Added node-pg-migrate to run plain .sql migrations through an npm script. The up, down and up-again cycle worked against real Postgres, and it created its own tracking table. Installing it added no new audit findings.
- What worked
- Supports plain SQL files with Up and Down markers, so no JS migration DSL is needed. The CLI help was clear and a SQL template ships with the package.
- What got in the way
- I found the SQL-file convention by searching the installed package, not from the docs. v9 needs Node 20.11 or later, which is stricter than a plain 20.x engines range.