NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2586 most downloaded on npm
A JS implementation of JSONPath with some additional operators
Last release 3 days ago
01 Oct 2026
Release timing varies
gaps range from 8 days to 1.4 years
Nearly every release is documented
notes for 50 of 50 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
50 releases · first in 2015
fix: avoid treating at sign within regex as current context; fixes #280
fix: allow bare @ in any position (e.g., $[?(@>1)], $[?(@)], $[?(!@)]) and stop rewriting @ inside quoted string literals (@spokodev)
@ in any position (e.g., $[?(@>1)], $[?(@)],
$[?(!@)]) and stop rewriting @ inside quoted string literals
(@spokodev)$['x','y'],
$["a,b",'c.d']) as literal names (fixes #159; see #268)$['a,b'])\', \", and \\ escapes within quoted property names
and escape ' and \ in toPathString output so paths round-tripOne column per quarter.
fix(security) nested filter bypass exploit (@andrewmacheret)
Require Node >= 22; drops older browser version support
BREAKING CHANGES
Require Node >= 22; drops older browser version support
JSONPath.cache is no longer exposed or mutable. Consumers that used JSONPath.cache to inspect, modify, or clear entries must remove that usage and call JSONPath.clearCache() when cache invalidation is needed.
chore: bump engines and browserslist and use v flag
chore: various changes in types, particularly with return values changing from any to unknown to ensure type safety (by forcing type casts of the results on the user).
fix!: isolate caches and add cache reset API
Other changes:
customTypes option for providing own other type callbacks (e.g., @blob()) (@brettz9)OtherTypeCallback callback type can accept a parentPropName with type number (@brettz9)JSONPath.prototype.evaluate, safeVm, and vm compatibility@c0rydoras: Arthur Deierlein <info@c0rydoras.dev>)docs: fix Markdown formatting of examples in README.md by @aspiers in #230
Full Changelog: v10.3.0...v10.4.0
fix(eval): rce using non-string prop names by @80avin in #237
Full Changelog: v10.2.0...v10.3.0
fix(eval): improve security of safe-eval
feat: add typeof operator to safe script
fix(security): prevent constructor access
constructor accessfix(security): prevent call/apply invocation of Function
call/apply invocation of Functionfix: remove overly aggressive disabling of native functions but disallow __proto__
__proto__fix(security): further prevent binding of Function calls which may evade detection
fix(security): prevent binding of Function calls which may evade detection
fix(security): prevent Function calls outside of member expressions
fix(security): prohibit Function in "safe" vm
Function in "safe" vmfix(security): use safe vm by default in Node
BREAKING CHANGES:
Require Node 18+
fix(security): use safe vm by default in Node
chore: bump jsep, devDeps. and lint
Removes preventEval property. Prefer eval: false instead.
BREAKING CHANGES:
Removes preventEval property. Prefer eval: false instead.
