
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
plpgsql-deparser
Advanced tools
PL/pgSQL AST Deparser - Converts PL/pgSQL function ASTs back to SQL strings.
⚠️ Experimental: This package is currently experimental. If you're looking for SQL deparsing (not PL/pgSQL), see
pgsql-deparser.
For full SQL + PL/pgSQL deparsing: If you need to deparse complete
CREATE FUNCTIONstatements (not just function bodies), useplpgsql-parserinstead. It handles the full heterogeneous parsing/deparsing pipeline automatically.
This package provides a body-only deparser for PL/pgSQL (PostgreSQL's procedural language) AST structures. It converts PL/pgSQL function bodies (the BEGIN...END part) back to strings. It works with the AST output from parsePlPgSQL function in @libpg-query/parser.
The PL/pgSQL AST is different from the regular SQL AST - it represents the internal structure of PL/pgSQL function bodies, including:
npm install plpgsql-deparser
import { parsePlPgSQL } from '@libpg-query/parser';
import { deparse, PLpgSQLDeparser } from 'plpgsql-deparser';
// Parse a PL/pgSQL function
const funcSql = `
CREATE OR REPLACE FUNCTION test_func()
RETURNS INTEGER AS $$
DECLARE
sum int := 0;
BEGIN
FOR n IN 1..10 LOOP
sum := sum + n;
END LOOP;
RETURN sum;
END;
$$ LANGUAGE plpgsql;
`;
const parseResult = await parsePlPgSQL(funcSql);
// Deparse the function body
const deparsed = await deparse(parseResult);
console.log(deparsed);
import { deparseSync, PLpgSQLDeparser } from 'plpgsql-deparser';
const deparsed = deparseSync(parseResult);
import { PLpgSQLDeparser } from 'plpgsql-deparser';
const deparser = new PLpgSQLDeparser({
indent: ' ', // 4 spaces instead of default 2
newline: '\n', // newline character
uppercase: false, // lowercase keywords
});
const deparsed = deparser.deparseResult(parseResult);
import { PLpgSQLDeparser } from 'plpgsql-deparser';
// If you have just the function body AST
const funcBody = parseResult.plpgsql_funcs[0].PLpgSQL_function;
const deparsed = PLpgSQLDeparser.deparseFunction(funcBody);
deparse(parseResult, options?)Async function to deparse a PL/pgSQL parse result.
deparseSync(parseResult, options?)Synchronous version of deparse.
deparseFunction(func, options?)Deparse a single PL/pgSQL function body.
deparseFunctionSync(func, options?)Synchronous version of deparseFunction.
PLpgSQLDeparserThe main deparser class with full control over the deparsing process.
PLpgSQLDeparserOptionsinterface PLpgSQLDeparserOptions {
indent?: string; // Indentation string (default: ' ')
newline?: string; // Newline character (default: '\n')
uppercase?: boolean; // Uppercase keywords (default: true)
}
This package deparses only the function body (the BEGIN...END part), not the full CREATE FUNCTION statement.
For full SQL + PL/pgSQL deparsing, use plpgsql-parser:
import { parse, deparseSync, loadModule } from 'plpgsql-parser';
await loadModule();
const parsed = parse(`
CREATE FUNCTION my_func() RETURNS void LANGUAGE plpgsql AS $$
BEGIN
RAISE NOTICE 'Hello';
END;
$$;
`);
// Full round-trip: parses SQL + PL/pgSQL, deparses back to complete SQL
const sql = deparseSync(parsed);
The plpgsql-parser package handles:
CREATE FUNCTION statementRETURN statement handling based on function return typeMIT
🛠 Built by the Constructive team — creators of modular Postgres tooling for secure, composable backends. If you like our work, contribute on GitHub.
pgsql-parser.pgsql-parser for parsing and deparsing SQL queries.AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.
No developer or entity involved in creating Software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the Software code or Software CLI, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.
FAQs
PL/pgSQL AST Deparser - Converts PL/pgSQL function ASTs back to SQL
The npm package plpgsql-deparser receives a total of 202,618 weekly downloads. As such, plpgsql-deparser popularity was classified as popular.
We found that plpgsql-deparser demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.