xquery4 2.8.0

dotnet tool install --global xquery4 --version 2.8.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local xquery4 --version 2.8.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=xquery4&version=2.8.0
                    
nuke :add-package xquery4 --version 2.8.0
                    

xquery

Command-line XQuery 3.1/4.0 processor for .NET. Query XML documents from the terminal using the PhoenixmlDb XQuery engine.

Installation

dotnet tool install -g xquery4

Usage

# Query an XML file
xquery '//book/title' library.xml

# Count elements
xquery 'count(//item)' catalog.xml

# Read from a query file
xquery -f transform.xq input.xml

# Query a directory of XML files
xquery 'collection()//product[price > 50]' ./data/

# JSON output
xquery -o json 'map { "count": count(//item) }' data.xml

# Read from stdin
cat data.xml | xquery '//item/@name'

# Show execution plan
xquery --plan 'for $x in 1 to 10 return $x * $x'

# Show timing breakdown
xquery --timing '//item' large-catalog.xml

Features

  • XQuery 3.1/4.0 — FLWOR, maps/arrays, higher-order functions, string constructors
  • Multiple output methods — adaptive, XML, text, JSON
  • Context item — input XML is available as . (standard XQuery)
  • Multiple sources — files, directories, URLs, stdin
  • Full prolog support — namespaces, variable/function declarations, serialization options
  • Execution plans — inspect how queries are compiled and optimized
  • Timing — built-in performance profiling

Documentation

Full documentation at phoenixml.dev

License

Apache-2.0

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
2.8.0 34 10/9/2026
2.7.0 51 10/7/2026
2.6.0 74 10/6/2026
2.5.1 85 10/1/2026
2.4.1 86 9/28/2026
2.4.0 67 9/28/2026
2.2.0 372 9/25/2026
2.1.0 76 9/17/2026
2.0.0 77 9/15/2026
1.8.0 85 9/14/2026
1.7.0 80 9/11/2026
1.6.15 81 9/9/2026
1.6.14 96 9/7/2026
1.6.13 82 9/4/2026
1.6.12 82 9/1/2026
1.6.11 87 8/29/2026
1.6.10 87 8/29/2026
1.6.9 82 8/27/2026
1.6.8 80 8/26/2026
1.6.7 89 8/24/2026
Loading failed

The shared schema layer and schema caching; resource-policy security fixes. QT3: 251 failing of
31,331 (2.7.0: 257). Requires PhoenixmlDb.Core 2.4.0.

### Security: resource policy bypasses and host information disclosure with untrusted queries (GHSA-g2xr-r7jg-2v33)

Only hosts that evaluate queries from untrusted parties under a `ResourcePolicy` are affected.
Every HTTP redirect is now authorized against the policy, documents included with XInclude are
read under the policy of the including document, a refusal names only the location as the query
wrote it, and a relative base URI declaration is not resolved against the working directory under
a policy. See [GHSA-g2xr-r7jg-2v33](https://github.com/phoenixmldb/phoenixmldb-xquery/security/advisories/GHSA-g2xr-r7jg-2v33)
for the details and workarounds.

### Schemas

- **`XsdSchemaProvider` reads schemas through the shared schema layer** (PhoenixmlDb.Core). Changed
 behaviour to check on upgrade:
 - an `xs:include`, `xs:import` or `xs:redefine` that cannot be read fails the load (`XQST0059`);
   it used to be skipped;
 - a schema document with a DOCTYPE is refused;
 - schema text with no base URI does not resolve a relative `schemaLocation` against the current
   directory; use `AddFromString(namespace, text, baseUri)`;
 - a schema that requires XSD 1.1 says so, naming the document and the constructs (#217).
- **Schemas imported by `import schema` are compiled once and shared**
 (`XsdSchemaProvider.ImportCache`). Providers that import the same files share one compiled
 schema set, and a changed schema file or included file is seen by the next query. A query
 importing a 705 KB schema: 39.7 ms before, 1.6 ms now.
- **An atomic value keeps its schema-defined type**: a value from a cast, a constructor function
 or a validated node. `t:size('8') instance of t:size` is true.

### Other changes

- A cancelled query does not start a regex or pattern-facet match (#205).
- The `xquery4` CLI writes `xmlns=""` for an element in no namespace inside a default namespace
 (#105); it ships on `cli-v2.8.0`.

### API

- New: `JsonXmlConverter` (`ToXml`, `ToXmlText`) with `JsonToXmlOptions`; `XsdSchemaProvider(CompiledSchema)`,
 `XsdSchemaProvider.Catalog`, `XsdSchemaProvider.ImportCache`; `ISchemaProvider.AddSchemaText` and
 `ISchemaProvider.IsSchemaSimpleTypeDerivedFrom` (default implementations; custom providers
 compile unchanged); `XQueryParserFacade.Parse(string, Func<string, string?>)`.

### `xquery` CLI (ships on `cli-v2.8.0`)

- Runs on **PhoenixmlDb.Xslt 2.8.0**, so `fn:transform` from a query gets the 2.8.0 engine and its
 security fixes.
- Writes `xmlns=""` for an element in no namespace inside a default namespace (#105).