xslt 2.5.1

There is a newer version of this package available.
See the version list below for details.
dotnet tool install --global xslt --version 2.5.1
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local xslt --version 2.5.1
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=xslt&version=2.5.1
                    
nuke :add-package xslt --version 2.5.1
                    

xslt

Command-line XSLT 3.0/4.0 processor for .NET. Transform XML documents from the terminal using the PhoenixmlDb XSLT engine.

Installation

dotnet tool install -g xslt

Usage

# Transform XML with a stylesheet
xslt stylesheet.xsl input.xml

# Write output to a file
xslt -o result.html report.xsl data.xml

# Start from a named template (no source needed)
xslt -it main generate.xsl

# Pass parameters
xslt -p year=2026 -p title="Report" style.xsl data.xml

# Read source from stdin
cat data.xml | xslt transform.xsl

# Show timing breakdown
xslt --timing style.xsl large-input.xml

# Validate a stylesheet without running
xslt --dry-run style.xsl

# Stream large files (lower memory)
xslt --stream style.xsl large-input.xml

Features

  • XSLT 3.0/4.0 — packages, streaming, maps/arrays, higher-order functions, JSON output
  • Multiple output methods — XML, HTML, XHTML, text, JSON, adaptive
  • Streaming — process large files without loading into memory
  • xsl:result-document — generate multiple output files in one transform
  • Parameters — pass values from the command line
  • Timing — built-in performance profiling
  • Tracing — log template matching, function calls, and built-in rules

Documentation

Full documentation at phoenixml.dev

License

Apache-2.0

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
2.8.0 0 10/9/2026
2.7.0 53 10/7/2026
2.6.0 67 10/6/2026
2.5.1 76 10/1/2026
2.4.1 99 9/28/2026
2.4.0 70 9/28/2026
2.2.0 348 9/25/2026
2.1.0 78 9/17/2026
2.0.0 81 9/15/2026
1.8.0 70 9/14/2026
1.7.0 79 9/11/2026
1.6.15 84 9/9/2026
1.6.14 84 9/7/2026
1.6.13 97 9/2/2026
1.6.12 91 8/30/2026
1.6.11 79 8/29/2026
1.6.10 87 8/27/2026
1.6.9 257 8/26/2026
1.6.8 85 8/26/2026
1.6.7 91 8/24/2026
Loading failed

Takes **PhoenixmlDb.XQuery 2.5.1** and **PhoenixmlDb.Core 2.0.0**. There is no Xslt 2.5.0: the
Xslt version follows the XQuery it is built on, and XQuery needed a 2.5.1 patch, found by this
release's own testing, before Xslt could ship.

### Security: `ResourcePolicy` is enforced on every read, fetch and evaluation (GHSA-86rg-wxgp-9p5j)

`XsltTransformer.ResourcePolicy`, `ServerDefault` included, was not enforced on several paths. It
is now enforced on all of them, through the PhoenixmlDb.XQuery check
(`ResourcePolicy.Authorize`), and the reader opens the URI it returns.

What is checked now:

- **Reads:**
 - `xsl:source-document` (streamed or not) and the `unparsed-text` family, rooted paths
   included.
 - `fn:transform`, both the XSLT function and the XQuery-side provider. The stylesheet location
   needs import access and the source location read access, and the nested transformation runs
   under the caller's policy.
 - `xsl:import`/`xsl:include`, `xsl:import-schema` and everything a schema includes,
   `xsl:merge` sources, and parameter documents.
 - `json-doc` and `load-xquery-module`, through PhoenixmlDb.XQuery 2.5.x.
- **Load time:**
 - The stylesheet pre-fetch checks every URL before fetching, so loading a stylesheet makes no
   request the policy forbids.
 - Static expressions (`use-when`, `xsl:use-when`, static variables and parameters, shadow
   attributes) are evaluated under the policy while the stylesheet loads.
- **Evaluation:** `xsl:evaluate` honours `AllowXslEvaluate` and raises `XTDE3175` when it is off.
- **HTTP:** redirects are re-authorised at every hop.
- **Availability:** `unparsed-text-available`, `doc-available` and `stream-available` return false
 for refused resources, and a refused import reads as "not found", so neither reveals whether a
 file exists.

**With no policy configured, nothing changes.** Hosts that run untrusted stylesheets should
upgrade. Hosts that filter stylesheet text should account for shadow attributes (`_href`,
`_schema-location`), which replace the real attribute when the stylesheet is compiled.

### Fixed

- **Streaming:**
 - Grouping over attribute and text nodes (#216).
 - Streamability of calls to and bodies of streamable functions (#217).
 - Attribute-only uses of `current-group()` (#220).
 - `accumulator-after()` before the template descends is `XTSE3430` (#225).
 - A streamable accumulator's initial value must not navigate the input (#222).
- **Grouping focus:** within a declared-streamable construct, an invocation clears the current
 group and grouping key; elsewhere they are kept, as in XSLT 2.0 (XSLT 3.0 §14.2; #219, #229).
- **Accumulators:** `accumulator-before`/`-after` with no context item is `XTDE3350` (#224).
- **`system-property()` and `element-available()`** resolve prefixes in the scope where the
 function item was created.
- **Error codes:**
 - A duplicate key in a map constructor is `XTDE3365`.
 - A map or function item in the principal result is the serialization error `SENR0001` (#226).
- **Packages:**
 - A used package's private global no longer clashes with a same-named global (#227).
 - `xsl:expose` validates its names (`XTSE0020`, `XTSE3020`; #228).
- **`xsl:import-schema`:** a location is one URI, resolved against its own module.
- **Schemas referencing `xml:id`** import reliably on every runtime (through XQuery 2.5.1).

### Behaviour changes

- An accumulator not applicable to the principal source tree is `XTDE3362` (#213).
- The `unparsed-text` family resolves against the calling module and raises `FOUT1170` (#195).

### Conformance

W3C XSLT 3.0: **275 failing at the start of this cycle → 216 at 2.5.1.** Five cases that expect
one implementation-dependent order of distinct trees are recorded in BUGS.md #118, not changed.