NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #46 most downloaded on npm
YAML 1.2 parser and serializer
Last release 21 days ago
13 Sep 2026
Ships unpredictably
gaps range from 8 days to 4.6 years
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
91 releases · first in 2011
forceQuotes no longer quotes non-string scalars, #798.
forceQuotes no longer quotes non-string scalars, #798.Hard-limit merge sequence size to 100.
maxTotalMergeKeys to limit
CPU usage, #797.Added the scalarStyleRules dumper option to customize string formatting. See Scalar styling for details.
One column per quarter.
scalarStyleRules dumper option to customize string formatting.
See Scalar styling for details.SCALAR_STYLE and COLLECTION_STYLE values;
explicit tags use the separate tagged property. Alias nodes now contain
only kind and anchor. This only affects code that directly constructs or
edits AST nodes.sortKeys option was rewritten using AST mutation to avoid
side effects.quoteFlowKeys and flowSkipColonSpace,
including alias and property-only keys, #786.The old exports are still preserved, but deprecated.
This release focuses on reworking the documentation and making small architectural improvements before moving forward.
DUMP_SCHEMA, the default schema used by the dumper.YAMLException.throwAt() for throwing an error at a source position.EVENT_ID, SCALAR_STYLE,
COLLECTION_STYLE, and CHOMPING_MODE, along with their value types. The old
exports are still preserved, but deprecated.identify mandatory for custom tag definitions. Use
identify: () => false for load-only tags.MERGE_KEY export (not used anymore after last fixes).<< sequence items at merge time, so aliased merge sources are
checked too.<< outside of a mapping key as the plain string '<<', matching
v4, instead of leaking an internal symbol into the result.Prevent prototype fallback when resolving tags and mapping entries, #782.
!!timestamp years 0000-0099 correctly, #775.present(); dump() and loading are unaffected, #780.Quote flow scalars where a colon precedes a flow indicator, #773.
Add Map support to !!omap (should work when realMapTag used)
Map support to !!omap (should work when realMapTag used)addItem. Regression from v5
(usually not critical, because YAML11_SCHEMA is not default anymore).Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.
maxTotalMergeKeys (10000) loader option to limit the total number of
keys processed by YAML merge (<<) across one load() / loadAll() call.maxAliases (-1) loader option to limit the number of YAML aliases per
document.maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge
processing.1e21)Collection tags can finalize an incrementally populated carrier into a different result value.
quoteStyle now selects the preferred quote style; use the
restored forceQuotes option to force quoting non-key strings.Deprecated the loadAll signature with an iterator (still works, but is a candidate for removal).
JSON_SCHEMA and CORE_SCHEMA with spec-compliant scalar resolution
rules, and added YAML11_SCHEMA.realMapTag for lossless mappings with non-string and complex keys.
Object-based mappings now reject complex keys instead of stringifying them.dump() transform option for changing the generated AST before
rendering.dump() options seqInlineFirst, flowBracketPadding,
flowSkipCommaSpace, flowSkipColonSpace, quoteFlowKeys, quoteStyle and
tagBeforeAnchor.CORE_SCHEMA (loader default), JSON_SCHEMA,
FAILSAFE_SCHEMA.YAML11_SCHEMA, a combination of all YAML 1.1 tags (YAML 1.1 does not
specify a schema, only "types").load/dump default behaviour is now specified exactly via schemas:
load uses CORE_SCHEMA, without !!merge by default.dump uses YAML11_SCHEMA + CORE_SCHEMA for the quoting check, to
guarantee backward compatibility by default.!!set is now loaded as a JavaScript Set.Type API with a tags API. Similar, but more precise and
simpler. See examples for details. Tags can be defined via
defineScalarTag(), defineSequenceTag() and defineMappingTag(), or as a
spread + override of an existing tag.Schema.extend() to Schema.withTags().load() now throws on empty input instead of returning undefined.js-yaml/browser export.loadAll signature with an iterator (still works, but is a
candidate for removal).safeLoad(), safeLoadAll() and safeDump() exports.DEFAULT_SCHEMA and the nested types export.onWarning, legacy and listener.styles, replacer, noCompatMode, condenseFlow,
quotingType and forceQuotes. Renamed noArrayIndent to seqNoIndent.
Formatting and representation are now configured through presenter options,
schemas and tag definitions. See migration guide on how to replace.lib/.Nothing published for this version
Nothing published for this version
Backported maxTotalMergeKeys option.
maxTotalMergeKeys option.Added docs/safety.md with notes about processing untrusted YAML.
docs/safety.md with notes about processing untrusted YAML.maxDepth (100) loader option. Not a problem, but gives a better
exception instead of RangeError on stack overflow.merge fix, but an additional restriction for safety.dist/ builds.dist/ files are no longer kept in the repository.Fix prototype pollution issue in yaml merge (<<) operator.
Types are now exported as yaml.types.XXX.
yaml.types.XXX.options property with original arguments kept as they were
(see yaml.types.int.options as an example).Schema.extend() now keeps old type order in case of conflicts
(e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as abcd instead of cbad).Check migration guide for details of all breaking changes.
