NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #144 most downloaded on npm
Selector parser with built in methods for working with selector strings.
Last release 1 months ago
03 Sep 2026
Release timing varies
gaps range from 4 weeks to 10 months
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
69 releases · first in 2015
fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability ( GHSA-rj75-hqrm-r3gf , reported by Wayde Shi)
fix: don't treat a non-prefix token before | as a namespace ( #324 by @spokodev )
One column per quarter.
fix: tolerate non-node children when serializing selectors
Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)
Fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 ( #316 by @MoOx )
perf: replace startsWith with strict equality
feat: insert(Before|After) support multiple new node
Feat: make insertions during iteration safe (major)
fix: tolerate non-node children when serializing selectors
Fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of ( #316 by @MoOx )
Fixed: erroneous trailing combinators in pseudos
Fixed: improve typings of constructor helpers
Feature: add sourceIndex to Selector nodes
sourceIndex to Selector nodes (#290)Fixed: add missing index argument to each/walk callback types
index argument to each/walk callback types (#289)Fixed: Node#prev and Node#next type for the first/last node
# 6.0.14 - Fixed: type definitions
Fixed: throw on unexpected pipe symbols
Fixed: clone arguments should be optional
clone arguments should be optionalFixed: parse attribute case insensitivity flag
Fixed: isPseudoElement() supports :first-letter and :first-line
isPseudoElement() supports :first-letter and :first-lineFixed: Combinator.raws property type
Combinator.raws property type# 6.0.8 - Fixed: reduced size
Fixed: parse animation percents
Fixed: parse quoted attributes containing a newline correctly
Perf: rework unesc for a 63+% performance boost
- Fixed: ts errors
Fixed: replace node built-in "util" module with "util-deprecate"
Fixed an issue with parsing and stringifying an empty attribute value
Fixed an issue with unicode surrogate pair parsing
Updated: cssesc to 3.0.0 (major)
cssesc to 3.0.0 (major)id and class selectorsThis release has BREAKING CHANGES that were required to fix regressions in 4.0.0 and to make the Combinator Node API consistent for all combinator typ…
.a .b) is stored in the AST has changed..a /for/ .b) are now properly parsed as a combinator./ was encountered have been fixed.v6.0.0.In prior releases, the value of a descendant combinator with multiple spaces included all the spaces.
.a .b: Extra spaces are now stored as space before.
combinator.value === " "combinator.value === " " && combinator.spaces.before === " ".a /*comment*/.b: A comment at the end of the combinator causes extra space to become after space.
combinator.value === " "combinator.raws.value === " /*comment/"combinator.value === " "combinator.spaces.after === " "combinator.raws.spaces.after === " /*comment*/".a<newline>.b: whitespace that doesn't start or end with a single space character is stored as a raw value.
combinator.value === "\n"combinator.raws.value === undefinedcombinator.value === " "combinator.raws.value === "\n"Although, nonstandard and unlikely to ever become a standard, combinators like /deep/ and /for/ are now properly supported.
Because they've been taken off the standardization track, there is no spec-official name for combinators of the form /<ident>/. However, I talked to Tab Atkins and we agreed to call them "named combinators" so now they are called that.
Before this release such named combinators were parsed without intention and generated three nodes of type "tag" where the first and last nodes had a value of "/".
.a /for/ .b is parsed as a combinator.
root.nodes[0].nodes[1].type === "tag"root.nodes[0].nodes[1].value === "/"root.nodes[0].nodes[1].type === "combinator"root.nodes[0].nodes[1].value === "/for/".a /F\6fR/ .b escapes are handled and uppercase is normalized.
root.nodes[0].nodes[2].type === "tag"root.nodes[0].nodes[2].value === "F\\6fR"root.nodes[0].nodes[1].type === "combinator"root.nodes[0].nodes[1].value === "/for/"root.nodes[0].nodes[1].raws.value === "/F\\6fR/"A new API was added to look up a node based on the source location.
const selectorParser = require("postcss-selector-parser");
// You can find the most specific node for any given character
let combinator = selectorParser.astSync(".a > .b").atPosition(1,4);
combinator.toString() === " > ";
// You can check if a node includes a specific character
// Whitespace surrounding the node that is owned by that node
// is included in the check.
[2,3,4,5,6].map(column => combinator.isAtPosition(1, column));
// => [false, true, true, true, false]
This release has BREAKING CHANGES that were required to fix regressions in 4.0.0 and to make the Combinator Node API consistent for all combinator types. Please read carefully.
