NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2073 by repository stars
Last release 2 months ago
06 Aug 2026
Release timing varies
gaps range from 8 days to 6 months
Some releases are documented
notes for 10 of 22 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
57 releases · first in 2023
One column per quarter.
Fix: Materialized view reconstruction uses WITH NO DATA
During plan validation, setSchemaForEmptyDatabase reconstructs the source schema in a temporary database. For materialized views, the Add() method previously emitted CREATE MATERIALIZED VIEW ... AS <query> without WITH NO DATA, causing Postgres to execute the view's stored query. This is unnecessary (the temp DB is discarded immediately) and potentially unsafe.
WITH NO DATA to all CREATE MATERIALIZED VIEW DDL generated during schema reconstructionpg_get_viewdef() output to prevent syntax errors when appending WITH NO DATApkg/diff/materialized_view_sql_generator.gopkg/diff/schema_migration_plan_test.go (3 new unit tests)Full PR: #305
Fixes search_path shadowing in bigint-to-timestamp column migrations ( CVE-2018-1058 , #298 ).
Fixes search_path shadowing in bigint-to-timestamp column migrations (CVE-2018-1058, #298).
USING clause (sql_generator.go)When migrating a bigint column to timestamp without time zone, pg-schema-diff emits a to_timestamp() call in the ALTER COLUMN ... USING clause. An unqualified call resolves via search_path, so a user with CREATE on a schema can plant shadow functions that run during apply instead of the built-ins.
Fix: emit a fully qualified expression:
pg_catalog.to_timestamp(
col::pg_catalog.float8 OPERATOR(pg_catalog./) 1000.0::pg_catalog.float8
)Full Changelog: v1.0.7...v1.0.8
Fixes two additional SQL injection sinks identified via the same root cause as v1.0.6 (enum labels, #295 ). Schema-derived values were re-emitted into
Fixes two additional SQL injection sinks identified via the same root cause as v1.0.6 (enum labels, #295). Schema-derived values were re-emitted into generated DDL without proper escaping.
policy_sql_generator.go)AppliesTo role names (sourced from pg_roles.rolname) were interpolated raw into CREATE POLICY ... TO and ALTER POLICY ... TO statements. A user with CREATEROLE privilege could plant a role whose name contains an embedded double-quote to inject arbitrary SQL during plan execution.
Fix: Added escapeRoleNames() helper that applies EscapeIdentifier to each role name, preserving PUBLIC as an unquoted SQL keyword.
schema.go buildProcName)The function used hand-rolled quoting (fmt.Sprintf("\"%s\"(%s)", name, ...)) that did not double embedded double-quotes. A user with CREATE FUNCTION privilege could create a function with " in its name to inject SQL when DROP FUNCTION/DROP PROCEDURE statements are generated.
Fix: Replaced the hand-rolled quoting with EscapeIdentifier(name).
Full Changelog: v1.0.6...v1.0.7
Escapes enum labels in generated SQL to prevent a second-order SQL injection.
Escapes enum labels in generated SQL to prevent a second-order SQL injection.
Enum labels were interpolated into generated DDL using raw fmt.Sprintf("'%s'", val). A label containing a single quote could break out of the string literal and inject arbitrary SQL, which then executes with the plan runner's (often superuser) privileges when pg-schema-diff generates migration SQL — enabling RCE via COPY ... TO PROGRAM.
All three enum sinks (CREATE TYPE ... AS ENUM, ALTER TYPE ... ADD VALUE, and the BEFORE ordering clause) now route through a new EscapeLiteral helper that doubles single quotes and strips null bytes.
See #295 for details and test evidence.
Recommendation: upgrade to v1.0.6, especially if you run pg-schema-diff against databases where lower-privileged users can create enum types.
Table privilege support by @bplunkett-stripe in #264
Dump command prototype by @bplunkett-stripe in #263
Materialized view index support by @bplunkett-stripe in #262
Full Changelog: v1.0.2...v1.0.3
Nothing published for this version
Ensure command prints to stdout by @bplunkett-stripe in #245
Full Changelog: v1.0.1...v1.0.2
Update readme by @bplunkett-stripe in #240
GENERATED ALWAYS AS columns to reduce migration failures (#212) by @lmcrean in #232Full Changelog: v1.0.0...v1.0.1
Nothing published for this version
Nothing published for this version
Releasing first major version, since the API has stabilized.
Releasing first major version, since the API has stabilized.
Full Changelog: v0.9.3...v1.0.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →