What dblift validate-sql checks, and how hard it fails. The command is Pro. Named profiles and the packs beyond security are Enterprise — Pro uses --rules-file (or --rules security) instead.
Default output format when the command is run without --format.
The four packs
security — rules that map to access, injection and privilege controls.
performance — statements that will lock, scan or rewrite more than they need to.
best_practices — schema hygiene that keeps later releases reversible.
naming — identifier conventions. Noisy on an existing codebase; useful on a new one.
The four profiles
A profile is a named selection over the packs. Setting one is usually all the configuration a project needs.
Profile
Selects
When to use it
core
security + three named rules
The security pack plus no_drop_without_backup, update_delete_must_have_where and require_primary_key. The smallest useful gate.
enterprise
security, best_practices, performance
Everything that affects safety and runtime, without the naming opinions.
strict
naming, security, best_practices, performance
All four packs. Expect naming findings on an existing codebase.
technical-debt
naming, best_practices, performance
The quality packs without security — for a cleanup pass rather than a release gate.
Representative rules
Six from each pack. Every rule reports a severity and, where it can, the fix. A rule that maps to a control names it, so a finding can be traced to the requirement it serves.
security
Rule
Severity
Control
no_dynamic_sql_without_validation
error
no_grant_all_privileges
error
no_public_schema_access
error
no_hardcoded_credentials
error
performance
Rule
Severity
Control
no_select_star
warning
require_limit_on_large_queries
warning
no_like_with_leading_wildcard
warning
no_function_on_indexed_column_in_where
warning
prefer_exists_over_in_for_subqueries
info
best_practices
Rule
Severity
Control
require_primary_key
error
use_proper_date_types
error
no_drop_without_backup
warning
SOC2-CC7.2 · ISO27001-A.12.1.2
require_audit_timestamps
warning
fk_must_specify_cascade
warning
use_if_exists_for_drops
info
naming
Rule
Severity
Fix
table_name_no_reserved_words
error
Use descriptive names that do not conflict with SQL keywords.
schema_name_no_special_chars
error
Letters, digits and underscores only.
table_name_snake_case
warning
Lowercase snake_case — ^[a-z][a-z0-9_]*$.
column_name_snake_case
warning
Lowercase snake_case — ^[a-z][a-z0-9_]*$.
boolean_columns_naming
info
Start boolean columns with is_, has_, can_, should_ or will_.
index_name_prefix
info
Prefix index names with idx_, ix_, pk_, uk_ or fk_.
Overrides expire
The rules that carry a control mapping also carry an override policy. Suppressing one requires an owner, a reason, a ticket and an expiry date, and the expiry is capped — 30 days for the security rules, 14 for no_drop_without_backup. An expired override stops suppressing.