Sitelet https://github.com/Pawansingh3889/sql-sop/pull/23
Skip to content

feat: add T-SQL rules T001-T004 and FETCH NEXT pagination support - #23

Merged
Pawansingh3889 merged 1 commit into
mainfrom
add-tsql-rules
Apr 20, 2026
Merged

Pawansingh3889 merged 1 commit into
mainfrom
add-tsql-rules

Conversation

@Pawansingh3889

Copy link
Copy Markdown
Owner

Closes #22.

Adds four T-SQL-specific rules and a small regex tweak so T-SQL
pagination no longer trips the LIMIT-aware warnings.

New rules

  • T001 with-nolock (warning). Flags WITH (NOLOCK) table hints.
    Causes dirty reads.
  • T002 xp-cmdshell (error). Flags EXEC xp_cmdshell. Shell-exec
    surface that should never appear in application SQL.
  • T003 cursor-declaration (warning). Flags DECLARE ... CURSOR.
    Row-by-row processing where set-based SQL usually does better.
  • T004 deprecated-outer-join (error). Flags *= and =* old-style
    outer-join syntax. Unsupported in SQL Server 2012 and later. Uses a
    negative lookbehind to avoid matching modern compound-assignment
    expressions like SET @x *= 2.

Regex tweak

W002 missing-limit and W006 orderby-without-limit now match
FETCH\s+(FIRST|NEXT) instead of only FETCH\s+FIRST, so T-SQL's
OFFSET n ROWS FETCH NEXT m ROWS ONLY pagination counts as bounded.

Scope notes

The originally proposed old-style-join rule is already covered by
S001 ImplicitCrossJoin, so dropped to avoid duplicate findings.

Version bump, README rule-count refresh, and .pre-commit-config.yaml
rev update are intentionally left for a release-prep PR so
precommit_rev_matches_tag does not complain about a tag that does
not yet exist.

Tests

18 new tests in tests/test_tsql.py covering each rule's positive
and negative cases, including:

  • T001 flags all whitespace variants and case, ignores WITH cte AS.
  • T002 flags xp_cmdshell case-insensitively, ignores sp_executesql.
  • T003 flags cursor declarations, ignores DECLARE @i INT.
  • T004 flags *= and =*, ignores compound assignment, plain
    assignment, and modern JOIN syntax.
  • W002 and W006 accept both FETCH FIRST (existing) and
    FETCH NEXT (new) T-SQL pagination.

Full suite: 80 passed, 1 skipped.

Closes #22.

T001 with-nolock, T002 xp-cmdshell, T003 cursor-declaration,
T004 deprecated-outer-join. Plus W002/W006 regex tweak so T-SQL
OFFSET/FETCH NEXT pagination counts as bounded.

18 new tests, 80 total passing.
@Pawansingh3889 Pawansingh3889 changed the title Add T-SQL rules T001-T004 and FETCH NEXT pagination support feat: add T-SQL rules T001-T004 and FETCH NEXT pagination support Apr 20, 2026
@Pawansingh3889
Pawansingh3889 merged commit a706d06 into main Apr 20, 2026
7 of 8 checks passed
@Pawansingh3889
Pawansingh3889 deleted the add-tsql-rules branch April 20, 2026 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add T-SQL-specific rules for SQL Server shops

1 participant