xquery4 2.8.0
dotnet tool install --global xquery4 --version 2.8.0
dotnet new tool-manifest
dotnet tool install --local xquery4 --version 2.8.0
#tool dotnet:?package=xquery4&version=2.8.0
nuke :add-package xquery4 --version 2.8.0
xquery
Command-line XQuery 3.1/4.0 processor for .NET. Query XML documents from the terminal using the PhoenixmlDb XQuery engine.
Installation
dotnet tool install -g xquery4
Usage
# Query an XML file
xquery '//book/title' library.xml
# Count elements
xquery 'count(//item)' catalog.xml
# Read from a query file
xquery -f transform.xq input.xml
# Query a directory of XML files
xquery 'collection()//product[price > 50]' ./data/
# JSON output
xquery -o json 'map { "count": count(//item) }' data.xml
# Read from stdin
cat data.xml | xquery '//item/@name'
# Show execution plan
xquery --plan 'for $x in 1 to 10 return $x * $x'
# Show timing breakdown
xquery --timing '//item' large-catalog.xml
Features
- XQuery 3.1/4.0 — FLWOR, maps/arrays, higher-order functions, string constructors
- Multiple output methods — adaptive, XML, text, JSON
- Context item — input XML is available as
.(standard XQuery) - Multiple sources — files, directories, URLs, stdin
- Full prolog support — namespaces, variable/function declarations, serialization options
- Execution plans — inspect how queries are compiled and optimized
- Timing — built-in performance profiling
Documentation
Full documentation at phoenixml.dev
License
Apache-2.0
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 2.8.0 | 34 | 10/9/2026 |
| 2.7.0 | 51 | 10/7/2026 |
| 2.6.0 | 74 | 10/6/2026 |
| 2.5.1 | 85 | 10/1/2026 |
| 2.4.1 | 86 | 9/28/2026 |
| 2.4.0 | 67 | 9/28/2026 |
| 2.2.0 | 372 | 9/25/2026 |
| 2.1.0 | 76 | 9/17/2026 |
| 2.0.0 | 77 | 9/15/2026 |
| 1.8.0 | 85 | 9/14/2026 |
| 1.7.0 | 80 | 9/11/2026 |
| 1.6.15 | 81 | 9/9/2026 |
| 1.6.14 | 96 | 9/7/2026 |
| 1.6.13 | 82 | 9/4/2026 |
| 1.6.12 | 82 | 9/1/2026 |
| 1.6.11 | 87 | 8/29/2026 |
| 1.6.10 | 87 | 8/29/2026 |
| 1.6.9 | 82 | 8/27/2026 |
| 1.6.8 | 80 | 8/26/2026 |
| 1.6.7 | 89 | 8/24/2026 |
The shared schema layer and schema caching; resource-policy security fixes. QT3: 251 failing of
31,331 (2.7.0: 257). Requires PhoenixmlDb.Core 2.4.0.
### Security: resource policy bypasses and host information disclosure with untrusted queries (GHSA-g2xr-r7jg-2v33)
Only hosts that evaluate queries from untrusted parties under a `ResourcePolicy` are affected.
Every HTTP redirect is now authorized against the policy, documents included with XInclude are
read under the policy of the including document, a refusal names only the location as the query
wrote it, and a relative base URI declaration is not resolved against the working directory under
a policy. See [GHSA-g2xr-r7jg-2v33](https://github.com/phoenixmldb/phoenixmldb-xquery/security/advisories/GHSA-g2xr-r7jg-2v33)
for the details and workarounds.
### Schemas
- **`XsdSchemaProvider` reads schemas through the shared schema layer** (PhoenixmlDb.Core). Changed
behaviour to check on upgrade:
- an `xs:include`, `xs:import` or `xs:redefine` that cannot be read fails the load (`XQST0059`);
it used to be skipped;
- a schema document with a DOCTYPE is refused;
- schema text with no base URI does not resolve a relative `schemaLocation` against the current
directory; use `AddFromString(namespace, text, baseUri)`;
- a schema that requires XSD 1.1 says so, naming the document and the constructs (#217).
- **Schemas imported by `import schema` are compiled once and shared**
(`XsdSchemaProvider.ImportCache`). Providers that import the same files share one compiled
schema set, and a changed schema file or included file is seen by the next query. A query
importing a 705 KB schema: 39.7 ms before, 1.6 ms now.
- **An atomic value keeps its schema-defined type**: a value from a cast, a constructor function
or a validated node. `t:size('8') instance of t:size` is true.
### Other changes
- A cancelled query does not start a regex or pattern-facet match (#205).
- The `xquery4` CLI writes `xmlns=""` for an element in no namespace inside a default namespace
(#105); it ships on `cli-v2.8.0`.
### API
- New: `JsonXmlConverter` (`ToXml`, `ToXmlText`) with `JsonToXmlOptions`; `XsdSchemaProvider(CompiledSchema)`,
`XsdSchemaProvider.Catalog`, `XsdSchemaProvider.ImportCache`; `ISchemaProvider.AddSchemaText` and
`ISchemaProvider.IsSchemaSimpleTypeDerivedFrom` (default implementations; custom providers
compile unchanged); `XQueryParserFacade.Parse(string, Func<string, string?>)`.
### `xquery` CLI (ships on `cli-v2.8.0`)
- Runs on **PhoenixmlDb.Xslt 2.8.0**, so `fn:transform` from a query gets the 2.8.0 engine and its
security fixes.
- Writes `xmlns=""` for an element in no namespace inside a default namespace (#105).