NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3741 most downloaded on npm
a low-level, lightweight protocol buffers implementation in JavaScript
Last release 2 months ago
09 Jul 2026
Ships unpredictably
gaps range from 9 days to 4.7 years
Rarely documented
notes for 8 of 37 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
37 releases · first in 2014
Fix a minor vulnerability in the compiler (potential code injection via unsafe schema) #149
Fix a minor vulnerability in the compiler (potential code injection via unsafe schema) #149
Add a fast path for writePackedVarint (20% speedup on the vector tiles encoding benchmark) (h/t @dcodeIO)
writePackedVarint (20% speedup on the vector tiles encoding benchmark) (h/t @dcodeIO)PbfReader and PbfWriter to honor non-zero byteOffset of the backing buffer (h/t @mattico #147)One column per quarter.
Added a new PbfReader nextField(end) method that allows writing more compact, readable and bulletproof decoding code while preserving performance. #14
PbfReader nextField(end) method that allows writing more compact, readable and bulletproof decoding code while preserving performance. #144pbf/compile to take advantage of nextField.The Pbf class is split into separate PbfReader and PbfWriter classes, so bundlers can tree-shake the half you don't use.
Breaking changes
Pbf class is split into separate PbfReader and PbfWriter classes, so bundlers can tree-shake the half you don't use.readVarint64 method — use readVarint(true) for signed 64-bit reads.Performance
On the Mapbox vector-tile benchmark (439 tiles, 37.5 MB), v5 is ~25% faster to decode and ~27% faster to encode than v4. Highlights:
while loops with direct field-number dispatch, letting V8 fully inline each reader (biggest decode win).writeVarint / readVarint got single-byte fast paths for the common case (tags, small ints).makeRoomForExtraLength now uses Uint8Array.copyWithin instead of a manual byte-shift loop (biggest encode win).writeBytes uses typedArray.set instead of a manual copy loop.Other improvements
compile.js) was significantly simplified — generated code is cleaner and easier to read.packed sfixed64 fields.Add sanitization of field names in pbf/compile to protect against injection via malicious proto schema.
pbf/compile to protect against injection via malicious proto schema.Avoid creating redundant zero-byte buffer when writing Pbf.
Pbf.Pbf constructor typings (mark buf as optional).⚠️ Expose the library as a ES module, dropping CommonJS support.
--legacy mode.ieee754 package and use native DataView instead, which is faster and universally supported.Fix incorrect code generation for enums. https://github.com/mapbox/pbf/commit/2e0dfa7b553eef932ce3f83daa151a3b3600bcb5
undefined instead of null as the default value for generated code (by @Timmmm in https://github.com/mapbox/pbf/pull/112)js_type annotations for generated code (by @UlysseM in https://github.com/mapbox/pbf/pull/121)TextDecoder in certain environments (by @evertbouw in https://github.com/mapbox/pbf/pull/113)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →