PhoenixmlDb.Xslt 2.5.1

dotnet add package PhoenixmlDb.Xslt --version 2.5.1
                    
NuGet\Install-Package PhoenixmlDb.Xslt -Version 2.5.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="PhoenixmlDb.Xslt" Version="2.5.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="PhoenixmlDb.Xslt" Version="2.5.1" />
                    
Directory.Packages.props
<PackageReference Include="PhoenixmlDb.Xslt" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add PhoenixmlDb.Xslt --version 2.5.1
                    
#r "nuget: PhoenixmlDb.Xslt, 2.5.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package PhoenixmlDb.Xslt@2.5.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=PhoenixmlDb.Xslt&version=2.5.1
                    
Install as a Cake Addin
#tool nuget:?package=PhoenixmlDb.Xslt&version=2.5.1
                    
Install as a Cake Tool

PhoenixmlDb.Xslt

XSLT 4.0 transformation engine for PhoenixmlDb — transform XML documents into HTML, JSON, CSV, text, or other XML formats.

Features

  • XSLT 3.0/4.0 — template matching, streaming, accumulators, packages, maps/arrays
  • All output methods — HTML5, XML, XHTML, JSON, text, CSV, adaptive
  • Multiple outputs — xsl:result-document for multi-file generation
  • Full XPath 4.0 — 240+ built-in functions available in all expressions
  • Packages — reusable stylesheet libraries with visibility control

Quick example

using PhoenixmlDb.Xslt;

var transformer = new XsltTransformer();
await transformer.LoadStylesheetAsync(
    File.ReadAllText("style.xsl"),
    new Uri(Path.GetFullPath("style.xsl")));

transformer.SetParameter("title", "My Report");
var html = await transformer.TransformAsync(
    File.ReadAllText("data.xml"));

// Handle secondary outputs (xsl:result-document)
foreach (var (href, content) in transformer.SecondaryResultDocuments)
    File.WriteAllText(Path.Combine(outputDir, href), content);

See the full API overview in the README.

Package Description
PhoenixmlDb.Core Core types and XDM data model (dependency)
PhoenixmlDb.XQuery XQuery 4.0 query engine (dependency)
PhoenixmlDb.Xslt.Cli xslt command-line tool

Documentation

Full documentation at phoenixml.dev

License

Apache 2.0

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.5.1 36 10/1/2026
2.4.1 325 9/28/2026
2.4.0 95 9/28/2026
2.2.0 116 9/25/2026
2.1.0 181 9/17/2026
2.0.0 166 9/15/2026
1.8.0 234 9/14/2026
1.7.0 126 9/11/2026
1.6.15 193 9/9/2026
1.6.14 134 9/7/2026
1.6.13 168 9/2/2026
1.6.12 128 8/30/2026
1.6.11 116 8/29/2026
1.6.10 181 8/27/2026
1.6.9 108 8/26/2026
1.6.8 109 8/26/2026
1.6.7 111 8/24/2026
1.6.6 118 8/23/2026
1.6.5 137 8/22/2026
1.6.4 137 8/16/2026
Loading failed

Takes **PhoenixmlDb.XQuery 2.5.1** and **PhoenixmlDb.Core 2.0.0**. There is no Xslt 2.5.0: the
Xslt version follows the XQuery it is built on, and XQuery needed a 2.5.1 patch, found by this
release's own testing, before Xslt could ship.

### Security: `ResourcePolicy` is enforced on every read, fetch and evaluation (GHSA-86rg-wxgp-9p5j)

`XsltTransformer.ResourcePolicy`, `ServerDefault` included, was not enforced on several paths. It
is now enforced on all of them, through the PhoenixmlDb.XQuery check
(`ResourcePolicy.Authorize`), and the reader opens the URI it returns.

What is checked now:

- **Reads:**
 - `xsl:source-document` (streamed or not) and the `unparsed-text` family, rooted paths
   included.
 - `fn:transform`, both the XSLT function and the XQuery-side provider. The stylesheet location
   needs import access and the source location read access, and the nested transformation runs
   under the caller's policy.
 - `xsl:import`/`xsl:include`, `xsl:import-schema` and everything a schema includes,
   `xsl:merge` sources, and parameter documents.
 - `json-doc` and `load-xquery-module`, through PhoenixmlDb.XQuery 2.5.x.
- **Load time:**
 - The stylesheet pre-fetch checks every URL before fetching, so loading a stylesheet makes no
   request the policy forbids.
 - Static expressions (`use-when`, `xsl:use-when`, static variables and parameters, shadow
   attributes) are evaluated under the policy while the stylesheet loads.
- **Evaluation:** `xsl:evaluate` honours `AllowXslEvaluate` and raises `XTDE3175` when it is off.
- **HTTP:** redirects are re-authorised at every hop.
- **Availability:** `unparsed-text-available`, `doc-available` and `stream-available` return false
 for refused resources, and a refused import reads as "not found", so neither reveals whether a
 file exists.

**With no policy configured, nothing changes.** Hosts that run untrusted stylesheets should
upgrade. Hosts that filter stylesheet text should account for shadow attributes (`_href`,
`_schema-location`), which replace the real attribute when the stylesheet is compiled.

### Fixed

- **Streaming:**
 - Grouping over attribute and text nodes (#216).
 - Streamability of calls to and bodies of streamable functions (#217).
 - Attribute-only uses of `current-group()` (#220).
 - `accumulator-after()` before the template descends is `XTSE3430` (#225).
 - A streamable accumulator's initial value must not navigate the input (#222).
- **Grouping focus:** within a declared-streamable construct, an invocation clears the current
 group and grouping key; elsewhere they are kept, as in XSLT 2.0 (XSLT 3.0 §14.2; #219, #229).
- **Accumulators:** `accumulator-before`/`-after` with no context item is `XTDE3350` (#224).
- **`system-property()` and `element-available()`** resolve prefixes in the scope where the
 function item was created.
- **Error codes:**
 - A duplicate key in a map constructor is `XTDE3365`.
 - A map or function item in the principal result is the serialization error `SENR0001` (#226).
- **Packages:**
 - A used package's private global no longer clashes with a same-named global (#227).
 - `xsl:expose` validates its names (`XTSE0020`, `XTSE3020`; #228).
- **`xsl:import-schema`:** a location is one URI, resolved against its own module.
- **Schemas referencing `xml:id`** import reliably on every runtime (through XQuery 2.5.1).

### Behaviour changes

- An accumulator not applicable to the principal source tree is `XTDE3362` (#213).
- The `unparsed-text` family resolves against the calling module and raises `FOUT1170` (#195).

### Conformance

W3C XSLT 3.0: **275 failing at the start of this cycle → 216 at 2.5.1.** Five cases that expect
one implementation-dependent order of distinct trees are recorded in BUGS.md #118, not changed.