Skip to content
CAI
Software that uses CAICheck a score

brianc/node-postgres

60.7

Adequate · 1 October 2026

6.9k

lines of production code

JavaScript

with TypeScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive PostgreSQL client library for Node.js, structured as a monorepo containing core connection handling, connection pooling, and protocol parsing packages. It provides multiple execution modes, including a pure JavaScript implementation, a high-performance native binding via libpq, and a specialized adapter for Cloudflare Workers edge environments. The system supports modern module standards through explicit ESM exports and includes utilities for connection string parsing, cursor-based streaming, and query pipelining.

How it got here

2010–2019 — Monorepo modernization and ESM migration

18 changes.

The project was restructured into a monorepo using Yarn workspaces and Lerna, consolidating core packages and upgrading tooling to TypeScript and modern ESLint. This period focused on migrating the codebase to ES modules, introducing ES6 classes, and adding support for Cloudflare Workers and native libpq clients. Comprehensive test suites were added to validate the new architecture, ESM exports, and various client implementations.

2020–2024 — TypeScript migration and native bindings

13 changes.

This period focused on rewriting core packages like pg-protocol and pg-query-stream in TypeScript to improve performance and type safety, while introducing new capabilities such as Cloudflare Worker support and a high-performance native libpq binding. The work also included significant security enhancements for authentication and connection string parsing, alongside comprehensive testing infrastructure to support these architectural shifts.

2025–2026 — ESM support and testing infrastructure

8 changes.

This period focused on adding native ES Module entry points across all pg sub-packages to ensure compatibility with modern module systems and bundlers. Comprehensive testing infrastructure was established, including specific suites for ESM/CJS export verification, Cloudflare Workers integration, and bundler compatibility. Additionally, a new A/B benchmarking tool was introduced to facilitate performance comparisons between library versions.

Features

Add Cloudflare Worker compatible socket implementation

The pg-cloudflare package now includes a new \CloudflareSocket\ class that wraps the Cloudflare built-in \cloudflare:sockets\ API, enabling the PostgreSQL client to function within Cloudflare Workers environments. This change introduces the necessary socket abstraction (including \connect\, \write\, \end\, and \startTls\ methods) and corresponding TypeScript type definitions, allowing users to establish database connections in edge computing contexts where standard Node.js sockets are unavailable.

packages/pg-cloudflare/src · high confidence

Add ESM exports for pg-protocol

The pg-protocol package now supports ES Module imports via a new ESM wrapper. Users can import named exports such as DatabaseError, SASL, serialize, and parse, as well as the default export, directly from the esm entry point, enabling compatibility with modern bundlers and Node.js ESM environments.

packages/pg-protocol/esm · high confidence

Add ESM wrapper for pg-connection-string

The package now includes an ESM-compatible entry point at \packages/pg-connection-string/esm/index.mjs\. This wrapper re-exports the existing \parse\, \toClientConfig\, and \parseIntoClientConfig\ functions as named exports and provides a default export for \parse\, allowing consumers using ES modules to import these utilities directly without bundler configuration workarounds.

packages/pg-connection-string/esm · high confidence

Added ESM entry points for pg sub-packages

Users can now import the pg sub-packages (pg-cloudflare, pg-cursor, pg-native, pg-pool, and pg-query-stream) using native ES module syntax. This change introduces new ESM wrapper files (index.mjs) for each package that re-export the existing CommonJS functionality, ensuring compatibility with modern module systems while maintaining the same API surface as the CommonJS versions.

(repo-wide) · high confidence

Initial release of pg-cursor package

The pg-cursor package is now available, providing a PostgreSQL result cursor API for the pure JavaScript node-postgres client. The implementation uses an ES6 class extending EventEmitter to manage named portals, handling row streaming, queue management, and connection lifecycle events like readyForQuery and error states.

packages/pg-cursor · high confidence

Introduce ESM exports and refactor core modules to ES6 classes

The library now supports ES modules via a new \esm/index.mjs\ entry point that re-exports all public APIs (Client, Pool, Connection, types, etc.) from the CommonJS core. Internally, the main components (Client, Connection, Query, Result) have been converted to ES6 classes, and the connection logic has been refactored to support Cloudflare Workers through a new stream abstraction that detects the runtime and uses \pg-cloudflare\ when appropriate. Additionally, SSL configuration handling has been tightened to ensure non-enumerable SSL keys are forwarded correctly and to support the \sslnegotiation=direct\ option for PostgreSQL 17 compatibility.

packages/pg/lib · high confidence

Introduce pg-native package with high-performance PostgreSQL bindings

This change adds the \pg-native\ package to the monorepo, providing high-performance native bindings between Node.js and PostgreSQL via libpq. The package exposes a \Client\ class that supports both asynchronous and synchronous operations, including \connect\, \query\, \prepare\, and \execute\. It also introduces a \getTransactionStatus()\ method to retrieve the current transaction state (Idle, In-Transaction, or In-Error) and includes synchronous variants (\connectSync\, \querySync\, etc.) for use in scripts or bootstrapping. The implementation handles result building, error propagation, and notification listening, with a README detailing installation requirements for libpq across various operating systems.

packages/pg-native · high confidence

Introduce pg-native package with optimized result parsing and COPY streaming

This change adds the \pg-native\ package to the monorepo, providing a high-performance PostgreSQL client implementation. The \build-result.js\ module introduces optimized result handling by pre-allocating arrays for rows and fields, caching type parsers per column to avoid repeated lookups, and using pre-built empty objects to efficiently construct result rows. Additionally, the \copy-stream.js\ module implements a Duplex stream for handling PostgreSQL COPY operations, managing asynchronous data flow and error states via the native libpq interface.

packages/pg-native/lib · high confidence

Native PostgreSQL client implementation for pg

The native client module has been introduced to allow users to connect to PostgreSQL using the native libpq library instead of the pure-JavaScript implementation. This change adds a new client class that wraps \pg-native\, supporting features such as query pipelining, per-query timeouts, named prepared statements, and detailed error fields (detail, hint, etc.). Users can opt into this client via the \nativeConnectionString\ parameter or by explicitly requiring the native module, gaining potentially better performance and lower memory overhead for high-throughput workloads.

packages/pg/lib/native · high confidence

New A/B benchmarking tool for comparing library versions

Added a new benchmarking suite in the \benchmark/\ directory that enables A/B testing of two different checkouts of the repository (e.g., a base branch vs. a PR head) against the same database. The tool runs scenarios covering row parsing, parameter encoding, prepared statements, transactions, pooling, cursors, streams, and pipelining, then reports the median speedup ratio and noise levels. This allows developers to visually compare performance changes in the PR comment, focusing on relative ratios rather than absolute queries per second.

benchmark · high confidence

New standalone pg-connection-string package with enhanced SSL and TypeScript support

The \pg-connection-string\ module is now available as a standalone package, providing a \parse\ function for PostgreSQL connection strings and new TypeScript helper functions (\parseIntoClientConfig\, \toClientConfig\) to ensure compatibility with \pg.Client\'s \ClientConfig\ interface. The parser now supports the \sslnegotiation=direct\ parameter (required for PostgreSQL 17) and offers granular \sslmode\ handling, including a \useLibpqCompat\ option to align with libpq semantics. Additionally, the package improves security by redacting input URLs in error messages and warns users when non-standard SSL options are used.

packages/pg-connection-string · high confidence

Architecture

Repository restructured into a monorepo with Yarn workspaces and TypeScript tooling

The project has been reorganized into a monorepo structure managed by Lerna and Yarn workspaces, consolidating core packages like pg, pg-pool, pg-cursor, pg-query-stream, and pg-protocol under a single repository. This change introduces a new build and development workflow: TypeScript compilation is now configured via a root tsconfig.json with project references, linting uses a modern flat ESLint configuration (eslint.config.mjs), and the repository enforces consistent line endings via .gitattributes. Users and contributors should now install dependencies using Yarn and bootstrap the workspace with Lerna, replacing previous single-package setup methods.

(repo-wide) · high confidence

Behavioural changes

Connection pool behavior and configuration updates

The pg-pool library now supports a minimum client count (min option) to maintain a baseline number of connections, and allows Node.js to exit gracefully when the pool is idle (allowExitOnIdle). It also introduces a maxUses option to close connections after a specific number of uses, and an onConnect callback for client setup. Additionally, the pool now emits a 'release' event when a connection is returned, handles non-function callbacks more robustly, and ensures that pool.end() resolves before the last query completes.

packages/pg-pool · high confidence

Modernize script syntax and update module paths

The dump-db-types script has been moved to the packages/pg directory and updated to use modern JavaScript syntax, replacing var with const and removing \_\_dirname references in require calls. This change improves code consistency and aligns with current linting standards while maintaining the same functionality for database type dumping.

packages/pg/script · high confidence

Reimplementation of pg-query-stream in TypeScript with explicit callback handling

The pg-query-stream package has been rewritten in TypeScript, introducing a new \QueryStream.Config\ type for configuration options and explicitly invoking the internal callback on cursor end or error events to ensure proper cleanup and error propagation.

packages/pg-query-stream/src · high confidence

Rewritten binary protocol parser and serializer for improved performance

The \pg-protocol\ package has been completely rewritten in TypeScript to replace the previous implementation, introducing new \BufferReader\ and \Writer\ classes for handling binary data. This change significantly improves performance, particularly for \bytea\ data and \Bind\ message serialization, by optimizing buffer management and reducing string encoding passes. The new parser correctly reads \ParameterDescription\ type OIDs and other identifiers as unsigned integers, fixing potential issues with large OIDs, and includes a dedicated microbenchmark file (\b.ts\) to track these performance gains.

