惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
博客园 - 【当耐特】
Stack Overflow Blog
Stack Overflow Blog
S
Schneier on Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LINUX DO - 热门话题
Spread Privacy
Spread Privacy
雷峰网
雷峰网
博客园 - 叶小钗
L
LangChain Blog
MyScale Blog
MyScale Blog
Security Latest
Security Latest
AWS News Blog
AWS News Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
C
CXSECURITY Database RSS Feed - CXSecurity.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Hugging Face - Blog
Hugging Face - Blog
S
Securelist
The Hacker News
The Hacker News
T
Threatpost
Martin Fowler
Martin Fowler
Vercel News
Vercel News
Scott Helme
Scott Helme
S
Security @ Cisco Blogs
B
Blog RSS Feed
Microsoft Azure Blog
Microsoft Azure Blog
The GitHub Blog
The GitHub Blog
L
Lohrmann on Cybersecurity
Google Online Security Blog
Google Online Security Blog
T
Threat Research - Cisco Blogs
The Register - Security
The Register - Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
A
About on SuperTechFans
爱范儿
爱范儿
G
Google Developers Blog
B
Blog
C
Check Point Blog
G
GRAHAM CLULEY
T
Troy Hunt's Blog
V
Visual Studio Blog
T
The Blog of Author Tim Ferriss
C
Cisco Blogs
Webroot Blog
Webroot Blog
Blog — PlanetScale
Blog — PlanetScale
TaoSecurity Blog
TaoSecurity Blog
W
WeLiveSecurity
AI
AI
Security Archives - TechRepublic
Security Archives - TechRepublic
T
Tailwind CSS Blog

