NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #91 most downloaded on npm
A querystring parser that supports nesting and arrays, with a depth limit
Last release 1 months ago
29 Aug 2026
Release timing varies
gaps range from 4 weeks to 12 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
15 versions withdrawn
withdrawn after publishing
16 years old
150 releases · first in 2011
[Fix] use safer-buffer instead of Buffer constructor
safer-buffer instead of Buffer constructormodule.exports one thing, instead of mutating exports (#230)browserify, eslint, iconv-lite, safer-buffer, tape, browserify[Fix] Fix parsing & compacting very deep objects
eslint, @ljharb/eslint-config, tapenode v8.4; use nvm install-latest-npm so newer npm doesn’t break older nodenode v8.2; fix npm on node 0.6One column per quarter.
[New] pass default encoder/decoder to custom encoder/decoder functions
utils.assignparse/stringify: add ignoreQueryPrefix/addQueryPrefix options, respectively (#213)options argument (#207)parse: cache index to reuse in else statement (#182)eslint, browserify, iconv-lite, tapenode v8.1, v7.10, v6.11; npm v4.6 breaks on node < v1; npm v5+ breaks on node < v4editorconfig-tools[Fix] fix regressions from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)safer-buffer instead of Buffer constructorutils.merge: avoid a crash with a null target and an array sourceutils.merge: avoid a crash with a null target and a truthy non-array sourcestringify: fix a crash with strictNullHandling and a custom filter/serializeDate (#279)utils: merge: fix crash when source is a truthy primitive & no options are providedparseArrays is false, properly handle keys ending in []stringify: avoid relying on a global undefined (#427)Array.isArraystringify: Avoid arr = arr.concat(...), push to the existing instance (#269)[New] qs.stringify: add encodeValuesOnly option
qs.stringify: add encodeValuesOnly optionallowPrototypes option during merge (#201, #201)eslintnode v7.7, v6.10, v4.8; disable osx builds since they block linux builds[Fix] fix regressions from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)utils.merge: avoid a crash with a null target and an array sourceutils.merge: avoid a crash with a null target and a truthy non-array sourcestringify: fix a crash with strictNullHandling and a custom filter/serializeDate (#279)utils: merge: fix crash when source is a truthy primitive & no options are providedparseArrays is false, properly handle keys ending in []stringify: avoid relying on a global undefined (#427)Array.isArraystringify: Avoid arr = arr.concat(...), push to the existing instance (#269)safer-buffer instead of Buffer constructor[Fix] follow allowPrototypes option during merge (#201, #200)
allowPrototypes option during merge (#201, #200)eslintnode v7.7, v6.10, v4.8; disable osx builds since they block linux builds[Fix] ensure that allowPrototypes: false does not ever shadow Object.prototype properties (thanks, @snyk!)
allowPrototypes: false does not ever shadow Object.prototype properties (thanks, @snyk!)eslint, @ljharb/eslint-config, browserify, iconv-lite, qs-iconv, tapeallowDots (#195)sort (#191)stringify: throw faster with an invalid encoderqs is no longer part of hapi (#183)[New] Add support for RFC 1738 (#174, #173)
stringify: Add serializeDate option to customize Date serialization (#159)utils.merge handles merging two arraysformats: cache String#replacebrowserify, eslint, @ljharb/eslint-config; add safe-publish-latestnode v6.8, v4.6; improve test matrix[Fix] fix regression from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)[Fix] parse: ignore __proto__ keys
parse: ignore __proto__ keys (#428)utils.merge: avoid a crash with a null target and an array sourceutils.merge: avoid a crash with a null target and a truthy non-array sourceutils: merge: fix crash when source is a truthy primitive & no options are providedparseArrays is false, properly handle keys ending in []stringify: avoid relying on a global undefined (#427)Array.isArraysafer-buffer instead of Buffer constructor[Fix] follow allowPrototypes option during merge (#201, #200)
