Semver Range Checker (npm, Composer)
Check which versions a dependency range accepts, in npm or Composer syntax. See the range desugared into plain comparators, the highest match and why each version passes or fails; sort versions by SemVer precedence and work out the next major, minor, patch or pre-release.
How to Use
- Pick npm (package.json) or Composer (composer.json) — the same range can mean different things in each.
- Type a range such as
^1.2.3,~1.2or1.2 - 2.3 || >=3.1.0 <3.2.0. - List the versions to test, one per line. Each one is marked as a match or not, with the comparator it failed.
- Read the comparator set under the results: that is the range with every
^,~,xand hyphen replaced by plain>=and<bounds. - Switch to Sort to order a list by precedence, or Bump to get the next major, minor, patch and pre-release of a version.
Worked Example
A package.json lists "^1.2.3", and the registry has 1.2.2, 1.2.3, 1.9.0, 1.3.0-beta.1, 2.0.0-beta.1 and 2.0.0.
First desugar the caret. The major is 1, so anything up to the next major is allowed: ^1.2.3 → >=1.2.3 <2.0.0-0. Then test each version against both bounds:
- 1.2.2 fails
>=1.2.3. - 1.2.3 and 1.9.0 pass both bounds — matches.
- 2.0.0-beta.1 and 2.0.0 fail
<2.0.0-0; the-0is what keeps 2.0.0’s pre-releases out. - 1.3.0-beta.1 is inside the bounds, but it is a pre-release and no comparator names a pre-release of 1.3.0, so it is refused.
Result: 2 of 6 match, and the highest match — what npm install would pick — is 1.9.0.
The common mistake: assuming ~1.2 means the same in composer.json as in package.json. npm reads it as >=1.2.0 <1.3.0-0, so of 1.1.9, 1.2.0, 1.2.9, 1.5.0, 1.9.9 and 2.0.0 only 1.2.0 and 1.2.9 match. Composer reads it as >=1.2 <2.0.0, so 1.2.0, 1.2.9, 1.5.0 and 1.9.9 all match. Write ~1.2.0 in Composer if you want patch updates only.
Show Work
Range Syntax Reference
Where Semantic Versioning Came From
Tom Preston-Werner, a co-founder of GitHub, wrote the Semantic Versioning specification to give version numbers an agreed meaning: MAJOR changes break compatibility, MINOR adds features without breaking anything, PATCH only fixes bugs. Version 2.0.0 of the specification, published in 2013, is the one in use today. It defines the pre-release and build-metadata suffixes and the precedence rules this tool applies.
The specification only says how versions compare; it says nothing about ranges. Each package manager invented its own range language on top. npm’s comes from the node-semver library, written by npm’s creator Isaac Z. Schlueter, and Composer, created by Nils Adermann and Jordi Boggiano for PHP, adopted the same symbols with some different meanings — which is why ~1.2 resolves differently in the two.
About This Tool
This tool parses SemVer 2.0.0 versions, including pre-release and build metadata, and tests them against npm ranges (caret, tilde, x-ranges, hyphen ranges, || and the pre-release rule, with an includePrerelease switch) or Composer constraints (caret, tilde, wildcards, hyphen ranges, comma and space AND, ||, !=, stability flags and minimum stability). It also sorts versions by precedence and works out npm-style bumps.
Show Work lists each part of the range, the rule used to desugar it and the comparator it became, then every version with the bound it passed or failed. Versions that are not valid SemVer are flagged with the reason, such as a leading zero. Everything runs in your browser; nothing is sent anywhere.
Related tools: JSON Formatter, Regex Tester, and .gitignore Generator.
Frequently Asked Questions
What is the difference between ^ and ~ in package.json?
The caret allows every update that keeps the first non-zero number: ^1.2.3 is >=1.2.3 <2.0.0-0. The tilde allows patch updates only: ~1.2.3 is >=1.2.3 <1.3.0-0. Below 1.0.0 the caret tightens: ^0.2.3 stops before 0.3.0 and ^0.0.3 accepts only 0.0.3 and its pre-releases.
Why does ^1.2.3 not match 1.3.0-beta.1?
npm keeps pre-releases out of ranges unless you ask for them. 1.3.0-beta.1 is inside the bounds >=1.2.3 <2.0.0-0, but a pre-release only matches when one of the range’s own comparators names a pre-release of the same 1.3.0. >=1.3.0-beta.1 would accept it, and so would the includePrerelease option.
Does ~1.2 mean the same in Composer as in npm?
No. In npm ~1.2 is >=1.2.0 <1.3.0-0, so 1.9.9 is refused. Composer’s tilde lets the last number you wrote rise and fixes the one before it, so ~1.2 is >=1.2 <2.0.0 and 1.9.9 is accepted. With three numbers they agree: ~1.2.3 is >=1.2.3 <1.3.0 in both.
How are pre-release versions ordered?
By the SemVer 2.0.0 rules: 1.0.0-alpha < 1.0.0-alpha.1 < 1.0.0-alpha.beta < 1.0.0-beta < 1.0.0-beta.2 < 1.0.0-beta.11 < 1.0.0-rc.1 < 1.0.0. Numeric identifiers compare as numbers (2 before 11), a numeric identifier ranks below a word, and when all shared identifiers are equal the shorter list comes first.
What does the -0 in <2.0.0-0 mean?
2.0.0-0 is the lowest possible version with major 2, because 0 is the smallest pre-release identifier. Writing the upper bound as <2.0.0-0 rather than <2.0.0 shuts out 2.0.0-alpha and 2.0.0-rc.1 as well as 2.0.0. Build metadata such as +build.5 plays no part in any comparison.
How do I use the Semver Range Checker (npm, Composer)?
Simply type your numbers and read the result, which refreshes the instant you change something. There is nothing to submit and nothing to wait for.
Does it cost anything or need an account?
No. The tool is completely free, there is no account to create, and it keeps working offline after the page first loads.
Is anything I type uploaded?
No. The tool works entirely on your device, so the values you enter never leave your browser.
Common Use Cases
Auditing a dependency range
Paste the published versions of a package and see which ones ^4.17.0 lets in before you run an install: 4.17.21 yes, 5.0.0 no.
Moving a project to Composer
Check that a constraint copied from package.json still means what you think: ~1.2 accepts 1.9.9 in Composer but not in npm.
Release candidates
Bump 1.2.4-beta.1 with the identifier rc to get 1.2.4-rc.0, then a patch bump turns 1.2.4-rc.0 into the 1.2.4 release.
Sorting git tags
Sort tags like v1.10.0, v1.9.0 and v1.10.0-rc.1 by precedence, not alphabetically: 1.9.0, then 1.10.0-rc.1, then 1.10.0.
Explaining a failed install
When a resolver says no version satisfies a range, the desugared comparators and the failed bound for each version show exactly why.
Last updated: