NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #139 most downloaded on npm
JavaScript parser and stringifier for YAML
Last release 24 days ago
11 Sep 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
105 releases · first in 2011
Nothing published for this version
Nothing published for this version
Nothing published for this version
Limit recursive merge aliases ( #685 , #713 )
One column per quarter.
Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which yaml CVEs have been issued so far.
The changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of parseDocument() and parseAllDocuments(): I've removed the claim that they'll "never throw".
It remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which yaml CVEs have been issued so far.
Starting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.
Array.prototype.push.apply() with large source arrayDisable alias resolution with maxAliasCount:0
Add trailingComma ToString option for multiline flow formatting
Do not double newlines for empty map values
Preserve empty block literals
Add node cache for faster alias resolution
--merge option to CLI tool (#611)Do not allow seq with single-line collection value on same line with map key
The library is now available on JSR as @eemeli/yaml and on deno.land/x as yaml. In addition to Node.js and browsers, it should work in Deno, Bun, and
The library is now available on JSR as @eemeli/yaml and on deno.land/x as yaml. In addition to Node.js and browsers, it should work in Deno, Bun, and Cloudflare Workers.
Do not strip :00 seconds from !!timestamp values (#578, with thanks to @qraynaud)
:00 seconds from !!timestamp values (#578, with thanks to @qraynaud)!!bool (#587, with thanks to @vra5107)Use a proper tag for !!merge << keys
!!merge << keys (#580)stringKeys parse option (#581)Include range in flow sequence pair maps
Add --indent option to CLI tool (#559, with thanks to @danielbayley)
--indent option to CLI tool (#559, with thanks to @danielbayley)... (#558)minContentWidth if greater than lineWidth (#562)Collection.maxFlowStringSingleLineLength (#522, #421)Improve tab handling (#553, yaml-test-suite tests DK95 & Y79Y)
With special thanks to @RedCMD for finding and reporting all of the following:
With special thanks to @RedCMD for finding and reporting all of the following:
[]{} immediately after : with plain key (#550)? explicit-key contents (#551)Improve error when parsing a non-string value
-.NaN or +.nan as NaN (#546)# within %TAG prefixes with trailing #commentsRestrict YAML 1.1 boolean strings to their explicit capitalization
cst: Do not drop trailing newline after line comment in block-map if followed by unindented block-seq value
Use the lineWidth option for line breaking in flow collections
lineWidth option for line breaking in flow collections (#522)Do not throw for carriage return in tag shorthand
Do not throw error on malformed URI escape in tag
Do not require quotes for implicit keys with flow indicators
Drop npm from package.json "engines" config
"engines" config (#476)This release corresponds with the release of `yaml-types` v0.2.0, an expanding library of custom tags or types for use with yaml.
This release corresponds with the release of yaml-types v0.2.0, an expanding library of custom tags or types for use with yaml.
This release contains no changes from v2.3.0-5, and the notes below include all changes from the v2.3.0-x prereleases.
createNode() & createPair() to 'yaml/util' (#457)from() methods to simplify tag development, and otherwise make extending custom collections easier (#467)Strict to Document instances. (#441)StringifyContext type from 'yaml/util' (#464)toJS(doc, options?) method to nodes (#451, #458)createNode() for non-default tags (#464)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Corner case failure in error pretty-printer (CVE-2023-2251)
This patch release includes a fix for an error that could be thrown in parseDocument for degenerate input. Otherwise, it's a patch release uplifting a few fixes from the ongoing v2.3 work to v2.2:
Quote top-level map keys containing document markers
Add flowCollectionPadding toString option
flowCollectionPadding toString option (#420)Set correct node-end position for block collections with comments
Set correct node-end position for empty values with comments
No changes in executable code, only TS types.
No changes in executable code, only TS types.
Fixes for TypeScript users. Arguably this could've been a patch release as well.
Fixes for TypeScript users. Arguably this could've been a patch release as well.
_directives to resolve type conflict with ToString options (#389)Fix tags and anchors on map keys
The breaking changes introduced here are mostly originating from the v1 CST parser having become a rather difficult beast to work with. So it's here r…
This update has been in the works for the last year and a half. Its prerelease versions have been thoroughly tested by a wide number of users, and I think it's finally ready for "actual" release, for use in the mythical "production".
