Docs/Configuration/validation
ProEnterprise

validation

What dblift validate-sql checks, and how hard it fails. The command is Pro. Named profiles and the packs beyond security are Enterprise — Pro uses --rules-file (or --rules security) instead.

The block

yaml
validation: enabled: true rule_profile: enterprise fail_on: error severity_threshold: warning exclude_patterns: - "migrations/vendor/**" environments: prod: validation: rule_profile: strict fail_on: warning
KeyDefaultWhat it does
enabledtrueTurns SQL validation off entirely for this project or environment.
rule_profile—One of core, enterprise, strict or technical-debt.
rules[]Explicit pack or rule names, instead of — or alongside — a profile.
rules_file—Path to your own rule pack, in the same YAML shape as the built-in packs.
fail_onerrorThe severity that makes the command exit non-zero.
severity_thresholdwarningThe lowest severity that gets reported at all. Anything below is dropped.
performance_enabledtrueRuns the performance analyser in addition to the pattern rules.
exclude_patterns[]File globs skipped entirely — vendor SQL, generated migrations.
output_formatconsoleDefault output format when the command is run without --format.

The four packs

  • security — rules that map to access, injection and privilege controls.
  • performance — statements that will lock, scan or rewrite more than they need to.
  • best_practices — schema hygiene that keeps later releases reversible.
  • naming — identifier conventions. Noisy on an existing codebase; useful on a new one.

The four profiles

A profile is a named selection over the packs. Setting one is usually all the configuration a project needs.

ProfileSelectsWhen to use it
coresecurity + three named rulesThe security pack plus no_drop_without_backup, update_delete_must_have_where and require_primary_key. The smallest useful gate.
enterprisesecurity, best_practices, performanceEverything that affects safety and runtime, without the naming opinions.
strictnaming, security, best_practices, performanceAll four packs. Expect naming findings on an existing codebase.
technical-debtnaming, best_practices, performanceThe quality packs without security — for a cleanup pass rather than a release gate.

Representative rules

Six from each pack. Every rule reports a severity and, where it can, the fix. A rule that maps to a control names it, so a finding can be traced to the requirement it serves.

security

RuleSeverityControl
no_dynamic_sql_without_validationerror
no_grant_all_privilegeserror
no_public_schema_accesserror
no_hardcoded_credentialserror

performance

RuleSeverityControl
no_select_starwarning
require_limit_on_large_querieswarning
no_like_with_leading_wildcardwarning
no_function_on_indexed_column_in_wherewarning
prefer_exists_over_in_for_subqueriesinfo

best_practices

RuleSeverityControl
require_primary_keyerror
use_proper_date_typeserror
no_drop_without_backupwarningSOC2-CC7.2 · ISO27001-A.12.1.2
require_audit_timestampswarning
fk_must_specify_cascadewarning
use_if_exists_for_dropsinfo

naming

RuleSeverityFix
table_name_no_reserved_wordserrorUse descriptive names that do not conflict with SQL keywords.
schema_name_no_special_charserrorLetters, digits and underscores only.
table_name_snake_casewarningLowercase snake_case — ^[a-z][a-z0-9_]*$.
column_name_snake_casewarningLowercase snake_case — ^[a-z][a-z0-9_]*$.
boolean_columns_naminginfoStart boolean columns with is_, has_, can_, should_ or will_.
index_name_prefixinfoPrefix index names with idx_, ix_, pk_, uk_ or fk_.

Overrides expire

The rules that carry a control mapping also carry an override policy. Suppressing one requires an owner, a reason, a ticket and an expiry date, and the expiry is capped — 30 days for the security rules, 14 for no_drop_without_backup. An expired override stops suppressing.

On this page