xslt 2.7.0

There is a newer version of this package available.
See the version list below for details.
dotnet tool install --global xslt --version 2.7.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local xslt --version 2.7.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=xslt&version=2.7.0
                    
nuke :add-package xslt --version 2.7.0
                    

xslt

Command-line XSLT 3.0/4.0 processor for .NET. Transform XML documents from the terminal using the PhoenixmlDb XSLT engine.

Installation

dotnet tool install -g xslt

Usage

# Transform XML with a stylesheet
xslt stylesheet.xsl input.xml

# Write output to a file
xslt -o result.html report.xsl data.xml

# Start from a named template (no source needed)
xslt -it main generate.xsl

# Pass parameters
xslt -p year=2026 -p title="Report" style.xsl data.xml

# Read source from stdin
cat data.xml | xslt transform.xsl

# Show timing breakdown
xslt --timing style.xsl large-input.xml

# Validate a stylesheet without running
xslt --dry-run style.xsl

# Stream large files (lower memory)
xslt --stream style.xsl large-input.xml

Features

  • XSLT 3.0/4.0 — packages, streaming, maps/arrays, higher-order functions, JSON output
  • Multiple output methods — XML, HTML, XHTML, text, JSON, adaptive
  • Streaming — process large files without loading into memory
  • xsl:result-document — generate multiple output files in one transform
  • Parameters — pass values from the command line
  • Timing — built-in performance profiling
  • Tracing — log template matching, function calls, and built-in rules

Documentation

Full documentation at phoenixml.dev

License

Apache-2.0

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
2.8.0 0 10/9/2026
2.7.0 53 10/7/2026
2.6.0 67 10/6/2026
2.5.1 76 10/1/2026
2.4.1 99 9/28/2026
2.4.0 70 9/28/2026
2.2.0 348 9/25/2026
2.1.0 78 9/17/2026
2.0.0 81 9/15/2026
1.8.0 70 9/14/2026
1.7.0 79 9/11/2026
1.6.15 84 9/9/2026
1.6.14 84 9/7/2026
1.6.13 97 9/2/2026
1.6.12 91 8/30/2026
1.6.11 79 8/29/2026
1.6.10 87 8/27/2026
1.6.9 257 8/26/2026
1.6.8 85 8/26/2026
1.6.7 91 8/24/2026
Loading failed

Requires PhoenixmlDb.XQuery 2.7.0 and PhoenixmlDb.Core 2.2.0. W3C XSLT 3.0: 131 failing, unchanged.

### Security: limits and resource policy with untrusted stylesheets (GHSA-xxjq-rwpx-m5ww)

Only hosts that run stylesheets from untrusted parties are affected.

- `RegexMatchTimeout` and the cancellation token now reach static expressions (`use-when`,
 static variables and parameters, shadow attributes), a nested `fn:transform`, and
 `fn:transform` called from a query. A timeout or cancellation is never swallowed.
- `RegexMatchTimeout` bounds XSD `pattern` facets in imported schemas and in validation.
- A text load that the host's resolver or the policy refuses ends with `FOUT1170`. It was read
 anyway.
- New `IResourceResolver.ResolveContent` support: a host can supply the content of imports,
 includes, source documents and text itself. Imports ask the host even with no base URI.

Not fixed: when the host neither refuses a location nor supplies its content, the file can be
replaced between the check and the open.

### Fixed

- **A string returned through `fn:transform` is not parsed as XML (#314).** With
 `delivery-format='raw'`, a string result that held markup was parsed into nodes: the text of
 an XML file read with `unparsed-text()` came back as two whitespace items, and
 `'<a>hello</a>'` as an element. A regression in 2.4.0; XSpec suites run with
 `run-as="external"` hit it. Constructed result trees still come back as nodes.
- **`unparsed-text-available` answers false for an encoding the runtime refuses** (`utf-7`)
 where it threw, and content a named encoding rejects is `FOUT1190`.
- **DocBook xslTNG image sizing**: `width`/`height` and the viewport wrapper now match xslTNG's
 expected output (`duck-small.002`, `stamp.002`).

### New

- **Synchronous `LoadStylesheet` and `Transform` overloads**, for desktop and plugin hosts that
 must stay on their own thread (#309). The async methods are unchanged: after `await`, a host
 with no `SynchronizationContext` resumes on a thread-pool thread, and the methods' remarks
 now say so.

### From PhoenixmlDb.XQuery 2.7.0

Schema-aware typing, `fn:idref` on schema-typed nodes and the changed error codes listed in
the XQuery 2.7.0 notes apply to XPath in stylesheets.