!!js/function, !!js/regexp, !!js/undefined are
moved to js-yaml-js-types package.safe* functions. Use load, loadAll, dump
instead which are all now safe by default.yaml.DEFAULT_SAFE_SCHEMA and yaml.DEFAULT_FULL_SCHEMA are removed, use
yaml.DEFAULT_SCHEMA instead.yaml.Schema.create(schema, tags) is removed, use schema.extend(tags) instead.!!binary now always mapped to Uint8Array on load./lib folder.01234 is now decimal,
0o1234 is octal, 1:23 is parsed as string instead of base60).dump() no longer quotes :, [, ], (, ) except when necessary, #470, #557.(X:Y) instead of
at line X, column Y (also present in compact format), #332.dump() now serializes undefined as null in collections and removes keys with
undefined in mappings, #571.! are now dumped as !tag instead of !<!tag>, #576.tag:yaml.org,2002: are now shorthanded using !!, #258..mjs (es modules) support.quotingType and forceQuotes options for dumper to configure
string literal style, #290, #529.styles: { '!!null': 'empty' } option for dumper
(serializes { foo: null } as "foo: "), #570.replacer option (similar to option in JSON.stringify), #339.Tag can now handle all tags or multiple tags with the same prefix, #385.dump(), #587.[foo,,bar]) now throw an exception
instead of producing null, #321.__proto__ key no longer overrides object prototype, #164.bower.json.load() and url-encoded in dump()
(previously usage of custom non-ascii tags may have led to invalid YAML that can't be parsed).Nothing published for this version
Nothing published for this version
Nothing published for this version
### Security - Backported v4.1.1 fix to v3
Fix possible code execution in (already unsafe) .load() (in &anchor).
.load() (in &anchor).Support safe/loadAll(input, options) variant of call.
safe/loadAll(input, options) variant of call.= in plain scalars #519.!<?> tag in case user manually specifies it.Fix possible code execution in (already unsafe) .load(), #480.
.load(), #480.Security fix: safeLoad() can hang when arrays with nested refs used as key. Now throws exception for nested arrays. #475.
safeLoad() can hang when arrays with nested refs
used as key. Now throws exception for nested arrays. #475.Fix noArrayIndent option for root level, #468.
noArrayIndent option for root level, #468.Added noArrayIndent option, #432.
noArrayIndent option, #432.Support arrow functions without a block statement, #421.
Add arrow functions suport for !!js/function.
!!js/function.Fix condenseFlow output (quote keys for sure, instead of spaces), #371, #370.
condenseFlow output (quote keys for sure, instead of spaces), #371, #370.Ensure stack is present for custom errors in node 7.+, #351.
Add condenseFlow option (to create pretty URL query params), #346.
condenseFlow option (to create pretty URL query params), #346.Dumper: prevent space after dash for arrays that wrap, #343.
Should not allow numbers to begin and end with underscore, #335.
Fix !!float 123 (integers) parse, #333.
!!float 123 (integers) parse, #333.Maintenance: update browserified build.
Fix reported position for duplicated mapping key errors. Now points to block start instead of block end. (#243, thanks to @shockey).
duplicated mapping key errors.
Now points to block start instead of block end.
(#243, thanks to @shockey).Support polymorphism for tags (#300, thanks to @monken).
Fix output cut on a pipe, #286.
Dumper rewrite, fix multiple bugs with trailing \n. Big thanks to @aepsilon!
\n.
Big thanks to @aepsilon!Date parse fix: don't allow dates with on digit in month and day, #268.
noCompatMode for dumper, to disable quoting YAML 1.1 values.
noCompatMode for dumper, to disable quoting YAML 1.1 values.### Changed - Maintenance release.
Maintenance: missed comma in bower config.
Removed inherit dependency, #239.
inherit dependency, #239.Dumper. Fold strings only, #217.
norefs option, to clone linked objects, #229.esprima & Buffer excluded).Use standalone inherit to keep browserified files clear.
inherit to keep browserified files clear.Added lineWidth option to dumper.
lineWidth option to dumper.Fixed floats dump (missed dot for scientific format), #220.
Maintenance release - deps bump (esprima, argparse).
Fixed serialization of duplicated entries in sequences, #205. Thanks to @vogelsgesang.
Fixed stacktrace handling in generated errors, for browsers (FF/IE).
Don't throw on warnings anymore. Use onWarning option to catch.
onWarning option to catch.Added .sortKeys dumper option, thanks to @rjmunro.
.sortKeys dumper option, thanks to @rjmunro.Significantly improved long strings formatting in dumper, thanks to @isaacs.
### Changed - Maintenance release. - Updated dependencies. - HISTORY.md -> CHANGELOG.md
Fixed encoding of UTF-16 surrogate pairs. (e.g. "\U0001F431" CAT FACE).
Fixed resolving of all built-in types on empty nodes.
Fixed resolving of !!null tag on an empty node.
Implemented dumping of objects with circular and cross references.
Your coding agent can read these notes before it upgrades. Set up the MCP server →