Show HN

GitHub - flightdeckhq/flightdeck: Observability and control plane for AI agents. CSP Radar GitHub - Light-Heart-Labs/DreamServer: Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation. GitHub - Diplomat-ai/diplomat-agent-ts: What can your TypeScript AI agent do to the real world? Scan your code. See which tool calls have zero checks Code Block Selector - Visual Studio Marketplace Prometheus dependency graph — interactive showcase | Riftmap Show HN: I made a vi-like modal keyboard plugin for Figma GitHub - run-llama/liteparse: A fast, helpful, and open-source document parser GitHub - dalemyers/Roar: A macOS CLI tool for notifications GitHub - district-solutions/open-agent-tools-coder: Enables small-to-large self-hosted ai models to use local source code when running tool-calling agentic workloads. We actively data mine 20,900+ (2+ TB) popular github repos using large and small ai models to create reuseable: json, markdown and parquet files for local-first tool-calling models. GitHub - progapandist/stripeek: A local TUI proxy for real-time Stripe API debugging, built for navigating complex payloads fast. GitHub - sir1st/hermes-desktop: All-in-one cross-platform desktop app for Hermes Agent — bundles Python + hermes-agent + hermes-web-ui GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: Generate Claude Code Workflows using Spec Driven Development approach GitHub - nixys/nxs-universal-chart: The Helm chart you can use to install any of your applications into Kubernetes/OpenShift Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code. GitHub - tamerh/enju: Coordinating Humans, AI Agents, and Compute as Peers on a Shared Workflow Graph Show HN: Continuity-auth – Respect-weighted rate limits for the open web GitHub - luml-ai/luml: AI lifecycle platform where engineers and agents track experiments, train models, and ship to production. GitHub - mrdanielcasper/CoreTex: A UNIX-inspired, biomimetic, flat-file AI harness and knowledge engine. GitHub - clemg/pierre-github: Pierre's diffs.com and trees.software for Github GitHub - lyriks-io/unspaghettit: Behavior-driven AI development without prompt spaghetti. GitHub - sofumel/claude-handoff-revive: Resume Claude Code work after rate/usage/context limits without replaying the prior transcript. Auto-saves at 90%/95% usage. Plugin-installable, 10 languages. GitHub - dotexorg/saferpc: Typed, end-to-end encrypted RPC over any bidirectional channel. GitHub - BeeZeeAgent/beezee: Agent harness orchestration Legato Next.js Boilerplate for Internal Tools · CoreUI GitHub - clark-labs-inc/clark-hash: Clark Hash, 32x smaller searchable sketches for embeddings GitHub - ZeroPointRepo/youtube-mcp: The fastest YouTube transcript + YouTube search MCP for AI agents. Try for free. Typing Mastery — climb toward 100+ WPM, deliberately GitHub - Andebugulin/Awareen GitHub - fayzan123/claude-workflow-composer: Visual desktop app for composing multi-agent coding workflows. Drag agents, attach skills and MCPs, wire handoffs, export to .claude/ GitHub - harshaneel/humanize: Best static AI text humanizer. Two research-grounded skills that work in any LLM (Claude, ChatGPT, Gemini, Codex): humanize beats perplexity-based detectors, ai-check produces forensic scoring with evidence-quoted flags. Nine levers, 50+ peer-reviewed sources, 2024-2026 detection literature. GitHub - StackOneHQ/stack-nudge GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. We hardened an LLM agent. Each defense we added made it more exploitable. GitHub - alkait/WhatsKept: Agent-queryable WhatsApp history from an iOS backup — a single Go binary. GitHub - octelium/cordium: Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials. WAR.GOV/UFO Microfilm5 GitHub - scosman/videowright: Build animated explainer videos with your coding agent GitHub - dipankar/dscode: The code editor you can take apart. GitHub - zoharbabin/web-researcher-mcp: MCP server (Go) for AI assistants: web search, content extraction, academic/patent/news research. Multi-provider routing, 4-tier scraping, search lenses. Works with Claude, Cursor, and any MCP client. GitHub - ruvnet/RuView: π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video. GitHub - scanaislop/aislop: Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 7 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed. GitHub - kouhxp/cheap-im: CPU-only voice agent approximating Thinking Machines' Interaction Models demo GitHub - unprovable/OrchidMantis: Orchid Mantis — standalone framework for Zero-Knowledge Proofs of eXploit (ZKPoX). GitHub - MarcellM01/TinySearch: Shrink the web for your local LLMs! GitHub - pileax-ai/pileax: PileaX is an all-in-one AI knowledge base system. 🍀 GitHub - TangibleResearch/Halgorithem: A Algo designed to detect AI Hallucitions GitHub - DO-SAY-GO/freelang: I love freelang GitHub - CarpseDeam/Aura-IDE: An AI coding harness that shaped itself - Planner/Worker agents, repo awareness, surgical edits, validation, recovery, and safe diff approvals. GitHub - chojs23/concord: A feature-rich TUI client for Discord GitHub - tommyjepsen/awesome-ux-skills: UX & AI Product designs skills you can use today in Claude Code GitHub - aerf-spec/aerf: Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions. GitHub - kklimuk/docx-cli: CLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity. GitHub - Jwrede/tokentoll: Catch LLM cost changes in code review. Infracost for LLM spend. GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - Higangssh/homebutler: 🏠 Manage your homelab from chat. Single binary, zero dependencies. GitHub - olalie/tapmap: See where your computer connects and what stands out on a live world map. GitHub - matisiekpl/neond: DX-focused control plane for Postgres dedicated to non-critical workloads. Your postgres:latest replacement 🐘 GitHub - Diplomat-ai/diplomat-agent: What can your AI agent do to the real world? Scan your code. See which tool calls have zero checks GitHub - Bajusz15/beacon: Open-source agent for secure remote access, monitoring, and deploys across home-lab and self-hosted machines like Raspberry Pi, N100, or any Linux server. Open web based TTY or tunnel Home Assistant and other local services securely without opening ports. BigTech AI News - Chrome 应用商店 GitHub - vinhnx/VTCode: VT Code is an open-source coding agent with LLM-native code understanding and robust shell safety. Supports multiple LLM providers with automatic failover and efficient context management. GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - Lumen-Labs/brainapi2: BrainAPI is a knowledge graph–powered AI memory layer that transforms unstructured data into structured knowledge, enabling intelligent search, recommendations, and contextual memory for AI agents and applications. GitHub - familiar-software/familiar: Let AI watch you work. Familiar lets your AI update its memory, skills, and knowledge by watching your screen. GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. make sidebar/address bar rounded corner toggleable
GitHub - migradiff/migra: The actively maintained fork of migra — PostgreSQL schema diff and migration script generator.
lateos-ai · 2026-05-30 · via Show HN

migra — PostgreSQL Schema Diff Tool

PyPI version Python versions License: MIT

The actively maintained fork of djrobstep/migra.

migra compares two PostgreSQL database schemas and generates the SQL migration script needed to transform one into the other. Drop it into your CI pipeline and stop writing ALTER TABLE by hand.


Why This Fork

The original migra was officially deprecated in 2024. This fork picks up where it left off — fixing known issues, adding Python 3.12+ support, and extending coverage for advanced PostgreSQL features.

If you were using djrobstep/migra, this is your drop-in continuation. Nothing has changed about how the tool works. We're just keeping the lights on and making it better.

A note on naming: This is an independent community fork. The CLI command remains migra for drop-in backward compatibility with existing scripts and pipelines. The package name is migradiff to distinguish it from the deprecated upstream. If you are looking for the original djrobstep/migra, it is archived at https://github.com/djrobstep/migra.


Quickstart

Install

Requires Python 3.10+ and a running PostgreSQL instance (12+).

To install from source:

git clone https://github.com/migradiff/migra
cd migra
pip install -e .

Note: PyPI package is available on all releases.

Basic Usage

Point migra at two database connections and it outputs the DDL needed to migrate from one to the other:

migra \
  postgresql://user:pass@localhost/db_production \
  postgresql://user:pass@localhost/db_branch \
  --unsafe

Output is plain SQL — pipe it, review it, apply it:

migra postgres://db_a postgres://db_b > migration.sql
psql postgres://db_production < migration.sql

Schema Dumps (No Live Connection Required)

If you can't or don't want to point migra at a live database, use pg_dump -s to generate a schema dump and diff that instead:

pg_dump -s postgres://db_production > schema_a.sql
pg_dump -s postgres://db_branch     > schema_b.sql
migra --from-file schema_a.sql schema_b.sql

This is the recommended approach for CI pipelines and security-conscious environments — no production credentials required.

Migrations Directory (No Live Branch Database Required)

If your target state is defined by a folder of migration files:

migra --from-migrations-dir ./migrations postgres://db_production

MigraDiff applies the migrations to an ephemeral database and diffs the result. Supports Supabase, Flyway, and standard numeric naming conventions.

Scoped to a Schema

# Single schema
migra --schema myschema postgres://db_a postgres://db_b

# Multiple schemas (comma-separated)
migra --schema public,reporting postgres://db_a postgres://db_b

JSON Output

For programmatic consumption or CI pipelines:

migra --output json postgres://db_a postgres://db_b

Output includes per-statement risk classification (safe, warning, destructive) and a summary with overall risk level.


AI-Powered Explanation (Optional)

MigraDiff can explain any migration in plain English — what each change does, what risks it carries, and safer alternatives for destructive operations.

migra --explain postgres://db_a postgres://db_b

Output:

--- Migration SQL ---
ALTER TABLE public.users ADD COLUMN email text;
DROP TABLE public.legacy_sessions;

--- AI Explanation ---
This migration makes 2 changes to your database:

1. SAFE: Adds an email column (text) to the users table.
   No existing data is affected.

2. ⚠ DESTRUCTIVE: Drops the legacy_sessions table entirely.
   All data in this table will be permanently lost.
   Consider archiving before dropping.

Overall risk: HIGH

Powered by Claude (Anthropic). Bring your own API key — no data is sent to MigraDiff servers.

Setup

Install the AI extras:

pip install migradiff[ai]

Configure your API key once:

Or set the environment variable:

export ANTHROPIC_API_KEY=sk-ant-...

Get an API key at https://console.anthropic.com

AI Rollback Generation (--rollback)

Generate the exact reverse migration — the SQL needed to undo any migration:

migra --rollback migration.sql
migra --rollback postgres://db_a postgres://db_b

MigraDiff uses your source schema context to reconstruct DROP TABLE and DROP COLUMN reversals accurately. Non-reversible operations (TRUNCATE, bulk DELETE) are flagged explicitly.

Combine with --explain for a complete picture:

migra --explain --rollback postgres://db_a postgres://db_b

Requires pip install migradiff[ai] and an Anthropic API key.

AI Schema Drift Analysis (--explain-drift)

Compare two live PostgreSQL databases and get an AI-powered explanation of their differences — ideal for answering "What changed in production?":

migra --explain-drift \
    --from-db "postgresql://user:pass@old.example.com/db" \
    --to-db "postgresql://user:pass@prod.example.com/db"

Output categorizes each change as BREAKING, WARNING, or INFO, and includes live table sizes for risk assessment:

Schema Drift Analysis: old → prod

Changes Detected:

1. Table "users" — DROPPED
   - Columns: id, email, created_at

2. Table "accounts" — MODIFIED
   - Column "status" type changed: VARCHAR → ENUM
   - New column: "last_login_at"

Risk Analysis:
- BREAKING: "users" table was dropped. Historical data loss.
- INFO: New "accounts.last_login_at" column. No migration needed.

Requires pip install migradiff[ai] and an Anthropic API key.

AI Performance Advisor (--advise)

Before applying any migration, get a performance risk assessment — locking behavior, table rewrite risk, and zero-downtime alternatives:

migra --advise postgres://db_a postgres://db_b
migra --advise migration.sql

MigraDiff analyzes each statement for PostgreSQL-specific risks: table locks, full rewrites, irreversible data loss. When a live connection is provided, table row counts are used to estimate lock duration at your actual data scale.

Combine all three AI features for a complete picture:

migra --explain --advise --rollback postgres://db_a postgres://db_b

Requires pip install migradiff[ai] and an Anthropic API key.