To ease adoption of the v5.0 release, we have relaxed the node version check performed by npm at installation time to allow for node 4, which remains officially unsupported, but likely to continue working for the time being.
cssesc to 2.0.0 (major).Fixed and issue where comments immediately after an insensitive (in attribute) were not parsed correctly.
cssesc to 2.0.0 (major).Nothing published for this version
Nothing published for this version
To ease adoption of the v5.0 release, we have relaxed the node version check performed by npm at installation time to allow for node 4, which remains
To ease adoption of the v5.0 release, we have relaxed the node version check performed by npm at installation time to allow for node 4, which remains officially unsupported, but likely to continue working for the time being.
The way a descendent combinator that isn't a single space character (E.g. .a .b) is stored in the AST has changed.
.a .b) is stored in the AST has changed..a /for/ .b) are now properly parsed as a combinator./ was encountered have been fixed.v6.0.0.This release has BREAKING CHANGES that were required to fix regressions in 4.0.0 and to make the Combinator Node API consistent for all combinator types. Please read carefully.
.a .b) is stored in the AST has changed..a /for/ .b) are now properly parsed as a combinator./ was encountered have been fixed.v6.0.0.In prior releases, the value of a descendant combinator with multiple spaces included all the spaces.
.a .b: Extra spaces are now stored as space before.
combinator.value === " "combinator.value === " " && combinator.spaces.before === " ".a /*comment*/.b: A comment at the end of the combinator causes extra space to become after space.
combinator.value === " "combinator.raws.value === " /*comment/"combinator.value === " "combinator.spaces.after === " "combinator.raws.spaces.after === " /*comment*/".a<newline>.b: whitespace that doesn't start or end with a single space character is stored as a raw value.
combinator.value === "\n"combinator.raws.value === undefinedcombinator.value === " "combinator.raws.value === "\n"Although, nonstandard and unlikely to ever become a standard, combinators like /deep/ and /for/ are now properly supported.
Because they've been taken off the standardization track, there is no spec-official name for combinators of the form /<ident>/. However, I talked to Tab Atkins and we agreed to call them "named combinators" so now they are called that.
Before this release such named combinators were parsed without intention and generated three nodes of type "tag" where the first and last nodes had a value of "/".
.a /for/ .b is parsed as a combinator.
root.nodes[0].nodes[1].type === "tag"root.nodes[0].nodes[1].value === "/"root.nodes[0].nodes[1].type === "combinator"root.nodes[0].nodes[1].value === "/for/".a /F\6fR/ .b escapes are handled and uppercase is normalized.
root.nodes[0].nodes[2].type === "tag"root.nodes[0].nodes[2].value === "F\\6fR"root.nodes[0].nodes[1].type === "combinator"root.nodes[0].nodes[1].value === "/for/"root.nodes[0].nodes[1].raws.value === "/F\\6fR/"A new API was added to look up a node based on the source location.
const selectorParser = require("postcss-selector-parser");
// You can find the most specific node for any given character
let combinator = selectorParser.astSync(".a > .b").atPosition(1,4);
combinator.toString() === " > ";
// You can check if a node includes a specific character
// Whitespace surrounding the node that is owned by that node
// is included in the check.
[2,3,4,5,6].map(column => combinator.isAtPosition(1, column));
// => [false, true, true, true, false]
This release has BREAKING CHANGES that were required to fix bugs regarding values with escape sequences. Please read carefully.
This release has BREAKING CHANGES that were required to fix bugs regarding values with escape sequences. Please read carefully.
Identifiers with escapes - CSS escape sequences are now hidden from the public API by default.
The normal value of a node like a class name or ID, or an aspect of a node such as attribute
selector's value, is unescaped. Escapes representing Non-ascii characters are unescaped into
unicode characters. For example: bu\tton, .\31 00, #i\2764\FE0Fu, [attr="value is \"quoted\""]
will parse respectively to the values button, 100, i❤️u, value is "quoted".
The original escape sequences for these values can be found in the corresponding property name
in node.raws. Where possible, deprecation warnings were added, but the nature
of escape handling makes it impossible to detect what is escaped or not. Our expectation is
that most users are neither expecting nor handling escape sequences in their use of this library,
and so for them, this is a bug fix. Users who are taking care to handle escapes correctly can
now update their code to remove the escape handling and let us do it for them.
Mutating values with escapes - When you make an update to a node property that has escape handling
The value is assumed to be unescaped, and any special characters are escaped automatically and
the corresponding raws value is immediately updated. This can result in changes to the original
escape format. Where the exact value of the escape sequence is important there are methods that
allow both values to be set in conjunction. There are a number of new convenience methods for
manipulating values that involve escapes, especially for attributes values where the quote mark
is involved. See https://github.com/postcss/postcss-selector-parser/pull/133 for an extensive
write-up on these changes.
