Gathering detailed insights and metrics for sqlite3
Gathering detailed insights and metrics for sqlite3
Gathering detailed insights and metrics for sqlite3
Gathering detailed insights and metrics for sqlite3
npm install sqlite3
Typescript
Module System
Node Version
NPM Version
53.2
Supply Chain
94.9
Quality
80.3
Maintenance
100
Vulnerability
96.1
License
PLpgSQL (70.95%)
JavaScript (14.48%)
C++ (13.86%)
Python (0.23%)
Makefile (0.2%)
C (0.17%)
Dockerfile (0.08%)
HTML (0.03%)
Total Downloads
168,340,019
Last Day
60,934
Last Week
953,681
Last Month
3,973,583
Last Year
46,628,006
6,253 Stars
1,455 Commits
817 Forks
184 Watching
10 Branches
93 Contributors
Minified
Minified + Gzipped
Latest Version
5.1.7
Package Id
sqlite3@5.1.7
Unpacked Size
3.19 MB
Size
3.09 MB
File Count
23
NPM Version
10.2.3
Node Version
18.19.0
Publised On
05 Jan 2024
Cumulative downloads
Total Downloads
Last day
1.4%
60,934
Compared to previous day
Last week
1.5%
953,681
Compared to previous week
Last month
-5.7%
3,973,583
Compared to previous month
Last year
22.7%
46,628,006
Compared to previous year
4
1
1
Asynchronous, non-blocking SQLite3 bindings for Node.js.
You can use npm
or yarn
to install sqlite3
:
1npm install sqlite3 2# or 3yarn add sqlite3
master
branch: npm install https://github.com/tryghost/node-sqlite3/tarball/master
sqlite3
v5+ was rewritten to use Node-API so prebuilt binaries do not need to be built for specific Node versions. sqlite3
currently builds for both Node-API v3 and v6. Check the Node-API version matrix to ensure your Node version supports one of these. The prebuilt binaries should be supported on Node v10+.
The module uses prebuild-install
to download the prebuilt binary for your platform, if it exists. These binaries are hosted on GitHub Releases for sqlite3
versions above 5.0.2, and they are hosted on S3 otherwise. The following targets are currently provided:
darwin-arm64
darwin-x64
linux-arm64
linux-x64
linuxmusl-arm64
linuxmusl-x64
win32-ia32
win32-x64
Unfortunately, prebuild cannot differentiate between armv6
and armv7
, and instead uses arm
as the {arch}
. Until that is fixed, you will still need to install sqlite3
from source.
Support for other platforms and architectures may be added in the future if CI supports building on them.
If your environment isn't supported, it'll use node-gyp
to build SQLite, but you will need to install a C++ compiler and linker.
It is also possible to make your own build of sqlite3
from its source instead of its npm package (See below.).
The sqlite3
module also works with node-webkit if node-webkit contains a supported version of Node.js engine. (See below.)
SQLite's SQLCipher extension is also supported. (See below.)
See the API documentation in the wiki.
Note: the module must be installed before use.
1const sqlite3 = require('sqlite3').verbose(); 2const db = new sqlite3.Database(':memory:'); 3 4db.serialize(() => { 5 db.run("CREATE TABLE lorem (info TEXT)"); 6 7 const stmt = db.prepare("INSERT INTO lorem VALUES (?)"); 8 for (let i = 0; i < 10; i++) { 9 stmt.run("Ipsum " + i); 10 } 11 stmt.finalize(); 12 13 db.each("SELECT rowid AS id, info FROM lorem", (err, row) => { 14 console.log(row.id + ": " + row.info); 15 }); 16}); 17 18db.close();
To skip searching for pre-compiled binaries, and force a build from source, use
1npm install --build-from-source
The sqlite3 module depends only on libsqlite3. However, by default, an internal/bundled copy of sqlite will be built and statically linked, so an externally installed sqlite3 is not required.
If you wish to install against an external sqlite then you need to pass the --sqlite
argument to npm
wrapper:
1npm install --build-from-source --sqlite=/usr/local
If building against an external sqlite3 make sure to have the development headers available. Mac OS X ships with these by default. If you don't have them installed, install the -dev
package with your package manager, e.g. apt-get install libsqlite3-dev
for Debian/Ubuntu. Make sure that you have at least libsqlite3
>= 3.6.
