NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1945 most downloaded on npm
A small, fast, and correct TOML parser/serializer
Last release 13 days ago
22 Sep 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 27 of 29 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
29 releases · first in 2023
One column per quarter.
The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50 .
Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.
Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.
Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.
Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.
Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.
Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).
A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.
Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.
Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.
import * instead. Proposed in #50.Full Changelog: v1.8.0...v1.9.0
feat: stringify temporal objects by @Gouvernathor and @cyyynthia
Full Changelog: v1.7.2...v1.8.0
refactor: improve performance of the parser by @cyyynthia
Full Changelog: v1.7.1...v1.7.2
This release includes flagging internal functions as @internal to strip them from the emitted type declarations.
This release includes flagging internal functions as @internal to strip them from the emitted type declarations.
⚠️ Includes a fix for GHSA-7w5x-hrqm-74c2
Full Changelog: v1.7.0...v1.7.1
This version slightly changes the behaviour of stringify: integers beyond the safe range are always emitted as float numbers.
This version slightly changes the behaviour of stringify: integers beyond the safe range are always emitted as float numbers.
String decode logic has been rewritten, it is a bit faster now and uses a single-pass approach instead of a dual-pass approach as it did previously. The code should be a bit smaller too, though I didn't actually measure that.
The package is now published with source-maps, declaration-maps, and a copy of the original TypeScript source files. This will improve your DX if you're like me and like Ctrl+Click'ing things a lot. ;)
Full Changelog: v1.6.1...v1.7.0
This release addresses a minor security vulnerability where an attacker-controlled TOML document can exploit an unrestricted recustion and cause a sta…
This release addresses a minor security vulnerability where an attacker-controlled TOML document can exploit an unrestricted recustion and cause a stack overflow error with a document that contains thousands of sucessive commented lines. Security advisory: GHSA-v3rj-xjv7-4jmq
As of this version, smol-toml now supports the newly released TOML 1.1.0 specification!
As of this version, smol-toml now supports the newly released TOML 1.1.0 specification!
TOML 1.1.0 now allows inline tables to have newlines, as well as trailing commas.
database = {
driver = "postgresql",
server = {
host = "127.0.0.1",
port = 3307,
},
}TOML 1.1.0 renders the seconds component of time elements optional.
datetime-tz = 1979-05-27 07:32Z
datetime = 2001-09-21 10:17
time = 13:37
Strings now support 2 additional escape sequences:
\xHH for code points between 0 and 255\e for the escape character (U+001B)Full Changelog: v1.5.2...v1.6.0
fix: properly stringify arrays of tables by @cyyynthia
Hot fix for v1.5.1... 🙃
Full Changelog: v1.5.1...v1.5.2
Smol fix that makes newlines actually consistent when stringifying objects to TOML.
Smol fix that makes newlines actually consistent when stringifying objects to TOML.
Full Changelog: v1.5.0...v1.5.1
This version improves the TOML output of the library when stringifying objects, courtesy of the folks over at Cloudflare.
This version improves the TOML output of the library when stringifying objects, courtesy of the folks over at Cloudflare.
Most notably, the lib no longer emits unnecessary table headers, and doesn't add an empty line between successive table headers anymore:
[look.at.me]
note = "In earlier versions, there would've been [look] and [look.at] generated as well."
[empty.table]
[another.empty.table]
[look.how.compact]
this = "looks"Full Changelog: v1.4.2...v1.5.0
A smol fix to better handle strings with many successive backslash characters.
A smol fix to better handle strings with many successive backslash characters.
fix: string escape detection in util.ts by @cyyynthia
Full Changelog: v1.4.1...v1.4.2
A little fix for asNeeded not being implemented correctly.
A little fix for asNeeded not being implemented correctly.
fix: properly implement asNeeded by @cyyynthia
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.4.0...v1.4.1
This release introduces better support for integers, courtesy of @Gouvernathor! It is now possible to parse integers that are larger than 53 bits as B
This release introduces better support for integers, courtesy of @Gouvernathor! It is now possible to parse integers that are larger than 53 bits as BigInts. It is also possible to parse all integers as BigInts, enabling full type preservation of TOML documents.
