semver

The semantic version parser and range matcher that powers npm itself.

Library
npm
v7.8.5
5,467 stars
ISC

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
60 /100 Good
Development Activity 40
Maintenance 20
Community 80
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
86 /100 Excellent
Architecture 85
Code Quality 90
Innovation 82
Learning Curve 88

semver is the JavaScript implementation of the Semantic Versioning 2.0.0 specification, maintained by the npm CLI team and used internally by npm to parse, validate, compare, and sort package versions. It exposes both a full range-matching engine (tilde, caret, hyphen, and x-ranges) and a collection of small, pure comparison functions that can be imported individually to minimize bundle size.

Beyond the library API, semver ships a standalone command-line tool for validating and incrementing version strings from shell scripts and CI pipelines. Because it underpins version resolution across the entire npm ecosystem, it has become the de facto standard for semver parsing in JavaScript, with hundreds of millions of weekly downloads.

What You Get

  • SemVer, Comparator, and Range classes for structured version and range objects
  • A full set of comparison functions (gt, lt, eq, satisfies, compare, diff, etc.) importable individually
  • Range utilities for max/min satisfying versions, intersection checks, and range simplification
  • A standalone semver CLI binary for shell and CI version comparisons and increments

Common Use Cases

  • Resolving which published version satisfies a dependency’s declared range
  • Validating and normalizing user- or config-supplied version strings
  • Bumping a package’s version programmatically during a release script
  • Sorting a list of tags or releases by semantic precedence

Under The Hood

Architecture semver’s execution flow starts at index.js, which eagerly requires every submodule and re-exports them as a single flat object; a preload.js entry point exists solely to force this eager loading for environments that need pre-warmed regex caches. Parsing centers on classes/semver.js, whose SemVer constructor runs the input string through a single greedy regex (internal/re.js, built from anchored token fragments in internal/constants.js) to populate major/minor/patch/prerelease/build fields, memoizing repeat parses of the same version+options pair via an LRU cache in internal/lrucache.js. Range matching layers classes/range.js (which desugars hyphen, tilde, caret, and x-range syntax into primitive comparator sets) on top of classes/comparator.js (a single operator+SemVer pair), with the ranges/ directory (max-satisfying.js, min-version.js, outside.js, subset.js, etc.) implementing higher-level range algebra by iterating candidate comparators rather than re-parsing strings. Nearly all consumer-facing behavior in functions/ (compare.js, satisfies.js, diff.js, coerce.js, etc.) is a thin wrapper that constructs a SemVer or Range and delegates to its methods, keeping the public API a flat set of pure functions layered over a small, well-isolated OOP core.

Tech Stack semver is dependency-free at runtime — package.json declares zero production dependencies, keeping it safe to install transitively without pulling in an ecosystem. Its devDependencies are entirely tooling: tap for testing (configured in package.json’s tap block with a coverage-map pointing at map.js), @npmcli/eslint-config and @npmcli/template-oss for lint and style enforcement shared across npm’s own packages, and benchmark for the perf suite under benchmarks/. The engines field requires a modern Node.js runtime, and the code is plain CommonJS (require/module.exports) with no build or transpile step — index.js and every submodule ship as-is, and the files field in package.json whitelists exactly the directories published to the registry (bin/, lib/, classes/, functions/, internal/, ranges/).

Code Quality Test coverage is comprehensive and mirrors the source layout 1:1 — test/classes/, test/functions/, test/internal/, and test/ranges/ each contain a file per corresponding source module, plus test/bin/semver.js for the CLI and test/integration/whitespace.js for edge-case regression coverage, all run through tap with an nyc coverage-map (map.js) that excludes tap-snapshots/. Error handling is explicit and typed: the SemVer constructor throws TypeError with descriptive messages (“Invalid Version: …”, version-too-long errors) rather than returning null or undefined, while the top-level functions/ wrappers instead catch and return null for invalid input, giving callers a predictable choice between throw-on-parse and null-on-check semantics. Naming is consistent and short (gt/lt/eq/gte/lte/cmp/rcompare mirror mathematical comparison conventions), internal state is guarded (the LRU cache size is capped via constants in internal/constants.js), and a debug() helper (internal/debug.js) gated behind an environment flag replaces ad hoc console.log calls.

API Design The public API favors small, single-purpose pure functions (gt, lt, satisfies, coerce, diff, inc) that can be required individually straight from functions/ or ranges/ to minimize bundle size, alongside three classes (SemVer, Comparator, Range) for callers who need richer objects — this dual surface lets consumers pick the minimal-footprint or object-oriented style per use case. Naming directly mirrors mathematical and spec vocabulary (gt/lt/gte/lte/eq/neq/cmp) so experienced developers can guess most of the API without reading docs, and the top-level require(‘semver’) convenience export needs zero configuration to produce a working comparison. The README is exhaustive, documenting every range-syntax edge case (hyphen ranges, x-ranges, tilde/caret semantics, prerelease-tag matching rules) with runnable examples for each exported function, and the CLI (semver -h) mirrors the library’s flag names closely, reducing the conceptual gap between scripting and programmatic use.

Used by 112 apps in this directory

HTML
46%
LGPL-2.1

Horilla

ERP · Human Resources

1,437

Open-source HRMS covering recruitment, attendance, payroll, and biometrics in one self-hosted Django application.

View details
91
Repo Health
60
Technical
65
Dependency
Built with
HTML 46%
Python 38%
JavaScript 12%
Updated 1 weeks ago
TypeScript
74%
Apache 2.0

Jitsi Meet

Collaboration · Team Chat · Video Conferencing

30,004

Open-source, end-to-end encrypted video conferencing you can self-host or embed into any web or mobile app.

View details
95
Repo Health
85
Technical
66
Dependency
Built with
TypeScript 74%
JavaScript 10%
Updated 1 weeks ago
TypeScript
62%
MIT

Jitsu

Data Engineering

5,094

Open-source, fully-scriptable data ingestion engine that streams events from web, apps, and APIs to any data warehouse in real time.

View details
88
Repo Health
79
Technical
66
Dependency
Built with
TypeScript 62%
Go 36%
Updated 2 weeks ago
Java
58%
Apache 2.0

Kestra

Automation · Data Engineering · Devops

28,388

Event-driven orchestration platform for data, AI, and infrastructure workflows — define everything in YAML, run anywhere at scale.

View details
93
Repo Health
81
Technical
72
Dependency
Built with
Java 58%
TypeScript 26%
Vue 15%
Updated 2 weeks ago
TypeScript
98%
Other

Kibana

Analytics · Monitoring

21,301

Your open source window into the Elastic Stack — query, visualize, and act on data stored in Elasticsearch with real-time dashboards, AI-assisted search, and automated alerting.

View details
98
Repo Health
87
Technical
63
Dependency
Built with
TypeScript 98%
Updated 1 weeks ago
TypeScript
98%
MIT

Kimi Code CLI

AI Agents · AI Code Assistants · Developer Tools

7,705

A single-binary, terminal-native coding agent that reads, edits, and runs code end to end, built by Moonshot AI for Kimi models but pluggable with Anthropic, OpenAI, and Google providers too.

View details
82
Repo Health
87
Technical
67
Dependency
Built with
TypeScript 98%
Updated 1 weeks ago
Go
97%
Apache 2.0

kopia

File Storage

14,209

Fast, encrypted, deduplicated backups to any cloud or local storage with full client-side control.

View details
91
Repo Health
83
Technical
68
Dependency
Built with
Go 97%
Updated 1 weeks ago
TypeScript
84%
Apache 2.0

ktx

AI Development · Analytics · Data Engineering

1,603

ktx builds a self-improving context layer over your data warehouse so AI agents like Claude Code and Codex query it with approved metric definitions instead of reinventing SQL logic from scratch.

View details
66
Repo Health
85
Technical
72
Dependency
Built with
TypeScript 84%
Updated 4 weeks ago
TypeScript
94%
AGPL 3.0

Laudspeaker

Automation · Marketing

2,626

Open-source customer engagement platform for building visual, event-triggered messaging journeys across email, SMS, push, in-app, and webhooks.

View details
51
Repo Health
66
Technical
62
Dependency
Built with
TypeScript 94%
Updated 3 months ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers