## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Bug fix (sanitization hardening).
## What is the current behavior?
`pg-format`'s `keyword()` helper validates with `/^[A-Za-z][A-Za-z0-9_
]*$/`, which allows any space-separated word sequence. Phrases like
`'DROP TABLE'` or `'DELETE FROM users'` pass validation and can be
interpolated into queries.
## What is the new behavior?
`keyword()` accepts either a single word matching
`[A-Za-z][A-Za-z0-9_]*` (no spaces) or a phrase from a small
case-insensitive allow-list (`'INSTEAD OF'`, `'BY DEFAULT'`) — which
covers every multi-word value real callers actually produce (trigger
activation, identity generation). Arbitrary multi-word phrases now
throw. Tests updated accordingly.
## Additional context
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Reinforced SQL keyword validation with stricter security controls to
prevent unsafe keyword usage. The system now only permits single-word
identifiers or specific pre-approved multi-word keyword phrases.
Previously accepted multi-word inputs that don't match the curated
allowlist are now properly rejected with improved error messaging.
<!-- review_stack_entry_start -->
[](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46076?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)
<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
* **New Features**
* Added new SQL formatting utilities including keyword validation and
safe SQL composition functions
* Introduced type-safe SQL fragment handling with branded types to
prevent SQL injection vulnerabilities
* Expanded available exports for improved code organization and
accessibility
* Enhanced SQL query building capabilities with improved validation and
composition support
Sorted all imports in all packages, `cms`, `design-system` and
`ui-library` apps by running `pnpm format` on them.
All changes in this PR are done by the script.