Upgrade/API Example
In 3.x there was no unescape handling and internal consistency of several properties was the caller's job to maintain. It was very easy for the developer
to create a CSS file that did not parse correctly when some types of values
were in use.
const selectorParser = require("postcss-selector-parser");
let attr = selectorParser.attribute({attribute: "id", operator: "=", value: "a-value"});
attr.value; // => "a-value"
attr.toString(); // => [id=a-value]
// Add quotes to an attribute's value.
// All these values have to be set by the caller to be consistent:
// no internal consistency is maintained.
attr.raws.unquoted = attr.value
attr.value = "'" + attr.value + "'";
attr.value; // => "'a-value'"
attr.quoted = true;
attr.toString(); // => "[id='a-value']"
In 4.0 there is a convenient API for setting and mutating values
that may need escaping. Especially for attributes.
const selectorParser = require("postcss-selector-parser");
// The constructor requires you specify the exact escape sequence
let className = selectorParser.className({value: "illegal class name", raws: {value: "illegal\\ class\\ name"}});
className.toString(); // => '.illegal\\ class\\ name'
// So it's better to set the value as a property
className = selectorParser.className();
// Most properties that deal with identifiers work like this
className.value = "escape for me";
className.value; // => 'escape for me'
className.toString(); // => '.escape\\ for\\ me'
// emoji and all non-ascii are escaped to ensure it works in every css file.
className.value = "😱🦄😍";
className.value; // => '😱🦄😍'
className.toString(); // => '.\\1F631\\1F984\\1F60D'
// you can control the escape sequence if you want, or do bad bad things
className.setPropertyAndEscape('value', 'xxxx', 'yyyy');
className.value; // => "xxxx"
className.toString(); // => ".yyyy"
// Pass a value directly through to the css output without escaping it.
className.setPropertyWithoutEscape('value', '$REPLACE_ME$');
className.value; // => "$REPLACE_ME$"
className.toString(); // => ".$REPLACE_ME$"
// The biggest changes are to the Attribute class
// passing quoteMark explicitly is required to avoid a deprecation warning.
let attr = selectorParser.attribute({attribute: "id", operator: "=", value: "a-value", quoteMark: null});
attr.toString(); // => "[id=a-value]"
// Get the value with quotes on it and any necessary escapes.
// This is the same as reading attr.value in 3.x.
attr.getQuotedValue(); // => "a-value";
attr.quoteMark; // => null
// Add quotes to an attribute's value.
attr.quoteMark = "'"; // This is all that's required.
attr.toString(); // => "[id='a-value']"
attr.quoted; // => true
// The value is still the same, only the quotes have changed.
attr.value; // => a-value
attr.getQuotedValue(); // => "'a-value'";
// deprecated assignment, no warning because there's no escapes
attr.value = "new-value";
// no quote mark is needed so it is removed
attr.getQuotedValue(); // => "new-value";
// deprecated assignment,
attr.value = "\"a 'single quoted' value\"";
// > (node:27859) DeprecationWarning: Assigning an attribute a value containing characters that might need to be escaped is deprecated. Call attribute.setValue() instead.
attr.getQuotedValue(); // => '"a \'single quoted\' value"';
// quote mark inferred from first and last characters.
attr.quoteMark; // => '"'
// setValue takes options to make manipulating the value simple.
attr.setValue('foo', {smart: true});
// foo doesn't require any escapes or quotes.
attr.toString(); // => '[id=foo]'
attr.quoteMark; // => null
// An explicit quote mark can be specified
attr.setValue('foo', {quoteMark: '"'});
attr.toString(); // => '[id="foo"]'
// preserves quote mark by default
attr.setValue('bar');
attr.toString(); // => '[id="bar"]'
attr.quoteMark = null;
attr.toString(); // => '[id=bar]'
// with no arguments, it preserves quote mark even when it's not a great idea
attr.setValue('a value \n that should be quoted');
attr.toString(); // => '[id=a\\ value\\ \\A\\ that\\ should\\ be\\ quoted]'
// smart preservation with a specified default
attr.setValue('a value \n that should be quoted', {smart: true, preferCurrentQuoteMark: true, quoteMark: "'"});
// => "[id='a value \\A that should be quoted']"
attr.quoteMark = '"';
// => '[id="a value \\A that should be quoted"]'
// this keeps double quotes because it wants to quote the value and the existing value has double quotes.
attr.setValue('this should be quoted', {smart: true, preferCurrentQuoteMark: true, quoteMark: "'"});
// => '[id="this should be quoted"]'
// picks single quotes because the value has double quotes
attr.setValue('a "double quoted" value', {smart: true, preferCurrentQuoteMark: true, quoteMark: "'"});
// => "[id='a "double quoted" value']"
// setPropertyAndEscape lets you do anything you want. Even things that are a bad idea and illegal.
attr.setPropertyAndEscape('value', 'xxxx', 'the password is 42');
attr.value; // => "xxxx"
attr.toString(); // => "[id=the password is 42]"
// Pass a value directly through to the css output without escaping it.
attr.setPropertyWithoutEscape('value', '$REPLACEMENT$');
attr.value; // => "$REPLACEMENT$"
attr.toString(); // => "[id=$REPLACEMENT$]"
Nothing published for this version
There were a number of bugs in the 3.x releases relating to how escape sequences were handled.
