NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #828 most downloaded on npm
Serialize JavaScript to a superset of JSON that includes regular expressions and functions.
Last release 11 days ago
23 Sep 2026
Ships unpredictably
gaps range from 8 days to 1.7 years
Nearly every release is documented
notes for 34 of 35 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
35 releases · first in 2014
See: GHSA-gfhx-hw2g-v5hg
fix: fix XSS bypass via split </script payload across function bodies by @okuryu in #226
</script payload across function bodies by @okuryu in #226Full Changelog: v7.1.0...v7.1.1
One column per quarter.
feat: add Node.js 26 to test matrix by @okuryu in #224
Full Changelog: v7.0.7...v7.1.0
fix: reject spoofed RegExp objects with non-string source property by @redonkulus in #222
Full Changelog: v7.0.6...v7.0.7
build(deps-dev): bump lodash from 4.17.23 to 4.18.1 by @dependabot [bot] in #215
Full Changelog: v7.0.5...v7.0.6
Improve robustness and validation for array-like object serialization.
For more details, please see GHSA-qj8w-gfj5-8c6v.
release: v7.0.4 by @okuryu in #211
fix( CVE-2020-7660 ): fix for RegExp.flags and Date.prototype.toISOString ( #207 ) 2e609d0
ci: bump GitHub Actions to latest versions by @okuryu in #203
Add warning about using this package to send arbitrary data to worker threads by @valadaptive in #200
Full Changelog: v7.0.0...v7.0.1
Bump mocha from 10.2.0 to 10.4.0 by @dependabot [bot] in #178
Full Changelog: v6.0.2...v7.0.0
fix: serialize URL string contents to prevent XSS ( #173 ) f27d65d
Bump mocha from 9.0.1 to 9.0.2 by @dependabot in https://github.com/yahoo/serialize-javascript/pull/126
Full Changelog: https://github.com/yahoo/serialize-javascript/compare/v6.0.0...v6.0.1
Bump lodash from 4.17.19 to 4.17.21
Changelog
Behavior changes for URL objects
It serializes URL objects as follows since this version. The result of serialization may be changed if you are passing URL object values into the serialize-javascript.
const serialize = require("serialize-javascript");
serialize({u: new URL("http://example.com/")}); // '{"u":new URL("http://example.com/")}'
Thank you @rrdelaney for this release.
Exclude .vscode and .github directories from package
Changelog
Bump lodash from 4.17.15 to 4.17.19
Changelog
Behavior changes for sparse arrays
It serializes sparse arrays as follows since this version. The result of serialization may be changed if you are passing sparse arrays values into the serialize-javascript.
const serialize = require('serialize-javascript');
var a = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10];
delete a[0];
a.length = 3;
a[5] = 'wat';
serialize(a) // 'Array.prototype.slice.call({"1":2,"2":3,"5":"wat","length":6})'
Thank you @victorporof for this release.
It serializes BigInt values as follows since this version. The result of serialization may be changed if you are passing BigInt values into the serial
Changelog
Behavior changes for BigInt
It serializes BigInt values as follows since this version. The result of serialization may be changed if you are passing BigInt values into the serialize-javascript.
v4.x:
const serialize = require('serialize-javascript');
serialize({big: BigInt('10')}); // '{"big":BigInt("10")}'
v3.x:
const serialize = require('serialize-javascript');
serialize({big: BigInt('10')}); // throws error
Thank you @mum-never-proud for this release.
Don't replace regex / function placeholders within string literals
Note: the randombytes has been added to the dependency package to improve the generation of UIDs. Check the #22 for more information. Thanks to @JordanMilne and @Siebes for this change.
Introduce support for Infinity (@vthibault, #72)
InfinityIt serializes Infinity values as follows since this version. The result of serialization may be changed if you are passing Infinity values into the serialize-javascript.
v3.x
const serialize = require('serialize-javascript');
serialize({inf: Infinity}); // '{"inf":Infinity}'
v2.x
const serialize = require('serialize-javascript');
serialize({inf: Infinity}); // '{"inf":null}'
Ignore .nyc_output (@styfle, #64)
Fix regular expressions Cross-Site Scripting (XSS) vulnerability (see security advisory)
Add ignoreFunction option (@realdennis, #58)
ignoreFunction option (@realdennis, #58)re-landed #54 with bump major version (see: #57)
undefinedIt serializes undefined values as follows since this version. The result of serialization may be changed if you are passing undefined values into the serialize-javascript.
v2.x
const serialize = require('serialize-javascript');
serialize({undef: undefined}); // '{"undef":undefined}'
v1.x
const serialize = require('serialize-javascript');
serialize({undef: undefined}); // '{}'
Revert #54 for breaking changes (see: https://github.com/yahoo/serialize-javascript/issues/57)
support serialize undefined (@nqdy666, #54)
Enhanced object literals don't have arrows (@jowenjowen, #51)
Add support for serializing ES6 sets & maps (@pimterry, #45)
Please note that serialization for ES6 Sets & Maps requires support for Array.from (not available in IE or Node < 0.12), or an Array.from polyfill.
Remove arrow functions (@eddyerburgh, #42)
Enhanced object literals support (@kwolfy, #39)
Nothing published for this version
Update Node.js versions on CI (#28, @okuryu)
This minor release drastically improves the perf of serializing pure JSON data with the new {isJSON: true} flag. https://github.com/yahoo/serialize-ja
This minor release drastically improves the perf of serializing pure JSON data with the new {isJSON: true} flag. https://github.com/yahoo/serialize-javascript/pull/17
Passing a replacer function to JSON.stringify() slows it down dramatically. If possible, we should avoid this this path, and the new isJSON option is the signal that the object passed-in contains no functions or regexp values. But still protect against XSS by properly escaping for a <script> context.
Node v0.12.10
simpleObj:
JSON.stringify( simpleObj ) x 1,303,349 ops/sec ±0.66% (99 runs sampled)
JSON.stringify( simpleObj ) with replacer x 386,634 ops/sec ±0.72% (96 runs sampled)
serialize( simpleObj ) x 284,535 ops/sec ±0.92% (98 runs sampled)
serialize( simpleObj, {isJSON: true} ) x 951,798 ops/sec ±0.92% (96 runs sampled)
This minor release adds a space option that passes through to JSON.stringify's `space` option.
This minor release adds a space option that passes through to JSON.stringify's space option.
serialize({foo: 'foo'}, 2);
{
"foo": "foo"
}
There are no known exploits in the wild, but this improves the safety of this package.
There are no known exploits in the wild, but this improves the safety of this package.
This release fixes #5 by using generated UIDs and generated RegExps which use those UIDs making the placeholder token pattern used for serializing functions and regular expressions dynamic and unguessable.
Note: v1.1.0 and v1.1.1 have been unpublished from npm and PR #4 has been reverted because it was a hack and caused more problems than good.
The code in this package began its life as an internal module to express-state. To expand its usefulness, it now lives as serialize-javascript — an in
The code in this package began its life as an internal module to express-state. To expand its usefulness, it now lives as serialize-javascript — an independent package on npm.
npm install serialize-javascript
Your coding agent can read these notes before it upgrades. Set up the MCP server →