Togoder security

Go package security report

github.com/thrasher-corp/sqlboiler Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v1.0.1-0.20191001234224-71e17f37a85e Files reviewed 66 Size 611.7 KB Scanned

Summary

Togoder Security scanned the Go package github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e on Oct 5, 2026. An AI review of 66 source files produced 5 medium, 12 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
5
medium
12
low

Findings 17

medium

Dynamic execution of external binaries

NPS-3ABD5F4C7B93

The execute function calls external binaries with arguments ('assemble', 'templates', 'imports') and passes JSON input via stdin. While this is the intended functionality of the driver, it relies on trust in the external binary. Malicious or compromised binaries could perform arbitrary actions, including data exfiltration, since they receive configuration data and run with the same privileges as the calling process.

drivers/binary_driver.go:52
medium

Spawning processes or shell commands

NPS-213CB3D9C13B

The code uses os/exec to spawn external binaries based on the binaryDriver string. The executable path comes from the driver configuration and is passed directly to exec.Command without validation or sanitization. If an attacker can control the driver name (e.g., through configuration), they could execute arbitrary binaries on the system. This is a potential command execution vector.

drivers/binary_driver.go:64
medium

Potential connection string injection / improper escaping

NPS-F9CE45EE6D39

PSQLBuildQueryString constructs a PostgreSQL connection string by directly interpolating user, password, dbname, host, and sslmode values with fmt.Sprintf without proper escaping. If any of these values contain spaces or special characters (e.g. a password with a space, or a host value containing ' sslmode=disable'), it could allow an attacker who controls config values to inject additional connection parameters, potentially weakening TLS (e.g. sslmode=disable) or redirecting connections. This is a classic connection-string injection pattern.

drivers/sqlboiler-psql/driver/psql.go:113
medium

Process spawning

NPS-421844485C0B

preRun() uses exec.LookPath and later boilingcore registers the driver binary path; the driver is executed as an external process. While expected for this tool, the driver name/path is derived from user input and may be manipulated (e.g. path traversal via os.PathSeparator check) to execute an arbitrary binary.

main.go:175
medium

Environment variable harvesting

NPS-304124D6AC14

allKeys() iterates over os.Environ() and collects all environment variables matching a prefix derived from user-supplied driver name, which could inadvertently capture sensitive environment variables (e.g. API keys, credentials) if they share the prefix. This data is then placed into DriverConfig and potentially passed to the driver binary.

main.go:220
low

Potential information disclosure via error handling

NPS-DB2AB2829C69

Error messages include the executable path and may leak details about the environment or configuration. While not directly malicious, verbose error messages could aid attackers in reconnaissance.

drivers/binary_driver.go:75
low

Untrusted input handling / missing bounds check

NPS-7006B259C9E6

os.Args[1] is accessed directly without verifying len(os.Args) > 1, which would cause a panic if the binary is invoked with no arguments. More importantly, the 'method' value is used to select driver behavior; if the driver implementation is supplied by a third party and the dispatcher is generic, unexpected methods are silently ignored (output remains nil), which could mask errors.

drivers/driver_main.go:11
low

Potential information disclosure via verbose error output

NPS-C5CC27A04F91

When JSON parsing fails, the error handler prints the entire raw input buffer (b) to stderr. If the config contains secrets (tokens, credentials, environment-specific values), they could be leaked into logs or CI output. This is a minor concern for a driver helper but worth noting.

drivers/driver_main.go:24
low

init() function registration

NPS-0E8499644FCA

The init() function registers a mock driver with the sqlboiler driver registry. This is a standard Go pattern for plugin registration in test/mock packages and does not perform any suspicious activity such as network access, file system manipulation, or code execution.

drivers/mocks/mock.go:8
low

Panic recovery using unsafe type assertion

NPS-64A5A0FE2DA8

The deferred recover in Assemble does err = r.(error), which will itself panic if the recovered value is not an error (e.g. a string panic). This is not directly malicious, but it can crash the generator in unexpected ways and is a robustness concern rather than a security exploit.

drivers/sqlboiler-psql/driver/psql.go:79
low

Weak default TLS policy

NPS-3068265D1F0E

The default sslmode is set to 'require' which encrypts traffic but does not verify the server certificate (no hostname/cert verification). An attacker in a MITM position could impersonate the database server. Prefer 'verify-full' or 'verify-ca' for stronger guarantees.

drivers/sqlboiler-psql/driver/psql.go:90
low

Unbounded stderr output of database-derived identifiers

NPS-8FA2EBAE46F8

In TranslateColumnType, fmt.Fprintf(os.Stderr, "warning: incompatible data type detected: %s\n", c.UDTName) writes a database-controlled UDT name to stderr. While not a direct code execution vector, writing unsanitized database metadata to a terminal could enable terminal escape sequence injection if output is later reviewed in a vulnerable terminal. Typically low impact.

drivers/sqlboiler-psql/driver/psql.go:538
low

File system manipulation

NPS-5DAE8646DE92

The --wipe flag causes deletion of the output folder (rm -rf) before generation. If the output path is misconfigured or influenced by environment/config, it could delete unintended directories.

main.go:118
low

Dynamic code execution via templates

NPS-91AE7DF9739D

TemplateDirs and Replacements flags allow specifying external template directories and replacement files, which are processed at generation time. Malicious templates could execute arbitrary code within the generation context, though this is an intended feature.

main.go:150
low

Input validation using regex

NPS-FEC5C111309D

Uses rgxIdentifier and rgxInClause to validate and quote identifiers, reducing SQL injection risk.

queries/query_builders.go
low

SQL string concatenation

NPS-3B6830BCB3F1

Multiple places build SQL via string concatenation and fmt.Fprintf; however, identifiers are quoted and values use placeholders, mitigating injection.

queries/query_builders.go
low

Panic on invalid SQL structure

NPS-71934E381295

Calls panic in convertInQuestionMarks, convertQuestionMarks, whereClause, and buildSelectQuery (unsupported join kind). This is a reliability concern, not a security vulnerability.

