NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4054 most downloaded on npm
traverse and transform objects by visiting every node on a recursive walk
Last release 3 months ago
11 Jun 2026
Ships unpredictably
gaps range from 9 days to 1.8 years
Most releases are documented
notes for 11 of 17 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
20 releases · first in 2024
### Patch Changes - 90e854d: Add /safe to readme
neotraverse 1.0 makes the tree-shakeable functional API the main export and demotes the class-based API to a thin, deprecated, opt-in import. The func…
7f7d18a: # 1.0 — the functional API is now the default
neotraverse 1.0 makes the tree-shakeable functional API the main export and demotes the class-based API to a thin, deprecated, opt-in import. The functions, their behaviour, the security hardening, and the performance work from 0.7 are unchanged — the entry points moved.
| 0.7 | 1.0 |
|---|---|
import traverse from 'neotraverse' (classic default) |
import traverse from 'neotraverse/legacy' |
import { Traverse } from 'neotraverse' |
import { Traverse } from 'neotraverse/modern' |
import { map, clone, … } from 'neotraverse/modern' |
import { map, clone, … } from 'neotraverse' |
neotraverse) is now functional-only — map, clone, merge, diff, get/set, walk, sanitize, and the rest of the helpers, plus the TraverseOptions / TraverseContext / TraverseNodeType types. No default export, no Traverse class.neotraverse/modern now exports ONLY the deprecated Traverse class (and the TraverseContext / TraverseOptions types its signatures use). The functional helpers it used to re-export move to the root. The class is also trimmed to the same method set as the legacy Traverse (get/has/set/map/forEach/reduce/paths/nodes/clone) — a deprecated API should not gain new powers. It will be removed in v2.neotraverse/legacy is unchanged: the classic traverse-compatible drop-in (ES2015, CJS + ESM). require('neotraverse') (CommonJS) still resolves here. The legacy build intentionally will not receive the modern security/performance work — it stays byte-for-byte behaviour-compatible with the original traverse.production/development conditions, no dist/min).utils/clone/context/path/ops) instead of one large file; the legacy build lives under src/legacy/. dist/modern.js reuses the root build's shared chunk instead of re-bundling the functional API. No change to what consumers import.7f7d18a: # neotraverse/safe: a stack-safe, memory-bounded traversal core
A new opt-in entry point, neotraverse/safe. It is a companion to the default functional API (not a replacement), for input that is deep, untrusted, huge, or only partially consumed.
The default neotraverse walk is recursive, which is why it is fast, but a recursive walker overflows the call stack on deep enough input. neotraverse/safe runs on an iterative engine, so it traverses arbitrarily deep trees that crash a recursive walker. Measured: the default overflows past ~2,000 levels; /safe handles 200,000+. It is also lazy and copy-on-write.
visit: a lazy iterator of Visit records that composes with native ES2025 iterator helpers (.filter / .map / .find / .take / .toArray, Map.groupBy, for-of + break), prunes with v.skip(), and matches a glob pattern.transform / transformAsync: copy-on-write rewriting. Untouched subtrees are shared with the input, and transform(x, () => {}) === x. Edits are branded commands (replace / remove / skip / stop) returned from a destructurable edit factory, including a pattern-keyed rules record form.get / set / has: one path family (dot string, JSON Pointer, or key array), template-literal typed, with copy-on-write set.clone / equal / merge / diff / patch / resolveRefs: structural ops. merge adds array strategies (concat / union / by) and per-pattern at overrides./safe is not a universal upgrade. On a full eager scan it runs at roughly 0.8x the default (still about 4x faster than the original traverse), and materializing a whole tree costs a little more memory. It wins on stack safety, on early-exit and streaming memory (about 6x less on a filter then take chain), and on copy-on-write edits.
Requires Node 22+ or evergreen browsers (it uses native ES2025 iterator helpers). See the guide: https://neotraverse.puruvj.dev/guide/safe
One column per month.
### Patch Changes - 07e5f02: fix: CI build
c73840d: fix: Actually add provenance
af2405a: patch: Add changesets, provenance
PINNED: traverse@0.6.9 ### Patch Changes Pin engines field to >= 10
PINNED: traverse@0.6.9
Pin engines field to >= 10
Fix regression in legacy.mjs introduced in 0.6.13.
PINNED: traverse@0.6.9
Fix regression in legacy.mjs introduced in 0.6.13.
Fix types for neotraverse/legacy for pre-TypeScript 4.5(when export maps were not supported).
PINNED: traverse@0.6.9
Fix types for neotraverse/legacy for pre-TypeScript 4.5(when export maps were not supported).
Earlier, neotraverse/legacy did not work with WebPack 4, as it does not support export maps. Now this package provides direct fallback for CJS.
PINNED: traverse@0.6.9
Earlier, neotraverse/legacy did not work with WebPack 4, as it does not support export maps. Now this package provides direct fallback for CJS.
Fix types for neotraverse/legacy. I am sacrificing types for CJS in favor of ESM.
PINNED: traverse@0.6.9
Fix types for neotraverse/legacy. I am sacrificing types for CJS in favor of ESM.
Use the following to get type-safety
const traverse = require("neotraverse/legacy");
// ^ It isn't typed
const neoTraverse = traverse as traverse["default"];
// ^ It is typed
Fix types for neotraverse/legacy. Now both CJS and ESM are properly typed. CAVEAT: ESM import in typescript doesn't provide TraverseContext and Traver
PINNED: traverse@0.6.9
Fix types for neotraverse/legacy. Now both CJS and ESM are properly typed. CAVEAT: ESM import in typescript doesn't provide TraverseContext and TraverseOptions types. Import that from neotraverse instead.
Fresh start. Check out the CHANGELOG 0.6.9 for a list of changes prior to this release.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →