drizzle-orm
Drizzle ORM package for SQL databases
About
Drizzle ORM package for SQL databases
What detecting drizzle-orm tells you about a site
drizzle-orm reveals a SQL-first, TypeScript-native ORM — schema and queries written as typed code that stays close to raw SQL — chosen by teams that wanted type safety without Prisma's heavier runtime and code-generation step. Its presence signals a modern, edge-friendly data layer (though it more often runs server-side than ships to the browser).
Why the exact drizzle-orm version matters
Drizzle's query and schema APIs are still evolving pre-1.0, so the exact version is a meaningful read on which API generation the code targets.
drizzle-orm in a real-world stack
When you find drizzle-orm in a bundle, it rarely travels alone. A database driver (postgres, @neondatabase/serverless, mysql2) and frequently zod via drizzle-zod for validation.
Quick facts
npm install drizzle-ormCommon pairings
Packages this one expects to find in the same project. Each is also a Sourcemap Explorer detection target.
How Sourcemap Explorer detects drizzle-orm
drizzle-orm ships as v0.45.2 and carries 0 direct dependencies, 28 peer dependencies (pg, gel, knex), 559 versions on the registry. Those exact numbers are the footprint Sourcemap Explorer matches when drizzle-orm rides inside a deployed bundle — here is how the detection works.
We catch drizzle-orm from two complementary signals: bundled source paths and the embedded package.json. Modern bundlers (webpack, Vite, esbuild, Rollup, Turbopack) preserve the original node_modules/drizzle-orm/ paths inside the JavaScript sourcemap's sources[] array — that's the canonical signal. When the matching package.json is also captured in sourcesContent[], we read the exact version field — patch number included. No regex guessing, no version inference.
- 1
Confirm the site exposes sourcemaps
In DevTools Network, check the response headers of any application script for `SourceMap` or `X-SourceMap`. Failing that, fetch the script's last 4 KB and look for a `//# sourceMappingURL=` comment — that map is where the `drizzle-orm` paths live.
- 2
Find the package in the bundle
Open DevTools → Network → reload. Click any application script and look at its sourcemap. Inside, search `sources[]` for entries matching `node_modules/drizzle-orm/` — every match confirms the package is bundled. The matching `sourcesContent[i]` for `node_modules/drizzle-orm/package.json` gives you the exact installed version.
- 3
Read the version directly from package.json
Run `jq -r '. as $m | $m.sources | to_entries[] | select(.value | endswith("node_modules/drizzle-orm/package.json")) | $m.sourcesContent[.key] | fromjson | .version' bundle.js.map`. Sourcemap Explorer automates the same query in the popup.
Recent security advisories for drizzle-orm
The 1 most recent advisories affecting some versions of drizzle-orm, aggregated from OSV.dev (GitHub Advisory + CVE data). A listing here doesn't mean the version a given site ships is affected — each advisory applies to a specific version range. Sourcemap Explorer reads the exact bundled version so you can check it against these ranges.
Drizzle ORM has SQL injection via improperly escaped SQL identifiers
Recent versions
drizzle-orm README
Live mirror of the GitHub README, for reference. Updated whenever the repo's default branch changes.
What's Drizzle?
Drizzle is a modern TypeScript ORM developers wanna use in their next project. It is lightweight at only ~7.4kb minified+gzipped, and it's tree shakeable with exactly 0 dependencies.
Drizzle supports every PostgreSQL, MySQL and SQLite database, including serverless ones like Turso, Neon, Xata, PlanetScale, Cloudflare D1, FlyIO LiteFS, Vercel Postgres, Supabase and AWS Data API. No bells and whistles, no Rust binaries, no serverless adapters, everything just works out of the box.
Drizzle is serverless-ready by design. It works in every major JavaScript runtime like NodeJS, Bun, Deno, Cloudflare Workers, Supabase functions, any Edge runtime, and even in browsers.
With Drizzle you can be fast out of the box and save time and costs while never introducing any data proxies into your infrastructure.
While you can use Drizzle as a JavaScript library, it shines with TypeScript. It lets you declare SQL schemas and build both relational and SQL-like queries, while keeping the balance between type-safety and extensibility for toolmakers to build on top.
Ecosystem
While Drizzle ORM remains a thin typed layer on top of SQL, we made a set of tools for people to have best possible developer experience.
Drizzle comes with a powerful Drizzle Kit CLI companion for you to have hassle-free migrations. It can generate SQL migration files for you or apply schema changes directly to the database.
We also have Drizzle Studio for you to effortlessly browse and manipulate data in your database of choice.
Documentation
Check out the full documentation on the website.
Our sponsors ❤️
FAQ
What is drizzle-orm used for?
Drizzle ORM package for SQL databases
How can I tell if a website is using drizzle-orm?
Open the page in Chrome with the Sourcemap Explorer extension installed and read the Stack tab. We catch `drizzle-orm` from two complementary signals: `node_modules/drizzle-orm/` paths inside the JavaScript sourcemap, and the embedded `package.json` we read for exact-version detection. Without the extension you can do the same lookup manually in DevTools — the steps are listed in the "How Sourcemap Explorer detects" section above.
How do I find out which version of drizzle-orm a website is running?
Read it straight from the site's JavaScript sourcemap. When a build ships source maps, the bundled `drizzle-orm/package.json` carries the exact `version` string — Sourcemap Explorer extracts it in one click on the Stack tab, and you can do it by hand in DevTools by opening the `.map` file and searching for `node_modules/drizzle-orm/package.json`. That is far more reliable than inferring the version from an asset-hash or a `?ver=` query string, which is all surface-level detectors have to go on. The current npm release is 0.45.2, but real deployments frequently run an older pinned version — which is exactly why reading the bundled number matters.
What is the latest version of drizzle-orm?
0.45.2, as published on the npm registry. The "Recent versions" table on this page lists the most recent 8 releases with their release dates. Sourcemap Explorer reports the version actually bundled into a site, which can lag the latest release by months on real-world deployments.
Does drizzle-orm have known security vulnerabilities?
1 recent advisory affecting some versions of drizzle-orm is listed in the "Recent security advisories" section above, aggregated from OSV.dev (GitHub Advisory + CVE data). Whether a particular site is exposed depends entirely on the exact version it ships — each advisory applies to a specific version range, not to the package as a whole. That is why the precise bundled version matters: Sourcemap Explorer reads the version a site actually runs, so you can check it against the affected ranges instead of assuming the latest release is what's deployed.
Where can I read more?
Project homepage: https://orm.drizzle.team. Source code: https://github.com/drizzle-team/drizzle-orm. Published on npm: https://www.npmjs.com/package/drizzle-orm. Licensed as Apache-2.0.
Keep reading on Sourcemap Explorer
Practical guides
Detected by Sourcemap Explorer
When a bundle ships sourcemaps, we read the embedded package.json for drizzle-orm and report the precise version (registry latest: v0.45.2). Without sourcemaps, an import / require in the page's scripts is enough to flag it.