allowPrototypes option during merge (#201, #200)node v7.7, v6.10, v4.8; disable osx builds since they block linux builds[Fix] ensure that allowPrototypes: false does not ever shadow Object.prototype properties
allowPrototypes: false does not ever shadow Object.prototype properties[Fix] ensure key[]=x&key[]&key[]=y results in 3, not 2, values
key[]=x&key[]&key[]=y results in 3, not 2, valuesObject.prototype.hasOwnProperty.callparallelshell since it does not reliably report failuresnode v6.3, v5.12tape, eslint, @ljharb/eslint-config, qs-iconv[New] pass Buffers to the encoder/decoder directly
[Fix] fix regression from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)[Fix] follow allowPrototypes option during merge (#201, #200)
allowPrototypes option during merge (#201, #200)node v7.7, v6.10, v4.8; disable osx builds since they block linux builds[Fix] ensure that allowPrototypes: false does not ever shadow Object.prototype properties
allowPrototypes: false does not ever shadow Object.prototype properties[New] allowDots option for stringify
stringify (#151)dist directory; will be removed in v7 (#148)[Fix] fix regression from robustness refactor
npmignore to autogenerate an npmignore file[Robustness] avoid .push, use void
.push, use voidparseArrays and arrayLimit documentation (#543)[Fix] follow allowPrototypes option during merge (#201, #200)
allowPrototypes option during merge (#201, #200)node v7.7, v6.10, v4.8; disable osx builds since they block linux builds[Fix] ensure that allowPrototypes: false does not ever shadow Object.prototype properties
allowPrototypes: false does not ever shadow Object.prototype propertiesdist directory; will be removed in v7 (#148)Revert ES6 requirement and restore support for node down to v0.8.
- #127 Fix engines definition in package.json
- #124 Use ES6 and drop support for node < v4
[Fix] ensure key[]=x&key[]&key[]=y results in 3, not 2, values
key[]=x&key[]&key[]=y results in 3, not 2, values- #64 Add option to sort object keys in the query string
- #117 make URI encoding stringified results optional - #106 Add flag skipNulls to optionally skip null values in stringify
- #114 default allowDots to false - #100 include dist to npm
- #98 make returning plain objects and allowing prototype overwriting properties optional
- #89 Add option to disable "Transform dot notation to bracket notation"
- #80 qs.parse silently drops properties - #77 Perf boost - #60 Add explicit option to disable array parsing - #74 Bad parse when turning array into o
filter optionNothing published for this version
- #73 Property 'hasOwnProperty' of object # is not a function
- #70 Add arrayFormat option
- #59 make sure array indexes are >= 0, closes #57 - #58 make qs usable for browser loader
- #55 allow merging a string into an object
- #52 Return "undefined" and "false" instead of throwing "TypeError".
- #50 add option to omit array indices, closes #46
- #39 Is there an alternative to Buffer.isBuffer? - #49 refactor utils.merge, fixes #45 - #41 avoid browserifying Buffer, for #39
- #38 how to handle object keys beginning with a number
- #37 parser discards first empty value in array - #36 Update to lab 4.x
- #33 Error when plain object in a value - #34 use Object.prototype.hasOwnProperty.call instead of obj.hasOwnProperty - #24 Changelog? Semver?
- #32 account for circular references properly, closes #31 - #31 qs.parse stackoverflow on circular objects
- #26 Don't use Buffer global if it's not present - #30 Bug when merging non-object values into arrays - #29 Don't call Utils.clone at the top of Util
- #22 Enable using a RegExp as delimiter
- #18 Why is there arrayLimit? - #20 Configurable parametersLimit - #21 make all limits optional, for #18, for #20
- #19 Don't overwrite null values
- #16 ignore non-string delimiters - #15 Close code block
- #12 Add optional delim argument - #13 fix #11: flattened keys in array are now correctly parsed
- #7 Empty values of a POST array disappear after being submitted - #9 Should not omit equals signs (=) when value is null - #6 Minor grammar fix in R
- #5 array holes incorrectly copied into object on large index
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →