NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #910 most downloaded on npm
Parser and generator for CSS color strings
Last release 10 months ago
15 Nov 2025
Release timing varies
gaps range from 8 days to 2.8 years
Some releases are documented
notes for 20 of 42 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
42 releases · first in 2011
feat: Make string checks case insensitive by @camdecoster in https://github.com/Qix-/color-string/pull/81
Full Changelog: 2.1.3...2.1.4
fix: get.rgb() returning invalid results with named color by @d4rya38 in https://github.com/Qix-/color-string/pull/86
Full Changelog: 2.1.2...2.1.3
One column per quarter.
Functionally identical release to 2.1.0 .
Functionally identical release to 2.1.0.
Version 2.1.1 is compromised. Please see debug-js/debug#1005.
parsing no comma rgb(a) by @gallyamow in https://github.com/Qix-/color-string/pull/74
Full Changelog: 2.0.1...2.1.0
Change typings to always return null instead of undefined by @screendriver in https://github.com/Qix-/color-string/pull/73
Full Changelog: 2.0.0...2.0.1
Move to ESM and remove swizzle support by @LitoMore in https://github.com/Qix-/color-string/pull/69
Full Changelog: 1.9.1...2.0.0
Nothing published for this version
Add parsing of exponential alpha values for HWB and HSL
Thanks to @babycannotsay for their contribution!
Fix incorrect handling of optional comma in rgb() regex
Thanks to @gerdasi and @mastertheblaster for reporting and confirming the bug!
Fix rgb alpha percentage parsing from int to float
Thanks to @cq360767996 for their contribution!
Thanks to @cq360767996 for their contribution!
Fix bug in .to.hex() output if the inputs aren't rounded numbers
.to.hex() output if the inputs aren't rounded numbers (#25)Thanks to @adroitwhiz for their contributions.
Thanks to @adroitwhiz for their contributions.
Fix issue where color-string with incorrectly return a color for properties on Object's prototype like "constructor".
Thanks to @tolmasky for their contributions.
Reduce acceptable characters in keyword matching regex
Thanks to @benmccann for their contributions!
Add support for space-separated RGB
Thanks to @JJC1138 and @clytras for their contributions!
Thanks @htunnicliff for the contribution :)
Thanks @htunnicliff for the contribution :)
A ReDos (Regular Expression Denial of Service) vulnerability was responsibly disclosed to me via email by Colin on Mar 5 2021 regarding an exponential…
Release notes copied verbatim from the commit message, which can be found here: 0789e21284c33d89ebc4ab4ca6f759b9375ac9d3
Discovered by Yeting Li, c/o Colin Ife via Snyk.io.
A ReDos (Regular Expression Denial of Service) vulnerability
was responsibly disclosed to me via email by Colin on
Mar 5 2021 regarding an exponential time complexity for
linearly increasing input lengths for `hwb()` color strings.
Strings reaching more than 5000 characters would see several
milliseconds of processing time; strings reaching more than
50,000 characters began seeing 1500ms (1.5s) of processing time.
The cause was due to a the regular expression that parses
hwb() strings - specifically, the hue value - where
the integer portion of the hue value used a 0-or-more quantifier
shortly thereafter followed by a 1-or-more quantifier.
This caused excessive backtracking and a cartesian scan,
resulting in exponential time complexity given a linear
increase in input length.
Thank you Yeting Li and Colin Ife for bringing this to my
attention in a secure, responsible and professional manner.
A CVE will not be assigned for this vulnerability.
Removes rounding of alpha values in RGBA hex (#rrggbbaa) and condensed-hex (#rgba) parsers, which caused certain unique inputs to result in identical
#rrggbbaa) and condensed-hex (#rgba) parsers, which caused certain unique inputs to result in identical outputs (see https://github.com/qix-/color/issues/174).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Changed: Invalid conversions now return null instead of undefined
null instead of undefinedFixed: ability to parse signed number
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →