NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #91 most downloaded on npm
A querystring parser that supports nesting and arrays, with a depth limit
Last release 1 months ago
29 Aug 2026
Release timing varies
gaps range from 4 weeks to 12 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
15 versions withdrawn
withdrawn after publishing
16 years old
150 releases · first in 2011
[New] stringify: add a depth option to bound recursion depth (default Infinity)
stringify: add a depth option to bound recursion depth (default Infinity)parse: enforce arrayLimit on comma groups under []= when throwOnLimitExceeded is setparse: flatten a collection appended to an overflowed array (#571)utils: isBuffer: do not invoke a non-callable constructor.isBufferstringify: do not let allowEmptyArrays skip cycle detection (or drop own keys) on an empty array with own propertiesstringify: encode dots in a top-level key with a primitive value when encodeDotInKeys is set (#562)stringify deep-nesting DoS is caller-boundedarrayLimit is a representation threshold, not an element-count capparse: remove a test that pinned []= comma groups escaping arrayLimitstringify: pin current encodeDotInKeys separator-dot behavior@ljharb/eslint-config, eslinteslint, evalmdOne column per quarter.
[Fix] parse: enforce throwOnLimitExceeded for cumulative array growth via combine/merge
parse: enforce throwOnLimitExceeded for cumulative array growth via combine/mergeutils: respect encoding of surrogate pairs across chunks (#559)parse: throw the arrayLimit error before splitting oversized comma valuesutils.merge / utils.assign: avoid invoking __proto__ setter when copying own propertiesutils: enforce arrayLimit consistently across merge's array pathsutils: make compact O(n) via a side-channel visited-set instead of Array.indexOfside-channeleslint, mock-property, tapeparse: characterize current lenient handling of unbalanced bracket keys (#558)[Fix] stringify: skip null/undefined entries in arrayFormat: 'comma' + encodeValuesOnly instead of crashing in encoder
stringify: skip null/undefined entries in arrayFormat: 'comma' + encodeValuesOnly instead of crashing in encoderstringify: use configured delimiter after charsetSentinel (#555)stringify: apply formatter to encoded key under strictNullHandling (#554)stringify: skip null/undefined filter-array entries instead of crashing in encoder (#551)parse: handle nested bracket groups and add regression tests (#530); changes output for some unbalanced bracket keys (see #558)@ljharb/eslint-config[Fix] parse: parameterLimit: Infinity with throwOnLimitExceeded: true silently drops all parameters
parse: parameterLimit: Infinity with throwOnLimitExceeded: true silently drops all parameters@ljharb/eslint-config@ljharb/eslint-config, iconv-lite[New] parse: add strictMerge option to wrap object/primitive conflicts in an array (#425, #122)
parse: add strictMerge option to wrap object/primitive conflicts in an array (#425, #122)duplicates option should not apply to bracket notation keys (#514)[Fix] parse: mark overflow objects for indexed notation exceeding arrayLimit
parse: mark overflow objects for indexed notation exceeding arrayLimit (#546)arrayLimit means max count, not max index, in combine/merge/parseArrayValueparse: throw on arrayLimit exceeded with indexed notation when throwOnLimitExceeded is true (#529)parse: enforce arrayLimit on comma-parsed valuesparse: fix error message to reflect arrayLimit as max index; remove extraneous comments (#545).push, use voidaddQueryPrefix does not add ? to empty output (#418)parseArrays and arrayLimit documentation (#543)arrayLength → arrayLimit)[Fix] ensure arrayLimit applies to [] notation as well
arrayLimit applies to [] notation as wellparse: when a custom decoder returns null for a key, ignore that keyparse: extract key segment splitting helperstringify: increase coverageeslint, @ljharb/eslint-config, npmignore, es-value-fixtures, for-each, object-inspect[New] parse: add throwOnParameterLimitExceeded option
parse: add throwOnParameterLimitExceeded option (#517)parse: use utils.combine moreparse: add explicit throwOnLimitExceeded defaultside-channeles-value-fixtures, has-bigints, has-proto, has-symbols[Fix] fix regressions from robustness refactor [actions] update reusable workflows
[Fix] fix regressions from robustness refactor [actions] update reusable workflows
[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] stringify: avoid a crash when a filter key is null
stringify: avoid a crash when a filter key is nullutils.merge: functions should not be stringified into keysparse: avoid a crash with interpretNumericEntities: true, comma: true, and iso charsetstringify: ensure a non-string filter does not crash__proto__ syntax instead of Object.create for null objectsutils.merge: add some coveragees-value-fixtures, mock-property, object-inspect, tape[New] parse: add strictDepth option
parse: add strictDepth option (#511)npm audit instead of aud[Fix] fix regressions from robustness refactor