Changed behavior of eval property. In the browser, eval/Function won't be used by default to evaluate expressions. Instead, we'll safely evaluate using a subset of JavaScript. To resume using unsafe eval in the browser, pass in the option eval: "native"
feat: add safe eval for browser and eval option (#185) (@80avin)
feat: add ignoreEvalErrors property (@80avin)
feat: add basic cli (#206) (@vid)
Breaking change: Bump Node engines to 14
engines to 14perf: optimize walk method by 10%-34% (@jacobroschen)
perf: improve evaluation speed of conditional queries (@jacobroschen)
Breaking change: Bump engines to 12
engines to 12console.log when error is thrown (@sh33dafi)Fix: Some package.json paths needed updating (@matushorvath)
package.json paths needed updating (@matushorvath)Breaking change: Utilize .cjs extension for UMD and CJS builds (very old browsers might not support, but needed with the change given that Webpack may…
.cjs extension for UMD and CJS builds (very
old browsers might not support, but needed with the change given that
Webpack may complain if there even exists CJS within what it thinks is
an ESM file, the ".js", our default).js extension instead of .mjs for now default
ESM buildslint scriptEnhancement: support double-quoted bracket notation
Fix: Add packge.json to exports (@sebastiendavid)
packge.json to exports (@sebastiendavid)Fix: Remove static modifiers (@sdolski)
static modifiers (@sdolski)Fix: Avoid cache corruption when the returned structure is modified. Fixes #102. (@tejodorus)
Fix: allow falsey at values in filter (now may require checking for presence of @ in some cases); fixes #136
@ in some cases); fixes #136Fix: Add package exports for browser and umd (#145) (@gjvoosten)
eslint-plugin-sonarjs to eslint-plugin-radarFix: Proper Node CommonJS export; fixes #144
Fix: Proper Node CommonJS export; fixes #143
Breaking change: Add type: 'commonjs' and exports: {import, require} (with node-import-test npm script to demo)
type: 'commonjs' and exports: {import, require}
(with node-import-test npm script to demo)dist/index-browser-umd.js or dist/index-browser-es.js)
(for Node, main and module point to new Node-specific dist)browser for browser bundling;
allowing static analysis environments, doesn't have however
conditional code to require vm); for ESM browser bundling,
now must check browser in Rollup Node resolver plugin;
see README.match) example on value (@jeffreypriebe).match) example on propertydist field to avoid extra config reportingrollup-plugin-babel to @rollup/plugin-babel
(and make babelHelpers explicit)Breaking change/fix: Disallow resultType from being lower-cased (broke parentProperty)
resultType from being lower-cased
(broke parentProperty)Breaking change: Expect Node >= 8
json as "own" propertyresultType is "all", if path resolves internally to a
non-array (string), ensure it is converted to an array before
converting to pointer for pointeresm)test-cov scriptBreaking change: Throw TypeError instead of Error for missing otherTypeCallback when using @other
TypeError instead of Error for missing
otherTypeCallback when using @otherTypeError instead of Error for missing pathTypeError for missing json (fixes #110)new Function over eval;
also allows use of cyclic context objects@root filter selector.editorconfigpath or jsonpackage-lock.jsonEnhancement: Add explicit 'any' to evaluate() declaration (for use with noImplicitAny TypeScript option)
evaluate() declaration (for use
with noImplicitAny TypeScript option).idea/.remarkrc files- Add TypeScript declaration
npm: Avoid adding core-js-bundle as peerDep. (fixes #95)
core-js-bundle as peerDep. (fixes #95)Build: Add browserslist for Babel builds
browserslist for Babel buildsDocs (README): Indicate features, including performance (removing old note)
.json extensionFix: Expose pointer on resultType: "all"
pointer on resultType: "all"Security enhancement: Use global eval instead of regular eval
wrap behaviorBreaking change: With Node use, must now use require('jsonpath-plus').JSONPath.
require('jsonpath-plus').JSONPath.includes
(can get with @babel/polyfill or own)JSONPath.evaltoString() had not been working properly with them)module in package.jsonnode-static and add opn-cli;
mostly switch to ESMpackage-lock.json; remove non-functioning remarkBreaking change: Give preference to treating special chars in a property as special (override with backtick operator)
toPathArray caching bugFix: Fixing support for sandbox in the case of functions
this if present for global exporteslint, remark, lint, nodeunitnpm run browser-testFeature: Add @scalar() type operator (in JavaScript mode, will also include)
@scalar() type operator (in JavaScript mode, will also
include)Fix: Avoid double-encoding path in results
Breaking change (from version 0.11): Silently strip ~ and ^ operators and type operators such as @string() in JSONPath.toPathString() calls.
~ and ^ operators
and type operators such as @string() in JSONPath.toPathString() calls.Array.isArray polyfill as no longer
supporting IE <= 8JSONPathJSONPath.toPointer() and "pointer" resultType option.callback and otherTypeCallback as numbered
arguments to JSONPath.@ or other special characters in at-sign-prefixed
property names (by use of [?(@['...'])] or [(@['...'])]).Breaking change: Problems with upper-case letters in npm is causing us to rename the package, so have renamed package to "jsonpath-plus" (there are al…
Your coding agent can read these notes before it upgrades. Set up the MCP server →