packages/pg-protocol/src · high confidence

SCRAM-SHA-256 authentication now uses SASLprep and supports channel binding

The PostgreSQL client now normalizes passwords using SASLprep (RFC 4013) before SCRAM-SHA-256 authentication, ensuring compatibility with PostgreSQL servers that apply the same normalization. It also adds support for SCRAM-SHA-256-PLUS (channel binding) when a TLS stream is present, improving security by binding the authentication to the TLS session. Additionally, a new scramMaxIterations option allows limiting the PBKDF2 iteration count to prevent excessive resource usage.

packages/pg/lib/crypto · high confidence

Test coverage

Add bundler compatibility tests for the workerd export condition; Add pg-native benchmarking scripts; Added Cloudflare Workers integration test; Added ESM/CJS export compatibility tests; Added TLS test certificates and build infrastructure; Added and updated unit tests for connection parameter parsing; Added benchmarking scripts and Cloudflare Worker test support; Added comprehensive test suite for pg-query-stream; Added integration tests for client API, configuration, and error handling; Added integration tests for connection pool behavior; Added test coverage for connection string parsing and client configuration conversion; Added test for password preservation in pooled connection copies; Added test infrastructure and Cloudflare Workers test configuration; Added test suite for native PostgreSQL client; Added test utilities for constructing PostgreSQL protocol messages; Added unit tests for connection SSL, Sync, and stream factory behavior; Added unit tests for result parsing and query utilities; Expanded integration test coverage for PostgreSQL client edge cases; Expanded test coverage for pg-pool lifecycle and configuration; Expanded unit test coverage for PostgreSQL client authentication and query handling; Initial test suite for pg-native client.

Dependencies

Monorepo structure with ESM exports and updated tooling

The project has been restructured into a monorepo containing individual packages for pg, pg-pool, pg-protocol, pg-cursor, pg-query-stream, pg-connection-string, pg-native, and pg-cloudflare. This change introduces explicit ESM exports (\.mjs\/\.mjs\ conditions) across these packages to support modern bundlers and Node.js environments. The documentation site has been migrated to a Next.js-based setup using Nextra, and the root workspace now utilizes Lerna for management. Development tooling has been upgraded, including TypeScript to version 6, ESLint to version 10, and Mocha to version 11, while the minimum supported Node.js version is set to 16.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 66 → 61 (-4.8)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 64 → 63 (-0.7)
  • Architecture 91 → 89 (-1.7)
  • Maturity 63 → 63 (-0.1)
  • Readiness 66 → 53 (-12.6)
  • Security 72 → 72 (+0.0)
  • Performance 85 (new)

Resolved (15)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • Hotspot: packages/pg-protocol/src/parser.ts (packages/pg-protocol/src/parser.ts)
  • Medium CVE: [GHSA redacted] (yarn.lock)
  • Off-boarding risk: anonymized user #1
  • _pulsePipelinedQueryQueue (cognitive 26) (packages/pg/lib/native/client.js)
  • _pulsePipelinedQueryQueue (cyclomatic 16) (packages/pg/lib/native/client.js)
  • pipeline (cognitive 24) (packages/pg-native/index.js)
  • pipeline (cyclomatic 16) (packages/pg-native/index.js)
  • submit (cognitive 24) (packages/pg/lib/native/query.js)
  • submit (cyclomatic 16) (packages/pg/lib/native/query.js)

New (33)

  • Circular dependency
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High vulnerability: [GHSA redacted] (yarn.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: packages/pg-native/index.js (packages/pg-native/index.js)
  • Hotspot: packages/pg/lib/native/client.js (packages/pg/lib/native/client.js)
  • Off the main sequence: pg-cloudflare
  • Off the main sequence: pg-protocol
  • Off-boarding risk: anonymized user #1
  • Outdated (npm): next
  • Outdated (npm): nextra
  • Outdated (npm): nextra-theme-docs
  • Outdated (npm): pg-types
  • …and 13 more

Changes since last survey

  • 7 commits — 3 feature/other, 4 fixes

By area

  • packages/pg — 3 commits
  • (root) — 2 commits
  • packages/pg-connection-string — 1 commit
  • packages/pg-cursor — 1 commit

Notable commits

  • fix: fix(pg): expose detail and hint on errors from the native client (#3780)
  • fix: fix(pg): run a named statement with an empty text more than once (#3781)
  • fix: fix(pg-connection-string): strip IPv6 URI brackets from the parsed host (#3698)
  • fix: fix(pg-cursor): preserve cursor state after late responses (#3785)
  • change: Publish
  • change: chore(pg-connection-string): remove unused istanbul dependency (#3790)
  • change: ci: benchmark every pull request against its base branch (#3775)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

brianc/node-postgres was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0980cefebe0ae461da8883703be049fe13ca96cf — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.