Note, if building against homebrew-installed sqlite on OS X you can do:
1npm install --build-from-source --sqlite=/usr/local/opt/sqlite/
The default sqlite file header is "SQLite format 3". You can specify a different magic, though this will make standard tools and libraries unable to work with your files.
1npm install --build-from-source --sqlite_magic="MyCustomMagic15"
Note that the magic must be exactly 15 characters long (16 bytes including null terminator).
Because of ABI differences, sqlite3
must be built in a custom to be used with node-webkit.
To build sqlite3
for node-webkit:
Install nw-gyp
globally: npm install nw-gyp -g
(unless already installed)
Build the module with the custom flags of --runtime
, --target_arch
, and --target
:
1NODE_WEBKIT_VERSION="0.8.6" # see latest version at https://github.com/rogerwang/node-webkit#downloads 2npm install sqlite3 --build-from-source --runtime=node-webkit --target_arch=ia32 --target=$(NODE_WEBKIT_VERSION)
You can also run this command from within a sqlite3
checkout:
1npm install --build-from-source --runtime=node-webkit --target_arch=ia32 --target=$(NODE_WEBKIT_VERSION)
Remember the following:
You must provide the right --target_arch
flag. ia32
is needed to target 32bit node-webkit builds, while x64
will target 64bit node-webkit builds (if available for your platform).
After the sqlite3
package is built for node-webkit it cannot run in the vanilla Node.js (and vice versa).
npm test
of the node-webkit's package would fail.Visit the “Using Node modules” article in the node-webkit's wiki for more details.
For instructions on building SQLCipher, see Building SQLCipher for Node.js. Alternatively, you can install it with your local package manager.
To run against SQLCipher, you need to compile sqlite3
from source by passing build options like:
1npm install sqlite3 --build-from-source --sqlite_libname=sqlcipher --sqlite=/usr/ 2 3node -e 'require("sqlite3")'
If your SQLCipher is installed in a custom location (if you compiled and installed it yourself), you'll need to set some environment variables:
Set the location where brew
installed it:
1export LDFLAGS="-L`brew --prefix`/opt/sqlcipher/lib" 2export CPPFLAGS="-I`brew --prefix`/opt/sqlcipher/include/sqlcipher" 3npm install sqlite3 --build-from-source --sqlite_libname=sqlcipher --sqlite=`brew --prefix` 4 5node -e 'require("sqlite3")'
Set the location where make
installed it:
1export LDFLAGS="-L/usr/local/lib" 2export CPPFLAGS="-I/usr/local/include -I/usr/local/include/sqlcipher" 3export CXXFLAGS="$CPPFLAGS" 4npm install sqlite3 --build-from-source --sqlite_libname=sqlcipher --sqlite=/usr/local --verbose 5 6node -e 'require("sqlite3")'
Running sqlite3
through electron-rebuild does not preserve the SQLCipher extension, so some additional flags are needed to make this build Electron compatible. Your npm install sqlite3 --build-from-source
command needs these additional flags (be sure to replace the target version with the current Electron version you are working with):
1--runtime=electron --target=18.2.1 --dist-url=https://electronjs.org/headers
In the case of MacOS with Homebrew, the command should look like the following:
1npm install sqlite3 --build-from-source --sqlite_libname=sqlcipher --sqlite=`brew --prefix` --runtime=electron --target=18.2.1 --dist-url=https://electronjs.org/headers
1npm test
Thanks to Orlando Vazquez, Eric Fredricksen and Ryan Dahl for their SQLite bindings for node, and to mraleph on Freenode's #v8 for answering questions.
This module was originally created by Mapbox & is now maintained by Ghost.
We use GitHub releases for notes on the latest versions. See CHANGELOG.md in git history for details on older versions.
node-sqlite3
is BSD licensed.
Stable Version
2
8.1/10
Summary
sqlite vulnerable to code execution due to Object coercion
Affected Versions
>= 5.0.0, < 5.1.5
Patched Versions
5.1.5
7.5/10
Summary
Denial-of-Service when binding invalid parameters in sqlite3
Affected Versions
>= 5.0.0, < 5.0.3
Patched Versions
5.0.3
No security vulnerabilities found.