AI Migration Generator (--generate)

Describe what you want in plain English — MigraDiff generates the migration SQL grounded in your actual schema:

migra --generate "add email verification to users table" \
  postgres://db_production

Unlike generic AI tools, MigraDiff knows your real table names, column types, and constraints — no hallucinated column names or wrong types.

Generate and immediately review the risk:

migra --generate "add index on orders.user_id" \
  --advise postgres://db_production

Requires pip install migradiff[ai] and an Anthropic API key.


Development Setup

The test suite requires a running PostgreSQL instance. The easiest way to get one is via Docker Compose:

This starts a Postgres 16 container on localhost:5432 with trust authentication. No password required.

To stop it:

Data persists between restarts via the migradiff-pgdata volume. To reset completely:


Docker

No Python environment? Use the official image:

docker run --rm ghcr.io/migradiff/migra \
  postgres://db_a postgres://db_b

GitHub Actions

Add schema diffing to your pull request workflow:

- uses: migradiff/migra@v1
  with:
    base_url: ${{ secrets.DB_PRODUCTION_URL }}
    head_url: ${{ secrets.DB_BRANCH_URL }}

Fail the build automatically if destructive operations are detected:

- uses: migradiff/migra@v1
  with:
    base_url: ${{ secrets.DB_PRODUCTION_URL }}
    head_url: ${{ secrets.DB_BRANCH_URL }}
    fail_on_destructive: "true"

Use schema dump files instead of live connections:

- uses: migradiff/migra@v1
  with:
    base_file: schema_production.sql
    head_file: schema_branch.sql

See docs/action-usage.md for full configuration options.


Pre-commit Hook

# .pre-commit-config.yaml
repos:
  - repo: https://github.com/migradiff/migra
    rev: v1.1.0
    hooks:
      - id: migra

See pre-commit-config.example.yaml in the repo root for full configuration options.


What migra Understands

  • Tables, columns, constraints, indexes
  • Views and materialized views
  • Functions and stored procedures
  • Sequences
  • Enums, composite types, domains
  • Row-Level Security (RLS) policies
  • Foreign data wrappers
  • Column-level privileges
  • Partitioned tables
  • Object comments (COMMENT ON)

Improvements Over Upstream

Area Upstream (deprecated) This Fork
Python 3.12+ Deprecation warnings Clean — no warnings
RLS policies Partial, equality bug Full CREATE/DROP, partition support
Error messages Cryptic on unsupported types Actionable with object name and issue link
--schema flag Edge cases in multi-schema DBs Comma-separated, cross-schema dependencies resolved
pg_dump input Not supported First-class --from-file mode
JSON output Not supported --output json with risk classification
Docker image None ghcr.io/migradiff/migra
GitHub Action None migradiff/migra-action
Pre-commit hook None .pre-commit-hooks.yaml
Dev environment Manual Docker commands docker compose up -d
AI explanation None --explain flag with Claude — plain English diff explanation, risk analysis, safer alternatives
COMMENT ON diffing Not supported Full diffing — add/change/remove across all object types
AI drift analysis None --explain-drift — compare two live databases, AI explains differences with risk categorization

See CHANGELOG.md for the full fix history.


Known Limitations

migra generates the SQL diff — it does not apply it. Review every generated script before running against production. Destructive operations (DROP TABLE, DROP COLUMN) are flagged in JSON output mode but not blocked in plain SQL mode.

migra requires a live PostgreSQL connection to introspect schemas, or schema dump files via --from-file. It does not parse raw DDL text.


Contributing Notice

Thank you for your interest in this project. Please note that we are currently not accepting any external code contributions, pull requests, bug fixes, or feature submissions at this time.

Any pull requests opened will be automatically closed without review.


Licensing

MigraDiff is free and open source under the MIT license.

All features work for everyone. No paywalls, no code restrictions, no gatekeeping.

A Quick Story

I spent 8+ years as an engineer at Philips, supporting hospital IT systems that keep patients safe. When the VC who acquired our division let me go, I was 50+ years old in a market where age matters. Finding another job became nearly impossible. I still need to support my family and put food on the table.

That's why MigraDiff exists. I'm building tools that help you, because this is how I stay employed.

Here's the Ask

If you're a student, hobbyist, or open source project: MIT license, free forever. No agreement needed.

If you're a for-profit company using MigraDiff: Please sign a Business License Agreement. This isn't about gatekeeping code—every feature stays free, you run it locally, nothing changes for you technically. It's about fairness: if my tool is helping you make money, help me feed my family.

You still own everything. You control your data. You access all features. We're just being transparent about how we sustain development.

I'm not asking for charity. I'm asking for fairness.

Get a Business License | View MIT License


Acknowledgements

This project is a fork of djrobstep/migra, created and originally maintained by Robert Lechte. The core diffing engine is his work. We are grateful for it.