Hub rules-drizzle

rules-drizzle

v5 public Verified

Drizzle

Drizzle ORM is a lightweight, type-safe TypeScript ORM with SQL-like syntax. These rules govern schema definition, migrations, and efficient database querying for modern TypeScript projects.

@sigmashakeinc 2 pulls 5 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-drizzle →
Severity
4 error 1 warn 0 info
demo.cast
Drizzle ORM is a lightweight, type-safe TypeScript ORM with SQL-like syntax. These rules govern schema definition, migrations, and efficient database querying for modern TypeScript projects.

Rules index

5 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

drizzle

drizzle-delete-without-where error block

RISK: db.delete(table) without a .where() clause deletes ALL rows in the table — this is a catastrophic data loss operation equivalent to TRUNCATE. FIX: Always chain .where(eq(table.id, id)) or similar; if a bulk delete is intended, add an explicit comment and a safety check.

Rule source requires an active Pro or Enterprise subscription.
drizzle-hardcoded-connection-string error log

RISK: A database connection string with credentials is hardcoded in source code and will be committed to version control, leaking credentials. FIX: Read the connection URL from process.env.DATABASE_URL and store it in a .env file (gitignored) or a secrets manager.

Rule source requires an active Pro or Enterprise subscription.
drizzle-raw-sql-template warning log

Drizzle sql`` tagged template detected. Ensure all interpolated values are either static Drizzle references (table/column objects) or wrapped with sql.placeholder()/sql.param() — never interpolate raw user input. See drizzle-sql-injection-interpolation rule for the hard block.

Rule source requires an active Pro or Enterprise subscription.
drizzle-sql-injection-interpolation error block

RISK: Interpolating a non-sql() value directly into a Drizzle sql`` tagged template bypasses parameterization and enables SQL injection (CWE-89). FIX: Wrap any variable with sql.placeholder() or pass it as a Drizzle column/table reference; use parameterized placeholders via the Drizzle query builder rather than raw interpolation.

Rule source requires an active Pro or Enterprise subscription.
drizzle-update-without-where error block

RISK: db.update(table).set({...}) without a .where() clause applies the update to every row in the table. FIX: Always chain .where(eq(table.id, id)); use Drizzle's drizzle.config.ts strict mode to enforce this at compile time.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
ad0a3243fcea7871cac810905562a140402ffeb60823a516aa5f4333b554dcfc
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-drizzle/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-drizzle. The published version only bumps when a maintainer resyncs.

No commit history available.