There were a number of bugs in the 3.x releases relating to how escape sequences were handled.
We took a step back and thought through these issues and decided that the best course was to change our public API in some subtle but important ways. The new API means that users don't have to worry about escape sequences anymore. By default, the selector parser always returns unescaped strings and then re-escapes them when converting back to CSS strings, using the originally authored escape sequences if possible. If you didn't handle escape sequences or deal with quoted values in attribute selectors, then this release is probably just fixing bugs that you didn't know you had.
If you are manipulating selectors with nonstandard CSS syntax, escape sequences, or special characters, this new API means your code is going to need to change.
There is a full writeup of the changes here: https://github.com/postcss/postcss-selector-parser/pull/133
SECURITY FIX: update dot-prop to 5.2.0
dot-prop to 5.2.08.Fix: typescript definitions weren't in the published package.
Fixed numerous bugs in attribute nodes relating to the handling of comments and whitespace. There's significant changes to attrNode.spaces and attrNod
attrNode.spaces and attrNode.raws since the 3.0.0 release.Attribute#offsetOf(part) to get the offset location of
attribute parts like "operator" and "value". This is most
often added to Attribute#sourceIndex for error reporting.Some tweaks to the tokenizer/attribute selector parsing mean that whitespace locations might be slightly different to the 2.x code.
process API is now
async, and the sync API is now accessed through processSync instead.process() and processSync() now return a string instead of the Processor
instance.ast() and astSync() methods have been added to the Processor. These
return the Root node of the selectors after processing them.transform() and transformSync() methods have been added to the
Processor. These return the value returned by the processor callback
after processing the selectors.process, ast and transform (and their sync variants) now accept a
postcss rule node. When provided, better errors are generated and selector
processing is automatically set back to the rule selector (unless the updateSelector option is set to false.)The pattern of:
rule.selector = processor.process(rule.selector).result.toString();
is now:
processor.processSync(rule)
Some tweaks to the tokenizer/attribute selector parsing mean that whitespace locations might be slightly different to the 2.x code.
process API is now
async, and the sync API is now accessed through processSync instead.Resolves an issue where the parser would not reduce multiple spaces between an ampersand and another simple selector in lossy mode (thanks to @adam-26
No longer hangs on an unescaped semicolon; instead the parser will throw an exception for these cases.
Allows a consumer to specify whitespace tokens when creating a new Node (thanks to @Semigradsky).
Added a new option to normalize whitespace when parsing the selector string (thanks to @adam-26).
Better unquoted value handling within attribute selectors (thanks to @evilebottnawi).
This release contains the following breaking changes:
# 2.0.0
This release contains the following breaking changes:
eachInside iterators to walk. For example, eachTag is now
walkTags, and eachInside is now walk.Node#removeSelf() to Node#remove().Container#remove() to Container#removeChild().Node#raw to Node#raws (thanks to @davidtheclark).& as the nesting selector, rather than a tag selector.#{foo}) as an
id selector (thanks to @davidtheclark).and;
[data-attr="foo=bar"]) (thanks to @montmanu).quoted and raw.unquoted properties to attribute nodes
(thanks to @davidtheclark).Nothing published for this version
Fixes an infinite loop on ) and ] tokens when they had no opening pairs. Now postcss-selector-parser will throw when it encounters these lone tokens.
) and ] tokens when they had no opening pairs.
Now postcss-selector-parser will throw when it encounters these lone tokens.# 1.3.2
str.charCodeAt(0) for compiled builds.Nothing published for this version
Update flatten to v1.x (thanks to @shinnn).
Adds a new node type, String, to fix a crash on selectors such as foo:bar("test").
String, to fix a crash on selectors such as
foo:bar("test").Fixes a crash when the parser encountered a trailing combinator.
A more descriptive error is thrown when the parser expects to find a pseudo-class/pseudo-element (thanks to @ashelley).
Node#sourceIndex method (thanks to @davidtheclark).Fixes a crash when a selector started with a > combinator. The module will now no longer throw if a selector has a leading/trailing combinator node.
> combinator. The module will
now no longer throw if a selector has a leading/trailing combinator node.* Fixes a crash on @ tokens.
@ tokens.Fixes an infinite loop caused by using parentheses in a non-pseudo element context.
Your coding agent can read these notes before it upgrades. Set up the MCP server →