queries/query_builders.go

Files reviewed

FileVerdictWhat the reviewer saw
drivers/binary_driver.go medium The code spawns external binaries based on unvalidated input from driver configuration, which could lead to arbitrary command execution if the driver name is attacker-controlled; this is a medium-severity concern in a trusted driver context but warrants attention.
drivers/driver_main.go medium The file is a generic CLI dispatcher for driver plugins; it contains no exfiltration, credential harvesting, code execution, or network activity, but does leak raw stdin on JSON parse errors and lacks argument validation.
drivers/sqlboiler-psql/driver/psql.go medium No malicious code found; the driver is a legitimate sqlboiler PostgreSQL generator, but it builds connection strings via unsanitized string interpolation and defaults to a non-verifying SSL mode, which are minor security hygiene concerns rather than signs of malicious intent.
main.go medium The code is a legitimate CLI tool but contains patterns that could be abused if inputs are malicious, including environment variable collection, external binary execution, template-based code generation, and destructive file operations.
boil/columns.go safe Cleared by Jev triage; no further analysis needed
boil/db.go safe Cleared by Jev triage; no further analysis needed
boil/errors.go safe Cleared by Jev triage; no further analysis needed
boil/global.go safe No malicious patterns detected
boil/hooks.go safe Cleared by Jev triage; no further analysis needed
boilingcore/aliases.go safe Cleared by Jev triage; no further analysis needed
boilingcore/boilingcore.go safe No malicious patterns detected; the code is a legitimate SQLBoiler code generation library with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
boilingcore/config.go safe Cleared by Jev triage; no further analysis needed
boilingcore/output.go safe No malicious patterns detected; the code is a legitimate Go code generator that writes template output to files under a configured output folder.
boilingcore/templates.go safe No malicious patterns detected in the provided Go source code.
boilingcore/text_helpers.go safe Cleared by Jev triage; no further analysis needed
drivers/column.go safe Cleared by Jev triage; no further analysis needed
drivers/config.go safe No malicious patterns detected; the code is a straightforward configuration utility with type assertions and no network, filesystem, or process manipulation.
drivers/interface.go safe Cleared by Jev triage; no further analysis needed
drivers/keys.go safe Cleared by Jev triage; no further analysis needed
drivers/mocks/mock.go safe The code is a benign mock database driver implementation with no malicious patterns detected.
drivers/registration.go safe No malicious patterns detected
drivers/relationships.go safe Cleared by Jev triage; no further analysis needed
drivers/sqlboiler-mssql/driver/bindata.go safe No malicious patterns detected; this is standard go-bindata generated code for embedding template files.
drivers/sqlboiler-mssql/driver/mssql.go safe No malicious patterns detected: the code is a legitimate MSSQL driver for SQLBoiler with standard database operations and no exfiltration, credential harvesting, obfuscation, or backdoors.
drivers/sqlboiler-mssql/main.go safe Cleared by Jev triage; no further analysis needed
Show 41 more files
FileVerdictWhat the reviewer saw
drivers/sqlboiler-mysql/driver/bindata.go safe No malicious patterns detected; this is a standard go-bindata generated file embedding template data, with no network calls, exfiltration, credential harvesting, obfuscated code, process spawning, or suspicious install/import-time behavior.
drivers/sqlboiler-mysql/driver/mysql.go safe This is a legitimate MySQL driver implementation for sqlboiler that performs standard database introspection queries with no malicious patterns detected.
drivers/sqlboiler-mysql/main.go safe Cleared by Jev triage; no further analysis needed
drivers/sqlboiler-psql/driver/bindata.go safe This is a standard go-bindata generated file that embeds gzipped template assets for the sqlboiler-psql driver, with no malicious patterns detected.
drivers/sqlboiler-psql/main.go safe Cleared by Jev triage; no further analysis needed
drivers/table.go safe Cleared by Jev triage; no further analysis needed
importers/imports.go safe Cleared by Jev triage; no further analysis needed
queries/eager_load.go safe No malicious patterns detected
queries/helpers.go safe Cleared by Jev triage; no further analysis needed
queries/qm/query_mods.go safe Cleared by Jev triage; no further analysis needed
queries/qmhelper/qmhelper.go safe Cleared by Jev triage; no further analysis needed
queries/query.go safe No malicious patterns detected in this SQL query builder code; it contains no exfiltration, credential harvesting, obfuscation, process spawning, or network activity.
queries/query_builders.go safe No malicious patterns such as exfiltration, credential harvesting, obfuscation, code execution, or network activity were found; the code is a legitimate SQL query builder with standard input validation.
queries/reflect.go safe No malicious patterns detected
randomize/random.go safe No malicious patterns detected; the code is a legitimate random data generation library for database testing.
randomize/randomize.go safe Cleared by Jev triage; no further analysis needed
strmangle/buf_pool.go safe Cleared by Jev triage; no further analysis needed
strmangle/inflect.go safe Cleared by Jev triage; no further analysis needed
strmangle/sets.go safe Cleared by Jev triage; no further analysis needed
strmangle/strmangle.go safe No malicious patterns detected in this string manipulation utility package.
types/array.go safe No malicious patterns detected; the code is a standard PostgreSQL array type implementation with no network, filesystem, process, or obfuscation concerns.
types/byte.go safe Cleared by Jev triage; no further analysis needed
types/decimal.go safe Cleared by Jev triage; no further analysis needed
types/hstore.go safe Cleared by Jev triage; no further analysis needed
types/json.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/box.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/circle.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/general.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/line.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/lseg.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/main.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/nullBox.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/nullCircle.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/nullLine.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/nullLseg.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/nullPath.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/nullPoint.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/nullPolygon.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/path.go safe No malicious patterns detected
types/pgeo/point.go safe Cleared by Jev triage; no further analysis needed
types/pgeo/polygon.go safe Cleared by Jev triage; no further analysis needed

Scanned versions of github.com/thrasher-corp/sqlboiler

VersionVerdictFilesScanned
v1.0.1-0.20191001234224-71e17f37a85e Needs review 66 Oct 5, 2026

Frequently asked questions

Is github.com/thrasher-corp/sqlboiler safe to use?

No confirmed malware was found in github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e, but the review flagged 5 medium, 12 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/thrasher-corp/sqlboiler contain malware?

No malware was identified in github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/thrasher-corp/sqlboiler checked?

Togoder Security downloaded the published Go package and had an AI model read its 66 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/thrasher-corp/sqlboiler together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e, cost nothing.

Related security reports