You're Invited:Meet the Socket Team at BlackHat and DEF CON in Las Vegas, Aug 4-6.RSVP โ†’
Socket
Book a DemoInstallSign in
Socket

pgsql-parser

Package Overview
Dependencies
Maintainers
1
Versions
168
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

pgsql-parser

The real PostgreSQL query parser

17.7.10
latest
Source
npmnpm
Version published
Maintainers
1
Created
Source

pgsql-parser

The real PostgreSQL parser for Node.js. Built with the actual PostgreSQL parser, pgsql-parser delivers true-to-spec SQL parsing and reconstruction. Transform SQL queries into ASTs, modify them programmatically, and convert them back to SQL with complete fidelity.

Installation

npm install pgsql-parser

Features

  • ๐Ÿ”„ Symmetric Parsing & Deparsing โ€“ Parse SQL to AST and reconstruct it back to SQL with perfect round-trip accuracy
  • ๐Ÿงช Battle-Tested Reliability โ€“ Validated against 23,000+ SQL statements ensuring production-grade stability
  • ๐Ÿ”ง Direct from PostgreSQL โ€“ Uses the official Postgres C parser compiled to WebAssembly for 100% spec compliance
  • ๐Ÿš€ WebAssembly Powered: - Cross-platform compatibility without native dependencies.
  • ๐Ÿ› ๏ธ AST Manipulation: - Easily modify parts of a SQL statement through the AST.

API

The package exports both async and sync methods. Async methods handle initialization automatically, while sync methods require explicit initialization.

โš ๏ธ If you don't need the parser functionality, consider using the TS-only (no WASM, zero runtime dependencies) pgsql-deparser for a super fast, lightweight deparser. Battle-tested with 23,000+ SQL statements ๐Ÿš€

import { parse, deparse } from 'pgsql-parser';

// Parse SQL to AST
const stmts = await parse('SELECT * FROM test_table');

// Deparse AST back to SQL
const sql = await deparse(stmts);

Sync Methods

Sync methods require explicit initialization using loadModule():

import { loadModule, parseSync, deparseSync } from 'pgsql-parser';

// Initialize first (required for sync methods)
await loadModule();

// Now safe to use sync methods
const stmts = parseSync('SELECT * FROM test_table');
const sql = deparseSync(stmts);

Note: We recommend using async methods as they handle initialization automatically. Use sync methods only when necessary, and always call loadModule() first.

Parser Example

Rewrite part of a SQL query:

import { parse, deparse } from 'pgsql-parser';

const stmts = await parse('SELECT * FROM test_table');

// Assuming the structure of stmts is known and matches the expected type
stmts[0].RawStmt.stmt.SelectStmt.fromClause[0].RangeVar.relname = 'another_table';

console.log(await deparse(stmts));

// SELECT * FROM "another_table"

Deparser Example

The pgsql-deparser module serializes ASTs to SQL in pure TypeScript, avoiding the full parser's native dependencies. It's useful when only SQL string conversion from ASTs is needed, and is written in pure TypeScript for easy cross-environment deployment.

Here's how you can use the deparser in your TypeScript code, using @pgsql/utils to create an AST for deparse:

import * as t from '@pgsql/utils';
import { RangeVar, SelectStmt } from '@pgsql/types';
import { deparse } from 'pgsql-deparser';

// This could have been obtained from any JSON or AST, not necessarily @pgsql/utils
const stmt: { SelectStmt: SelectStmt } = t.nodes.selectStmt({
  targetList: [
    t.nodes.resTarget({
      val: t.nodes.columnRef({
        fields: [t.nodes.aStar()]
      })
    })
  ],
  fromClause: [
    t.nodes.rangeVar({
      relname: 'some_table',
      inh: true,
      relpersistence: 'p'
    })
  ],
  limitOption: 'LIMIT_OPTION_DEFAULT',
  op: 'SETOP_NONE'
});

// Modify the AST if needed  
(stmt.SelectStmt.fromClause[0] as {RangeVar: RangeVar}).RangeVar.relname = 'another_table';

// Deparse the modified AST back to a SQL string
console.log(await deparse(stmt));

// Output: SELECT * FROM another_table

Credits

Built on the excellent work of several contributors:

  • pgsql-parser: The real PostgreSQL parser for Node.js, providing symmetric parsing and deparsing of SQL statements with actual PostgreSQL parser integration.
  • pgsql-deparser: A streamlined tool designed for converting PostgreSQL ASTs back into SQL queries, focusing solely on deparser functionality to complement pgsql-parser.
  • @pgsql/parser: Multi-version PostgreSQL parser with dynamic version selection at runtime, supporting PostgreSQL 15, 16, and 17 in a single package.
  • @pgsql/types: Offers TypeScript type definitions for PostgreSQL AST nodes, facilitating type-safe construction, analysis, and manipulation of ASTs.
  • @pgsql/enums: Provides TypeScript enum definitions for PostgreSQL constants, enabling type-safe usage of PostgreSQL enums and constants in your applications.
  • @pgsql/utils: A comprehensive utility library for PostgreSQL, offering type-safe AST node creation and enum value conversions, simplifying the construction and manipulation of PostgreSQL ASTs.
  • @pgsql/traverse: PostgreSQL AST traversal utilities for pgsql-parser, providing a visitor pattern for traversing PostgreSQL Abstract Syntax Tree nodes, similar to Babel's traverse functionality but specifically designed for PostgreSQL AST structures.
  • pg-proto-parser: A TypeScript tool that parses PostgreSQL Protocol Buffers definitions to generate TypeScript interfaces, utility functions, and JSON mappings for enums.
  • libpg-query: The real PostgreSQL parser exposed for Node.js, used primarily in pgsql-parser for parsing and deparsing SQL queries.

Disclaimer

AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.

No developer or entity involved in creating Software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the Software code or Software CLI, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.

Keywords

sql

FAQs

Package last updated on 23 Jul 2025

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts