic SELECT queries but full SQL support will hopefully come in time. See the specs for examples of currently supported queries.
The package is distributed on NPM and can be installed with...
npm install ng-sql-parser
To build from source you'll need to run the following from the root of the project...
npm install
cake build
Tests are written using Mocha and can be run with...
npm test
The lexer takes a SQL query string as input and returns a stream of tokens in the format
['NAME', 'value', lineNumber]
Here is a simple example...
lexer.tokenize('select * from my_table')
[
['SELECT','select',1],
['STAR','*',1],
['FROM','from',1],
['LITERAL','my_table',1]
]
The tokenized output is in a format compatible with JISON.
The parser only currently supports SELECT queries but is able to produce a Select object with properties for where, group, order, limit. See lib/nodes.coffee for more info of the returned object structure. Calling .toString() on a Select object should give you back a well formatted version of the original SQL input.
tokens = lexer.tokenize('select * from my_table where foo = 'bar')
parser.parse(tokens).toString()
SELECT *
FROM `my_table`
WHERE `foo` = 'bar'
A lot of the boilerplate and compilation code in this project is borrowed from the CoffeeScript project as it was the best example of a project using JISON that I could find. Thanks.
Contributions in the form of pull requests that add syntax support are very welcome but should be supported by both Lexer and Parser level tests.
FAQs
Lexer and Parser for SQL Syntax
The npm package ng-sql-parser receives a total of 2 weekly downloads. As such, ng-sql-parser popularity was classified as not popular.
We found that ng-sql-parser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.