Drizzle ORM 0.45.2 fixes SQL identifier escaping
Drizzle ORM 0.45.2 fixes improper escaping in sql.identifier() and sql.as() that could enable SQL injection. Teams using either helper should prioritize the patch and run query-generation tests.
- Published
- Coverage
- Backend
- Desk
- OpenStack Daily Editorial

Release overview
drizzle-team/drizzle-orm published 0.45.2 on 2026-03-27. This page was generated deterministically from the public GitHub release and does not use an LLM.
View the official GitHub release
The report preserves upstream wording wherever possible. The breaking-change badge is based on explicit keywords, not semantic interpretation.
Official release notes
- Fixed
sql.identifier(),sql.as()escaping issues. Previously all the values passed to this functions were not properly escaped causing a possible SQL Injection (CWE-89) vulnerability
Thanks to @EthanKim88, @0x90sh and @wgoodall01 for reaching out to us with a reproduction and suggested fix
Breaking changes and migration
The upstream notes do not contain an explicit breaking-change signal. This automated check is conservative, so verify deprecations and changed defaults in the official notes before upgrading.
Before the upgrade
1. Pin the currently deployed version.
2. Run the existing test and build suites.
3. Record warnings, bundle output, and runtime behavior.
After the upgrade
1. Install the exact release tag in a dedicated branch.
2. Run the same tests and production build.
3. Compare warnings, output, and critical user flows.
Verification checklist
- Read the complete upstream release notes and linked migration documents.
- Search the codebase for deprecated APIs and configuration keys named upstream.
- Upgrade in an isolated branch with a lockfile diff that can be reviewed.
- Run unit, integration, end-to-end, and production-build checks that apply to the project.
- Keep a rollback commit or previously deployed artifact available.
Frequently asked questions
Is this report generated by artificial intelligence?
No. The sync script fetches structured release data from GitHub and writes a fixed Markdown template. It does not call an LLM or send release content to an AI provider.
How is the breaking-change badge determined?
The script looks for explicit phrases such as "breaking change," "backward incompatible," "migration required," and "removed." This is a useful signal, but it cannot replace a developer reading the upstream notes.
Does the site modify the official release notes?
It only demotes heading levels so the upstream notes fit inside the article hierarchy. The original release link is always included for verification.
Can this report decide whether an upgrade is safe?
No. It provides discovery, provenance, and a consistent checklist. Compatibility decisions still require project-specific tests and engineering review.