[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] parse: properly account for strictNullHandling when allowEmptyArrays
parse: properly account for strictNullHandling when allowEmptyArrays[Fix] parse: parse encoded square brackets
parse: parse encoded square brackets (#506)[Fix] parse: Disable decodeDotInKeys by default to restore previous behavior
parse: Disable decodeDotInKeys by default to restore previous behavior (#501)utils: Optimize performance under large data volumes, reduce memory usage, and speed up processing (#502)utils: use +=[New] parse/stringify: add decodeDotInKeys/encodeDotKeys options
parse/stringify: add decodeDotInKeys/encodeDotKeys options (#488)parse: add duplicates optionparse/stringify: add allowEmptyArrays option to allow [] in object values (#487)parse/stringify: move allowDots config logic to its own variablestringify: move option-handling code into normalizeStringifyOptionsstringify: clarify default arrayFormat behaviorside-channelsideEffects flagparse: remove useless tests; add coveragestringify: increase coveragemock-propertystringify: improve coverage@ljharb/eslint-config , aud, has-override-mistake, has-property-descriptors, mock-property, npmignore, object-inspect, tapeglob, since v10.3.8+ requires a broken jackspeakjackspeak since 2.1.2+ depends on npm aliases, which kill the install process in npm < 6[Fix] fix regressions from robustness refactor
[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] parse: Fix parsing when the global Object prototype is frozen
parse: Fix parsing when the global Object prototype is frozen (#473)[Fix] stringify: encode comma values more consistently
stringify: encode comma values more consistently (#463)filter option for injecting custom serialization, i.e. of custom types (#447)@ljharb/eslint-config, aud, object-inspect, tape[New] [Fix] stringify: revert 0e903c0; add commaRoundTrip option
stringify: revert 0e903c0; add commaRoundTrip option (#442)[Fix] fix regressions from robustness refactor
[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] stringify: with arrayFormat: comma, properly include an explicit [] on a single-item array
stringify: with arrayFormat: comma, properly include an explicit [] on a single-item array (#434)[Fix] stringify: with arrayFormat: comma, include an explicit [] on a single-item array
stringify: with arrayFormat: comma, include an explicit [] on a single-item array (#441)npmignore to autogenerate an npmignore fileeslint, @ljharb/eslint-config, aud, has-symbol, object-inspect, tape[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)stringify: avoid relying on a global undefined (#427)eslint, @ljharb/eslint-config, object-inspect, tape[Fix] stringify: actually fix cyclic references
stringify: actually fix cyclic references (#426)stringify: avoid encoding arrayformat comma when encodeValuesOnly = true (#424)eslint, @ljharb/eslint-config, aud, object-inspect, safe-publish-latest, tape[Fix] stringify: avoid exception on repeated object values
stringify: avoid exception on repeated object values (#402)[New] stringify: throw on cycles, instead of an infinite loop (#395, #394, #393)
stringify: throw on cycles, instead of an infinite loop (#395, #394, #393)parse: add allowSparse option for collapsing arrays with missing indices (#312)npm run dist in publish, not installeslint, @ljharb/eslint-config, aud, has-symbols, tapeljharb/actions/node/install instead of ljharb/actions/node/run[Fix] fix regressions from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)stringify: avoid encoding arrayformat comma when encodeValuesOnly = true (#424)stringify: avoid relying on a global undefined (#427)[Fix] restore dist dir; mistakenly removed in d4f6c32
dist dir; mistakenly removed in d4f6c32[Fix] stringify: do not encode parens for RFC1738
stringify: do not encode parens for RFC1738stringify: fix arrayFormat comma with empty array/objects (#350)format: remove util.assign callpull_request_target eventstringify: add tests for #378nyc on all tests; use tape runnereslint, @ljharb/eslint-config, browserify, mkdirp, object-inspect, tape; add aud[Fix] stringify: when arrayFormat is comma, respect serializeDate
stringify: when arrayFormat is comma, respect serializeDate (#364)stringify: reduce branching (part of #350)maybeMap to utilsbrowserify, tape[Fix] proper comma parsing of URL-encoded commas
[Fix] parse: Fix parsing array from object with comma true
parse: Fix parsing array from object with comma true (#359)parse: throw a TypeError instead of an Error for bad charset (#349)eslint, @ljharb/eslint-config, object-inspect, has-symbols, tape, mkdirp, iconv-lite[Fix] parse: with comma true, handle field that holds an array of arrays
parse: with comma true, handle field that holds an array of arrays (#335)parse: with comma true, do not split non-string values (#334)funding fieldeslint, @ljharb/eslint-config[New] parse/stringify: Pass extra key/value argument to decoder
