PhoenixmlDb.Xslt
2.5.1
dotnet add package PhoenixmlDb.Xslt --version 2.5.1
NuGet\Install-Package PhoenixmlDb.Xslt -Version 2.5.1
<PackageReference Include="PhoenixmlDb.Xslt" Version="2.5.1" />
<PackageVersion Include="PhoenixmlDb.Xslt" Version="2.5.1" />
<PackageReference Include="PhoenixmlDb.Xslt" />
paket add PhoenixmlDb.Xslt --version 2.5.1
#r "nuget: PhoenixmlDb.Xslt, 2.5.1"
#:package PhoenixmlDb.Xslt@2.5.1
#addin nuget:?package=PhoenixmlDb.Xslt&version=2.5.1
#tool nuget:?package=PhoenixmlDb.Xslt&version=2.5.1
PhoenixmlDb.Xslt
XSLT 4.0 transformation engine for PhoenixmlDb — transform XML documents into HTML, JSON, CSV, text, or other XML formats.
Features
- XSLT 3.0/4.0 — template matching, streaming, accumulators, packages, maps/arrays
- All output methods — HTML5, XML, XHTML, JSON, text, CSV, adaptive
- Multiple outputs —
xsl:result-documentfor multi-file generation - Full XPath 4.0 — 240+ built-in functions available in all expressions
- Packages — reusable stylesheet libraries with visibility control
Quick example
using PhoenixmlDb.Xslt;
var transformer = new XsltTransformer();
await transformer.LoadStylesheetAsync(
File.ReadAllText("style.xsl"),
new Uri(Path.GetFullPath("style.xsl")));
transformer.SetParameter("title", "My Report");
var html = await transformer.TransformAsync(
File.ReadAllText("data.xml"));
// Handle secondary outputs (xsl:result-document)
foreach (var (href, content) in transformer.SecondaryResultDocuments)
File.WriteAllText(Path.Combine(outputDir, href), content);
See the full API overview in the README.
Related packages
| Package | Description |
|---|---|
| PhoenixmlDb.Core | Core types and XDM data model (dependency) |
| PhoenixmlDb.XQuery | XQuery 4.0 query engine (dependency) |
| PhoenixmlDb.Xslt.Cli | xslt command-line tool |
Documentation
Full documentation at phoenixml.dev
License
Apache 2.0
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- PhoenixmlDb.Core (>= 2.0.0)
- PhoenixmlDb.XQuery (>= 2.5.1)
-
net8.0
- PhoenixmlDb.Core (>= 2.0.0)
- PhoenixmlDb.XQuery (>= 2.5.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 2.5.1 | 36 | 10/1/2026 |
| 2.4.1 | 325 | 9/28/2026 |
| 2.4.0 | 95 | 9/28/2026 |
| 2.2.0 | 116 | 9/25/2026 |
| 2.1.0 | 181 | 9/17/2026 |
| 2.0.0 | 166 | 9/15/2026 |
| 1.8.0 | 234 | 9/14/2026 |
| 1.7.0 | 126 | 9/11/2026 |
| 1.6.15 | 193 | 9/9/2026 |
| 1.6.14 | 134 | 9/7/2026 |
| 1.6.13 | 168 | 9/2/2026 |
| 1.6.12 | 128 | 8/30/2026 |
| 1.6.11 | 116 | 8/29/2026 |
| 1.6.10 | 181 | 8/27/2026 |
| 1.6.9 | 108 | 8/26/2026 |
| 1.6.8 | 109 | 8/26/2026 |
| 1.6.7 | 111 | 8/24/2026 |
| 1.6.6 | 118 | 8/23/2026 |
| 1.6.5 | 137 | 8/22/2026 |
| 1.6.4 | 137 | 8/16/2026 |
Takes **PhoenixmlDb.XQuery 2.5.1** and **PhoenixmlDb.Core 2.0.0**. There is no Xslt 2.5.0: the
Xslt version follows the XQuery it is built on, and XQuery needed a 2.5.1 patch, found by this
release's own testing, before Xslt could ship.
### Security: `ResourcePolicy` is enforced on every read, fetch and evaluation (GHSA-86rg-wxgp-9p5j)
`XsltTransformer.ResourcePolicy`, `ServerDefault` included, was not enforced on several paths. It
is now enforced on all of them, through the PhoenixmlDb.XQuery check
(`ResourcePolicy.Authorize`), and the reader opens the URI it returns.
What is checked now:
- **Reads:**
- `xsl:source-document` (streamed or not) and the `unparsed-text` family, rooted paths
included.
- `fn:transform`, both the XSLT function and the XQuery-side provider. The stylesheet location
needs import access and the source location read access, and the nested transformation runs
under the caller's policy.
- `xsl:import`/`xsl:include`, `xsl:import-schema` and everything a schema includes,
`xsl:merge` sources, and parameter documents.
- `json-doc` and `load-xquery-module`, through PhoenixmlDb.XQuery 2.5.x.
- **Load time:**
- The stylesheet pre-fetch checks every URL before fetching, so loading a stylesheet makes no
request the policy forbids.
- Static expressions (`use-when`, `xsl:use-when`, static variables and parameters, shadow
attributes) are evaluated under the policy while the stylesheet loads.
- **Evaluation:** `xsl:evaluate` honours `AllowXslEvaluate` and raises `XTDE3175` when it is off.
- **HTTP:** redirects are re-authorised at every hop.
- **Availability:** `unparsed-text-available`, `doc-available` and `stream-available` return false
for refused resources, and a refused import reads as "not found", so neither reveals whether a
file exists.
**With no policy configured, nothing changes.** Hosts that run untrusted stylesheets should
upgrade. Hosts that filter stylesheet text should account for shadow attributes (`_href`,
`_schema-location`), which replace the real attribute when the stylesheet is compiled.
### Fixed
- **Streaming:**
- Grouping over attribute and text nodes (#216).
- Streamability of calls to and bodies of streamable functions (#217).
- Attribute-only uses of `current-group()` (#220).
- `accumulator-after()` before the template descends is `XTSE3430` (#225).
- A streamable accumulator's initial value must not navigate the input (#222).
- **Grouping focus:** within a declared-streamable construct, an invocation clears the current
group and grouping key; elsewhere they are kept, as in XSLT 2.0 (XSLT 3.0 §14.2; #219, #229).
- **Accumulators:** `accumulator-before`/`-after` with no context item is `XTDE3350` (#224).
- **`system-property()` and `element-available()`** resolve prefixes in the scope where the
function item was created.
- **Error codes:**
- A duplicate key in a map constructor is `XTDE3365`.
- A map or function item in the principal result is the serialization error `SENR0001` (#226).
- **Packages:**
- A used package's private global no longer clashes with a same-named global (#227).
- `xsl:expose` validates its names (`XTSE0020`, `XTSE3020`; #228).
- **`xsl:import-schema`:** a location is one URI, resolved against its own module.
- **Schemas referencing `xml:id`** import reliably on every runtime (through XQuery 2.5.1).
### Behaviour changes
- An accumulator not applicable to the principal source tree is `XTDE3362` (#213).
- The `unparsed-text` family resolves against the calling module and raises `FOUT1170` (#195).
### Conformance
W3C XSLT 3.0: **275 failing at the start of this cycle → 216 at 2.5.1.** Five cases that expect
one implementation-dependent order of distinct trees are recorded in BUGS.md #118, not changed.