NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #16 most downloaded on npm
Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.
Last release 1 months ago
24 Aug 2026
Release timing varies
gaps range from 6 weeks to 1.8 years
Most releases are documented
notes for 23 of 35 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
35 releases · first in 2018
fix: handle terminal globstars in parenthesized patterns by @mrmlnc in #198
fix: scan full pattern when tokens are requested by @mrmlnc in #197
One column per quarter.
Full Changelog: 4.0.5...4.0.6
scan() now scans the full pattern when tokens are requested, instead of merging the remaining path segments into the final token (#62, 5f5819d).scan() now returns complete pattern parts, including leading and trailing empty segments, and handles nested and escaped parentheses correctly (#58, f201165).fix: preserve all branches when rewriting risky repeated extglobs by @MerlijnW70 in #182
Full Changelog: 4.0.4...4.0.5
This is a security release fixing several security relevant issues.
This is a security release fixing several security relevant issues.
Full Changelog: 4.0.3...4.0.4
maxExtglobRecursion option defaults to 0; positive numeric values allow limited nesting, while false disables the safeguard (CVE-2026-33671, 5eceecd).fix: exception when glob pattern contains constructor by @Jason3S in #144
Bump deps. Move isWindows to lib/utils.
Requires Node.js >=12
Requires Node.js >=12
On supported Node.js versions, 4.0.0 does not remove any public matcher API or change matching semantics. Its compatibility change is the removal of P
toRegex() behavior: a non-matching fallback by default and the native RegExp error when debug: true (#129, 907d706).text values when parse() combines adjacent text tokens (#100, #125, #126, 563f534). Thanks to @connor4312.os dependency from the main entry point to support browser environments (#124, b0ff9b1). Thanks to @gwsbhqt.sideEffects: false to package.json (#128, 8f18eb6). Thanks to @frandiox.picomatch.constants, on the package's main export (335eac6).This is a security release fixing several security relevant issues.
This is a security release fixing several security relevant issues.
Full Changelog: 3.0.1...3.0.2
maxExtglobRecursion values allow limited nesting, while false disables the safeguard (CVE-2026-33671, 05c0743).3.0.0 was published a couple of hours ago. This should have been done at that time.
3.0.0 was published a couple of hours ago. This should have been done at that time.
Windows path-separator handling in the core and static APIs is now controlled by the windows option instead of automatic platform detection. Calls wit
windows option instead of automatic platform detection. Calls without an options object use POSIX behavior; pass windows: true when backslashes should be treated as path separators. The main picomatch() entry point applies platform detection only when an options object is provided (#73, 49d10c4).picomatch.constants property is no longer copied to the package's main export (7e120bb). It is restored in 4.0.0 (335eac6).matchBase() implementation did not forward Windows mode to its platform-independent basename helper. As a result, backslash-separated inputs did not match by basename, even with windows: true. This is fixed in 4.0.5 (#183, ab8bc4d).picomatch/posix entry point for browser and other non-Node.js environments. It uses POSIX path semantics unless windows: true is passed (7e120bb).path dependency and automatic process.platform detection from the core matcher, and documented the existing windows option (#73).This is a security release fixing several security relevant issues.
This is a security release fixing several security relevant issues.
Full Changelog: 2.3.1...2.3.2
maxExtglobRecursion values allow limited nesting, while false disables the safeguard (CVE-2026-33671, eec17ae).Fixes bug when a pattern containing an expression after the closing parenthesis (/!(*.d).{ts,tsx}) was incorrectly converted to regexp (9f241ef).
Fixes bug where file names with two dots were not being matched consistently with negation extglobs containing a star
Do not skip pattern seperator for square brackets (fb08a30).
Correctly handle parts of the pattern after parentheses in the scan method (e15b920).
scan method (e15b920).Fixes #49, so that braces with no sets or ranges are now propertly treated as literals.
Disable fastpaths mode for the parse method
tokens, slashes, and parts to the object returned by picomatch.scan().Nothing published for this version
Add eslint object-curly-spacing rule
noparen in scan (3d37569)update .verb.md file with typo change
Nothing published for this version
Nothing published for this version
options.capture now works as expected when fastpaths are enabled. See https://github.com/micromatch/picomatch/pull/12/commits/26aefd71f1cfaf95c37f1c1f
options.capture now works as expected when fastpaths are enabled. See https://github.com/micromatch/picomatch/pull/12/commits/26aefd71f1cfaf95c37f1c1fcab68a693b037304. Thanks to @DrPizza.Nothing published for this version
Nothing published for this version
Nothing published for this version
Adds support for options.onIgnore. See the readme for details
options.onIgnore. See the readme for detailsoptions.onResult. See the readme for detailswindowsNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
numerous improvements and optimizations for matching and parsing
.onMatch option.scan methodYour coding agent can read these notes before it upgrades. Set up the MCP server →