parse/stringify: Pass extra key/value argument to decoder (#333)eslint, @ljharb/eslint-config, evalmdparse: add passing arrayFormat testsposttest using npx aud to run npm audit without a lockfilenode v12.10, v11.15, v10.16, v8.16Buffer.from in node v5.0-v5.9 and v4.0-v4.4 requires a TypedArray[Fix] fix regressions from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)stringify: avoid relying on a global undefined (#427)stringify: avoid encoding arrayformat comma when encodeValuesOnly = true (#424)stringify: reduce branching[Fix] proper comma parsing of URL-encoded commas
[Fix] parse: Fix parsing array from object with comma true
parse: Fix parsing array from object with comma true (#359)parse: throw a TypeError instead of an Error for bad charset (#349)parse: with comma true, handle field that holds an array of arrays (#335)parse: with comma true, do not split non-string values (#334)funding fieldeslint, @ljharb/eslint-config, tape, safe-publish-latest, evalmd, has-symbols, iconv-lite, mkdirp, object-inspectparse: add passing arrayFormat testsBuffer.from in node v5.0-v5.9 and v4.0-v4.4 requires a TypedArray[New] add depth=false to preserve the original key; [Fix] depth=0 should preserve the original key
depth=false to preserve the original key; [Fix] depth=0 should preserve the original key (#326)formats: tiny bit of cleanup.eslint, @ljharb/eslint-config, browserify, safe-publish-latest, iconv-lite, tapedepth=0 and depth=false behavior, both current and intuitive/intended (#326)eclint instead of editorconfig-tools[Fix] fix regressions from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)stringify: avoid encoding arrayformat comma when encodeValuesOnly = true (#424)stringify: avoid relying on a global undefined (#427)nyc for coverage[Fix] proper comma parsing of URL-encoded commas
[Fix] parse: Fix parsing array from object with comma true
parse: Fix parsing array from object with comma true (#359)parse: with comma true, handle field that holds an array of arrays (#335)parse: with comma true, do not split non-string values (#334)parse: throw a TypeError instead of an Error for bad charset (#349)formats: tiny bit of cleanup.funding fieldeslint, @ljharb/eslint-config, tape, safe-publish-latest, evalmd, iconv-lite, mkdirp, object-inspect, browserifyparse: add passing arrayFormat testsBuffer.from in node v5.0-v5.9 and v4.0-v4.4 requires a TypedArraydepth=0 and depth=false behavior, both current and intuitive/intendedeclint instead of editorconfig-tools[New] stringify/parse: add comma as an arrayFormat option (#276, #219)
stringify/parse: add comma as an arrayFormat option (#276, #219)utils.merge: avoid a crash with a null target and a truthy non-array source, also with an array sourcestringify: cache Object.prototype.hasOwnPropertyutils: isBuffer: small tweak; add testsArray.isArrayparse/stringify: make a function to normalize the optionsutils: reduce observable [[Get]]sstringify/utils: cache Array.isArrayString(x) over x.toString()[Fix] fix regressions from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)utils.merge: avoid a crash with a null target and an array sourceutils.merge: avoid a crash with a null target and a truthy non-array sourcestringify: avoid relying on a global undefined (#427)stringify: cache Object.prototype.hasOwnPropertyformats: tiny bit of cleanup.utils: isBuffer: small tweak; add testsstringify/utils: cache Array.isArrayutils: reduce observable [[Get]]sArray.isArrayparse/stringify: make a function to normalize the optionsString(x) over x.toString()[New] Add support for iso-8859-1, utf8 "sentinel" and numeric entities
utils function (#189)stringify: fix a crash with strictNullHandling and a custom filter/serializeDate (#279)parseArrays is false, properly handle keys ending in [] (#260)stringify: do not crash in an obscure combo of interpretNumericEntities, a bad custom decoder, & iso-8859-1utils: merge: fix crash when source is a truthy primitive & no options are providedstringify: Avoid arr = arr.concat(...), push to the existing instance (#269)parse: only need to reassign the var onceparse/stringify: clean up charset options checking; fix defaultsparse: one less concat callutils: compactQueue: make it explicitly side-effectingbrowserify, eslint, @ljharb/eslint-config, iconv-lite, safe-publish-latest, tapenode v10.10, v9.11, v8.12, v6.14, v4.9; pin included builds to LTS[Fix] fix regressions from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)addQueryPrefix does not add ? to empty output (#418)[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)utils.merge: avoid a crash with a null target and a truthy non-array sourcestringify: fix a crash with strictNullHandling and a custom filter/serializeDate (#279)utils: merge: fix crash when source is a truthy primitive & no options are providedparseArrays is false, properly handle keys ending in []utils.merge: avoid a crash with a null target and an array sourceutils: reduce observable [[Get]]sArray.isArraystringify: Avoid arr = arr.concat(...), push to the existing instance (#269)parse: only need to reassign the var oncestringify: avoid relying on a global undefined (#427)String(x) over x.toString()Your coding agent can read these notes before it upgrades. Set up the MCP server →