NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3031 most downloaded on npm
Gets the job done when JSON.stringify can't
Last release 12 days ago
22 Sep 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 54 of 54 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
54 releases · first in 2018
12ad9d6 : chore: remove dts-buddy
c13cf6a : fix: populate error.path for values reached through a promise in stringifyAsync
error.path for values reached through a promise in stringifyAsyncstringify and uneval skip per-character escaping for strings with nothing to escapeInvalid input instead of a raw TypeError for malformed typed array and boxed primitive payloadsuneval for typed array views whose backing buffer ends with a partial elementOne column per quarter.
afb3cb4 : breaking: use tagged template js for uneval replacers instead of nested uneval
js for uneval replacers instead of nested uneval067b125 : perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake
Object.freeze calls as pure so unused operation tables tree-shake6861dbb : fix: avoid scanning sparse array holes in uneval traversal and shared-array population
uneval traversal and shared-array populationparse and unflatten to prevent bypassing the __proto__ checkstringifyAsync when serializing multiple promisesuneval output expansion for repeated strings and bigintsunevalstringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool8b2a456 : fix: reject out-of-bounds indices
39457ce : fix: uneval emits valid JS for graphs with more than 65534 repeated references
07d6a38 : feat: export filterArrayIndices , the array-index filtering used by the indicesOf stringify operation, so custom operations can reuse it ins
filterArrayIndices, the array-index filtering used by the indicesOf stringify operation, so custom operations can reuse it instead of reimplementing itoperations option to parse/unflatten, allowing customization of how values are constructed while reviving (e.g. cross-realm or foreign-runtime revival)operations option to stringify/stringifyAsync, allowing customization of how values are introspected during serialization (e.g. side-effect-free or foreign-runtime serialization)48cc81f : fix: serialize DataView subviews with the correct byte offset and length
uneval now produces valid output for a repeated empty Map or SetunevalBigInt64Array and BigUint64Array in unevaluneval206ca67 : fix: force sparse arrays to allocate sparsely
c5115b0 : feat: add stringifyAsync for async serialization
stringifyAsync for async serialization8becc7c : fix: handle regexes consistently in uneval's value and reference formats
df2e284 : feat: use native alternatives to encode/decode base64
87c1f3c : fix: reject __proto__ keys in malformed Object wrapper payloads
87c1f3c: fix: reject __proto__ keys in malformed Object wrapper payloads
This validates the "Object" parse path and throws when the wrapped value has an own __proto__ key.
40f1db1: fix: ensure sparse array indices are integers
87c1f3c: fix: disallow __proto__ keys in null-prototype object parsing
This disallows __proto__ keys in the "null" parse path so null-prototype object hydration cannot carry that key through parse/unflatten.
0f04d4d : fix: Properly handle __proto__
1175584 : fix: validate input for ArrayBuffer parsing
2161d44: fix: add hasOwn check before calling reviver
a3d09d4: feat: expose DevalueError for instanceof checks in catch clauses
DevalueError for instanceof checks in catch clausesvalue and root properties in DevalueError instances828fa1c: Enable support for custom reducer/reviver for "function" values
5c26c0d: fix: allow custom revivers to revive things serialized by builtin reducers
ca3c7b6: chore: Remove impossible void type from replacer's uneval
void type from replacer's uneval9306d09: feat: pass uneval to replacer, for handling nested custom types
uneval to replacer, for handling nested custom typesuneval output with null-proto objects0623a47: fix: disallow array method access when parsing
__proto__ properties on objectsae904c5: fix: correctly differentiate between +0 and -0
2896e7b: feat: support Temporal
URL and URLSearchParams objectsHandle custom classes with null proto as pojo
Only iterate over own properties of reducers
Handle typed arrays and array buffers
Ignore non-enumerable symbolic keys
Fix incorrect error.path when object contains a map
- Better type declarations
- Faster
- Support custom types
Correctly escape control characters
- Remove pkg.main
pkg.main (#56)- Re-use internal helper
- Add unflatten
unflatten (#48)Only deduplicate non-primitives
Remove devalue export so that run time errors become build time errors
devalue export so that run time errors become build time errorsRename devalue function to uneval
devalue function to unevalparse and stringify functions- Add pkg.main
pkg.main- Include pkg.types
pkg.types- Include types in pkg.files
types in pkg.filesInclude path in error object if value is unserializable
path in error object if value is unserializablePrevent duplicate parameter names
Prevent regex XSS vulnerability in non-Node environments
- Change license to MIT
Prevent object key XSS vulnerability
- Escape lone surrogates
- Smaller output
- Detect POJOs cross-realm (#7) - Error on symbolic keys
- Fix global name for UMD build
- XSS mitigation
- First release
Your coding agent can read these notes before it upgrades. Set up the MCP server →