Databasev0.1.8
@tekir/db
ActiveRecord ORM with fluent query builder, migrations, relationships, and hooks.
Installation
$
bun add @tekir/dbFeatures
- ActiveRecord BaseModel with CRUD, scopes, and casts
- Fluent QueryBuilder with where, join, orderBy, paginate
- Schema migrations with TableBuilder and ColumnBuilder
- Relationships: hasOne, hasMany, belongsTo, manyToMany
- Lifecycle hooks: beforeCreate, afterSave, beforeDelete, etc.
- Drizzle ORM integration with sql template literals
Quick Example
TypeScript
import { BaseModel, column, hasMany } from '@tekir/db'
class User extends BaseModel {
static table = 'users'
static schema = {
id: column.integer({ isPrimary: true }),
name: column.string(),
}
}
const users = await User.query().where('name', 'Ali').all()Changelog
v0.1.8LatestSeptember 16, 2026
- Transactions no longer replay or erase concurrent writes during rollback, migrations apply atomically, and SQLite snapshots preserve schema objects and integer values safely.
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.7July 23, 2026
- Optional PostgreSQL and MySQL drivers are resolved from the package module consistently, including combined and parallel test runs.
v0.1.5July 16, 2026
orWhereconditions now participate in update, delete, increment, and decrement mutations, preventing an OR-only mutation from accidentally affecting every row.- Database CLI, transaction, model, and query-builder error paths now fail explicitly instead of silently continuing with partial state.
v0.1.4June 13, 2026
- Database TLS verification is now on by default. When SSL is in play and no explicit object is given, the driver applies
{ rejectUnauthorized: true }; turning verification off now requires an explicit{ rejectUnauthorized: false }. Thesslconfig also accepts an optionalca. - Every SQL identifier (table and column names in
createTable/dropTable/renameColumnand foreign keys) is now validated against a strict allowlist, so quote/backtick escape attempts throwInvalid SQL identifierinstead of splicing into the query. Model aggregates (sum/avg/min/max/increment/decrement) now validate the column against the model schema. transaction()now runs a realBEGIN/COMMIT/ROLLBACKagainst a single dedicated connection for Postgres, MySQL, and SQLite, so queries inside the callback are genuinely atomic and roll back together on error. Migrations run all their DDL statements inside a transaction where the engine supports it.- Connection pools now apply sane defaults (
max/idle/connection timeouts) and the Postgres pool attaches an error handler so an idle-client error cannot crash the process. Driver connection errors are masked so the connection string password is no longer leaked into error messages. - Pagination clamps
page/perPageto safe bounds (no negativeOFFSET, no zero/NaNLIMIT). - Found and fixed with Fable.
v0.1.3May 17, 2026
select(...)now rejects column strings that contain parentheses, whitespace, semicolons, or SQL comment markers. The previous behaviour silently passed any string containing(through as raw SQL so callers could writeselect('COUNT(*)'), but it also meant a request value that reachedselect()could splice arbitrary SQL into the query. Aggregate expressions move to a new opt-inselectRaw(expression)API; the built-incount()/sum()/avg()/min()/max()already use the raw path and keep working unchanged.forPage(page, perPage)rejects values below 1 and non-finite numbers instead of producing negativeLIMIT/OFFSET. The check funnels through the existinglimit()andoffset()guards so the rest of the builder sees a single validated state.drizzle-ormbumped to^0.45.2to pick up the upstream SQL identifier escaping fix.
v0.1.2May 12, 2026
- Internal release covered by 0.1.3 notes.
v0.1.1April 27, 2026
static hooks = { beforeCreate: [(user: User) => ...] }on a subclass now type-checks. Previously the hook callback's typed parameter clashed with the base class's stricterunknownsignature.DatabaseProvidernow auto-exposes its migration commands (migrate,migrate:rollback,migrate:status,migrate:fresh, etc.). Apps that register the provider get the commands wired intobun run index.ts <command>without listing them instart/commands.ts.
v0.1.0April 1, 2026
- Initial release