NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1564 most downloaded on npm
JSON parse with prototype poisoning protection
Last release 12 months ago
05 Oct 2025
Ships unpredictably
gaps range from 3 weeks to 1.6 years
Most releases are documented
notes for 14 of 17 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
17 releases · first in 2019
ci(.github): use latest node version by @Fdawgs in #136
safe option by @Fdawgs in #154Full Changelog: v4.0.0...v4.1.0
One column per quarter.
build(dependabot): reduce npm updates to monthly by @Fdawgs in #130
undefined on error instead of null by @Fdawgs in #133Full Changelog: v3.0.2...v4.0.0
build(deps-dev): bump airtap from 4.0.4 to 5.0.0 by @dependabot in #119
Full Changelog: v3.0.1...v3.0.2
style: remove trailing whitespace by @Fdawgs in #117
chore(.gitignore): add bun lockfile by @Fdawgs in #91
parse by @timursaurus in #95.gitattributes file by @Fdawgs in #102Full Changelog: v2.7.0...v3.0.0
Bump tsd from 0.24.1 to 0.25.0 by @dependabot in #88
Full Changelog: v2.6.0...v2.7.0
Bump tsd from 0.22.0 to 0.23.0 by @dependabot in #82
Full Changelog: v2.5.0...v2.6.0
chore: doc and ci updates by @Fdawgs in #31
Full Changelog: v2.4.0...v2.5.0
📚 PR: add types
📚 PR:
Throw only if the constructor key has a child named prototype - #25
Fixes:
📚 PR: - Add testing in browsers (#21) - Dropped .npmignore
📚 PR:
Access global Buffer conditionally
📚 PR:
Bump standard from 14.3.4 to 15.0.0
📚 PR:
Nothing published for this version
Now the library also detects the use of the constructor key, as it was doing with the __proto__ key. parse will throw an error by default, while safeP
Now the library also detects the use of the constructor key, as it was doing with the __proto__ key.
parse will throw an error by default, while safeParse will continue to work as before.
// old behavior
j.parse(
'{"a": 5, "b": 6, "constructor":{"prototype":{"bar":"baz"}}, "__proto__": { "x": 7 } }',
{ protoAction: 'remove' }
) // => { a: 5: b:6, constructor: { prototype: { bar: 'baz' } } }
// new bahavior
j.parse(
'{"a": 5, "b": 6, "constructor":{"prototype":{"bar":"baz"}}, "__proto__": { "x": 7 } }',
{ protoAction: 'remove' }
) // => SyntaxError
// for having the same behavior as before:
j.parse(
'{"a": 5, "b": 6, "constructor":{"prototype":{"bar":"baz"}}, "__proto__": { "x": 7 } }',
{ protoAction: 'remove', constructorAction: 'ignore' }
) // => { a: 5: b:6, constructor: { prototype: { bar: 'baz' } } }
Features:
constructorAction - https://github.com/fastify/secure-json-parse/pull/4Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →