What one range line in package.json really allows
How far ^1.2.3 climbs is easy to misremember, because each symbol follows its own rule. Enter a single range string and it is rewritten as >= and < bounds, with whether each bound includes its edge, examples of versions allowed and excluded, and how far an update can move. A per-comparator breakdown appears as a table too.
The reading follows the semver range rules. A caret pins the leftmost non-zero digit, so ^1.2.3 stops below 2.0.0, ^0.2.3 below 0.3.0 and ^0.0.3 below 0.0.4. A tilde moves the patch only, an omitted position and x mean that whole position, and || joins intervals as a union. Prerelease versions are not included in a range by default.
This page explains one range; it does not compare two ranges for containment. Prerelease tags and hyphen ranges are rejected rather than guessed. The version actually installed depends on what is published to the registry and on your package manager resolver. Written as of October 2026.
Frequently asked questions
1.2.3 up to but not including 2.0.0. The caret pins the leftmost non-zero digit, which holds the major at 1, so it climbs to 1.9.9 but never admits 2.0.0.
A tilde moves the patch only, giving 1.2.0 up to 1.3.0. A caret pins the major, giving 1.2.0 up to 2.0.0, so it accepts minor updates as well.
An omitted position behaves like a wildcard covering that whole position. 1.2 means 1.2.0 up to 1.3.0 and 1 means 1.0.0 up to 2.0.0. 1.2.x is the same as 1.2.