The project is now tested against Node 24 as well, ensuring stability on the latest versions of Node.js.
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.3.4...v1.4.0
Fixing some bugs that have been surfaced by the latest tests added to toml-test.
Fixing some bugs that have been surfaced by the latest tests added to toml-test.
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.3.3...v1.3.4
Follow up of v1.3.2, where the package is published in JavaScript instead of nocode. 🚀
Follow up of v1.3.2, where the package is published in JavaScript instead of nocode. 🚀
Fixes the issue reported in #37 -- the library would fail to parse a document containing a one-line string, with an escaped double-quote, preceded by
Fixes the issue reported in #37 -- the library would fail to parse a document containing a one-line string, with an escaped double-quote, preceded by an escaped backslash, such as key = "value \\\" value".
Apologies for the lack of proper v1.3.1 tag; this release addressed GHSA-pqhp-25j4-6hq9 by adding a maximum depth while parsing.
Additionally, releases are now published to NPM with provenance attestations
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.3.0...v1.3.2
Nothing published for this version
smol-toml is changing how it's distributed (again)! It's now a dual-package with native ESM and a CJS single-file build. This should make the package
smol-toml is changing how it's distributed (again)! It's now a dual-package with native ESM and a CJS single-file build. This should make the package available for even more targets, now including targets which can't treat CJS as faux ESM!
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.2.2...v1.3.0
Remove pnpm from engines by @jakebailey in https://github.com/squirrelchat/smol-toml/pull/23
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.2.1...v1.2.2
Minor change to the package.json; removing the use of conditional export syntax in favor of the simpler, more commonly supported main package key.
Minor change to the package.json; removing the use of conditional export syntax in favor of the simpler, more commonly supported main package key.
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.2.0...v1.2.1
smol-toml can now be used as a CJS library, while remaining fully compatible with ESM-style imports.
smol-toml can now be used as a CJS library, while remaining fully compatible with ESM-style imports.
It is also now possible to import the library to something similar to the JSON global:
import TOML from 'smol-toml'
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.1.4...v1.2.0
Improve toml-test integration by @arp242 in https://github.com/squirrelchat/smol-toml/pull/11
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.1.3...v1.1.4
This release fixes a few bugs that were not initially caught by the TOML test suite, further aligning this library with complete TOML specification co
This release fixes a few bugs that were not initially caught by the TOML test suite, further aligning this library with complete TOML specification conformance. 🎉
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.1.2...v1.2.3
Fixed a smol issue with types where TomlPrimitive was not exposed, despite being a user-facing type.
Fixed a smol issue with types where TomlPrimitive was not exposed, despite being a user-facing type.
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.1.1...v1.1.2
Fix usage in webpack by @decahedron1 in https://github.com/squirrelchat/smol-toml/pull/4
types to package.json to allow older TS versions and projects without a tsconfig to resolve type information (see #3)Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.1.0...v1.1.1
smol-toml can now serialize objects to TOML 🎉 A basic (and fast!) serializer has been implemented, with no customization capabilities for now. Refer t
smol-toml can now serialize objects to TOML 🎉 A basic (and fast!) serializer has been implemented, with no customization capabilities for now. Refer to the README for gotchas about the serializer and how it handles certain types that cannot be represented in TOML such as null!
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.0.1...v1.1.0
This releases fixes a bunch of issues related with spec-compliance, as well as a few bugs! This version now passes (almost) all of the extensive semi-
This releases fixes a bunch of issues related with spec-compliance, as well as a few bugs! This version now passes (almost) all of the extensive semi-official toml-test suite by BurntSushi! 🎉
\r alone is no longer considered a line returnThe library also got a significant performance improvement for small documents, and got slightly slower for huge documents. Benchmarks have been updated on the README.
Full Changelog: https://github.com/squirrelchat/smol-toml/compare/v1.0.0...v1.0.1
This is the first stable release of smol-toml! 🎉
This is the first stable release of smol-toml! 🎉
smol-toml can be considered production-ready and should be safe to use in a production app.
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →