Overview
Drizzle security — SQL injection in raw queries
Live from GitHub
This content is fetched directly from README.md on GitHub and cached for 1 hour.
AI-Optimized Security
Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.
Rules (1)
Browse all Drizzle security rules with CWE/OWASP mapping
Changelog
View version history and updates
Security rules for drizzle-orm (SQL injection prevention in raw queries).
⭐ If this plugin caught a real bug for you, star the repo — it's the signal that keeps these rules maintained.
Description
This plugin provides Security rules for drizzle-orm (SQL injection prevention in raw queries).
Why Drizzle-specific?
Being Drizzle-specific is what makes the rule precise. It knows which calls are raw-SQL sinks (.raw()) and which idioms are already safe, so it reports the patterns that actually lead to injection and stays quiet on parameterized queries. It also tracks variable taint across statements, so a query built on one line and executed on another is still reported.
The detection itself is shared with the other Interlace driver plugins through createSqlInjectionRule — install the one matching your stack and you get exactly one finding per line.
Philosophy
Interlace fosters strength through integration. Instead of stacking isolated rules, we interlace security directly into your workflow to create a resilient fabric of code. We believe tools should guide rather than gatekeep, providing educational feedback that strengthens the developer with every interaction.
Getting Started
- To check out the guide, visit eslint.interlace.tools. 📚
- 要查看中文 指南, 请访问 eslint.interlace.tools. 📚
- 가이드 문서는 eslint.interlace.tools에서 확인하실 수 있습니다. 📚
- ガイドは eslint.interlace.toolsでご確認ください。 📚
- Para ver la guía, visita eslint.interlace.tools. 📚
- للاطلاع على الدليل، قم بزيارة eslint.interlace.tools. 📚
npm install eslint-plugin-drizzle-security --save-dev⚙️ Configuration Presets
| Preset | Description |
|---|---|
recommended | Recommended preset - balanced security for most projects |
strict | Strict preset - all rules as errors |
flagship | Highest-signal rules only, for CI gates |
📚 Supported Libraries
Custom Configuration
import drizzle from 'eslint-plugin-drizzle-security';
export default [
{
plugins: { 'sequelize-security': sequelizeSecurity },
rules: {
'drizzle-security/no-unsafe-query': 'error',
},
},
];💡 What You Get
- Covers the escapes your ORM leaves open:
.raw() - Drizzle's own remediation: every finding names Drizzle's own safe API, not a generic "use parameterized queries"
- Cross-statement taint tracking: catches queries assembled over several lines, including with
+= - Quiet on safe code: parameterized queries, static SQL and builder calls do not report
- LLM-optimized messages: structured 2-line errors with CWE + fixes that AI assistants can apply
Every rule produces a structured error message:
src/db.ts
42:15 error 🔒 CWE-89 OWASP:A03-Injection CVSS:9.8 | Unsafe SQL query construction detected (template literal) | CRITICAL
Fix: Use the `sql` tagged template, which parameterizes interpolated values, instead of `sql.raw()`.📦 Compatibility
| Package | Version |
|---|---|
| ESLint | ^8.0.0 || ^9.0.0 || ^10.0.0 |
| Node.js | >=18.0.0 |
See the ESLint Version Support Policy — current ecosystem share data, the 20% gate, and the forward-looking exception that covers v10.
Rules
Legend
| Icon | Description |
|---|---|
| 💼 | Recommended: Included in the recommended preset. |
| ⚠️ | Warns: Set to warn in recommended preset. |
| 🔧 | Auto-fixable: Automatically fixable by the --fix CLI option. |
| 💡 | Suggestions: Providing code suggestions in IDE. |
| 🚫 | Deprecated: This rule is deprecated. |
| 🟢 | Type-unaware: AST-only, runs in oxlint JS-plugin tier. |
| 🟡 | Type-aware (refining): pure-AST primary path; types refine precision. |
| 🟠 | Type-aware (graceful): requires TS program; silent without it. |
| Rule | CWE | OWASP | CVSS | Description | 🧠 | 💼 | ⚠️ | 🔧 | 💡 | 🚫 |
|---|---|---|---|---|---|---|---|---|---|---|
| no-unsafe-query | CWE-89 | A03:2021 | Prevent SQL injection by disallowing string concatenation or interpolated template literals in Drizzle sql.… | 🟢 | 💼 | |||||
| no-unscoped-mutation | CWE-284 | A01:2021 | Require a chained .where() on Drizzle delete and update builders, so a bulk mutation cannot rewrite or de… | 🟢 |
🔗 Related ESLint Plugins
Part of the Interlace ESLint Ecosystem — AI-native security plugins with LLM-optimized error messages:
| Plugin | Downloads | Description |
|---|---|---|
eslint-plugin-secure-coding | General security rules & OWASP guidelines. | |
eslint-plugin-pg | PostgreSQL security & best practices. | |
eslint-plugin-node-security | Node.js core-module security (fs, child_process, vm, crypto, Buffer). | |
eslint-plugin-jwt | JWT security & best practices. | |
eslint-plugin-browser-security | Browser-specific security & XSS prevention. | |
eslint-plugin-express-security | Express.js security hardening rules. | |
eslint-plugin-lambda-security | AWS Lambda security best practices. | |
eslint-plugin-nestjs-security | NestJS security rules & patterns. | |
eslint-plugin-mongodb-security | MongoDB security best practices. | |
eslint-plugin-vercel-ai-security | Vercel AI SDK security hardening. | |
eslint-plugin-import-next | Next-gen import sorting & architecture. |
⭐ Support & follow
If this plugin caught a real bug for you, star the repo — stars are the signal that keeps the Interlace ESLint ecosystem maintained — and follow the writeups on Dev.to for the benchmarks and security research behind these rules.
📄 License
MIT © Ofri Peretz
View README.md on GitHub →
Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.