The breaking changes introduced here are mostly originating from the v1 CST parser having become a rather difficult beast to work with. So it's here rewritten pretty much completely, now with a lexer as a first stage. Along the way, the whole project was rewritten in TypeScript and the export paths and options refactored pretty deeply.
If you've been using the library just via its parse(), parseDocument() and stringify() functions, then it's quite likely that none of the changes affect your experience in any way. However, if you've been doing something more involved, then I would strongly recommend that you review the library's documentation site for the v2 docs.
Going forward, it's finally time to start experimenting with new YAML spec features that may eventually be included in YAML 1.3 and later. Those will be made available by specifying the version: 'next' option. However, beware! Any features available this way may be removed or have their API broken by any minor release of this library, and no compatibility guarantees with other libraries are given. In general, semver compatibility is guaranteed for features that are explicitly included in the documentation; everything else should be considered as internal implementation details.
The following is an overview of the breaking changes and new features introduced in each of the prerelease steps leading up to this release; the individual releases' notes and the PRs will contain more detail, along with specific migration guides.
set() in mappings & sequences (#185)resolve() API (#201)'yaml/parse-cst' endpoint (#223)'yaml/types' and some of 'yaml/util' into 'yaml' (#234)type property from all but Scalar nodes (#240)tokens namespace as CST (#252)[start, value-end, node-end] (#259)error.offset with error.pos: [number, number] (#260)doc.directives now indicates it as optional (#344)YAML.defaultOptions is removed (#346)directives.marker is renamed as directives.docStart (#371)set() & setIn() on doc with empty contents (#174)defaultKeyType option for finer control of scalar output (#179)asBigInt option for sexagesimal integer valueslogLevel option (#215)visit(node, visitor) to 'yaml' (#225)'yaml/util' that weren't exposed beforeuniqueKeys option (#271)COMMENT_SPACE error; use MISSING_CHAR for it instead<< merge keys, in addition to alias valuesaliasDuplicateObjects (#299)clone() methods to Document, Directives, Schema and all Nodes (#304)keepSoureToken parse option, adding srcToken values to Nodes (#309)customTags is defined (#325)directives.docEnd, for ... marker (#371)YAML.visitAsync() (#372)'next' YAML versionNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Allow for unindented comment after node props (prettier/prettier#10510)
This release backports the following non-breaking fixes made during the work on yaml@2 on top of yaml@1.10.0:
This release backports the following non-breaking fixes made during the work on yaml@2 on top of yaml@1.10.0:
__proto__ as mapping key & anchor identifier (#192)minContentWidth chars on the first line (#196)YAML.stringify() for certain null values (#197)type: "module" within browser/dist/ (#208)yaml/types & yaml/util (#208)Document.Parsed.contents (#221)Node.rangeAsLinePos (#222)lineWidth=0 is set (#232)This will probably be the last minor release of yaml@1. I'm aiming to release `yaml@2` within a few months; prereleases of that will be published usin
This will probably be the last minor release of yaml@1. I'm aiming to release yaml@2 within a few months; prereleases of that will be published using the next dist-tag on npm. Patch releases for 1.10 may still happen, if necessary.
dist/ paths from the release. If you want/need to use a class or function that is no longer public, please file an issue and we can add it to the exports.@babel/runtime. After this, the package has 0 runtime dependencies. 🎉{ Alias, Collection, Merge, Node } to 'yaml/types'Schema.createPair() & make its ctx arg optional (#157)getNodes(): string[] method to Anchors (#166)dist/ endpointsnpm start debuggingAST.{AstNode,ScalarNode,CollectionNode} (#160)toString() methods to AST nodes (#159)mapAsMap: true for out.yaml tests (4FJ6)- ts: Fix Node.toJSON() type
Node.toJSON() type (#154)Add onAnchor callback arg to doc.toJSON()
onAnchor callback arg to doc.toJSON()doc.toJSON()Your coding agent can read these notes before it upgrades. Set up the MCP server →